Join our Newsletter — 33% off our NHI Course

North Star Metric

A north star metric is the single outcome measure that tells a programme whether it is actually improving. In human risk management, it should reflect reduced exposure or loss, not activity volume, so leadership can judge value against a clear risk objective.

Expanded Definition

A north star metric is the one outcome measure that best represents whether a security, identity, or risk programme is moving in the right direction. For NHIMG, the key distinction is between outcome and activity: the metric should reflect reduced exposure, reduced loss, or improved control effectiveness, not simply more tickets closed, more alerts generated, or more training completed.

In practice, a north star metric acts as an executive-level signal that connects day-to-day work to a shared risk objective. For example, if the programme aims to reduce identity compromise, a meaningful metric might focus on fewer privileged account exposures or lower rates of unauthorized access, not just the number of policies published. This is aligned with the outcome-driven logic in the NIST Cybersecurity Framework 2.0, which emphasises governance, risk reduction, and measurable results.

Definitions vary across vendors and teams when the term is applied to product dashboards, because some organisations treat any headline KPI as a north star metric. That is too broad. A true north star metric should be stable enough to guide decisions, but sensitive enough to show whether the programme is actually reducing risk over time. The most common misapplication is using activity counts as the north star metric, which occurs when teams optimise for output instead of the underlying security outcome.

Examples and Use Cases

Implementing a north star metric rigorously often introduces measurement discipline and governance overhead, requiring organisations to weigh simplicity for leadership against the cost of collecting trustworthy data.

  • For an IAM programme, the north star metric may be the reduction in high-risk identity exposures, such as stale privileged access or orphaned accounts.
  • For a PAM initiative, it may be the percentage of privileged actions executed through controlled, audited pathways rather than standing access.
  • For a human risk programme, it may track the rate of risky user behaviour that leads to confirmed security incidents, not the number of phishing simulations completed.
  • For an NHI programme, it may measure the proportion of secrets with verified ownership, rotation, and scoped usage, linking directly to NIST Cybersecurity Framework 2.0-style governance outcomes.
  • For an agentic AI control programme, it may track the percentage of agents operating within approved tool and permission boundaries after review.

These examples show why the metric must be tied to a specific risk hypothesis. If the organisation is trying to reduce account takeover, the metric should show whether takeover conditions are becoming less likely, not whether more detections are being produced.

Why It Matters for Security Teams

A north star metric matters because security teams are frequently pressured to demonstrate progress in ways that look productive but do not reduce risk. Without a clear outcome measure, teams can overinvest in visible activity while missing the real drivers of exposure. This is especially important in identity and NHI contexts, where volume-based reporting can hide dangerous conditions such as excessive privilege, weak secret hygiene, or unmanaged service identities.

Used well, the metric becomes a governance tool. It helps leaders compare tradeoffs, prioritise remediation, and understand whether controls are improving the actual security posture. It also reduces the chance that operational teams chase local KPIs that conflict with the organisation’s broader risk objective. The same principle applies to AI systems, where control metrics should reflect safe use, not just deployment speed, and where frameworks such as the NIST Cybersecurity Framework 2.0 support outcome-based measurement.

Organisations typically encounter the cost of a weak north star metric only after a breach review reveals that the programme improved reporting volume but did not reduce the conditions that made the incident possible.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF, NIST SP 800-63 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.OV-01 The CSF frames governance oversight around measurable cybersecurity outcomes.
NIST AI RMF AI RMF emphasizes measurable, outcome-based risk management for AI systems.
OWASP Non-Human Identity Top 10 NHI guidance focuses on ownership, lifecycle, and exposure reduction for identities and secrets.
NIST SP 800-63 Digital identity assurance supports outcome measures tied to authentication and lifecycle risk.
NIST Zero Trust (SP 800-207) Zero Trust is outcome-oriented, focusing on reducing implicit trust and exposure.

Use identity assurance evidence to support a metric that reflects lower compromise likelihood.