Join our Newsletter — 33% off our NHI Course

How can organisations measure whether security training is actually improving identity hygiene?

Look for fewer support requests about basic usage, fewer unsafe credential habits, and better adherence to approved onboarding and offboarding steps. Stronger signals include more consistent use of secure sign-in workflows, less reliance on shared documents, and cleaner access removal when people leave. Training works when behaviour changes, not just when courses are completed.

Why This Matters for Security Teams

Security training is only useful if it changes day-to-day identity behaviour. For identity hygiene, that means fewer shared credentials, better sign-in discipline, cleaner offboarding, and less reliance on risky workarounds. NIST SP 800-53 Rev. 5 treats training as part of an operating control set, not a checkbox, which is why measurement has to look at outcomes, not attendance. That distinction matters in environments where identity mistakes become incident paths.

Practitioners should connect training to observable identity events: password reset volume, MFA enrolment completion, access review responsiveness, and how often users ask for exceptions to approved workflows. NHIMG research on Ultimate Guide to NHIs and the Top 10 NHI Issues shows that identity failures usually stem from behaviour gaps, not policy gaps. In practice, many security teams discover training weakness only after a credential misuse or offboarding miss has already created exposure, rather than through intentional measurement.

How It Works in Practice

The most reliable way to measure training impact is to define baseline identity hygiene metrics before the programme starts, then compare those metrics over time by team, role, and workflow. Current guidance suggests using a mix of leading and lagging indicators so the data reflects behaviour change rather than raw completion rates.

Leading indicators show whether people are adopting the right habits:

  • Use of approved sign-in workflows, including MFA and SSO where available
  • Reduction in shared accounts, shared documents, and informal credential transfer
  • Completion rates for onboarding and offboarding steps within defined time windows
  • Fewer help desk requests for basic identity tasks that training should have covered

Lagging indicators show whether the change is durable:

  • Lower rates of stale access after role changes
  • Fewer exceptions requested for routine identity controls
  • Cleaner revocation of access when users leave or move roles
  • Improved audit findings tied to identity handling

To avoid vanity metrics, map training topics to control expectations in NIST SP 800-53 Rev. 5 Security and Privacy Controls. If the training covers secrets handling, for example, track whether people stop storing credentials in shared locations and whether remediation improves. That pattern aligns with NHIMG research in The State of Secrets in AppSec, which reports that only 44% of developers are reported to follow secrets-management best practices. The real test is whether those habits improve after training, not whether a course was completed. These controls tend to break down in large, distributed organisations where onboarding is local, access tools are fragmented, and managers do not consistently reinforce the same identity workflow.

Common Variations and Edge Cases

Tighter measurement often increases administrative overhead, requiring organisations to balance better assurance against privacy, tooling, and reporting fatigue. Not every environment can measure identity hygiene the same way, and there is no universal standard for this yet.

For high-churn environments, like contractors or seasonal staffing, the best signal may be offboarding speed rather than detailed user behaviour. In regulated environments, access review completion and exception closure may matter more because auditability is the main outcome. In engineering teams, secret-handling behaviour may be the clearest indicator, especially when tied to incidents like the JetBrains GitHub plugin token exposure or the DeepSeek breach, where unsafe identity and secret practices had operational consequences.

Training can also look successful even when the underlying culture has not changed. That happens when managers enforce controls manually, masking poor habits, or when teams comply only during audit windows. The most credible programmes combine training data with workflow telemetry and periodic spot checks. Best practice is evolving, but the core principle is stable: measure whether people use identity controls correctly under normal pressure, not just whether they can pass a quiz.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.AT-01 Training effectiveness is measured through changed user behaviour and control use.
NIST SP 800-53 Rev 5 AT-2 Security awareness and training must be evidenced by improved practice, not attendance.
OWASP Non-Human Identity Top 10 NHI-03 Weak identity hygiene often shows up as poor secrets handling and credential misuse.
CSA MAESTRO TA-2 MAESTRO stresses continuous assurance for human and machine identity operations.
NIST AI RMF AI RMF helps assess whether training reduces risky identity-related decision making.

Link training to monitored outcomes, then adjust content when identity-risk behaviour does not improve.