PROVEN IMPACT

Focusing on
behaviours that
protect your people

Measure what matters: the real, lasting behavioural changes that reduce vulnerability and foster a resilient security culture.

Isometric Graphic. Three people and a laptop and graphs.

Proven with
our customers

Why this
approach matters

Targeted Threats

Simply tracking how many employees complete training or click on phishing emails fails to capture whether staff are genuinely adopting secure behaviours or understanding risks as a result of your security awareness activities.

Behavioural science for deeper insights

Applying principles from behavioural science helps security teams understand why people act as they do, helping you design interventions that are more engaging, relevant, and effective for your audiences.

Data-driven decision-making

Create meaningful metrics based on real behaviour. like engagement with security messaging and changes in risky habits. This empowers leaders to demonstrate measurable impact and continuously mature the awareness programme. Check how our customers have done it.

Why do traditional awareness metrics fall short?

Because “95% completed training” tells you nothing about what happened the next time someone received a convincing phishing email. Humans don’t suddenly develop perfect judgement after a multiple-choice quiz.

What should we measure instead?

Behaviour. Did fewer people click on risky links this month? Are people pausing more before sending sensitive data externally? These are the moments that matter, because they’re the ones that actually cause incidents.

How does Redflags help us measure behaviour?

It captures behavioural signals at the point of action — the messy, real-world moments where decisions are made quickly. Then it turns those signals into insights that show where your risk is genuinely shifting.

Why is context essential?

Because not all clicks are created equal. A data analyst opening a spreadsheet isn’t a headline, while someone in Finance opening an unknown attachment at 4.57pm absolutely can be. Context separates insight from noise.

How do we identify the behaviours that matter?

Redflags highlight the patterns that have the biggest effect on your human risk. It gives you clarity on where to intervene in, so you can intervene where it has the most impact.

How can metrics help gain leadership support?

Leaders respond well when data paints a story of progress rather than perfection. When you can show real, measurable behaviour changes, it becomes far easier to build long-term support.

What to watch next

Practitioner panel with Lucy Finlay
A live panel of security practitioners will reveal how they are moving beyond traditional compliance metrics to use data-driven insights that uncover risky habits and measure real behavioural change in ways tailored to each organisation.

Watch on-demand

Tech talk with Jamie Graves
Join Jamie Graves and Joel Estrada for an insightful session exploring how to empower security practitioners like yourself with a data-driven approach to managing behavioural risk.

Watch on-demand

Make your security awareness
programme data-driven using risk
management methodology

A successful campaign built around “Measuring What Matters” should be structured on key
activities that blend behavioural science with actionable data. These activities ensure that
awareness initiatives are measurable, effective and aligned with the organisation’s risk profile.

Identify risk based on business priorities and risk appetite.

Review emerging human-centric security risks highlighted in industry reports and research
Monitor relevant incidents and behavioural trends reported across the news and wider industry
Incorporate insights from internal sources, such as threat intelligence feeds or SOC findings

Evaluate the likelihood
and impact of the risk on
your business

Use available data (such as simulated exercises or email gateway data) to understand human risk, including its likelihood and potential impact on the business
Identify key metrics from this data to establish a baseline view of current risk, which can later be compared against results after interventions
Ensure measurements include a mix of quantitative and qualitative insights, as well as indicators of both performance and real-world effect

Design and implement
strategies to mitigate the risk

Align strategies with assessment-stage metrics, applying targeted interventions (training, nudges, role-based approaches) informed by employee behaviours and risk profiles
Drive engagement and behaviour change through interactive, contextual nudging, while reinforcing positive, “just” security culture practices (e.g. locking screens, verifying suspicious emails – as advocated by frameworks such as the NCSC Cyber Assessment Framework and NHS guidance)
Gather qualitative feedback from employees to identify barriers, motivators, and opportunities to improve effectiveness

Ongoing tracking of the risks
and the mitigation activities

Review the measurements that you ascertain and the assess stage- are they on track and trending in the way you’d like?
Use this stage to report to your key stakeholders and pre-empt any future tweaks or interventions you may want to make.

Review the intervention
effectiveness

Regularly review behavioural metrics and adapt interventions accordingly.
Use insights from interventions to iteratively refine content, delivery methods, and engagement tactics for sustained impact.

LinkedIn Live @Infosec25

We gathered industry experts to talk about Powerful metrics
from many different angles.

Danu Sivapalan, Head of Partnerships, WiCyS

Danu Sivapalan reflects on the role of allyship in shaping inclusive environments where women can thrive in cyber security.

Linton Geach, Technical 
Director, Secon

Linton Geach discusses the growing importance of human behaviour as a measurable aspect of cyber risk.

Robert Coles, Chairman, Redflags

Robert Coles shares his perspective on how cyber security becomes a lived part of organisational culture.

Redflags’ CEO, Tim Ward and Gareth Thomas, Technical Director, Lloyds Banking Group

Tim Ward & Gareth Thomas 
explore how organisations can shift from measuring activity to evaluating behavioural impact in cyber security.

Reading corner

In case you would like to learn more, access the Library

Industry
accolades

Frequently asked questions

Why do traditional awareness metrics fall short?

Traditional security awareness metrics usually measure activity, not impact. Completion rates, click-through rates and time spent on training show whether people engaged with content, but not whether risky behaviour changed. Phishing simulations can have the same flaw, proving someone spotted a controlled test rather than how they behave under real pressure. Redflags closes that gap by measuring behaviour at the point of risk, not just training activity.

What security awareness metrics should we measure instead?

The most meaningful security awareness metrics are behavioural ones. Are employees making fewer risky decisions, and is that improving over time? Track how often high-risk actions happen, whether that frequency reduces after an intervention, and whether people respond differently when the same situation appears again. Redflags brings awareness content, real-time nudges, behavioural monitoring and targeted campaigns together so teams can measure genuine risk reduction, not just engagement with training.

How does Redflags measure behaviour change?

Redflags measures behaviour change by tracking what employees actually do before, during and after an intervention. For example, it can capture how often people upload files to public AI tools or copy sensitive content into unapproved sites, then show whether that behaviour reduces as the campaign runs.

The result isn’t an assumption that awareness led to change, but instead a measurable, evidenced correlation between the programme activity and a reduction in the risky behaviour it was designed to address. That is a fundamentally different level of confidence than completion rates or simulation pass rates can offer.

For practitioners, this is significant. It means you can demonstrate to leadership not just that a programme was delivered, but that it had a tangible impact on human risk. Over time, as multiple campaigns are tracked and compared, it becomes possible to build a robust evidence base showing how your organisation’s risk profile is shifting as a result of your security behaviour management programme. 

 

 

How can behaviour metrics support board reporting?

Behaviour metrics help boards see human risk in the language they care about: whether it is increasing, decreasing, and what is being done to manage it. Instead of reporting that employees completed a module, practitioners can show that a targeted intervention reduced a specific risky behaviour, how trends are shifting over time, and where further investment may be needed. For regulated organisations, that strengthens both the risk and compliance narrative.

Can Redflags help identify high-risk behaviours and teams?

Yes. Redflags includes an on-host tracker that identifies risky behaviour directly at the point it occurs, rather than relying solely on self-reported data or generic risk assumptions. 

This gives practitioners visibility into who is engaging in risky behaviour and how often, which makes it possible to segment your workforce by actual risk rather than by job title or department alone. Individuals or teams who are repeatedly triggering nudges for a particular behaviour can be identified and given more targeted support, whether that is additional awareness content, a more direct intervention, or closer monitoring over time. 

This segmentation capability sits at the heart of the Assess / Target stage of an effective Secure Behaviour Management workflow, helping practitioners prioritise the people and teams who pose the greatest risk, such as those with elevated access or a pattern of risky activity, rather than treating the whole organisation as a single uniform audience.