Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Security culture metrics: what should security teams measure?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20377
Topic starter  

TL;DR: Security culture metrics are only useful when they connect workforce behavior to identity and access context, not just training completion or phishing clicks, according to Living Security Human Risk Management Platform. The shift from activity reporting to risk reduction is now central for teams trying to prove whether Human Risk Management is actually lowering exposure.

NHIMG editorial — based on content published by Living Security Human Risk Management Platform: Security Culture Metrics for Enterprise Security Teams

By the numbers:

Questions worth separating out

Q: How should security teams measure security culture without relying on training completion?

A: Start with behaviour that affects risk in real work, such as report rate, time to report, repeat risky actions, and policy exceptions.

Q: How do human risk signals fit into identity and access governance?

A: They should inform access reviews, onboarding, role design, and remediation decisions when repeated risky behaviour indicates that standard controls are not enough.

Q: What do security teams get wrong about culture dashboards?

A: They often confuse visibility with effectiveness.

Practitioner guidance

  • Measure behaviour in context Track phishing report rate, time to report, repeat risky actions, and policy exceptions alongside privilege level and business role so the same event is not over- or under-weighted.
  • Segment risk by access criticality Separate ordinary users from privileged users, operators, and high-impact workflow identities before assigning coaching, investigation, or compensating controls.
  • Define intervention triggers Tie each metric threshold to a specific response, such as manager reinforcement, targeted coaching, access review, or escalation for unusual repetition.

What's in the full article

Living Security Human Risk Management Platform's full blog post covers the operational detail this post intentionally leaves for the source:

  • A fuller breakdown of how the platform correlates 200-plus risk indicators across 60-plus tool integrations.
  • Example dashboard structures that turn culture metrics into board-ready exposure reporting.
  • Operational guidance on setting thresholds for targeted coaching, access review, and remediation.
  • The article's examples of how Living Security frames risk reduction versus passive reporting.

👉 Read Living Security Human Risk Management Platform's analysis of security culture metrics and Human Risk Management →

Security culture metrics: what should security teams measure?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19968
 

Security culture metrics are becoming an identity governance problem, not just a human-risk problem. Once behaviour is correlated with access level and threat context, the question shifts from whether people were trained to whether risky behaviour is concentrated where privilege can amplify impact. That is an IAM and PAM concern first, because the same human error has very different consequences across ordinary users, admins, service operators, and high-value NHI-like workflow roles. Practitioners should treat measurement as a governance control, not a communications dashboard.

A question worth separating out:

Q: How do you know if a human risk programme is actually reducing exposure?

A: Look for improvement in leading indicators such as report rate and time to report, plus a decline in lagging outcomes like incidents, data loss, or repeated risky behaviour. The key test is whether the numbers change after a defined intervention and whether the change persists.

👉 Read our full editorial: Security culture metrics need identity and threat context



   
ReplyQuote
Share: