Focusing on
behaviours that
protect your people
Measure what matters: the real, lasting behavioural changes that reduce vulnerability and foster a resilient security culture.
Proven with our customers
Why this
approach matters
Targeted Threats
Behavioural science for deeper insights
Data-driven decision-making
Create meaningful metrics based on real behaviour. like engagement with security messaging and changes in risky habits. This empowers leaders to demonstrate measurable impact and continuously mature the awareness programme. Check how our customers have done it.
Why do traditional awareness metrics fall short?
Because “95% completed training” tells you nothing about what happened the next time someone received a convincing phishing email. Humans don’t suddenly develop perfect judgement after a multiple-choice quiz.
What should we measure instead?
Behaviour. Did fewer people click on risky links this month? Are people pausing more before sending sensitive data externally? These are the moments that matter, because they’re the ones that actually cause incidents.
How does Redflags help us measure behaviour?
It captures behavioural signals at the point of action — the messy, real-world moments where decisions are made quickly. Then it turns those signals into insights that show where your risk is genuinely shifting.
Why is context essential?
Because not all clicks are created equal. A data analyst opening a spreadsheet isn’t a headline, while someone in Finance opening an unknown attachment at 4.57pm absolutely can be. Context separates insight from noise.
How do we identify the behaviours that matter?
Redflags highlight the patterns that have the biggest effect on your human risk. It gives you clarity on where to intervene in, so you can intervene where it has the most impact.
How can metrics help gain leadership support?
Leaders respond well when data paints a story of progress rather than perfection. When you can show real, measurable behaviour changes, it becomes far easier to build long-term support.
What to watch next
Practitioner panel with Lucy Finlay
Watch on-demand
Tech talk with Jamie Graves
Watch on-demand
Make your security awareness
programme data-driven using risk
management methodology
A successful campaign built around “Measuring What Matters” should be structured on key
activities that blend behavioural science with actionable data. These activities ensure that
awareness initiatives are measurable, effective and aligned with the organisation’s risk profile.
Identify risk based on business priorities and risk appetite.
Evaluate the likelihood
and impact of the risk on
your business
Design and implement
strategies to mitigate the risk
Ongoing tracking of the risks
and the mitigation activities
Review the intervention
effectiveness
LinkedIn Live @Infosec25
We gathered industry experts to talk about Powerful metrics
from many different angles.
Danu Sivapalan, Head of Partnerships, WiCyS
Danu Sivapalan reflects on the role of allyship in shaping inclusive environments where women can thrive in cyber security.
Linton Geach discusses the growing importance of human behaviour as a measurable aspect of cyber risk.
Robert Coles shares his perspective on how cyber security becomes a lived part of organisational culture.
Tim Ward & Gareth Thomas explore how organisations can shift from measuring activity to evaluating behavioural impact in cyber security.
Reading corner
In case you would like to learn more, access the Library
What Makes a Cyber Security Metric Useful
Read article
Why Timing Matters in Security Awareness
Read article
Cyber Security Metrics That Show Behaviour Is Shifting
Read article
Industry
accolades
Frequently asked questions
Why do traditional awareness metrics fall short?
Traditional security awareness metrics usually measure activity, not impact. Completion rates, click-through rates and time spent on training show whether people engaged with content, but not whether risky behaviour changed. Phishing simulations can have the same flaw, proving someone spotted a controlled test rather than how they behave under real pressure. Redflags closes that gap by measuring behaviour at the point of risk, not just training activity.
What security awareness metrics should we measure instead?
The most meaningful security awareness metrics are behavioural ones. Are employees making fewer risky decisions, and is that improving over time? Track how often high-risk actions happen, whether that frequency reduces after an intervention, and whether people respond differently when the same situation appears again. Redflags brings awareness content, real-time nudges, behavioural monitoring and targeted campaigns together so teams can measure genuine risk reduction, not just engagement with training.
How does Redflags measure behaviour change?
Redflags measures behaviour change by tracking what employees actually do before, during and after an intervention. For example, it can capture how often people upload files to public AI tools or copy sensitive content into unapproved sites, then show whether that behaviour reduces as the campaign runs.
The result isn’t an assumption that awareness led to change, but instead a measurable, evidenced correlation between the programme activity and a reduction in the risky behaviour it was designed to address. That is a fundamentally different level of confidence than completion rates or simulation pass rates can offer.
For practitioners, this is significant. It means you can demonstrate to leadership not just that a programme was delivered, but that it had a tangible impact on human risk. Over time, as multiple campaigns are tracked and compared, it becomes possible to build a robust evidence base showing how your organisation’s risk profile is shifting as a result of your security behaviour management programme.
How can behaviour metrics support board reporting?
Behaviour metrics help boards see human risk in the language they care about: whether it is increasing, decreasing, and what is being done to manage it. Instead of reporting that employees completed a module, practitioners can show that a targeted intervention reduced a specific risky behaviour, how trends are shifting over time, and where further investment may be needed. For regulated organisations, that strengthens both the risk and compliance narrative.
Can Redflags help identify high-risk behaviours and teams?
Yes. Redflags includes an on-host tracker that identifies risky behaviour directly at the point it occurs, rather than relying solely on self-reported data or generic risk assumptions.
This gives practitioners visibility into who is engaging in risky behaviour and how often, which makes it possible to segment your workforce by actual risk rather than by job title or department alone. Individuals or teams who are repeatedly triggering nudges for a particular behaviour can be identified and given more targeted support, whether that is additional awareness content, a more direct intervention, or closer monitoring over time.
This segmentation capability sits at the heart of the Assess / Target stage of an effective Secure Behaviour Management workflow, helping practitioners prioritise the people and teams who pose the greatest risk, such as those with elevated access or a pattern of risky activity, rather than treating the whole organisation as a single uniform audience.
