Completed Computing & AI Engineering

Machine Learning based Cybersecurity Human Risk Management (CHRM) platform

In plain English

AI plain-English summary

Most cybersecurity training treats all employees as identical, asking them to guess answers to test questions rather than measuring their actual behaviour. OutThink’s platform changes this by using machine learning, natural language processing, and software telemetry to analyse how individuals behave during training and in daily security tasks. The problem is that current Security Awareness Training has limited impact because it cannot identify specific human risk factors or target improvements. By understanding each person’s attitudes and behaviours, OutThink aims to deliver tailored training that turns employees into a defence against cybercrime rather than a vulnerability. If successful, the platform could save organisations an estimated €2.8 billion per year globally. This matters because human error remains a major cause of security breaches in businesses, public services, and critical infrastructure. The research is applied and commercially focused, with a clear practical goal: to reduce cyber risk by adapting training to the individual, not the average.

View original technical description
Security Awareness Training (SAT) has limited impact in reducing cybercrime, because it neglects the fact that every user is different. The current approach to targeting SAT is to ask explicit knowledge test questions and rely on users’ answers (often pure guesses), rather than analysing/measuring actual behaviour during training. This means SAT providers cannot identify specific human risk factors and allow targeted improvement actions. OutThink is different: it is the first Cybersecurity Human Risk Management (CHRM) platform. We use Machine Learning (ML), Natural Language processing (NLP), applied psychology, software telemetry, and future security system integrations (a key part of our project) to identify individuals’ attitudes/behaviours – both during training and daily security behaviours – and understand/measure individual human risk. Effective, targeted training will make humans part of the solution, not the problem, saving organisations €2.8 bn p.a. globally.

View the original record at the funder ↗

Related Research

Grants with similar aims, by meaning.

THREAT-ARREST Cyber Security Threats and Threat Actors Training - Assurance Driven Multi-Layer, end-to-end Simulation and Training
DISSIPATE - Dynamic Intelligent Spear-phishing Simulation for Improved Protection against cyber-ATacks
Reimagining Security Awareness Training
CHAI: Cyber Hygiene in AI enabled domestic life
Cyber Graph-to-Text: AI automation for Threat Intelligence, made accessible to all

Original classification

EU-Funded

Plain English summaries and category classifications on this site are generated by AI and may not perfectly reflect the original research.