Three people are sitting at a table and smiling

Security awareness is often measured by exposure, who completed training, who attended sessions, who passed a quiz. These signals show activity, but they don’t reveal whether behaviour has shifted.

Behavioural metrics focus on what people do in real situations. They show how individuals respond to everyday risk, and whether awareness efforts are influencing decisions over time.

Examples include consistent increases in phishing reporting, reductions in credential reuse on unapproved sites, fewer uploads to risky file-sharing tools, or quicker responses to suspicious activity. These indicators reflect lived behaviour and developing habits, not passive compliance.

Performance metrics can confirm that an action was completed. Behavioural data provides insight into whether that action made a difference. A team that completes training but continues to take the same risks shows little change. A team that reports incidents earlier, avoids risky shortcuts, and supports colleagues demonstrates cultural progress.

Frameworks such as the Human Aspects of Information Security Questionnaire help structure this understanding by linking knowledge, attitudes, and behaviour. When combined with telemetry and contextual insight, they offer a more complete picture of human risk.

Behavioural metrics also support prioritisation. They highlight where risky habits persist and where targeted support is likely to have the greatest effect. Over time, this allows programmes to adapt based on evidence rather than assumption.

As Tim Ward, CEO and Co-Founder of Redflags, notes, “Security is not a technical issue; it is a cultural one. It must be measured in ways that reflect how people behave, not just how systems respond.”

Metrics that reflect behaviour provide clearer insight into how risk is actually being managed across the organisation.