Start by building a multi-topic baseline that combines training challenges with assessment data. Use the results to compare understanding across key security domains, then segment findings by role or industry where possible. That sequence shows which topics need reinforcement, which user groups are most exposed, and where awareness efforts should move beyond a single phishing metric.
How to Build a Better Baseline for Employee Cyber Knowledge
The first move is to measure more than one behaviour or topic at once. A single phishing score can hide strong gaps in password hygiene, data handling, device practice, or escalation judgment. A multi-topic baseline gives security teams a clearer starting point for remediation because it shows whether a weakness is isolated or part of a wider pattern.
That baseline should be built from both challenge results and assessment data, then compared across core domains rather than only against a passing threshold. Once the data is grouped by topic, the team can see whether the issue is concentrated in awareness, policy understanding, or day-to-day decision-making.
Why Segmentation Matters More Than a Single Average Score
After the baseline exists, the next useful step is segmentation. Role, function, and industry often change what “good” looks like, because a finance user, an engineer, and a manager do not face the same exposures or make the same decisions. Comparing groups helps distinguish a broad training gap from a problem tied to a specific workflow or business context.
Segmentation also makes the data more actionable. If one group underperforms on secure document handling while another struggles with suspicious-link recognition, the response should not be a generic refresher for everyone. The point is to connect findings to the actual job conditions that shape risk, which makes the programme more precise and easier to defend.
What Security Teams Should Do With the Results
Use the baseline to decide where awareness should move next, not just to report a score. Topics that are consistently weak should become the first candidates for reinforcement, but the strongest value comes from identifying combinations of weakness, for example where low assessment performance and poor challenge outcomes appear in the same group.
Where the answer set shows repetition across multiple topics, teams should treat that as a signal that the issue is not only training content. It may point to weak process design, unclear policy language, or controls that are difficult for employees to follow in normal work. The baseline is most useful when it leads to a targeted intervention plan, not a broad awareness campaign with the same message for everyone.
Risk and Threat Considerations
When teams rely on a single metric, they can miss material exposure hidden behind a superficially acceptable score. A strong phishing result does not mean employees understand risky approvals, data sharing, or account recovery, and those blind spots can still create paths for social engineering or policy bypass.
Failure mechanism: The organisation measures only one behaviour, so it cannot see whether the same users are weak across other security decisions, or whether a specific role is carrying a disproportionate share of avoidable risk.
Impact: Misleading confidence can delay remediation, leave high-value groups undertrained, and allow attackers to exploit the weakest decision points rather than the most visible one.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-14 — Security Awareness and Skills Training | Employee cyber knowledge baselining is directly about awareness and skills measurement. |
| Recommendation — Measure awareness gaps and tailor training to the weakest topics and groups. | ||
| NIST CSF 2.0 | PR.AT-01 — All Users Are Provided Awareness and Training | A multi-topic baseline informs training coverage and user awareness outcomes. |
| ID.RA-01 — Asset Vulnerabilities Are Identified and Documented | Assessment findings reveal workforce vulnerabilities that should be documented and tracked. | |
| Recommendation — Use baseline results to target awareness content to the topics users do not understand. Document employee knowledge gaps as risk inputs and prioritise remediation by exposure. | ||
Practitioner Guidance
What to prioritise: Start with topics that are both common and consequential, then look for clusters of weakness by role or function. If a topic is weak across several groups, treat it as a programme-level issue; if it is concentrated, treat it as a workflow or audience issue.
What to verify: Make sure the baseline compares like with like. Scores should be normalised enough to support a fair comparison across groups, and the assessment set should cover more than one security behaviour so one metric does not dominate the conclusion. If the data cannot support a comparison, the team should tighten the assessment design before drawing conclusions.
Practitioner takeaway: The value of the first baseline is not the score itself, but the ability to separate broad awareness problems from targeted, role-specific gaps that need different fixes.
Related resources from NHI Mgmt Group
- What should security teams do first if they want to improve cyber insurance readiness?
- How should security teams structure API testing for an application when they only want to validate a specific exploit class first?
- What do security teams get wrong when they treat a matrix as a complete view of security?
- What should teams do first when they are reassessing their cyber security posture?