Templates & Checklists
Checklist
Top 10 Human Risk Metrics Every Security Team Should Track

Since the launch of ChatGPT, phishing attacks have grown by 4,151%, and deepfake attacks in the U.S. have grown 17-fold in a single year. Most organizations track patch coverage rates, mean time to detection, and vulnerability counts with precision, but human risk goes under-quantified even as it becomes attackers' most reliable way in. This report gives security teams 10 metrics that measure the human side of the organization with the same rigor as the technical one, covering behavior, exposure, training, and improvement over time, so you can see where risk is concentrating and where your program is actually working.
What’s inside:
- 1The organizational human risk score: A single dynamic index that synthesizes simulation results, training engagement, credential exposure, and reporting behavior into one number leadership can track
- 2Why phishing susceptibility rate, multi-channel attack susceptibility, and time-to-report are the core behavioral signals that show where risk concentrates and how fast your team can contain it
- 3How training completion rate and training effectiveness score reveal whether your program is changing behavior, not just checking a compliance box
- 4Why credential exposure count and executive and high-value target exposure surface risk before an attack is ever constructed
- 5How to track human risk improvement trend over rolling 30-, 60-, and 90-day windows to demonstrate program value to the board


