Firewalls and antivirus can't stop an employee from clicking a convincing email. Human Risk Management measures, trains, and continuously reduces the risk your people carry — powered by uSecure and fully managed by CSP.
Attackers stopped breaking in years ago — they log in, or they simply ask. A convincing invoice, a spoofed vendor email, a password reused on a site that got breached: these bypass every technical control you own because a legitimate user let them through. Human Risk Management treats that risk the way you already treat patching and backups — as something you measure, work on continuously, and can prove is improving.
CSP's Human Risk Management service is built on uSecure — a platform used by more than 15,000 organizations and 2,000 managed service providers across 30+ countries. Rather than a once-a-year training video everyone clicks through, uSecure runs a continuous program: it finds each employee's specific knowledge gaps, feeds them short lessons that close those gaps, tests them with realistic phishing simulations, tracks policy sign-off, and watches the dark web for their leaked credentials.
Every one of those signals rolls up into a single Human Risk Score — per person, per department, and per organization — so you can see exactly where your exposure sits and watch it drop month over month. CSP configures the whole program, keeps it running, and delivers the reporting.
Human Risk Management runs year-round in the background. Each stage feeds the next, and the whole loop repeats — so risk keeps going down instead of resetting every January.
Every user takes a short gap analysis — 36 questions across 12 security areas, about 15 minutes — revealing exactly what each person does and doesn't know.
AutoEnrol turns those gaps into a personalized course path — short monthly lessons that start with each user's weakest area, not generic content everyone skips.
Realistic phishing simulations land in real inboxes on an automated schedule. Anyone who clicks gets coached on the spot — not reprimanded later.
Training, simulation, policy, and breach data combine into one Human Risk Score per user and per department — which then drives the next round of training.
The cycle repeats continuously — measured risk from stage 4 reshapes the training in stage 2.
Short, interactive courses covering phishing, passwords, social engineering, remote work, data handling, and more — delivered a few minutes at a time rather than in one exhausting annual session. AutoEnrol assigns each user their weakest topics first, refreshes monthly, and handles all the reminder nudges. Content is available in 15+ languages, and CSP can load your own custom courses.
Over 400 templates modeled on live attack trends — brand impersonation, spoofed domains, and internal impersonation of your own executives. AutoPhish schedules campaigns automatically so testing never lapses, and message injection delivers simulations straight to the inbox for realistic results. Users who click are enrolled in targeted micro-training immediately.
Upload your existing policy PDFs or build them from templates, then push them to the right users or groups with a required eSign acknowledgement. Version control, automatic re-sign schedules, and new-hire auto-issue mean policies stay current, and real-time Pending / Visited / Signed status gives you an exportable audit trail when a regulator or insurer asks.
Weekly automated scans across dark web forums, paste sites, and breach marketplaces flag the moment one of your users' credentials appears in a leak. Alerts go to CSP and to you, redacted data snippets show what was exposed, and domain-wide monitoring covers every address on your domain — so you can force a reset before the password is used against you.
The intelligence layer that ties it all together. uHealth scores every user across four dimensions — awareness, credential hygiene, access and privilege, and target value — then ranks them Critical to Low. It surfaces the toxic combinations that actually cause breaches, like a leaked password on a privileged account with MFA disabled, and puts them at the top of the fix list. uHealth draws its identity, access and password-hygiene signals from Microsoft 365 or Google Workspace. Organizations on other mail platforms receive the training, simulation, policy and dark web modules in full.
Scheduled reports show training completion, phishing click and report rates, policy sign-off status, breach exposures, and the trend line on your Human Risk Score. It is the documentation cyber insurers and auditors ask for — proof that a real, ongoing security awareness program exists, with names, dates, and results attached.
Human Risk Management only works if someone actually runs it. That is the part CSP takes off your plate — you get the results and the reporting, not another console to log into.
CSP syncs your users from Microsoft 365 or Google Workspace — no software to install — then runs the initial gap analysis, an unannounced baseline phishing simulation, and a first dark web sweep of your domain. Within days you have a real number for where your organization actually stands.
We configure AutoEnrol training paths, set the AutoPhish simulation schedule, load and distribute your security policies for eSign, and turn on continuous breach monitoring. From that point the program runs itself — your team just gets a short lesson now and then.
CSP reviews the results, follows up on high-risk users, responds to credential exposures, and delivers reporting you can hand to your board, your auditor, or your insurance carrier. Each cycle the training retargets whatever the data says is still weak.
A fully managed human risk program — configured, automated, monitored, and reported on by CSP.
Cyber insurance applications and compliance audits increasingly ask one question directly: do you run ongoing security awareness training and phishing testing? Human Risk Management answers it with evidence — and closes the single largest gap in most Fresno-area businesses' security posture, for a few dollars per user per month.
Schedule a Free Risk Assessment (559) 251-7767Per-user flat-rate pricing · No agent to install · Local Fresno support
It arrives as a PDF from your largest customer, or from the compliance platform they use to vet their vendors, and somewhere in the middle of it are two questions. There is no partial credit on either one. You either have a documented program with completion records, or you put “no” in writing to the client you least want to say no to.
Law firms get them from corporate clients. Medical practices get them attached to business associate agreements. Suppliers, contractors and service providers get them from any customer large enough to run a vendor risk program. The wording changes; the two questions don’t.
“Does your company perform training on security awareness for all employees at least annually?”
“Does your company conduct social engineering and phishing simulations?”
Cyber insurance applications ask the same two. So do HIPAA business associate reviews, and the vendor risk assessments issued under the FTC Safeguards Rule.
A managed program answers both — and produces the completion reports, simulation results and policy attestation records to back the answer up when the client asks for evidence.
Every organization with employees, contractors, or volunteers carries human risk. These face the steepest consequences when it goes unmanaged.
HIPAA requires documented workforce security awareness training — uPolicy and uLearn produce the records to prove it
Wire fraud and business email compromise target the people who move money — simulations train them on the exact scenarios attackers use
Public entities are heavily targeted and heavily audited — an ongoing program with exportable evidence satisfies both
New hires arrive untrained and unaware of your policies — auto-enrollment onboards them into training and policy sign-off on day one
Growers, packers and processors run lean back offices with seasonal staff and payments large enough to be worth stealing. Business email compromise targets exactly that profile
Rotating boards, shared inboxes and volunteer officers. Member data and dues payments are attractive, and constant turnover means training has to run continuously rather than once a year
Human Risk Management reduces how often someone falls for an attack. Two-Factor Authentication makes a stolen password useless when they do, and the Email Spam Filter keeps most of the attempts from reaching the inbox at all. Layered together, they cover the human attack path end to end — all managed by CSP under one agreement.
CSP will run a no-obligation baseline — a phishing simulation and a dark web scan of your domain — and show you exactly what your human risk looks like today.