By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: Living Security Human Risk Management PlatformPublished July 29, 2026

TL;DR: Security awareness metrics must move beyond completion rates and include behaviour, identity and access data, and threat intelligence to measure real risk across human and AI activity, according to Living Security Human Risk Management Platform. That shift matters because risk programmes now need to predict and prevent incidents, not just report training attendance.


At a glance

What this is: This is a guide to security awareness risk benchmarks, with the central finding that completion rates are too shallow and organisations need behaviour-based, identity-aware, and threat-informed measurement.

Why it matters: It matters because IAM, IGA, and security leaders need metrics that reflect actual access risk, especially where human users, privileged accounts, and AI-based actors overlap.

By the numbers:

👉 Read Living Security Human Risk Management Platform's guide to security awareness risk benchmarks


Context

Security awareness programmes fail when they measure attendance instead of exposure, behaviour, and privilege. In hybrid environments, the practical question is not whether people finished training, but whether risky behaviour is changing across identities, access paths, and active threat conditions. That is where security awareness risk benchmarks become useful, especially when human users and AI agents both touch enterprise systems.

The article frames Human Risk Management as a way to correlate behaviour data with identity and access systems and real-time threat intelligence. That intersection is relevant to IAM and PAM teams because benchmark design increasingly determines which users, roles, and non-human identities are treated as operational risk rather than generic training audiences.


Key questions

Q: How should security teams measure human risk programmes beyond training completion?

A: Security teams should measure whether the programme changes behaviour, reduces repeat risky actions, and lowers exposure over time. Completion rates can still be reported, but they are not security outcomes. The useful measures are access risk trends, phishing susceptibility by segment, response rates to nudges, and whether high-risk groups improve after intervention.

Q: Why do identity and access decisions matter so much in risk assessment?

A: Identity and access decisions matter because they determine who or what can influence critical systems, data, and workflows. A weak access decision can increase both likelihood and blast radius, especially when privileged accounts, service accounts, or AI-driven workflows sit on operationally important paths. Risk assessment becomes more accurate when it treats identity as a business dependency, not just a control domain.

Q: What breaks when security awareness programmes rely on point-in-time assessments?

A: They miss risk trajectories. A one-off training test or annual phishing campaign cannot show whether risk is rising, falling, or shifting across roles and departments. Continuous measurement is needed to capture changes in behaviour, access, and targeting before those changes show up as incidents.

Q: How should teams include AI activity in security awareness benchmarks?

A: They should treat AI agents and automated workflows as part of the same risk model when those systems access enterprise data or services. That means tracking their actions, the identities they use, and the access they hold. If machine activity is excluded, the benchmark understates real exposure in hybrid environments.


Technical breakdown

Why completion rates are weak security signals

Completion rates measure participation, not capability. A person can finish an annual module and still click on phishing links, reuse unsafe workflows, or expose sensitive data later the same week. Benchmarking becomes useful only when it captures observed outcomes such as reporting speed, repeat-click reduction, and behaviour change over time. In practice, that means security awareness has to behave more like control measurement than training administration.

Practical implication: stop treating training completion as evidence of reduced risk and build benchmarks around observable behaviour.

How identity and threat data change human risk scoring

Behaviour alone does not explain operational risk. The same unsafe action means something very different when it comes from a low-privilege user versus someone with access to finance systems, admin tools, or sensitive workloads. Correlating identity and access data with threat intelligence turns a generic behaviour metric into a prioritisation signal. This is where identity governance adds value: it links who acted, what they can reach, and whether they are under active attack.

Practical implication: enrich behavioural metrics with access entitlements and threat targeting data before assigning risk scores.

Why continuous benchmarking beats point-in-time assessments

Static assessments create snapshots, not trajectories. Security risk changes as roles change, access expands, phishing pressure shifts, and AI-driven activity becomes more common. Continuous benchmarking tracks movement across those variables and reveals whether a control is actually reducing exposure or just producing cleaner reports. For teams managing human identity, privileged access, and non-human identities, that continuous view is closer to how risk behaves in production.

Practical implication: replace annual scorecards with continuous measurement tied to live identity and threat signals.


NHI Mgmt Group analysis

Completion-rate security is a governance blind spot: measuring training attendance tells leaders almost nothing about whether risky behaviour has changed. The article correctly treats behaviour as the control surface, but the stronger point is that identity and access context determines whether a mistake becomes an incident. In NHI and IAM programmes, that means the same user action can carry very different risk depending on privilege scope and adjacent access. The practitioner conclusion is simple: benchmark outcomes, not participation.

Identity context is what turns awareness data into decision-grade intelligence: behaviour metrics become meaningful only when they are correlated with access rights and threat pressure. That aligns with modern access governance thinking, where entitlements, privilege, and active targeting are the variables that separate noise from material risk. For programmes that cover human and non-human identities together, the benchmark has to answer who can do what, not just who clicked what. The practitioner conclusion is to make identity data part of every risk review.

Human risk management is converging with machine identity governance: the article notes AI-based activity alongside human behaviour, which is the right direction for hybrid environments. The emerging governance problem is not just unsafe users, but unmanaged AI actors and automated workflows operating with opaque access paths. That is a named concept worth sharpening: hybrid behavioural risk means measuring human and machine activity with one governance model instead of two disconnected dashboards. The practitioner conclusion is to align awareness, access, and NHI controls under a shared risk language.

Continuous measurement will outlast annual awareness cycles: static checkpoints cannot keep pace with changing access, changing threats, and changing behaviour. That shift matters because security teams need evidence that interventions are reducing exposure before incidents occur, not after the next assessment window. The programmes that win here will be the ones that treat benchmarking as an operational feedback loop rather than a reporting exercise. The practitioner conclusion is to fund live measurement, not yearly compliance theatre.

What this signals

Security awareness programmes are moving toward operational telemetry, not training administration. For IAM and PAM teams, that means risk scoring should increasingly incorporate access scope, privileged pathways, and whether a user or AI actor is operating inside an abnormal trust boundary. The practical signal is that benchmark design is becoming part of governance design.

Hybrid behavioural risk: organisations now need one measurement model for people, privileged accounts, and AI-based activity that can all influence the same systems. If your programme cannot correlate behaviour with entitlements, the resulting benchmark may be precise but still wrong. For teams building identity controls, the priority is to make behavioural insight actionable inside access governance and incident response.


For practitioners

  • Build behaviour-based benchmarks Replace completion-rate reporting with metrics such as phishing reporting speed, repeat-click reduction, and time-to-escalation after suspicious messages.
  • Correlate risk across identity and threat data Join training outcomes to access entitlements and active threat targeting so high-risk users with privileged access rise to the top of remediation queues.
  • Segment benchmarks by role and access level Create separate thresholds for finance, IT, developers, and high-privilege users so benchmark results reflect real operational exposure instead of blended averages.
  • Extend governance to AI-based activity Include AI agents and automated workflows in the same benchmarking model where they access sensitive systems, so machine activity does not sit outside the risk programme.

Key takeaways

  • Security awareness metrics are only useful when they measure behaviour change, not attendance or module completion.
  • Identity context and threat targeting are essential to turning human risk data into a governance signal that security teams can act on.
  • AI-based activity should be benchmarked alongside human behaviour whenever it can reach enterprise systems or sensitive data.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0ID.RA-1Risk awareness benchmarks align with identifying and analysing exposure from behaviour and access context.
NIST SP 800-53 Rev 5AU-6Behavioural measurement and response reporting depend on actionable review of security events.
NIST AI RMFMEASUREThe article explicitly argues for measuring AI-based activity and risk trajectories.
OWASP Agentic AI Top 10NHI-03AI-based activity in benchmark models intersects with agent identity and access governance.

Apply MEASURE to track how AI-related actions change risk over time and under real use conditions.


Key terms

  • Security Awareness Risk Benchmark: A security awareness risk benchmark is a comparative measure used to judge whether behaviour, access exposure, and response patterns are improving or deteriorating. Unlike a simple training metric, it ties outcomes to peer performance, role context, and operational risk so leaders can see whether controls are actually reducing exposure.
  • Human Risk Management: The practice of managing how people interact with security controls, especially under pressure, distraction, or deception. It combines training, policy, and friction management so identity systems are still usable enough that users do not bypass them in day-to-day work.
  • Hybrid Behavioural Risk: Hybrid behavioural risk is the combined exposure created when human users and AI-based actors both interact with the same systems and data. It requires a single governance model that can evaluate actions, entitlements, and targeting across both human and machine activity instead of treating them as separate problems.

What's in the full article

Living Security Human Risk Management Platform's full blog covers the operational detail this post intentionally leaves for the source:

  • The article's benchmark examples for phishing reporting, repeat-click reduction, and response-time measurement.
  • The way Living Security segments risk by behaviour, identity and access, and threat intelligence in its Human Risk Management model.
  • The article's discussion of autonomous remediation with human oversight and how benchmark data feeds intervention decisions.
  • The role of AI-based activity in the platform's measurement model when human and machine risk overlap.

👉 The full Living Security Human Risk Management Platform article expands the benchmark examples, role segmentation, and behaviour-to-prevention model.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, workload identity, and secrets management for practitioners who need to align identity controls with emerging machine and agent risk. It helps security leaders connect identity governance to operational decisions across human and non-human access.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 21, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org