Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Security culture metrics: what should security teams measure?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18707
Topic starter  

TL;DR: Security culture metrics are only useful when they connect workforce behavior to identity and access context, not just training completion or phishing clicks, according to Living Security Human Risk Management Platform. The shift from activity reporting to risk reduction is now central for teams trying to prove whether Human Risk Management is actually lowering exposure.

NHIMG editorial — based on content published by Living Security Human Risk Management Platform: Security Culture Metrics for Enterprise Security Teams

By the numbers:

Questions worth separating out

Q: How should security teams measure security culture without relying on training completion?

A: Start with behaviour that affects risk in real work, such as report rate, time to report, repeat risky actions, and policy exceptions.

Q: How do human risk signals fit into identity and access governance?

A: They should inform access reviews, onboarding, role design, and remediation decisions when repeated risky behaviour indicates that standard controls are not enough.

Q: What do security teams get wrong about culture dashboards?

A: They often confuse visibility with effectiveness.

Practitioner guidance

  • Measure behaviour in context Track phishing report rate, time to report, repeat risky actions, and policy exceptions alongside privilege level and business role so the same event is not over- or under-weighted.
  • Segment risk by access criticality Separate ordinary users from privileged users, operators, and high-impact workflow identities before assigning coaching, investigation, or compensating controls.
  • Define intervention triggers Tie each metric threshold to a specific response, such as manager reinforcement, targeted coaching, access review, or escalation for unusual repetition.

What's in the full article

Living Security Human Risk Management Platform's full blog post covers the operational detail this post intentionally leaves for the source:

  • A fuller breakdown of how the platform correlates 200-plus risk indicators across 60-plus tool integrations.
  • Example dashboard structures that turn culture metrics into board-ready exposure reporting.
  • Operational guidance on setting thresholds for targeted coaching, access review, and remediation.
  • The article's examples of how Living Security frames risk reduction versus passive reporting.

👉 Read Living Security Human Risk Management Platform's analysis of security culture metrics and Human Risk Management →

Security culture metrics: what should security teams measure?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
Share: