Human cyber risk has a measurement problem.
Security teams have more workforce data than they did a decade ago. Learning platforms generate completion rates, assessments and competency data. Phishing simulations produce click, report and response data. Identity systems, email security, DLP, SIEM, collaboration platforms and other enterprise systems generate events every day.
The problem is no longer simply getting a number.
It is working out which numbers matter, what they mean when connected, when they become a meaningful signal, and what the organization should do next.
That is the measurement shift Human Risk Management needs to make.
Cybersecurity has already gone through much of this evolution on the technical side. Better telemetry, APIs and interconnected systems dramatically improved visibility. Security also moved strategically from simply hardening infrastructure and responding to incidents toward continuously managing risk.
Human Risk Management is now going through a similar shift.
Human cyber risk measurement needs a data foundation that helps organizations observe risk, recognize patterns, understand context, establish meaningful thresholds and measure change over time.
That does not mean inventing hundreds of new Human Risk Management metrics.
It means building measurements that are fit for purpose, grounded in real evidence and relevant to the risk environment of the organization using them.
Human cyber risk is measured by combining relevant evidence about how people understand, experience and respond to cybersecurity risk.
Depending on the organization, that evidence can include:
The individual measurements are not the end goal.
They become more useful when an organization can connect them into signals, patterns and risk conditions, interpret them against real organizational context, and determine when action is needed.
The goal is to understand:
What is happening? Where does it matter? What may be driving it? What should we do? Did anything change afterward?
That is the data foundation of modern Human Risk Management.
A phishing click rate is generally the percentage of employees exposed to a simulated phishing message who click a link, open an attachment or perform another defined action.
It is useful data.
It tells you something happened.
It can help identify patterns across campaigns, reveal populations that warrant further investigation and provide evidence about how employees respond to specific forms of social engineering.
But a click is an event.
It is not a complete diagnosis of someone's cyber risk.
Two employees can click exactly the same simulated phishing message for completely different reasons.
One may not recognize the threat.
Another may be distracted.
Someone may respond because the message appears to come from a senior leader.
Someone working under heavy operational pressure may notice something suspicious but decide that finishing the task is more important.
Another person may click, immediately recognize the mistake and report it.
Those events should not automatically be interpreted in the same way.
This is why managed phishing and social-engineering testing works best when it sits inside a broader Human Risk Management program.
Phishing data is valuable evidence.
The problem starts when one source of evidence becomes the entire definition of human risk.
Our article Why Measuring Human Risk Success Is So Hard—and How HRM Solves It explores why phishing click rates can become misleading when they are separated from behavior, psychology, culture and context.
A security awareness training completion rate measures how many assigned employees completed a required learning activity.
Again: useful.
If 10,000 employees were assigned mandatory cybersecurity learning and only 6,000 completed it, the security team has an operational issue worth knowing about.
Completion rates are useful for:
What completion does not tell you is whether somebody:
A completed course demonstrates that an activity occurred.
It is not, by itself, evidence that human cyber risk decreased.
We have been arguing for years that security programs need to look beyond the security metrics they traditionally collect, because activity metrics provide only a small part of the information required to understand whether a program is actually working.
Moving beyond completion rates does not make learning less important.
It makes the data generated through learning more useful.
A well-designed continuous learning program can create repeated evidence about areas such as:
Cybermaniacs' Cyber Learning Experience (CLX) is built around continuous learning rather than a once-a-year training event.
That matters for Human Risk Management because longitudinal evidence is much more useful than a single annual snapshot.
A completion record might tell you:
Kate completed cybersecurity training in February.
Repeated measurement can start to tell you:
This population understands the topic but lacks confidence applying it.
Competency improved after an intervention but reporting behavior did not.
One workforce group is consistently struggling with a particular risk area.
Now the learning system is contributing to Human Risk Management rather than simply recording compliance.
Because knowing and doing are different human processes.
An employee can know that passwords should not be shared and still share one.
They can identify a phishing technique correctly in a quiz and miss it when an urgent message arrives during a busy afternoon.
They can understand a policy perfectly and still use a workaround because the approved process prevents them from getting their work done.
They can know they should question an unusual request but hesitate because the request appears to come from somebody significantly more senior.
Knowledge matters.
But behavior can also be influenced by:
This is why Human Risk Management needs a wider evidence base than knowledge testing alone.
The Behavioral Foundations of Effective Human Risk Management looks more closely at how psychology, behavior, habit, cognitive bias and organizational context influence security decisions.
Knowledge is an important piece of the picture.
It should not automatically be treated as a proxy for risk.
A human risk score is a value used to summarize selected indicators of workforce-related cyber risk for an individual, group or organization.
The idea can be useful.
The methodology underneath it matters much more than the label.
A score could be based on two variables.
It could be based on twenty.
Those variables could be equally weighted, manually weighted, statistically related, connected to observed outcomes or adjusted according to organizational context.
Two Human Risk Management platforms can therefore both offer something called a human risk score while measuring fundamentally different things.
That means enterprise security teams should always ask:
What is actually underneath this score?
Where did the data come from?
What does it represent?
How current is it?
How was it weighted or interpreted?
Why did the score change?
Did actual risk change, or did somebody simply generate another platform event?
Can the system explain why an employee or population has been classified as higher risk?
And most importantly:
Does the score help us make a better decision?
Human Risk Management needs to move from:
data → score → dashboard
toward:
data → signal → interpretation → decision → intervention → evidence of change
That is a very different measurement model.
This is where Human Risk Management starts to look much more like the rest of modern cybersecurity.
Cybersecurity's ability to manage technical risk improved dramatically as organizations gained:
At the same time, security strategy matured.
The goal stopped being simply:
Harden everything. Wait for something bad to happen. Respond.
Modern cyber risk management depends on visibility and observability.
You need to understand the environment.
You need to identify patterns.
You need enough evidence to determine when something becomes meaningful.
You need thresholds for action.
You need analysis and interpretation.
Human Risk Management needs the same kind of foundation.
For years, the human side of cybersecurity worked from an extraordinarily small data set:
Did they train?
Did they click?
Now we can do much more.
Cyber Risk Quantification for Human Risk: It's Time explores why human and technical evidence increasingly need to become part of the same risk conversation.
The opportunity is not to collect every available employee data point.
It is to build enough relevant, governed and meaningful evidence to understand workforce-related cyber risk.
One useful way to think about the next generation of Human Risk Management measurement is as a progression.
Something happened.
An employee completed learning.
A simulated phishing message was reported.
A policy-related event occurred.
An employee repeatedly ignored a security warning.
A competency assessment identified a gap.
A security system generated an event involving a workforce member.
An event is evidence.
It does not automatically mean there is material risk.
A metric measures or summarizes something.
Completion rate.
Reporting rate.
Assessment score.
Frequency.
Time to report.
Percentage of a workforce population demonstrating a particular behavior.
Metrics make events observable.
A signal is evidence that may indicate a condition worth paying attention to.
One phishing failure may be an event.
Repeated failures across relevant simulations, combined with weak reporting behavior or other evidence, may become a stronger signal.
Patterns emerge when evidence repeats, clusters or relates across time, populations or systems.
Perhaps a particular role repeatedly demonstrates weak verification behavior.
Perhaps one business unit has strong cybersecurity knowledge but consistently poor reporting confidence.
Perhaps risky behaviors increase during predictable periods of operational pressure.
Perhaps several individually weak signals appear together in one workforce population.
How to Map Human Risk in Your Organization Like a Threat Network explores this idea of looking for relationships across people, behavior, friction, culture and organizational context rather than treating human-risk events in isolation.
Patterns begin to tell a story.
Signals and patterns become much more useful when interpreted against factors such as:
Now the security team may have a risk condition worth managing.
Something happens because of the evidence.
Learning.
Testing.
Communications.
A manager conversation.
Process change.
Additional controls.
A deeper assessment.
Then we measure again.
Did anything actually change?
That loop —
event → metric → signal → pattern → risk condition → intervention → outcome
— is much closer to Human Risk Management than simply collecting a larger number of KPIs.
This distinction matters.
Modern enterprises can potentially collect an enormous amount of information about their workforce.
That does not mean they should.
Human Risk Management data needs to be:
There is no prize for creating the world's largest employee telemetry lake.
The objective is to identify the sources that provide meaningful evidence about the risks the organization actually needs to manage.
That means starting with the risk question rather than starting with whatever happens to be available through an API.
What are we trying to understand?
Then:
What evidence would help us understand it?
There is no universal list.
Depending on the organization and the risk being examined, useful evidence may come from:
The useful question is not:
Can our HRM platform integrate with this system?
It is:
What evidence could this system provide about the risk we're trying to understand?
Connecting systems is only the plumbing.
Interpreting what their data means is the harder part.
You cannot manage a risk you cannot see.
But visibility does not mean putting twelve charts on one screen.
Human-risk visibility should increasingly mean being able to observe:
This is closer to observability than conventional awareness reporting.
Technical observability is not simply a list of logs.
It is the ability to understand what is happening across a system.
Human Risk Management needs the same conceptual shift.
Culture sometimes gets pushed into the “soft stuff” bucket because it does not arrive as an event from a firewall.
That does not make it unmeasurable.
Security culture influences how people:
Useful cultural evidence can help organizations understand areas such as:
The mistake is using engagement statistics as a substitute for culture.
Our guide to Measuring Cyber Security Culture: NCSC-Aligned Metrics That Actually Work explores how culture measurement can connect perception, behavior and organizational structure instead of leaving the data in separate silos.
Cybermaniacs ASSURE also provides deeper strategic human-risk baselining and culture assessment when organizations need to understand the conditions underneath their ongoing program metrics.
People do not process security risk like deterministic systems.
Attention, confidence, emotion, cognitive load, habit, trust and bias can all influence decisions.
These factors have always mattered.
AI is making them much harder to ignore.
Employees increasingly operate in environments containing:
Security decisions are becoming increasingly cognitive:
Is this real?
Do I trust this?
Do I need to verify it?
Is the system better at this than I am?
Am I still responsible for checking?
When should I intervene?
That brings another concept into the Human Risk Management conversation: cognitive security.
In the context of Human Risk Management, cognitive security concerns the human processes involved in perceiving, interpreting, trusting and making decisions about information and digital systems.
It includes conditions that can influence judgment, including:
Traditional cybersecurity awareness often helps employees understand what threats look like.
Cognitive security increasingly asks whether people can make good security decisions when the information in front of them is convincing, personalized, generated at scale or delivered by a system they have learned to trust.
The Psychological Perimeter: Human Risk, AI, and Cyber Resilience explores this growing intersection between cognition, human behavior, AI, organizational culture and cyber risk.
Enterprise AI adoption makes the limitations of traditional awareness metrics especially obvious.
Imagine an organization deploys generative AI to 20,000 employees.
What does training completion tell you?
Perhaps everyone completed the AI course.
Good.
Leadership still needs to understand:
These are AI workforce risk questions.
And they require a richer data foundation.
Cybermaniacs AIECM focuses on the workforce side of enterprise AI adoption: readiness, competency, behavior, culture, enablement and risk.
How Do You Measure Human Risk in AI-Driven Work? looks more deeply at the signals organizations need when risk begins to emerge through trust, reliance, verification, workarounds and human-AI decision-making.
This is where Human Risk Management and AI governance increasingly meet.
There is no universal set of “best Human Risk Management metrics.”
There cannot be.
The right measures depend on:
A useful metric in one organization may be noise in another.
Human Risk Management metrics therefore need to be fit for purpose and fit for use.
They should answer an actual question.
They should have some relationship to ground truth.
They should represent something meaningful about the organization's real risk environment.
And collectively, they should tell a story somebody can act on.
The same principle applies when demonstrating business impact. How to Measure the ROI of Security Awareness and Human Risk Programs looks at why organizations need to connect behavior, readiness, response, culture and business outcomes rather than presenting leadership with another set of activity statistics.
A model is only as useful as its relationship with reality.
If the data tells you a population is “high risk,” can you validate that finding?
Does observed behavior support it?
Do security events support it?
Does culture provide relevant context?
Does qualitative evidence tell the same story?
Do the people who understand that part of the organization recognize the pattern?
Ground truth helps prevent measurement from becoming an elegant system for confidently describing something that is not actually happening.
This becomes even more important as organizations connect multiple data sources.
More sophisticated Human Risk Management analytics can improve the model.
They can also amplify bad assumptions.
So measurement needs to care about:
The ambition should not be to create the most impressive score.
It should be to create defensible evidence.
Good measurement eventually produces a narrative about risk.
Imagine a workforce population has strong cybersecurity knowledge.
But reporting confidence is low.
Culture assessment shows that people worry about looking foolish when they escalate a concern.
Reporting data confirms that the same population reports suspicious activity significantly less often than its peers.
Now you have a story.
Training score: 87% could never have told it.
More importantly, the story suggests a different intervention.
The answer probably isn't another phishing module.
Connected evidence lets the organization move from:
What happened?
to:
What does it mean?
to:
What should we do?
That is why Human Risk Management measurement needs to connect competency, behavior, culture and organizational conditions rather than treating every data source as a separate dashboard.
Not every event deserves intervention.
Not every signal is material.
Not every change is significant.
Human Risk Management therefore needs some concept of risk thresholds.
A threshold may help determine:
Those thresholds need to reflect the organization's actual risk posture.
Generic benchmarks can be useful context.
But the enterprise ultimately needs to know:
Is this condition meaningful for us?
That is the distinction between measuring human risk and actually managing it.
The future of Human Risk Management analytics is not another colorful dashboard.
Dashboards are useful.
But the real opportunity is to build a decision system capable of moving through:
visibility → observation → analysis → insight → decision → intervention → assurance
That requires a strong data foundation.
It requires connected evidence.
It requires enough context to interpret what the signals mean.
And it requires models that remain grounded in the actual human and organizational environment.
Human behavior is complicated.
That does not make it immeasurable.
It means we need to stop pretending the easiest things to count are automatically the most important things to know.
Do not begin by building a 100-metric HRM dashboard.
Start with the risk.
Choose a small number of questions the organization genuinely needs to answer.
For example:
Where are our most important workforce-related cyber risks?
Which populations are most exposed?
Do people have the competency required for the risks they face?
Are they confident enough to act when something looks wrong?
Does our security culture support reporting and challenge?
Are our interventions changing the behaviors they target?
What existing enterprise data could improve our visibility?
What emerging AI workforce behaviors do we currently have no way to see?
Then identify the evidence required to answer them.
The sequence matters:
risk question → evidence requirement → metric → signal → pattern → interpretation → intervention
Not:
available dashboard → convenient metric → invented story
Cybersecurity spent decades getting better at observing technical systems.
Human Risk Management now needs to mature the same capability across the human and organizational layer — carefully, proportionately and for a defined purpose.
The raw ingredients are increasingly available:
Better APIs.
More interconnected enterprise systems.
Better learning and competency data.
More behavioral evidence.
Better culture measurement.
More sophisticated analytics.
Security telemetry.
New AI workforce data.
The challenge is connecting those ingredients without losing the human context that makes them meaningful.
The next generation of Human Risk Management will not be defined by who creates the most scores.
It will be defined by who can turn evidence into understanding.
Grounded data. Meaningful signals. Recognizable patterns. Context-aware thresholds. Useful insights. Appropriate interventions. Measurable change.
That is how human cyber risk becomes something an enterprise can actually manage.
There is no universal set of Human Risk Management metrics. Useful measures depend on the organization's risk posture, workforce, threats, culture and objectives.
Relevant evidence may include competency, behavior, phishing performance, reporting, psychological factors, culture, role exposure, security events and intervention outcomes.
The important question is whether a metric helps the organization understand or manage a defined risk.
Yes, but they are only one source of behavioral evidence.
A phishing click records a response to a particular simulation under a particular set of conditions. Repeated patterns, reporting behavior, workforce context and other evidence can make that event more meaningful.
Click rate alone should not be treated as a complete measure of human cyber risk.
Completion rates tell you whether required learning occurred.
They do not tell you whether employees retained the material, can apply it, behave differently or work inside an environment that supports secure decisions.
Completion is an important operational and compliance metric. It is not a complete risk outcome.
A human risk score summarizes selected indicators of workforce-related cyber risk into a numerical value or category.
Its usefulness depends on the evidence, assumptions and methodology underneath it. Enterprises should understand what contributes to the score, how the evidence is interpreted and whether the system can explain why risk has changed.
A metric measures something, such as a completion rate, reporting rate or assessment result.
A signal is evidence that may indicate a risk condition worth investigating. Signals become more useful when connected with other evidence, organizational context and patterns over time.
A human-risk data foundation is the structured set of relevant evidence, data sources and measurement processes used to observe and understand workforce-related cyber risk.
It may include learning, competency, behavioral, cultural, psychological, organizational and security-system evidence.
Its purpose is to support reliable signals, patterns, risk interpretation and measurement of change.
Security culture can be assessed using structured evidence about factors such as psychological safety, leadership behavior, shared norms, attitudes toward security, confidence in reporting, organizational priorities and accepted workarounds.
Training engagement and phishing performance may contribute useful evidence, but they should not be used as substitutes for measuring culture itself.
For a deeper methodology, see Measuring Cyber Security Culture: NCSC-Aligned Metrics That Actually Work.
In a Human Risk Management context, cognitive security concerns the human processes involved in perceiving, interpreting, trusting and making decisions about information and digital systems.
It becomes particularly relevant where judgment can be influenced by deception, cognitive overload, persuasive technology, synthetic content, automation bias and AI-generated information.
AI introduces workforce behaviors involving trust, reliance, verification, data sharing, shadow AI, decision-making, automation and human oversight.
Organizations therefore need to measure more than whether employees completed AI training. They need evidence about whether people are ready and able to use AI safely, effectively and responsibly in real work.
No.
Human Risk Management metrics should align to the organization's workforce, threat environment, business model, technology, culture and risk posture.
External benchmarks can provide context, but the measures used to manage risk need to be fit for purpose and grounded in the conditions of the organization using them.