They measure activity, not exposure or behaviour change. Training completion can rise while risky access patterns remain unchanged, and phishing simulation results do not show who has the privilege to cause damage. Without identity and threat context, teams optimise for compliance optics instead of actual risk reduction.
Why This Matters for Security Teams
Training completion and phishing click rates are easy to report, which is exactly why they become dangerous proxies for human risk. They create a sense of control without showing whether people can still approve fraudulent payments, expose sensitive data, or misuse privileged tools. NIST Cybersecurity Framework 2.0 treats governance, risk management, and continuous improvement as core outcomes, not optional extras, which is why a metrics-only programme often falls short of what security leaders actually need. For identity and access teams, the real question is not who clicked a link, but who had the authority to create material impact if tricked, compromised, or socially engineered.
This matters even more where access is broad, workflows are fast, and business units rely on exceptions. A high completion rate can coexist with weak access review hygiene, poor segregation of duties, and stale privileged entitlements. That means the organisation may be measuring participation in awareness activity while missing the conditions that turn a simple mistake into an incident. In practice, many security teams encounter their weakest human-risk controls only after an account compromise, payment diversion, or data exposure has already occurred, rather than through intentional prevention.
How It Works in Practice
Effective human risk programmes combine behaviour signals, identity context, and exposure analysis. Completion data can still matter, but only as one input. The stronger question is whether the individual’s role, privilege, and workflow create a high-impact path for error or abuse. That requires connecting awareness data to IAM, PAM, ticketing, email security, and incident records so the programme reflects actual operational risk.
Practitioners usually get better results by segmenting users into risk-relevant groups and measuring outcomes that show change in control effectiveness. For example, security teams can distinguish between a person who completed annual training and a person who also handles payment approvals, manages production systems, or has delegated admin rights. MITRE ATT&CK is useful here because it frames common adversary behaviours such as phishing and credential abuse in terms of how they become operationally relevant, rather than treating all clicks as equal.
- Track who can approve, transfer, reset, or elevate, not just who attended training.
- Map phishing susceptibility to exposed workflows and privileged actions.
- Use control testing to see whether risky behaviour changes after intervention.
- Correlate identity events, such as privilege elevation or unusual logins, with awareness findings.
For organisations using detection tooling, CISA guidance on prioritising exploitable weakness is a useful mindset: focus on what can actually be used to cause harm. That principle applies to human risk too, because a low click rate is not protective if the same user can still authorise high-value transactions or access sensitive systems. These controls tend to break down when user populations are large, roles change quickly, and identity data is fragmented across HR, IAM, and business systems because no single team can see the full exposure picture.
Common Variations and Edge Cases
Tighter human-risk measurement often increases operational overhead, requiring organisations to balance richer insight against reporting simplicity. That tradeoff is real, especially where teams want a single executive metric. But current guidance suggests the programme becomes much more useful when it reflects both susceptibility and potential impact, not just participation. There is no universal standard for this yet, so teams should be explicit about what each metric can and cannot prove.
Some environments also need different treatment. In regulated finance or healthcare settings, the highest-risk users may not be the most careless users, but the ones with the most sensitive access. In engineering or cloud operations, the issue may be privileged tooling and automation rather than email behaviour. NIST AI RMF is not directly about awareness training, but its emphasis on governance and mapped risks is a helpful reminder that good metrics should support decisions, not decorate dashboards. For organisations subject to NIST Cybersecurity Framework 2.0, the practical test is whether the programme improves control decisions, escalation paths, and response readiness.
Phishing simulations also have edge cases. A click may reflect curiosity, fatigue, accessibility issues, or poor message design rather than unsafe intent. Best practice is evolving toward combining simulation results with coaching, privilege review, and scenario-based testing. That gives security teams a clearer view of whether people are actually more resilient, or merely more practiced at passing a metric.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC-01 | Metrics should support governance outcomes, not just awareness reporting. |
| MITRE ATT&CK | T1566 | Phishing is a common initial access path, but clicks alone do not show impact. |
| NIST AI RMF | Risk measurement should be outcome-focused and continuously evaluated. |
Use governance and measurement practices that test whether controls reduce real harm.
Related resources from NHI Mgmt Group
- How should security teams measure human risk programmes beyond training completion?
- What breaks when human-risk programmes stop at awareness training?
- What breaks when organisations rely on human oversight alone for AI risk?
- What breaks when access review programmes measure completion instead of risk reduction?