Behaviour-only scores miss the impact side of the equation. A person who clicks phishing links may be risky, but a lower-scoring privileged user can pose far greater damage if compromised. Security teams need context from access rights, critical asset exposure, and active threat targeting to distinguish nuisance risk from the users most likely to drive a breach.
Why This Matters for Security Teams
Behaviour-only scoring can be useful as a signal, but it is not a complete risk model. Security teams need to know not only who is likely to make a mistake, but also who can cause the most damage if that mistake is exploited. That distinction matters because user risk is shaped by access privilege, sensitive data reach, authentication strength, and whether the user is already in an active attack path. The NIST Cybersecurity Framework 2.0 frames this as a broader governance and risk-management problem, not just a behavioural one.
Where teams go wrong is treating score movement as if it were equivalent to exposure reduction. A low-friction phishing campaign may raise a score quickly, but the highest human risk often sits with users whose compromise would enable privilege escalation, financial fraud, data exfiltration, or lateral movement. That includes administrators, finance approvers, executive assistants with workflow authority, and any account tied to critical systems. In practice, many security teams encounter the real impact of behaviour-only scoring only after a high-value account has been misused, rather than through intentional prioritisation.
How It Works in Practice
A stronger approach combines behaviour with context. Behaviour signals indicate likelihood, while context indicates impact. The model should therefore bring together identity attributes, access entitlements, device trust, application sensitivity, transaction value, and current threat activity. This is especially important where identity is a control plane for cloud services, SaaS, and business workflows.
Practitioners typically build a composite view from multiple inputs:
- Identity and access context, such as role, privilege level, and privileged session activity
- Asset context, such as whether the user can reach crown-jewel systems or regulated data
- Threat context, such as phishing targeting, credential stuffing pressure, or suspicious login patterns
- Behavioural context, such as anomalous clicks, impossible travel, or unusual approval behaviour
- Control context, such as MFA strength, conditional access coverage, and passwordless adoption
That composite view supports better response decisions. A high-behaviour-risk user with low privilege may need awareness coaching and tighter email filtering. A moderate-behaviour-risk user with standing administrative access may need step-up authentication, privileged access review, or temporary restriction. This is consistent with NIST guidance on managing cybersecurity risk, where controls are selected according to business impact and exposure, not just observed unsafe behaviour.
For identity-led organisations, the practical question is not whether a user has a risky score, but whether that user can be exploited to reach a sensitive outcome. Current guidance suggests prioritising users whose compromise would unlock privileged actions, sensitive records, or trusted workflows. These controls tend to break down when identity data is fragmented across HR, IAM, PAM, and SaaS tools because the score cannot reliably see privilege depth or active attack targeting.
Common Variations and Edge Cases
Tighter scoring often increases operational overhead, requiring organisations to balance precision against the cost of collecting and normalising more signals. Best practice is evolving here, and there is no universal standard for how much context is enough.
Some environments do not need a highly complex model. Small organisations may get most of the value from adding simple role and privilege overlays to behavioural scores. Large enterprises, regulated firms, and managed service environments usually need richer segmentation because the damage potential varies sharply between users. In these settings, a single score can hide the difference between a contractor account and a domain administrator, even if both show similar risky behaviour.
There are also edge cases where behaviour is a weak predictor. A user may rarely click anything and still be highly dangerous if their account is externally accessible, overly privileged, or used in sensitive approval chains. Conversely, some users will generate frequent alerts because of job function, not because they are the highest risk. The practical answer is to combine behaviour scoring with access governance, privileged access monitoring, and asset criticality. That is the difference between spotting noisy activity and identifying the people who would create the largest breach impact if compromised.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM | Risk decisions should weigh likelihood and impact, not behaviour alone. |
| NIST Zero Trust (SP 800-207) | SC-3 | Zero trust relies on continuous verification using identity and context. |
| NIST SP 800-63 | IAL/AAL | Identity assurance and authenticator strength influence compromise impact. |
| OWASP Non-Human Identity Top 10 | Machine and service identities also need context-aware risk prioritisation. |
Use governance and risk management to rank users by exposure, privilege, and likely business impact.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org