Cybermaniacs Human Risk Management Guides

How to Measure Human Cyber Risk

Written by Team CM | Aug 23, 2026, 11:15:57 AM

Human cyber risk has a measurement problem.

Security teams have more workforce data than they did a decade ago. Learning platforms generate completion rates, assessments and competency data. Phishing simulations produce click, report and response data. Identity systems, email security, DLP, SIEM, collaboration platforms and other enterprise systems generate events every day.

The problem is no longer simply getting a number.

It is working out which numbers matter, what they mean when connected, when they become a meaningful signal, and what the organization should do next.

That is the measurement shift Human Risk Management needs to make.

Cybersecurity has already gone through much of this evolution on the technical side. Better telemetry, APIs and interconnected systems dramatically improved visibility. Security also moved strategically from simply hardening infrastructure and responding to incidents toward continuously managing risk.

Human Risk Management is now going through a similar shift.

Human cyber risk measurement needs a data foundation that helps organizations observe risk, recognize patterns, understand context, establish meaningful thresholds and measure change over time.

That does not mean inventing hundreds of new Human Risk Management metrics.

It means building measurements that are fit for purpose, grounded in real evidence and relevant to the risk environment of the organization using them.

Quick Answer: How Do You Measure Human Cyber Risk?

Human cyber risk is measured by combining relevant evidence about how people understand, experience and respond to cybersecurity risk.

Depending on the organization, that evidence can include:

  • cybersecurity competency and knowledge
  • confidence and self-efficacy
  • behavioral patterns
  • phishing and social-engineering activity
  • reporting behavior
  • security events
  • policy-related events
  • role, access and exposure
  • workforce context
  • security culture
  • relevant psychological and cognitive factors
  • intervention outcomes
  • changes over time

The individual measurements are not the end goal.

They become more useful when an organization can connect them into signals, patterns and risk conditions, interpret them against real organizational context, and determine when action is needed.

The goal is to understand:

What is happening? Where does it matter? What may be driving it? What should we do? Did anything change afterward?

That is the data foundation of modern Human Risk Management.

What Is a Phishing Click Rate?

A phishing click rate is generally the percentage of employees exposed to a simulated phishing message who click a link, open an attachment or perform another defined action.

It is useful data.

It tells you something happened.

It can help identify patterns across campaigns, reveal populations that warrant further investigation and provide evidence about how employees respond to specific forms of social engineering.

But a click is an event.

It is not a complete diagnosis of someone's cyber risk.

Two employees can click exactly the same simulated phishing message for completely different reasons.

One may not recognize the threat.

Another may be distracted.

Someone may respond because the message appears to come from a senior leader.

Someone working under heavy operational pressure may notice something suspicious but decide that finishing the task is more important.

Another person may click, immediately recognize the mistake and report it.

Those events should not automatically be interpreted in the same way.

This is why managed phishing and social-engineering testing works best when it sits inside a broader Human Risk Management program.

Phishing data is valuable evidence.

The problem starts when one source of evidence becomes the entire definition of human risk.

Our article Why Measuring Human Risk Success Is So Hard—and How HRM Solves It explores why phishing click rates can become misleading when they are separated from behavior, psychology, culture and context.

What Is a Security Awareness Training Completion Rate?

A security awareness training completion rate measures how many assigned employees completed a required learning activity.

Again: useful.

If 10,000 employees were assigned mandatory cybersecurity learning and only 6,000 completed it, the security team has an operational issue worth knowing about.

Completion rates are useful for:

  • compliance
  • learning administration
  • participation monitoring
  • identifying populations that have not received required education
  • demonstrating that required training was delivered

What completion does not tell you is whether somebody:

  • understood the material
  • retained it
  • can apply it
  • feels confident acting on it
  • behaves differently afterward
  • works in an environment that supports the expected behavior
  • faces the risk the training was intended to address

A completed course demonstrates that an activity occurred.

It is not, by itself, evidence that human cyber risk decreased.

We have been arguing for years that security programs need to look beyond the security metrics they traditionally collect, because activity metrics provide only a small part of the information required to understand whether a program is actually working.

Learning Should Be Part of the Human-Risk Data Foundation

Moving beyond completion rates does not make learning less important.

It makes the data generated through learning more useful.

A well-designed continuous learning program can create repeated evidence about areas such as:

  • competency
  • knowledge
  • confidence
  • attitudes
  • behavior
  • changes over time
  • differences between workforce populations

Cybermaniacs' Cyber Learning Experience (CLX) is built around continuous learning rather than a once-a-year training event.

That matters for Human Risk Management because longitudinal evidence is much more useful than a single annual snapshot.

A completion record might tell you:

Kate completed cybersecurity training in February.

Repeated measurement can start to tell you:

This population understands the topic but lacks confidence applying it.

Competency improved after an intervention but reporting behavior did not.

One workforce group is consistently struggling with a particular risk area.

Now the learning system is contributing to Human Risk Management rather than simply recording compliance.

Why Isn't Cybersecurity Knowledge Enough?

Because knowing and doing are different human processes.

An employee can know that passwords should not be shared and still share one.

They can identify a phishing technique correctly in a quiz and miss it when an urgent message arrives during a busy afternoon.

They can understand a policy perfectly and still use a workaround because the approved process prevents them from getting their work done.

They can know they should question an unusual request but hesitate because the request appears to come from somebody significantly more senior.

Knowledge matters.

But behavior can also be influenced by:

  • confidence
  • habit
  • workload
  • cognitive load
  • attention
  • trust
  • emotion
  • incentives
  • social influence
  • leadership
  • process design
  • organizational culture

This is why Human Risk Management needs a wider evidence base than knowledge testing alone.

The Behavioral Foundations of Effective Human Risk Management looks more closely at how psychology, behavior, habit, cognitive bias and organizational context influence security decisions.

Knowledge is an important piece of the picture.

It should not automatically be treated as a proxy for risk.

What Is a Human Risk Score?

A human risk score is a value used to summarize selected indicators of workforce-related cyber risk for an individual, group or organization.

The idea can be useful.

The methodology underneath it matters much more than the label.

A score could be based on two variables.

It could be based on twenty.

Those variables could be equally weighted, manually weighted, statistically related, connected to observed outcomes or adjusted according to organizational context.

Two Human Risk Management platforms can therefore both offer something called a human risk score while measuring fundamentally different things.

That means enterprise security teams should always ask:

What is actually underneath this score?

Where did the data come from?

What does it represent?

How current is it?

How was it weighted or interpreted?

Why did the score change?

Did actual risk change, or did somebody simply generate another platform event?

Can the system explain why an employee or population has been classified as higher risk?

And most importantly:

Does the score help us make a better decision?

Human Risk Management needs to move from:

data → score → dashboard

toward:

data → signal → interpretation → decision → intervention → evidence of change

That is a very different measurement model.

Human Risk Measurement Needs a Data Foundation

This is where Human Risk Management starts to look much more like the rest of modern cybersecurity.

Cybersecurity's ability to manage technical risk improved dramatically as organizations gained:

  • better telemetry
  • interconnected systems
  • APIs
  • identity data
  • event streams
  • centralized security monitoring
  • analytics
  • risk quantification
  • better ways to correlate information across systems

At the same time, security strategy matured.

The goal stopped being simply:

Harden everything. Wait for something bad to happen. Respond.

Modern cyber risk management depends on visibility and observability.

You need to understand the environment.

You need to identify patterns.

You need enough evidence to determine when something becomes meaningful.

You need thresholds for action.

You need analysis and interpretation.

Human Risk Management needs the same kind of foundation.

For years, the human side of cybersecurity worked from an extraordinarily small data set:

Did they train?

Did they click?

Now we can do much more.

Cyber Risk Quantification for Human Risk: It's Time explores why human and technical evidence increasingly need to become part of the same risk conversation.

The opportunity is not to collect every available employee data point.

It is to build enough relevant, governed and meaningful evidence to understand workforce-related cyber risk.

From Events to Signals to Patterns to Risk

One useful way to think about the next generation of Human Risk Management measurement is as a progression.

Event

Something happened.

An employee completed learning.

A simulated phishing message was reported.

A policy-related event occurred.

An employee repeatedly ignored a security warning.

A competency assessment identified a gap.

A security system generated an event involving a workforce member.

An event is evidence.

It does not automatically mean there is material risk.

Metric

A metric measures or summarizes something.

Completion rate.

Reporting rate.

Assessment score.

Frequency.

Time to report.

Percentage of a workforce population demonstrating a particular behavior.

Metrics make events observable.

Signal

A signal is evidence that may indicate a condition worth paying attention to.

One phishing failure may be an event.

Repeated failures across relevant simulations, combined with weak reporting behavior or other evidence, may become a stronger signal.

Pattern

Patterns emerge when evidence repeats, clusters or relates across time, populations or systems.

Perhaps a particular role repeatedly demonstrates weak verification behavior.

Perhaps one business unit has strong cybersecurity knowledge but consistently poor reporting confidence.

Perhaps risky behaviors increase during predictable periods of operational pressure.

Perhaps several individually weak signals appear together in one workforce population.

How to Map Human Risk in Your Organization Like a Threat Network explores this idea of looking for relationships across people, behavior, friction, culture and organizational context rather than treating human-risk events in isolation.

Patterns begin to tell a story.

Risk Condition

Signals and patterns become much more useful when interpreted against factors such as:

  • exposure
  • organizational context
  • role
  • culture
  • historical evidence
  • risk appetite
  • business impact

Now the security team may have a risk condition worth managing.

Intervention

Something happens because of the evidence.

Learning.

Testing.

Communications.

A manager conversation.

Process change.

Additional controls.

A deeper assessment.

Outcome

Then we measure again.

Did anything actually change?

That loop —

event → metric → signal → pattern → risk condition → intervention → outcome

— is much closer to Human Risk Management than simply collecting a larger number of KPIs.

Better Human Risk Data Does Not Mean More Human Risk Data

This distinction matters.

Modern enterprises can potentially collect an enormous amount of information about their workforce.

That does not mean they should.

Human Risk Management data needs to be:

  • relevant
  • proportionate
  • explainable
  • governable
  • connected to a defined purpose

There is no prize for creating the world's largest employee telemetry lake.

The objective is to identify the sources that provide meaningful evidence about the risks the organization actually needs to manage.

That means starting with the risk question rather than starting with whatever happens to be available through an API.

What are we trying to understand?

Then:

What evidence would help us understand it?

Where Can Human-Risk Data Come From?

There is no universal list.

Depending on the organization and the risk being examined, useful evidence may come from:

  • security awareness and learning platforms
  • competency assessments
  • employee surveys
  • phishing and social-engineering simulations
  • employee reporting channels
  • email security
  • SIEM
  • UEBA
  • DLP
  • identity and access systems
  • collaboration platforms
  • policy systems
  • security incidents
  • culture assessments
  • organizational and role data
  • AI and productivity platforms

The useful question is not:

Can our HRM platform integrate with this system?

It is:

What evidence could this system provide about the risk we're trying to understand?

Connecting systems is only the plumbing.

Interpreting what their data means is the harder part.

Human Risk Visibility Is More Than a Dashboard

You cannot manage a risk you cannot see.

But visibility does not mean putting twelve charts on one screen.

Human-risk visibility should increasingly mean being able to observe:

  • individual events
  • population-level patterns
  • changes over time
  • differences between groups
  • relationships between evidence sources
  • emerging risk conditions
  • intervention outcomes
  • organizational factors that may explain what is happening

This is closer to observability than conventional awareness reporting.

Technical observability is not simply a list of logs.

It is the ability to understand what is happening across a system.

Human Risk Management needs the same conceptual shift.

Security Culture Is Part of the Data

Culture sometimes gets pushed into the “soft stuff” bucket because it does not arrive as an event from a firewall.

That does not make it unmeasurable.

Security culture influences how people:

  • report mistakes
  • challenge authority
  • respond to security friction
  • interpret policy
  • handle uncertainty
  • adopt workarounds
  • respond to leadership behavior
  • decide whether security genuinely matters

Useful cultural evidence can help organizations understand areas such as:

  • psychological safety
  • leadership behavior
  • attitudes toward security
  • shared norms
  • confidence in reporting
  • perceptions of organizational priorities
  • tolerance for workarounds
  • whether security enables or obstructs work

The mistake is using engagement statistics as a substitute for culture.

Our guide to Measuring Cyber Security Culture: NCSC-Aligned Metrics That Actually Work explores how culture measurement can connect perception, behavior and organizational structure instead of leaving the data in separate silos.

Cybermaniacs ASSURE also provides deeper strategic human-risk baselining and culture assessment when organizations need to understand the conditions underneath their ongoing program metrics.

Psychology Is Becoming a More Important Cybersecurity Data Layer

People do not process security risk like deterministic systems.

Attention, confidence, emotion, cognitive load, habit, trust and bias can all influence decisions.

These factors have always mattered.

AI is making them much harder to ignore.

Employees increasingly operate in environments containing:

  • synthetic content
  • deepfakes
  • AI-generated communications
  • conversational interfaces
  • automated recommendations
  • probabilistic outputs
  • increasingly autonomous systems

Security decisions are becoming increasingly cognitive:

Is this real?

Do I trust this?

Do I need to verify it?

Is the system better at this than I am?

Am I still responsible for checking?

When should I intervene?

That brings another concept into the Human Risk Management conversation: cognitive security.

What Is Cognitive Security?

In the context of Human Risk Management, cognitive security concerns the human processes involved in perceiving, interpreting, trusting and making decisions about information and digital systems.

It includes conditions that can influence judgment, including:

  • deception
  • urgency
  • authority
  • cognitive overload
  • misplaced trust
  • persuasive technology
  • synthetic content
  • automation bias
  • AI-generated information

Traditional cybersecurity awareness often helps employees understand what threats look like.

Cognitive security increasingly asks whether people can make good security decisions when the information in front of them is convincing, personalized, generated at scale or delivered by a system they have learned to trust.

The Psychological Perimeter: Human Risk, AI, and Cyber Resilience explores this growing intersection between cognition, human behavior, AI, organizational culture and cyber risk.

AI Workforce Risk Makes the Measurement Gap Bigger

Enterprise AI adoption makes the limitations of traditional awareness metrics especially obvious.

Imagine an organization deploys generative AI to 20,000 employees.

What does training completion tell you?

Perhaps everyone completed the AI course.

Good.

Leadership still needs to understand:

  • Are people actually using AI?
  • What are they using it for?
  • Can they identify when verification is required?
  • Are they over-relying on AI outputs?
  • Are they sharing inappropriate information?
  • Do different roles have the competency required to use AI well?
  • Where is shadow AI appearing?
  • Are approved tools being avoided?
  • Are new AI-supported workflows bypassing existing controls?
  • Is the workforce becoming more capable, or simply more dependent?

These are AI workforce risk questions.

And they require a richer data foundation.

Cybermaniacs AIECM focuses on the workforce side of enterprise AI adoption: readiness, competency, behavior, culture, enablement and risk.

How Do You Measure Human Risk in AI-Driven Work? looks more deeply at the signals organizations need when risk begins to emerge through trust, reliance, verification, workarounds and human-AI decision-making.

This is where Human Risk Management and AI governance increasingly meet.

Human Risk Metrics Must Be Fit for Purpose

There is no universal set of “best Human Risk Management metrics.”

There cannot be.

The right measures depend on:

  • your threat environment
  • your workforce
  • your organizational structure
  • your technology
  • your business model
  • your risk appetite
  • your culture
  • your existing program maturity
  • the behaviors you are trying to influence
  • the outcomes you are trying to understand

A useful metric in one organization may be noise in another.

Human Risk Management metrics therefore need to be fit for purpose and fit for use.

They should answer an actual question.

They should have some relationship to ground truth.

They should represent something meaningful about the organization's real risk environment.

And collectively, they should tell a story somebody can act on.

The same principle applies when demonstrating business impact. How to Measure the ROI of Security Awareness and Human Risk Programs looks at why organizations need to connect behavior, readiness, response, culture and business outcomes rather than presenting leadership with another set of activity statistics.

Ground Truth Matters

A model is only as useful as its relationship with reality.

If the data tells you a population is “high risk,” can you validate that finding?

Does observed behavior support it?

Do security events support it?

Does culture provide relevant context?

Does qualitative evidence tell the same story?

Do the people who understand that part of the organization recognize the pattern?

Ground truth helps prevent measurement from becoming an elegant system for confidently describing something that is not actually happening.

This becomes even more important as organizations connect multiple data sources.

More sophisticated Human Risk Management analytics can improve the model.

They can also amplify bad assumptions.

So measurement needs to care about:

  • source quality
  • provenance
  • context
  • confidence
  • validation
  • conflicting evidence
  • changes over time

The ambition should not be to create the most impressive score.

It should be to create defensible evidence.

Human Risk Metrics Should Tell a Story

Good measurement eventually produces a narrative about risk.

Imagine a workforce population has strong cybersecurity knowledge.

But reporting confidence is low.

Culture assessment shows that people worry about looking foolish when they escalate a concern.

Reporting data confirms that the same population reports suspicious activity significantly less often than its peers.

Now you have a story.

Training score: 87% could never have told it.

More importantly, the story suggests a different intervention.

The answer probably isn't another phishing module.

Connected evidence lets the organization move from:

What happened?

to:

What does it mean?

to:

What should we do?

That is why Human Risk Management measurement needs to connect competency, behavior, culture and organizational conditions rather than treating every data source as a separate dashboard.

Risk Thresholds Turn Measurement Into Management

Not every event deserves intervention.

Not every signal is material.

Not every change is significant.

Human Risk Management therefore needs some concept of risk thresholds.

A threshold may help determine:

  • when a pattern warrants investigation
  • when a workforce population needs intervention
  • when several weak signals become meaningful together
  • when risk exceeds organizational tolerance
  • when enough improvement has occurred to change the treatment plan

Those thresholds need to reflect the organization's actual risk posture.

Generic benchmarks can be useful context.

But the enterprise ultimately needs to know:

Is this condition meaningful for us?

That is the distinction between measuring human risk and actually managing it.

Human Risk Analytics Should Connect the Dots

The future of Human Risk Management analytics is not another colorful dashboard.

Dashboards are useful.

But the real opportunity is to build a decision system capable of moving through:

visibility → observation → analysis → insight → decision → intervention → assurance

That requires a strong data foundation.

It requires connected evidence.

It requires enough context to interpret what the signals mean.

And it requires models that remain grounded in the actual human and organizational environment.

Human behavior is complicated.

That does not make it immeasurable.

It means we need to stop pretending the easiest things to count are automatically the most important things to know.

What Human Risk Metrics Should You Measure First?

Do not begin by building a 100-metric HRM dashboard.

Start with the risk.

Choose a small number of questions the organization genuinely needs to answer.

For example:

Where are our most important workforce-related cyber risks?

Which populations are most exposed?

Do people have the competency required for the risks they face?

Are they confident enough to act when something looks wrong?

Does our security culture support reporting and challenge?

Are our interventions changing the behaviors they target?

What existing enterprise data could improve our visibility?

What emerging AI workforce behaviors do we currently have no way to see?

Then identify the evidence required to answer them.

The sequence matters:

risk question → evidence requirement → metric → signal → pattern → interpretation → intervention

Not:

available dashboard → convenient metric → invented story

Human Risk Measurement Is Going Through a Paradigm Shift

Cybersecurity spent decades getting better at observing technical systems.

Human Risk Management now needs to mature the same capability across the human and organizational layer — carefully, proportionately and for a defined purpose.

The raw ingredients are increasingly available:

Better APIs.

More interconnected enterprise systems.

Better learning and competency data.

More behavioral evidence.

Better culture measurement.

More sophisticated analytics.

Security telemetry.

New AI workforce data.

The challenge is connecting those ingredients without losing the human context that makes them meaningful.

The next generation of Human Risk Management will not be defined by who creates the most scores.

It will be defined by who can turn evidence into understanding.

Grounded data. Meaningful signals. Recognizable patterns. Context-aware thresholds. Useful insights. Appropriate interventions. Measurable change.

That is how human cyber risk becomes something an enterprise can actually manage.

Frequently Asked Questions

What are the most important Human Risk Management metrics?

There is no universal set of Human Risk Management metrics. Useful measures depend on the organization's risk posture, workforce, threats, culture and objectives.

Relevant evidence may include competency, behavior, phishing performance, reporting, psychological factors, culture, role exposure, security events and intervention outcomes.

The important question is whether a metric helps the organization understand or manage a defined risk.

Are phishing click rates useful for measuring human risk?

Yes, but they are only one source of behavioral evidence.

A phishing click records a response to a particular simulation under a particular set of conditions. Repeated patterns, reporting behavior, workforce context and other evidence can make that event more meaningful.

Click rate alone should not be treated as a complete measure of human cyber risk.

Why aren't security awareness training completion rates enough?

Completion rates tell you whether required learning occurred.

They do not tell you whether employees retained the material, can apply it, behave differently or work inside an environment that supports secure decisions.

Completion is an important operational and compliance metric. It is not a complete risk outcome.

What is a human risk score?

A human risk score summarizes selected indicators of workforce-related cyber risk into a numerical value or category.

Its usefulness depends on the evidence, assumptions and methodology underneath it. Enterprises should understand what contributes to the score, how the evidence is interpreted and whether the system can explain why risk has changed.

What is the difference between a metric and a human-risk signal?

A metric measures something, such as a completion rate, reporting rate or assessment result.

A signal is evidence that may indicate a risk condition worth investigating. Signals become more useful when connected with other evidence, organizational context and patterns over time.

What is a human-risk data foundation?

A human-risk data foundation is the structured set of relevant evidence, data sources and measurement processes used to observe and understand workforce-related cyber risk.

It may include learning, competency, behavioral, cultural, psychological, organizational and security-system evidence.

Its purpose is to support reliable signals, patterns, risk interpretation and measurement of change.

How do you measure security culture?

Security culture can be assessed using structured evidence about factors such as psychological safety, leadership behavior, shared norms, attitudes toward security, confidence in reporting, organizational priorities and accepted workarounds.

Training engagement and phishing performance may contribute useful evidence, but they should not be used as substitutes for measuring culture itself.

For a deeper methodology, see Measuring Cyber Security Culture: NCSC-Aligned Metrics That Actually Work.

What is cognitive security in cybersecurity?

In a Human Risk Management context, cognitive security concerns the human processes involved in perceiving, interpreting, trusting and making decisions about information and digital systems.

It becomes particularly relevant where judgment can be influenced by deception, cognitive overload, persuasive technology, synthetic content, automation bias and AI-generated information.

How does AI change human-risk measurement?

AI introduces workforce behaviors involving trust, reliance, verification, data sharing, shadow AI, decision-making, automation and human oversight.

Organizations therefore need to measure more than whether employees completed AI training. They need evidence about whether people are ready and able to use AI safely, effectively and responsibly in real work.

Should every company use the same Human Risk Management metrics?

No.

Human Risk Management metrics should align to the organization's workforce, threat environment, business model, technology, culture and risk posture.

External benchmarks can provide context, but the measures used to manage risk need to be fit for purpose and grounded in the conditions of the organization using them.