For security leaders in regulated industries, the tension between innovation and compliance is a daily reality. On one hand, the threat landscape demands faster, more adaptive approaches to human risk management. On the other, regulators demand strict adherence to established frameworks. At HRMCon 2025, a panel of security leaders including PSA BDP CISO Jon Garza, Aveva's Jacob Revord, and Trove CEO Amjed Saffarini shared how to navigate this tension and turn compliance from a limitation into a launchpad for proactive risk reduction. Request a demo of Living Security's HRM platform to see how leading organizations bridge this gap.
Regulated industries face a unique challenge in human risk management. For security leaders asking how to balance innovation with compliance, the answer starts with understanding that regulatory frameworks serve a specific purpose while innovation serves another, and both are essential to a mature risk posture. The most effective approach treats compliance as the foundation and innovation as the next layer of defense.
Healthcare organizations must comply with HIPAA. Financial services firms answer to FINRA, SEC, and state regulators. Government contractors navigate FedRAMP and NIST frameworks. Each regulatory regime imposes specific requirements for security training, access control, and incident response. These frameworks are not optional, and noncompliance carries significant financial and reputational consequences.
The tension arises because regulatory frameworks are inherently backward-looking. They codify best practices from past incidents. Meanwhile, the threat landscape is forward-moving. Attackers are using AI, social engineering, and zero-day exploits that existing regulations never anticipated. The gap between what regulators require and what security teams need to do creates friction that can slow innovation.
But the panelists at HRMCon 2025 argued that this tension is solvable. The key is understanding that compliance and innovation are not opposites. They are different tools for the same goal: reducing organizational risk. According to the Ponemon Institute and IBM, organizations take an average of 73% days to discover an insider threat incident, highlighting why both compliance frameworks and proactive innovation are necessary to close detection gaps.
Human Risk Management (HRM), as defined by Living Security, provides a framework that bridges this gap. Organizations that treat compliance as a minimum standard rather than a ceiling consistently outperform those that view regulation as a limitation. Learn more about what human risk management means for regulated enterprises.
Regulated organizations can innovate within compliance boundaries by mapping regulatory requirements to risk outcomes, using HRM data to satisfy both auditors and security teams simultaneously, and designing innovations with compliance built in from the start. This approach eliminates the false choice between satisfying regulators and reducing risk.
Here is how the panelists recommended making this shift:
Watch the full HRMCon 2025 on-demand library to hear the complete panel discussion from Jon Garza, Jacob Revord, and Amjed Saffarini.
Not all compliance requirements carry the same risk weight, and not all human risks are equally material to regulated organizations. The most effective approach prioritizes risks that create both security exposure and regulatory liability, uses predictive intelligence to identify emerging threats, and automates remediation to ensure consistency and auditability.
The panelists emphasized that workforce risk management in regulated industries requires a disciplined approach to prioritization:
Read the Forrester Wave report on Human Risk Management where Living Security was named a Leader, validating its approach to unifying compliance and risk reduction.
The most effective strategies for innovating within compliance constraints include piloting new approaches on low-risk populations first, documenting every innovation against regulatory requirements, and engaging regulators proactively rather than defensively. These strategies enable organizations to innovate confidently while maintaining full compliance.
The panelists shared specific strategies that regulated organizations can use to innovate without breaking compliance:
Explore human risk management software features designed specifically for regulated environments.
Human risk management unifies compliance and risk reduction by providing a single data platform that serves both auditors and security teams, eliminating the silos that force organizations to choose between satisfying regulators and reducing risk. This unification is the defining characteristic of mature risk programs in regulated industries.
Living Security, a leader in Human Risk Management (HRM), helps regulated organizations unify their compliance and risk reduction efforts through a single AI-native platform. By correlating three data pillars - behavior, identity and access, and threat - the platform provides the comprehensive data that powers both compliance reporting and predictive risk intelligence. This means security teams no longer need to maintain separate tools for compliance and risk reduction. The same data that demonstrates regulatory adherence also identifies emerging threats and enables targeted interventions.
The results are measurable and validated. Independent Cyentia Institute research validates that organizations using predictive human risk management achieve a 50% reduction in risky users and a 98% decrease in data-loss exposure, all while maintaining full regulatory compliance. Living Security has been named a Forrester Wave Leader in Human Risk Management Solutions, Q3 2024, confirming that its approach represents the industry standard for unifying compliance and proactive risk reduction.
For regulated organizations at the start of this journey, the path forward is clear. Begin by selecting an HRM platform that provides the data and automation capabilities needed to serve both compliance and security objectives. Integrate it with existing security tools to capture the full spectrum of risk signals. And build internal processes that treat compliance as the starting point for innovation, not the boundary that limits it.
Watch the full HRMCon 2025 on-demand library for the complete panel and additional sessions on the future of human risk management.
Yes. Leading organizations in healthcare, financial services, and government are using AI-native HRM platforms to achieve both regulatory compliance and predictive risk reduction. The key is choosing a platform designed for regulated environments that provides documentation, audit trails, and human-in-the-loop oversight.
Document each AI-driven decision, maintain human-in-the-loop oversight, and ensure that all interventions are traceable and auditable. Modern HRM platforms automatically generate the documentation and reporting needed for regulatory review, eliminating the need for manual compliance reporting.
Many regulators are increasingly open to AI-based approaches when they are well-documented, transparent, and demonstrably effective. Proactive engagement with regulators and thorough documentation are the keys to acceptance. The trend toward regulatory sandboxes and innovation offices within regulatory bodies signals growing openness to well-governed AI applications.
Compliance-driven security training focuses on meeting regulatory requirements through annual training modules and policy acknowledgments. Human risk management goes further by measuring actual risk behaviors, correlating them with identity and threat data, and enabling targeted interventions that reduce measurable risk. HRM includes compliance as a foundation but extends beyond it to proactive risk reduction.
Organizations using predictive human risk management typically see measurable improvements within the first quarter, with a 50% reduction in risky users and a 98% decrease in data-loss exposure validated by independent Cyentia Institute research. Results accelerate as the platform accumulates organizational data and refines its predictive models.