The best approach is to correlate human behavior data with identity and access context, then layer in threat intelligence. Phishing results alone only show one slice of risk. A stronger model looks at who is targeted, who has privileged access, how people report incidents, and whether risky roles are concentrated in sensitive systems. That gives leaders a practical view of where intervention will reduce exposure fastest.
Why This Matters for Security Teams
Measuring security culture only through training completion or phishing click rates creates a false sense of confidence. Those signals describe awareness, not whether risky behavior is actually changing in the parts of the organisation that matter most. A more reliable view combines behavioural indicators, identity context, and threat exposure so leaders can see where human decisions intersect with privileged access, sensitive systems, and active attacker interest. That makes culture measurable as operational risk, not as a soft HR metric.
For example, a team that reports incidents quickly, uses approved authentication paths, and escalates unusual access requests is demonstrating healthier behaviour than one that simply passes annual awareness modules. Likewise, if high-risk roles cluster around critical services or sensitive data, the cultural issue is not just “compliance fatigue” but concentrated exposure. Current guidance suggests mapping these patterns to control objectives in NIST SP 800-53 Rev 5 Security and Privacy Controls, because culture metrics become more useful when they are tied to observable control outcomes.
In practice, many security teams discover weak culture only after a near miss, a repeated policy exception, or an access review that exposes chronic bypass behaviour.
How It Works in Practice
A practical measurement model starts by defining the behaviours that indicate secure decision-making, then connecting them to identity and threat data. The question is not “Are people compliant?” but “Where do human choices increase or reduce exposure?” That usually requires three layers: behaviour signals, identity and access signals, and threat signals. Each layer helps explain the others.
- Behaviour signals: phishing reporting rates, policy exception requests, MFA enrolment follow-through, suspicious link reporting, and how quickly users escalate anomalies.
- Identity signals: privileged role concentration, dormant accounts in sensitive groups, service account ownership, excessive access approvals, and unusual access patterns across teams.
- Threat signals: targeted campaign volume, credential theft attempts, role-based targeting, and whether security incidents are rising around specific business units or tools.
This is where correlation matters. If an engineering team shows low phishing clicks but high approval of risky access, the culture issue is different from a finance team that reports suspicious messages quickly but repeatedly reuses exceptions. Security teams should also check whether the same identities appear in multiple risk categories, because repeated exposure often reveals process friction or unmanaged privilege. For current attacker patterns, CISA cyber threat advisories help teams connect internal behaviour trends to active campaign themes.
Where AI-enabled attacks are in scope, culture measurement should also account for how staff respond to highly convincing lures, synthetic voices, and automated reconnaissance. Guidance is still evolving here, but the MITRE ATLAS adversarial AI threat matrix is useful for mapping how attackers may amplify social engineering or automate targeting. If an organisation is tracking AI-orchestrated intrusion patterns, the Anthropic — first AI-orchestrated cyber espionage campaign report is a useful reminder that human response quality now sits beside machine-scale attack velocity.
These controls tend to break down in large, decentralised environments where identity data is fragmented across HR, IAM, ticketing, and endpoint tools, because no single system can explain the behaviour-to-risk relationship on its own.
Common Variations and Edge Cases
Tighter culture measurement often increases governance overhead, requiring organisations to balance richer insight against employee privacy, data quality, and administrative burden. That tradeoff matters because not every environment can or should collect the same level of behavioural telemetry.
In highly regulated environments, teams may need to rely on aggregated trends rather than individual-level monitoring, especially where local privacy rules limit employee tracking. In smaller organisations, the signal set may be too thin to support statistically strong conclusions, so leaders should treat the model as directional rather than definitive. Best practice is evolving for AI-assisted monitoring, and there is no universal standard for whether synthetic phishing, incident sentiment, or tool-usage patterns should be weighted equally.
Identity-heavy environments create another edge case. If a business has strong zero trust controls but poor role hygiene, culture scores can look better than they are because technical enforcement masks weak decision-making. Conversely, a high-reporting environment may appear noisy, but that often indicates healthy vigilance rather than failure. The useful question is whether reporting, access behaviour, and threat exposure move together in a way that supports faster intervention. That operational reading is more actionable than any single score.
For teams building formal control mappings, NIST SP 800-53 Rev 5 Security and Privacy Controls remains the cleanest anchor for translating culture observations into measurable control expectations.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATLAS and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OC, PR.AC | Culture metrics should connect outcomes, access control, and risk governance. |
| NIST AI RMF | GOVERN | AI-assisted threat analysis and reporting need governance, accountability, and oversight. |
| MITRE ATLAS | T1585, T1566 | Adversarial AI can amplify targeting and social engineering against employees. |
| NIST SP 800-53 Rev 5 | AT-2, AC-2, AU-6 | Training, account management, and logging underpin measurable culture and response behaviour. |
| OWASP Agentic AI Top 10 | A03 | Agentic AI can alter communication patterns and trigger unsafe human responses. |
Define culture indicators that map to governance and access control outcomes, then review them as risk signals.
Related resources from NHI Mgmt Group
- How should security teams measure identity security maturity across human and machine identities?
- How should security teams implement threat hunting across identity, endpoint, and cloud data?
- How should security teams unify identity across cloud and data center environments?
- How should security teams measure the business value of identity security?