Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What should security teams do first when they…
Governance, Ownership & Risk

What should security teams do first when they want a more complete view of employee cyber knowledge?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 28, 2026 Domain: Governance, Ownership & Risk

Start by building a multi-topic baseline that combines training challenges with assessment data. Use the results to compare understanding across key security domains, then segment findings by role or industry where possible. That sequence shows which topics need reinforcement, which user groups are most exposed, and where awareness efforts should move beyond a single phishing metric.

How to Build a Better Baseline for Employee Cyber Knowledge

The first move is to measure more than one behaviour or topic at once. A single phishing score can hide strong gaps in password hygiene, data handling, device practice, or escalation judgment. A multi-topic baseline gives security teams a clearer starting point for remediation because it shows whether a weakness is isolated or part of a wider pattern.

That baseline should be built from both challenge results and assessment data, then compared across core domains rather than only against a passing threshold. Once the data is grouped by topic, the team can see whether the issue is concentrated in awareness, policy understanding, or day-to-day decision-making.

Why Segmentation Matters More Than a Single Average Score

After the baseline exists, the next useful step is segmentation. Role, function, and industry often change what “good” looks like, because a finance user, an engineer, and a manager do not face the same exposures or make the same decisions. Comparing groups helps distinguish a broad training gap from a problem tied to a specific workflow or business context.

Segmentation also makes the data more actionable. If one group underperforms on secure document handling while another struggles with suspicious-link recognition, the response should not be a generic refresher for everyone. The point is to connect findings to the actual job conditions that shape risk, which makes the programme more precise and easier to defend.

What Security Teams Should Do With the Results

Use the baseline to decide where awareness should move next, not just to report a score. Topics that are consistently weak should become the first candidates for reinforcement, but the strongest value comes from identifying combinations of weakness, for example where low assessment performance and poor challenge outcomes appear in the same group.

Where the answer set shows repetition across multiple topics, teams should treat that as a signal that the issue is not only training content. It may point to weak process design, unclear policy language, or controls that are difficult for employees to follow in normal work. The baseline is most useful when it leads to a targeted intervention plan, not a broad awareness campaign with the same message for everyone.

Risk and Threat Considerations

When teams rely on a single metric, they can miss material exposure hidden behind a superficially acceptable score. A strong phishing result does not mean employees understand risky approvals, data sharing, or account recovery, and those blind spots can still create paths for social engineering or policy bypass.

Failure mechanism: The organisation measures only one behaviour, so it cannot see whether the same users are weak across other security decisions, or whether a specific role is carrying a disproportionate share of avoidable risk.

Impact: Misleading confidence can delay remediation, leave high-value groups undertrained, and allow attackers to exploit the weakest decision points rather than the most visible one.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-14 — Security Awareness and Skills TrainingEmployee cyber knowledge baselining is directly about awareness and skills measurement.
Recommendation — Measure awareness gaps and tailor training to the weakest topics and groups.
NIST CSF 2.0PR.AT-01 — All Users Are Provided Awareness and TrainingA multi-topic baseline informs training coverage and user awareness outcomes.
ID.RA-01 — Asset Vulnerabilities Are Identified and DocumentedAssessment findings reveal workforce vulnerabilities that should be documented and tracked.
Recommendation — Use baseline results to target awareness content to the topics users do not understand. Document employee knowledge gaps as risk inputs and prioritise remediation by exposure.

Practitioner Guidance

What to prioritise: Start with topics that are both common and consequential, then look for clusters of weakness by role or function. If a topic is weak across several groups, treat it as a programme-level issue; if it is concentrated, treat it as a workflow or audience issue.

What to verify: Make sure the baseline compares like with like. Scores should be normalised enough to support a fair comparison across groups, and the assessment set should cover more than one security behaviour so one metric does not dominate the conclusion. If the data cannot support a comparison, the team should tighten the assessment design before drawing conclusions.

Practitioner takeaway: The value of the first baseline is not the score itself, but the ability to separate broad awareness problems from targeted, role-specific gaps that need different fixes.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 28, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org