Predicted Compromise Rate is a forecast of how many users are likely to fall for a given simulation scenario. Security teams use it to calibrate difficulty, compare expected versus actual susceptibility, and turn simulation outcomes into a more precise measure of resilience across roles, departments, and threat types.
Expanded Definition
Predicted Compromise Rate is a planning metric, not a fixed security threshold. It estimates the proportion of participants expected to be compromised in a specific simulation, using scenario difficulty, audience profile, and historical outcomes to forecast likely susceptibility. In practice, it sits between awareness measurement and risk modelling: it is more specific than a general training completion metric, but less absolute than an incident rate.
Definitions vary across vendors and maturity models, so the term should be treated as an analytical estimate rather than a universal standard. For organisations assessing human and machine-mediated exposure, the metric can also inform broader phishing resistance, privileged-user scrutiny, and role-based targeting decisions. It is most useful when paired with actual post-exercise results, because prediction alone does not show whether the model was accurate or whether the scenario was unrealistically easy or difficult. For context on how adversarial operations can exploit human and technical pathways together, see Anthropic — first AI-orchestrated cyber espionage campaign report.
The most common misapplication is treating predicted compromise rate as an employee score, which occurs when teams use it to rank individuals instead of calibrating scenario design and population-level resilience.
Examples and Use Cases
Implementing Predicted Compromise Rate rigorously often introduces a calibration burden, requiring organisations to balance measurement consistency against the realism of each simulation.
- A security team forecasts that a spear-phishing scenario aimed at finance staff will yield a higher compromise rate than a generic awareness test, then compares the prediction with actual click-through and submission outcomes.
- An organisation uses separate predicted compromise rates for executives, contractors, and new hires to understand how role exposure changes susceptibility and whether controls need to be tailored.
- A red-team programme estimates compromise likelihood before launching a campaign, helping it choose a scenario difficulty that is neither trivial nor so advanced that it produces misleadingly low results.
- A phishing analytics workflow compares predicted compromise rate to actual compromise rate over time, revealing whether awareness training, MFA adoption, or mailbox protections are changing behaviour.
- For organisations evaluating AI-assisted social engineering, the predicted compromise rate may be reviewed alongside threat intelligence such as the Anthropic report on AI-orchestrated espionage to test whether simulation assumptions still reflect current attacker tradecraft.
The metric is also useful when security leaders need to compare one simulation design against another, because raw failure counts alone can hide whether a harder scenario or a different audience drove the result.
Why It Matters for Security Teams
Predicted Compromise Rate matters because it turns awareness exercises into decision-support data. Without it, teams often overreact to a single poor campaign or underreact to a repeated pattern that points to a structural weakness in a business function, identity workflow, or threat channel. Used well, the metric helps security teams separate scenario quality from user behaviour, which is essential when measuring improvement over time.
It also has governance value for identity and access security. When a population with elevated privileges shows a high predicted compromise rate, that finding can inform stricter controls, stronger verification, or tighter monitoring around privileged access pathways. In that sense, the metric can complement broader identity assurance practices, even though it is not itself an identity standard. For teams mapping behavioural risk to broader resilience programmes, NIST guidance on identity assurance and cyber risk governance is often the closest formal reference point, especially when simulation results influence access control decisions.
Where AI-assisted phishing, synthetic personas, or automated targeting are in play, the metric becomes even more important because the attack surface can evolve faster than baseline training content. Organisations typically encounter the practical limits of predicted compromise rate only after a simulation result fails to match real-world incident patterns, at which point the metric becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST AI RMF and NIST IR 8596 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM-01 | Risk measurement supports governance decisions about human susceptibility and control prioritisation. |
| NIST SP 800-63 | AAL2 | Identity assurance becomes relevant when compromise risk influences credential and access expectations. |
| NIST AI RMF | AI risk governance applies when AI-assisted phishing changes the likelihood of user compromise. | |
| OWASP Agentic AI Top 10 | Agentic and AI-driven social engineering can amplify compromise likelihood in simulation exercises. | |
| NIST IR 8596 | Cyber AI profiles help teams reason about AI-shaped attack patterns affecting predicted compromise. |
Use the metric to inform risk treatment choices and prioritise controls where compromise likelihood is highest.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org