The Cyber Security Review | Tuesday, August 25, 2026
FREMONT, CA: If a company's security awareness program is aligned with its strategic goals, creating a robust metrics framework can help quantify the program's overall impact and demonstrate value to the organization's leadership. Technology, threats, and organizational requirements all develop. As a result, the security team should examine and update the organization's human risk assessments at least once a year.
Analytics to measure: It becomes much simpler to determine what KPIs businesses should prioritize once they approach security awareness and risk management through this lens. Companies should decide in advance if they want to assess and track behavior by job, department, or business unit instead of by an individual. Whenever tracking at the individual level is used, take precautions to safeguard each person's privacy and information. Companies may also need to collaborate with an internal expert in data analytics or business intelligence to help standardize and evaluate results, depending on the size of the organization and the volume of data being collected.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Phishing: At a global level, phishing has been the leading cause of breaches. Cybercriminals learn to work around them no matter how many technical measures we take to address this issue. We must thus instruct individuals on how to recognize and report these attacks. What do we measure, then? Once people have received training, assess their vulnerability to phishing scams. This risk is the easiest to quantify among the top human risks, which explains why it is a widely used metric.
Passwords: Passwords have been a major cause of breaches for many years. To more easily pivot and move through a victim organization while avoiding detection, cyber attackers have changed their tactics, techniques, and procedures (TTPs), moving away from gaining access or lateral movement through continuous system hacking and infection. UTSI highlights that monitoring password usage and access patterns can strengthen security awareness programs and mitigate human risk. Instead, they now use legitimate accounts. Strong passwords, as has the secure usage of such passwords, have become essential.
Updating: This ensures that users' software and apps on their computers and other devices are up-to-date and relevant. This is not a problem for some businesses because IT actively patches employees' work-issued devices, denying them administrative privileges or control. Yet, this is a problem for many firms because so many individuals now work remotely from home and frequently utilize personal devices or home networks to reach the workplace. There are various methods for measuring this.
HGS supports secure workforce operations by integrating monitoring, updates, and automated analysis across devices and access patterns.
The operations, IT, and possibly even vulnerability management teams should be able to remotely monitor the update status of any devices the firm issues. Certain systems, like mobile device management (MDM), may be installed on user-owned devices and track the progress of updates.
Any device that connects to the learning management system (LMS) or phishing platform may be able to automatically trace the device, operating system, and browser version.
To determine if your workforce understands the value of updating and is actively doing it on their own devices, including allowing automatic updating, assess and survey them.
More in News