Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Security awareness benchmarks and AI activity: what should teams track?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19382
Topic starter  

TL;DR: Security awareness metrics must move beyond completion rates and include behaviour, identity and access data, and threat intelligence to measure real risk across human and AI activity, according to Living Security Human Risk Management Platform. That shift matters because risk programmes now need to predict and prevent incidents, not just report training attendance.

NHIMG editorial — based on content published by Living Security Human Risk Management Platform: What Are Good Security Awareness Risk Benchmarks? A Guide to Security Awareness Risk Benchmarks

Questions worth separating out

Q: How should security teams measure human risk programmes beyond training completion?

A: Security teams should measure whether the programme changes behaviour, reduces repeat risky actions, and lowers exposure over time.

Q: Why do identity and access decisions matter so much in risk assessment?

A: Identity and access decisions matter because they determine who or what can influence critical systems, data, and workflows.

Q: What breaks when security awareness programmes rely on point-in-time assessments?

A: They miss risk trajectories.

Practitioner guidance

  • Build behaviour-based benchmarks Replace completion-rate reporting with metrics such as phishing reporting speed, repeat-click reduction, and time-to-escalation after suspicious messages.
  • Correlate risk across identity and threat data Join training outcomes to access entitlements and active threat targeting so high-risk users with privileged access rise to the top of remediation queues.
  • Segment benchmarks by role and access level Create separate thresholds for finance, IT, developers, and high-privilege users so benchmark results reflect real operational exposure instead of blended averages.

What's in the full article

Living Security Human Risk Management Platform's full blog covers the operational detail this post intentionally leaves for the source:

  • The article's benchmark examples for phishing reporting, repeat-click reduction, and response-time measurement.
  • The way Living Security segments risk by behaviour, identity and access, and threat intelligence in its Human Risk Management model.
  • The article's discussion of autonomous remediation with human oversight and how benchmark data feeds intervention decisions.
  • The role of AI-based activity in the platform's measurement model when human and machine risk overlap.

👉 Read Living Security Human Risk Management Platform's guide to security awareness risk benchmarks →

Security awareness benchmarks and AI activity: what should teams track?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 18973
 

Completion-rate security is a governance blind spot: measuring training attendance tells leaders almost nothing about whether risky behaviour has changed. The article correctly treats behaviour as the control surface, but the stronger point is that identity and access context determines whether a mistake becomes an incident. In NHI and IAM programmes, that means the same user action can carry very different risk depending on privilege scope and adjacent access. The practitioner conclusion is simple: benchmark outcomes, not participation.

A question worth separating out:

Q: How should teams include AI activity in security awareness benchmarks?

A: They should treat AI agents and automated workflows as part of the same risk model when those systems access enterprise data or services. That means tracking their actions, the identities they use, and the access they hold. If machine activity is excluded, the benchmark understates real exposure in hybrid environments.

👉 Read our full editorial: Security awareness benchmarks now need to include human and AI activity



   
ReplyQuote
Share: