· Kai Roer

Meaningful Baselines for Human Factors: Here's How To Do It

The most important reason for a baseline is to be able to know that what you do is the right thing to do in human risk management cybersecurity.

Meaningful Baselines for Human Factors: Here's How To Do It

Understanding program effectiveness requires measurement before and after implementation. The initial measurement — called a baseline metric — establishes your starting point before changes take effect.

What is a Baseline?

A baseline captures the current state of your program at its inception. It may consist of single or multiple metrics, but should always feature data available throughout your program’s lifecycle. Critically, metrics must be both relevant and reliable rather than vanity metrics designed to present favorable appearances.

Selecting the Right Metrics

Focus on identifying specific metrics most likely to be influenced by the change — directly or indirectly. Start simply and expand gradually as your understanding deepens.

Recommended data sources include:

  • Employee engagement measurements (surveys, completion rates, quality scoring)
  • Specialized assessments (workplace surveys, skills evaluations)
  • Behavioral assessments (phishing testing)
  • Actual behavioral data from system logs
  • Multiple datasets for comprehensive understanding
  • Modern analytical tools for sentiment analysis and risk modeling

Why Baselines Matter

Establishing a baseline serves four primary purposes:

  1. Track progress against a comparison point, enabling course corrections during implementation
  2. Understand current conditions to inform decision-making and validate planned interventions
  3. Guide program design by aligning activities with employee and organizational needs
  4. Demonstrate effectiveness through measurable before-and-after comparisons

The fundamental value lies in confirming your interventions achieve intended outcomes while enabling continuous program improvement.

Ready to measure your security culture?

Connect your Microsoft 365 and see months of employee security behavior data in 15 minutes. Free 30-day trial.

Start Free Trial