Measuring human risk means capturing a picture of how your people behave against a real deception, not of how much they know about security on a test. That picture is built from three signals that already exist in any company: which of your employees's credentials are exposed, how each person reacts to a simulated attack, and how critical their role is if they fall. The three combine into a risk score per person and per team, and that score is the baseline you will compare everything against later.
The first step is not buying a platform or sending a survey: it is deciding what you will observe before you observe it, starting with who is most exposed. Below is the method, with what you can capture in the first two weeks and what only comes with time.
What measuring human risk means (and what it is not)
Let's start with the most common confusion. Measuring human risk is not measuring how much training people completed or what score they got on the annual assessment. That measures declared knowledge, which is a different thing. Cisco's 90-5-5 framework estimates that close to 90 percent of breaches involve a human factor, so what really matters to measure is not whether the person knows the theory, but whether they act differently when a real attack pressures them.
Human risk is managed automatically.
Turn human risk into your first line of defense.
Book a demoFree demo · 30 minutes · No commitment
The distinction is not wordplay, and there is peer-reviewed evidence behind it. In a 2025 study at the IEEE Symposium on Security and Privacy, Grant Ho and his team found no relationship between having recently completed annual training and the likelihood of failing a phishing simulation. Completing the course does not predict behavior.
Earlier work by Daniele Lain and colleagues, presented at the same symposium in 2022 on a large, long-term sample, already pointed in that direction. That is why measuring human risk means observing conduct under realistic deception conditions and turning that observation into a signal you can track over time, not administering a questionnaire.
It is worth separating this from a similar but different question. If what you want to know is whether your training worked, that is a program-effectiveness measurement, and we cover it separately in how to measure if security training works. That one looks at whether the course moved the needle; this one looks at the state of the risk, whether or not a course is involved.
The three baseline signals: exposure, behavior and role
A useful baseline does not need twenty indicators. It needs three signals captured well, because each one answers a question the others cannot.
The first is exposure, and it is the one that waits the least. A leaked credential is not an abstract risk: according to Mandiant's M-Trends 2026 (Google Cloud), the hand-off time between initial access and the actor who executes the attack collapsed from more than eight hours in 2022 to 22 seconds in 2025. When the password of someone on your team shows up in a breach or a dark web forum, the window to react is measured in hours, not weeks. This signal only works if it is captured continuously, not once a year.
The second is behavior: how the person responds to a deception that looks legitimate and is not. Email is still the main door, which is why it is where you should look first. According to CISA, more than 90 percent of successful cyberattacks start with a phishing email. The honest way to capture this signal is a phishing simulation by email, measuring two things at once: the click rate, which tells you how many fell, and the report rate, which tells you how many raised the alarm. Both matter, and they do not always move together; we develop this in report rate, click rate and retest.
The third is role: how much damage that person would cause if they fall, based on their access, their privileges and the data they handle. A high risk score for someone in finance or IT does not weigh the same as for someone without sensitive access. Role is what turns a list of failures into a list of priorities.
| Signal | What it measures | How it is captured | Frequency |
|---|---|---|---|
| Exposure | Employee credentials leaked in breaches or on the dark web | Continuous monitoring of public breach databases and forums | Continuous |
| Behavior | How the person reacts to a realistic deception | Email phishing simulation, measuring click rate and report rate | Monthly, per person |
| Role | How much damage that person would cause if they fall | Access and privilege map with IT and HR | At start and when the role changes |
How to capture the first picture in two weeks
The baseline does not need a six-month project. With these five steps you have a first defensible picture in two weeks.
How to read the score: by team first, by person only with enough mass
A risk score per person is tempting, but it misleads when the group is small. A single failure in a simulation does not distinguish someone having a bad day from someone with a pattern, and acting on noise breaks the team's trust before the program even starts. That is why you need a mass of around 25 people for the individual score to make statistical sense.
The correct reading goes from the general to the particular. First by team, to see where the risk concentrates and which areas need attention sooner. Then, and only when there is enough data per person, you go down to the individual detail, always to direct help, never to single anyone out. Language matters here: we talk about the human factor, a risk surface that can be reduced, not about people who are the weak link. A score used to punish stops receiving honest reports, and without honest reports the signal goes dark.
How often to re-measure and against what to compare
A picture is not a film. The baseline exists to compare, and to compare you have to measure again with rhythm. A monthly behavior cadence keeps the signal alive without saturating people, while exposure is watched continuously and the role map is reviewed when someone changes position.
The most common comparison mistake is benchmarking against an industry average that does not know your context. Your best reference is yourself three months ago. And one form of measurement deserves a separate mention, because it validates what no other does: testing again. Weeks after someone fails, a new simulation of the same type and difficulty, but with a different template, confirms whether they learned the lesson or only remembered that one email. That testing again, the retest, is what separates a one-off success from sustained behavior change, and it is the difference between saying people know and showing they act differently.
From measurement to program: what decision each data point enables
Measuring without deciding is a pretty dashboard that changes nothing. The proof that a baseline is useful is that each signal enables a concrete action.
High exposure enables immediate remediation: notify the person, force the password change with a deadline, and verify it was done. Weak behavior in a team enables targeted training at the moment of failure and more practice for that group, not a generic course for the whole company. A critical role with weak behavior enables the highest priority, because that is where the potential damage is greatest.
And the combination of the three, tracked over time, enables the conversation with leadership: not a speech about awareness, but a number that goes down, with the evidence of why it goes down. That is the point where measuring human risk stops being a diagnosis and becomes a program.
At Fensivo we build human risk management (HRM) on exactly these three signals: we continuously monitor whether your team's credentials show up in breaches or on the dark web, we send phishing simulations by email personalized by role and behavior, and we add the criticality of the role, all combined into a risk score per person and per team. Weeks after each failure, a retest with a different template validates whether behavior actually changed. We work with companies of 25 to 500 people, the size where the per-person score already has enough mass to be reliable, and you can see how it fits in our human risk management.
So the uncomfortable question is not whether your people know about security. It is this: if you had to put a number on your company's human risk today, what evidence would you back it with, and against what baseline would you compare it three months from now?
Sources and references
- Cisco, "The 90-5-5 Concept: Your Key to Solving Human Risk in Cybersecurity", May 27, 2025: https://blogs.cisco.com/security/the-90-5-5-concept-your-key-to-solving-human-risk-in-cybersecurity
- CISA, "4 Things You Can Do To Keep Yourself Cyber Safe": https://www.cisa.gov/news-events/news/4-things-you-can-do-keep-yourself-cyber-safe
- Mandiant (Google Cloud), "M-Trends 2026 Report": https://cloud.google.com/security/resources/m-trends
- Ho, G. et al., "Understanding the Efficacy of Phishing Training in Practice", 2025 IEEE Symposium on Security and Privacy: https://ieeexplore.ieee.org/document/11023357
- Lain, D., Kostiainen, K. and Čapkun, S., "Phishing in Organizations: Findings from a Large-Scale and Long-Term Study", 2022 IEEE Symposium on Security and Privacy: https://ieeexplore.ieee.org/document/9833766
Human risk is managed automatically.
Turn human risk into your first line of defense.
Book a demoFree demo · 30 minutes · No commitment
