No Result
View All Result
  • Login
Tuesday, February 3, 2026
FeeOnlyNews.com
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading
No Result
View All Result
FeeOnlyNews.com
No Result
View All Result
Home Market Analysis

Measure Human Risk Management Metrics That Matter

by FeeOnlyNews.com
3 months ago
in Market Analysis
Reading Time: 4 mins read
A A
0
Measure Human Risk Management Metrics That Matter
Share on FacebookShare on TwitterShare on LInkedIn


For years, security leaders have wrestled with a simple but stubborn question: How do we prove the value of security awareness and training (SA&T)? For far too long now, we’ve leaned on vanity metrics, such as training completion rates or phishing click percentages, that we believed reflected the effectiveness of SA&T efforts — but in reality, they reveal little about actual risk reduction.

Today, that changes. Our latest research — Five Steps To Better Human Risk Management Metrics and The Essential List Of Human Risk Management Metrics — provides security leaders with the clarity they need to measure what truly matters. This isn’t just another comprehensive metrics framework — it’s the foundation for turning human risk management (HRM) from a conversation into a movement.

HRM introduces a significant change of mindset, strategy, process, and technology that not only provides the opportunity to answer the question of the value delivered by our training efforts but also enables us to go much deeper.

From Compliance To Culture: The Metrics Journey

Before HRM was even a term, back in 2019, I challenged the reliance on SA&T completion rates and Net Promoter Score℠ (NPS) — which are easy to report but meaningless for risk reduction — and urged leaders to measure behavioral change. This was easier said than done in those days because our collective understanding of behavior was limited, as was the technology.

In 2020, I criticized the tick-and-bash approach of compliance-driven metrics, which consumed resources but missed the point. Up to March 2022, I continued to question the obsession with phishing click rates and better content. When we finally published a report on the future of SA&T, introducing HRM for the first time, we saw a shift — HRM solutions were being used to measure and manage risks posed by or to people, based on actual behaviors. Today’s research announcement is the culmination of that journey, moving from measuring compliance to measuring what truly matters: risk reduction and behavioral change.

What To Measure — And Why

My toughest challenge in this research — and yours — was organizing metrics by altitude (tactical, operational, and strategic) and by indicator type (leading, lagging, or coincident). Thank goodness I had the patience of my colleague Chiara Bragato and the eagle eyes of Jeff Pollard to keep me on track. Once I found the right altitudes, I whittled my list down to the 45 metrics that matter the most. Next, I tackled the challenge of identifying HRM goals that demonstrate ROI, prove effectiveness, and help reduce human risk. I urge you to follow a similar path by:

Aligning every metric to a goal in your security function. This is nonnegotiable, and it’s not just an alignment exercise. Going through this step forces you to really understand the outcome you wish to achieve from your HRM program. Is your goal really to increase the percentage of people who complete training? What will that goal give you? You’ll quickly realize that completion isn’t the goal in and of itself but rather a method to get to a goal of compliance. A better goal would be to improve security behaviors, as this will highlight whether problematic behaviors have changed and if your interventions are working (see the figure below).
Using HRM metrics as the missing link to justify HRM investments. Metrics aren’t just numbers — they’re proof, and they’re the bridge between intent and impact. The right metrics prove ROI and drive executive buy-in. In addition to compliance and risk avoidance, clients I’ve spoken to have had to demonstrate how HRM helps them meet 12 goals, such as:

Improved HRM program management and administration experience. Your team should automate the detection, measurement, and management of cyber-safe behaviors and human risk.
Better security behaviors. You should be measuring and intervening in real time to identify and fix unsafe behaviors.
Reduced security friction and increased workforce productivity. You shouldn’t be training all of your people on security at random times.

Metrics Are The Missing Link: From Early Adopter To Early Majority

Early adopters embraced HRM because they believed in its promise. But to get the majority to adopt HRM, they need proof. The right HRM metrics will accelerate adoption by demonstrating tangible results. It’s hard to reject an HRM investment when you can clearly demonstrate its contribution to overall security and organizational goals. When you can show that targeted interventions cut workforce training time by 40% or reduce breach-related costs by millions, the conversation changes.

Example Metrics That You Should Measure If Your Goal Is To Improve Security Behaviors

 

Your Next Step

Download the report, as well as the Excel tool containing all 45 metrics, and measure what matters. Forrester clients can schedule a guidance session or inquiry with me. Remeber that, in cybersecurity, the future belongs to those who can demonstrate impact — not just talk about it.



Source link

Tags: humanmanagementMattermeasureMetricsRisk
ShareTweetShare
Previous Post

India’s Snabbit valuation doubled to $180M in 5 months on its quick house-help bet

Next Post

OpenAI lays groundwork for juggernaut IPO at up to $1 trillion valuation

Related Posts

A Defining Moment For CPQ: Inside The Conga-PROS Merger

A Defining Moment For CPQ: Inside The Conga-PROS Merger

by FeeOnlyNews.com
February 3, 2026
0

The Conga-PROS merger unites market leaders in CPQ configuration, quoting, workflows, and AI‑driven pricing optimization. Together, they will create an...

How I’ll Help You Win with IT Finance in 2026

How I’ll Help You Win with IT Finance in 2026

by FeeOnlyNews.com
February 3, 2026
0

Enterprises with high-performing IT organizations outgrow their peers because their IT organizations effectively collaborate with the business to cocreate value....

7 Deeply Oversold Stocks Entering February With Rebound Potential

7 Deeply Oversold Stocks Entering February With Rebound Potential

by FeeOnlyNews.com
February 3, 2026
0

January saw record highs on the stock market, but some stocks plummeted. How can you tell if a stock has...

When A Hosting Provider Becomes A Hostile Provider: The Notepad++ Compromise

When A Hosting Provider Becomes A Hostile Provider: The Notepad++ Compromise

by FeeOnlyNews.com
February 2, 2026
0

The detailed writeup from cybersecurity vendor Rapid7 about the Notepad++ compromise gives CISOs a clear demonstration of how a single...

Endpoint Security Is Dead. Long Live Endpoint Security.

Endpoint Security Is Dead. Long Live Endpoint Security.

by FeeOnlyNews.com
February 2, 2026
0

Today, Forrester is announcing the retirement of The Forrester Wave™: Endpoint Security. This evaluation has been published under multiple names...

MDF Sales: How Manufacturers Turn Marketing Funds Into Predictable Channel Revenue – Blog & Tips

MDF Sales: How Manufacturers Turn Marketing Funds Into Predictable Channel Revenue – Blog & Tips

by FeeOnlyNews.com
February 2, 2026
0

Computer Market Research (CMR): The Ultimate Channel Management Compendium PART 1 Table of Contents for Part 1 Introduction to Channel...

Next Post
OpenAI lays groundwork for juggernaut IPO at up to  trillion valuation

OpenAI lays groundwork for juggernaut IPO at up to $1 trillion valuation

Radioactive Tsunamis | Armstrong Economics

Radioactive Tsunamis | Armstrong Economics

  • Trending
  • Comments
  • Latest
Self-driving startup Waabi raises up to  billion, partners with Uber to deploy 25,000 robotaxis

Self-driving startup Waabi raises up to $1 billion, partners with Uber to deploy 25,000 robotaxis

January 28, 2026
Student Beans made him a millionaire, a heart condition made this millennial founder rethink life

Student Beans made him a millionaire, a heart condition made this millennial founder rethink life

December 11, 2025
Sellers Are Accepting Even Less

Sellers Are Accepting Even Less

January 23, 2026
Episode 242. “Our couples therapist couldn’t fix this. Please help.”

Episode 242. “Our couples therapist couldn’t fix this. Please help.”

January 6, 2026
US SEC Issues Key Crypto Custody Guidelines For Broker-Dealers

US SEC Issues Key Crypto Custody Guidelines For Broker-Dealers

December 19, 2025
How to sell a minority stake in RIA M&A

How to sell a minority stake in RIA M&A

November 11, 2025
Ukraine & Trump | Armstrong Economics

Ukraine & Trump | Armstrong Economics

0
Clorox outlines 0–1% category growth target and innovation-led recovery as ERP transition ends (NYSE:CLX)

Clorox outlines 0–1% category growth target and innovation-led recovery as ERP transition ends (NYSE:CLX)

0
Are Blue States Really Paying More for Electricity Than Red States? Here’s What the Data Says.

Are Blue States Really Paying More for Electricity Than Red States? Here’s What the Data Says.

0
Bitcoin Bounces as U.S. House Passes Bill To End Government Shutdown

Bitcoin Bounces as U.S. House Passes Bill To End Government Shutdown

0
How to Save Money on Your Electric Bill

How to Save Money on Your Electric Bill

0
Plus500 hits new peak after entering prediction market

Plus500 hits new peak after entering prediction market

0
Clorox outlines 0–1% category growth target and innovation-led recovery as ERP transition ends (NYSE:CLX)

Clorox outlines 0–1% category growth target and innovation-led recovery as ERP transition ends (NYSE:CLX)

February 3, 2026
China set to attend India’s upcoming AI summit signaling improving relations with New Delhi

China set to attend India’s upcoming AI summit signaling improving relations with New Delhi

February 3, 2026
Ukraine & Trump | Armstrong Economics

Ukraine & Trump | Armstrong Economics

February 3, 2026
Dividend Aristocrats In Focus: W.W. Grainger

Dividend Aristocrats In Focus: W.W. Grainger

February 3, 2026
Levi Strauss heir Daniel Lurie helped lure the Super Bowl when Levi’s Stadium was under construction. Now he’s mayor for the 0 million windfall

Levi Strauss heir Daniel Lurie helped lure the Super Bowl when Levi’s Stadium was under construction. Now he’s mayor for the $440 million windfall

February 3, 2026
A Defining Moment For CPQ: Inside The Conga-PROS Merger

A Defining Moment For CPQ: Inside The Conga-PROS Merger

February 3, 2026
FeeOnlyNews.com

Get the latest news and follow the coverage of Business & Financial News, Stock Market Updates, Analysis, and more from the trusted sources.

CATEGORIES

  • Business
  • Cryptocurrency
  • Economy
  • Financial Planning
  • Investing
  • Market Analysis
  • Markets
  • Money
  • Personal Finance
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • Clorox outlines 0–1% category growth target and innovation-led recovery as ERP transition ends (NYSE:CLX)
  • China set to attend India’s upcoming AI summit signaling improving relations with New Delhi
  • Ukraine & Trump | Armstrong Economics
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclaimers
  • About Us
  • Contact Us

Copyright © 2022-2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Sign In with Facebook
Sign In with Google
Sign In with Linked In
OR

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Business
  • Financial Planning
  • Personal Finance
  • Investing
  • Money
  • Economy
  • Markets
  • Stocks
  • Trading

Copyright © 2022-2024 All Rights Reserved
See articles for original source and related links to external sites.