Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Human cyber risk assessment benchmarks - what security teams should measure


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19382
Topic starter  

TL;DR: Human cyber risk assessment benchmarks now need to measure behaviour, identity and threat signals together because AI agents and other non-human actors have joined the attack surface, according to Living Security Human Risk Management Platform. Static annual awareness metrics are no longer enough; continuous, data-driven assessment is becoming the practical basis for targeted intervention and measurable risk reduction.

NHIMG editorial — based on content published by Living Security Human Risk Management Platform: What Are Human Cyber Risk Assessment Benchmarks?

Questions worth separating out

Q: What breaks when human risk assessments ignore AI agents and other non-human actors?

A: The benchmark becomes incomplete because it measures only human behaviour while missing delegated access, inherited privileges, and automated actions.

Q: Why do identity and access signals matter in human cyber risk scoring?

A: Because behaviour only becomes meaningful when you know what the person or account can actually access.

Q: How should security teams measure human risk programmes beyond training completion?

A: Security teams should measure whether the programme changes behaviour, reduces repeat risky actions, and lowers exposure over time.

Practitioner guidance

  • Correlate behaviour with identity scope Build benchmark dashboards that combine training outcomes, access entitlements, and threat exposure so high-risk behaviour is weighted by the privileges it can actually touch.
  • Add delegated-machine activity to human risk scoring Include service accounts, bots, and AI agents in the same measurement model when they act on behalf of users.
  • Measure behaviour change, not completion rates Track whether risky actions decline after intervention, whether incident reporting improves, and whether high-access users show sustained improvement.

What's in the full article

Living Security Human Risk Management Platform's full blog post covers the operational detail this post intentionally leaves for the source:

  • A step-by-step framework for combining behaviour telemetry, identity data, and threat signals into a continuous human-risk score
  • Examples of benchmark metrics for phishing susceptibility, reporting behaviour, and high-risk-user prioritisation
  • Guidance on how the platform correlates employee behaviour with AI-driven activity and delegated access paths
  • Board-reporting examples that show how to demonstrate behaviour change over time

👉 Read Living Security Human Risk Management Platform's analysis of human cyber risk assessment benchmarks →

Human cyber risk assessment benchmarks - what security teams should measure?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18973
 

Human risk benchmarks are becoming identity benchmarks. The moment an organisation includes AI agents, service accounts, and delegated workflows in its workforce model, assessment design crosses into IAM and NHI governance. Behaviour alone cannot explain exposure when identity scopes, privilege levels, and offboarding discipline determine the blast radius. Practitioners should treat benchmark design as an identity-control problem, not just a training metric problem.

A question worth separating out:

Q: How should organisations govern AI agents alongside human identity and device access?

A: Organisations should treat AI agents as a separate identity class with their own entitlement boundaries, logging expectations, and approval model. Human IAM controls often assume interactive sign-in and review cycles, which do not fit autonomous or programmatic access. The safer approach is to define actor-specific policy and verify which access paths can be delegated without expanding trust unnecessarily.

👉 Read our full editorial: Human cyber risk benchmarks must now include AI-driven activity



   
ReplyQuote
Share: