Blogs Security Culture Assessme...
A security culture assessment helps security teams understand whether people can recognize, avoid, and report risk in the flow of work, and whether the organization gives them the context to succeed. The strongest assessments connect what people do with identity and access context and real threat exposure, turning culture from an abstract idea into an actionable Human Risk Management (HRM) program.
See how Living Security helps security teams predict and reduce human risk.
A security culture assessment is a structured review of the beliefs, behaviors, working conditions, and risk signals that shape how an organization protects information. It combines employee perception with observed behavior, identity and access context, and threat exposure so a security team can identify priority risks, choose targeted interventions, and measure whether secure habits improve.
That definition matters because culture is not the same as training completion, a phishing click rate, or a survey score. Those measures can be useful inputs, but none explains the full risk picture on its own. An assessment should help leaders answer three practical questions:
The distinction also separates an assessment from a maturity model. A maturity model describes stages an organization may move through. An assessment produces evidence about the organization's current conditions and a prioritized plan for action. Living Security's security culture maturity model guide can help teams discuss maturity stages, while this framework focuses on running an assessment that leads to decisions.
A security culture assessment gives leaders a way to move beyond assumptions about the human element. A low training completion rate may indicate a communication or workflow problem. A high reporting rate may reflect healthy vigilance, or it may appear alongside privileged access and active targeting that require a different response. Context determines the right action.
Security teams also need a common language for communicating risk with executives and business leaders. A useful assessment connects frontline behavior to business impact without blaming employees. It shows where policy, access, tooling, incentives, or workload may be making secure behavior difficult. That turns culture work from a once-a-year campaign into an operating loop that security, IT, and business leaders can improve together.
The approach aligns with the NIST Cybersecurity Framework 2.0, which treats cybersecurity as an enterprise risk-management responsibility. It also reflects research on cyber-security culture assessment frameworks that use defined dimensions and evidence to evaluate organizational readiness rather than relying on a single sentiment measure.
A practical assessment brings together three data pillars: behavior, identity and access, and threat. This does not mean collecting every possible data point. It means selecting enough relevant evidence to explain what is happening, who or what is exposed, and what could happen next.
| Data pillar | Useful evidence | Decision it supports |
|---|---|---|
| Behavior | Reporting habits, risky actions, policy friction, response to guidance, and patterns over time | Which behaviors need coaching, reinforcement, workflow changes, or escalation? |
| Identity and access | Privileged access, sensitive systems, role changes, unusual access paths, and identity context | Which people, roles, or access points would increase business impact? |
| Threat | Targeting, phishing activity, malware signals, account compromise indicators, and data-loss exposure | Where is risk active now, and which interventions should be prioritized? |
Perception data adds another layer. Ask whether people understand what secure behavior looks like, know how to report a concern, believe leaders take security seriously, and can complete required actions without unreasonable friction. Compare those responses with observed evidence. A gap between positive confidence and risky behavior may call for better workflows or clearer guidance, not more generic training.
Use the following six-step process to produce an assessment that a security team can act on. The sequence is designed for enterprise environments where risk varies by role, access, location, workload, and threat exposure.
Start with a decision, not a survey. Are you prioritizing a high-risk business unit, preparing for a board discussion, evaluating a new security program, or investigating why a behavior has not changed? Define the population, time period, systems, and outcomes before selecting measures. A narrow decision produces more useful evidence than an organization-wide score with no owner.
Document the starting point for behavior, identity and access, and threat. Include perception questions, observed behaviors, relevant access context, and current threat signals. Record the source, timeframe, and limitations of each input. This prevents a common failure mode: comparing a current survey with a prior incident metric as if they measured the same thing.
Average scores can hide the people and workflows that matter most. Segment findings by role, access level, business unit, geography, employment relationship, and exposure to current threats where that data is appropriate and privacy-aware. The goal is not to label people. It is to understand where an intervention can reduce the most risk and where the organization may be creating avoidable friction.
Use short scenarios to test judgment in realistic situations, such as a suspicious request, an unexpected file-sharing prompt, or a request to bypass a control to meet a deadline. Pair those responses with observed behaviors and reporting patterns. Scenario responses explain understanding and intent; observed signals show what happens in practice. Together, they provide a stronger baseline than either one alone.

Do not treat every finding as equally urgent. Prioritize the combination of behavior pattern, access impact, active threat, and ability to intervene. A recurring low-risk behavior may need a workflow fix, while a less frequent behavior involving privileged access and active targeting may need immediate attention. Make the rationale visible so stakeholders understand why the team chose one action over another.
Every significant finding should have an owner, an intervention, a success measure, and a reassessment date. Actions may include contextual guidance, micro-training, policy clarification, access review, manager coaching, or a change to the workflow itself. Keep human oversight in the loop when AI helps recommend or orchestrate action. Security leaders should be able to review the evidence, understand why an action was selected, and approve exceptions.
Explore an AI-native HRM approach to connecting behavior, identity and access, and threat data.
The right measures depend on the decision and population, but a balanced assessment usually includes indicators from each pillar:
Avoid turning these into a universal scorecard. A metric is useful only when its definition, data source, owner, and decision are clear. For example, an increase in reports can be a positive sign if report quality improves and response time falls. Treating the raw count as a standalone culture score could lead to the wrong conclusion.
For a deeper measurement discussion, see Living Security's guide to measuring culture of security. That resource focuses on measurement; this assessment framework focuses on how to collect evidence and turn it into an intervention plan.
Assessment is valuable only when findings change what the organization does. Use a short feedback loop:
AI can help security teams correlate large volumes of behavior, identity and access, and threat data, recommend next steps, and carry out routine actions. The standard should be AI with human oversight: recommendations should be explainable, actions should be reviewable, and security leaders should retain control of decisions that affect people or access.
Living Security, a leader in Human Risk Management (HRM), uses this people-first approach to help organizations move from reactive detection to proactive prediction and prevention. The Living Security solutions overview describes how security, GRC, and SOC teams can apply risk intelligence to different operating needs.
Run a baseline assessment when launching or redesigning a program, then reassess on a cadence that matches the risk. A quarterly review can support an enterprise program with changing threats and access patterns. Monthly monitoring may be appropriate for a focused high-risk population, while a major incident, merger, technology rollout, or policy change should trigger an additional review.
Do not change the methodology every cycle. Keep core questions and definitions stable enough to compare results, then add focused modules for new risks. This makes it possible to distinguish real behavior change from changes caused by a new survey, a different population, or a different data source.
Build a more measurable security culture with Living Security's Human Risk Management platform.
The purpose is to identify how beliefs, behaviors, access context, and threat exposure combine to create or reduce security risk. A useful assessment gives the security team evidence for prioritization, targeted behavior change, and follow-up measurement.
Training delivers education or guidance. An assessment evaluates the conditions around secure behavior, including what people understand, what they do, the access they hold, and the threats they face. Assessment findings can help determine where training is appropriate and where workflow, access, or leadership changes are more effective.
The three core data pillars are behavior, identity and access, and threat. Perception, leadership, and workflow evidence can add important context, especially when the organization is trying to understand why behavior does or does not change.
Yes. AI can correlate signals, identify patterns, recommend interventions, and handle routine actions. Security teams should use AI with human oversight so recommendations are explainable, decisions remain reviewable, and higher-impact actions have an accountable owner.
Establish a baseline, then repeat the assessment quarterly or at another cadence that matches the organization's risk. Add reviews after major incidents, access changes, mergers, technology rollouts, or policy changes. Keep core definitions stable so results remain comparable.
Crystal Turnbull is Director of Marketing at Living Security, where she leads go-to-market strategy for the Human Risk Management platform. She partners closely with CISOs and security leaders through executive roundtables and industry events, helping organizations reduce human risk through behavior-driven security programs. Crystal brings over 10 years of experience across lifecycle marketing, customer marketing, demand generation, and ABM.