The Cyber Security Review | Monday, June 29, 2026
Companies can create a strong metrics framework to determine what matters in a security awareness program.
FREMONT, CA: If a company's security awareness program aligns with its strategic goals, developing a robust metrics framework can assist in quantifying the program's overall impact and demonstrate value to the organization's leadership. Technology, threats, and organizational needs all evolve. As a result, the security team should work with the organization's human risks to review and update them at least once a year.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Analytics to measure: It becomes much simpler to determine what KPIs businesses should prioritize once they approach security awareness and risk management through this lens. Companies should decide in advance if they want to assess and track behavior by job, department, or business unit instead of by an individual. Whenever tracking at the individual level is used, take precautions to safeguard each person's privacy and information. Companies may also need to collaborate with an internal expert in data analytics or business intelligence to help standardize and evaluate results, depending on the size of the organization and the volume of data being collected.
Phishing: At a global level, phishing has been the leading cause of breaches. Cybercriminals learn to work around them no matter how many technical measures we take to address this issue. We must thus instruct individuals on how to recognize and report these attacks. What do we measure, then? Once people have received training, assess their vulnerability to phishing scams. This risk is the easiest to quantify among the top human risks, which explains why it is a widely used metric.
Passwords: Passwords have been a major cause of breaches for many years. To more easily pivot and move through a victim organization while avoiding detection, cyber attackers have changed their tactics, techniques, and procedures (TTPs), moving away from gaining access or lateral movement through continuous system hacking and infection. Instead, they now use legitimate accounts. Strong passwords, as has the secure usage of such passwords, have become essential.
Updating: This ensures that users' software and apps on their computers and other devices are up-to-date and relevant. This is not a problem for some businesses because IT actively patches employees' work-issued devices, denying them administrative privileges or control. Yet, this is a problem for many firms because so many individuals now work remotely from home and frequently utilize personal devices or home networks to reach the workplace. There are various methods for measuring this.
The operations, IT, and possibly even vulnerability management teams should be able to remotely monitor the update status of any devices the firm issues. Certain systems, like mobile device management (MDM), may be installed on user-owned devices and track the progress of updates.
Any device that connects to the learning management system (LMS) or phishing platform may be able to automatically trace the device, operating system, and browser version.
To determine if your workforce understands the value of updating and is actively doing it on their own devices, including allowing automatic updating, assess and survey them.
More in News