The Praxis Practice Blog

Insights on measuring security behavior, proving what works, and the human side of cybersecurity.

Security awareness is not a checkbox. Here's how to measure if it works.
· Kai Roer

Security awareness is not a checkbox. Here's how to measure if it works.

Security awareness is not a checkbox. Completion rates measure activity, not effect. Here is how to measure whether awareness actually changes employee behaviour.

What "appropriate technical and organisational measures" actually requires under GDPR
· Kai Roer

What "appropriate technical and organisational measures" actually requires under GDPR

GDPR Article 32's “appropriate technical and organisational measures” includes a fourth subparagraph most organisations miss: proof your controls actually work.

Why training completion rates are not a security metric
· Kai Roer

Why training completion rates are not a security metric

Ninety per cent training completion tells you employees did the thing, not that anything changed. Under EU regulation, only effectiveness evidence counts. Here is why.

The difference between a compliance audit and security effectiveness monitoring
· Kai Roer

The difference between a compliance audit and security effectiveness monitoring

A compliance audit and continuous security monitoring answer different questions, and GDPR, NIS2, and DORA now require both. Here is the difference and why it matters.

What evidence does a NIS2 auditor actually want to see?
· Kai Roer

What evidence does a NIS2 auditor actually want to see?

A NIS2 policy is only the container. Article 21(2)(f) auditors want what is inside it: evidence your controls work. Here is what strong effectiveness evidence looks like.

The EU is suing France over NIS2. What that means for your board.
· Kai Roer

The EU is suing France over NIS2. What that means for your board.

The European Commission is taking France and three other states to court over NIS2. The real signal for boards is not the delay, but what enforcement now expects.

Three regulations. One question: can you prove your controls work?
· Kai Roer

Three regulations. One question: can you prove your controls work?

GDPR, NIS2, and DORA now converge on one demand: not whether you have security controls, but whether you can prove they work. Here is the evidence they require.

Receipts or Results – Part 3: Measuring Security Culture
· Thea Mannix

Receipts or Results – Part 3: Measuring Security Culture

Part 3 of the Receipts or Results series explores why one-size-fits-all security culture scoring fails, and how baseline-first measurement reveals meaningful behavioral change.

Receipts or Results – Part 2: The Wrong Metric for the Right Question
· Thea Mannix

Receipts or Results – Part 2: The Wrong Metric for the Right Question

Satisfaction surveys and post-training snapshots feel like progress but measure the wrong thing. Part 2 of the Receipts or Results series unpacks why culture change demands patience, behavioral signals, and a longer lens.

Receipts or Results – Part 1: The One-to-One Trap
· Thea Mannix

Receipts or Results – Part 1: The One-to-One Trap

Most human risk programs measure what they put in place, not what it did. This first instalment of the Receipts or Results series examines the one-to-one trap – the assumption that one activity metric maps directly to one outcome – and how to escape it.