Human Risk Management Platform

Your firewalls are world-class.
Attackers go around them.

AI-powered social engineering — deepfake calls, WhatsApp lures, QR drops — targets your people across 8 channels. NOUSEC tests, trains, and scores your workforce on every one, automatically.

GDPR ready · EU data residency (Frankfurt)

What is human risk management?

Human risk management is the practice of continuously measuring, scoring and reducing the risk created by how employees respond to real social engineering, rather than pushing training on a schedule. NOUSEC tests every employee across eight attack channels, assigns training from what they actually did, and federates the result into one Human Risk Score from 0 to 100 with a published methodology — per employee, per department, per company.

The Problem

The attack moved. Your defenses didn't.

1 in 3

employees click a phishing link when untested — a 33.2% average phish-prone rate before any testing begins (KnowBe4 2026 benchmark).

8 channels

attackers don’t stop at email. Most programs test one. 62% of organizations experienced a deepfake attack involving social engineering or exploiting automated processes (Gartner survey of 302 cybersecurity leaders, September 2025).

1 question

“Are we getting safer?” The board asks it every quarter. Siloed tools can’t answer it defensibly.

You can't reduce what you don't measure.
Security awareness without measurement is theater.

Platform

One platform. The entire human attack surface.

An AI engine runs the entire loop — generating simulations, scoring risk, building each employee's training program, and triaging reports — and plugs into the stack you already run: identity, mailboxes and your HR roster in, the score out to your SIEM.

The screens below are product demonstrations. Any attack messages shown are simulated examples generated by the NOUSEC platform — they are not real messages, and the senders and links in them are invented.

Live

Employees

RH
AK
MB
SC
JD
Security
awareness
Phishing
susceptibility
Policy
compliance
Personal program
Phishing basicsSocial engineeringPassword hygieneGenerated automatically
EmailSMSVoiceDeepfake voiceWhatsAppQRUSBCallback
Simulated example — NOUSEC product demo. Not a real message.NORDPOST: your parcel is held. Confirm the delivery address to release it.
Smishing simulation · SMS · sent to RH · just now
Lure deliveredReported
RHEmployee tapped “Report phishing”
No click, no credentials entered — the result is logged straight to the Human Risk Score.
Recognizing smishing+1 module
Micro-lesson · 2 min · auto-assigned from RH's gap
Branching scenario — “A courier texts you a link”
Tap the linkReport it
Susceptibility ticks −2; next module auto-queued
Invoice_Q4_final.pdfAI analyzing…
Reported from Outlook · routed to triage
Re: lunch Thursday?Safe — released
Auto-classified · employee notified
3h 40m analyst time saved this week
Programs — auto-scheduledUpdated automatically
Legal
Sales
Exec office
No spreadsheets, no manual enrolment — each program reschedules itself as behavior changes.
Board reportExport
48Learner 19 · 12 months
Company Human Risk Score · 12-month trend, all 8 channels federated

By department

Engineering
38
Finance
52
Sales
49
Legal
61
Exec office
46

Day-one assessment. AI turns each employee's results into a personal program, automatically.

Coverage

Every channel attackers use.

Email
SMS
Voice
Deepfake
WhatsApp
QR
USB
Callback
The Human Risk Score

How the Human Risk Score is built.

Every simulation, every report, every click — scored across all 8 channels and rolled up into a single measure of human risk.

48
Human Risk Score
Learner
19 · 12 months
Sources
SimulationsTrainingReportingCredential hygiene
Departments
Engineering
38
Finance
52
Sales
49
Legal
61
Exec office
46
Why NOUSEC

Why teams switch to NOUSEC

A score you can defend.

Published methodology, four measured sources, no black box.

Fits the stack you run.

Identity, mailboxes and your HR roster connect in; the score exports out to your SIEM.

8 attack channels.

Most platforms test one or two. Attackers don’t stop at email — neither do we.

Deepfake-grade realism.

Voice and video simulations your executives will believe — because attackers’ will be.

Day-one adaptive programs.

AI turns each assessment into a personalized program — zero admin effort.

Built for global teams.

GDPR native, EU data residency (Frankfurt), content in your employees’ native language.

Proof

Measured, not promised.

4.2%

average phish-prone rate after 12 months of continuous simulation and training — down from 33.2% at baseline (KnowBe4 Phishing by Industry Benchmarking Report 2026, 42M simulations)

  • Scoring methodology published openly — bring your security team’s hardest questions
  • Benchmarks anchored to public research (Verizon DBIR and large-scale industry phishing studies)
  • GDPR native — EU data residency in Frankfurt
  • See it live on your own tenant in a 30-minute demo
Questions

Human risk management, answered

What is human risk management?

Human risk management is the practice of continuously measuring, scoring and reducing the risk created by how employees respond to real social engineering — rather than pushing training on a schedule. It simulates real attacks across the channels attackers actually use, measures how people respond, quantifies that risk per employee and per department, and applies targeted training only where the data shows it is needed.

How is human risk management different from security awareness training?

Security awareness training pushes content to employees on a schedule. Human risk management is outcome-driven: the training is a component, not the programme. What decides who gets trained, when, and whether it worked is measured behaviour — not a compliance date.

What is a Human Risk Score and how is it calculated?

A Human Risk Score is a single, board-readable number that quantifies how vulnerable an organization's people are to social engineering. NOUSEC publishes the methodology openly: seven weighted components produce a 0–100 score — phishing behaviour 30%, training discipline 25%, endpoint 15%, identity hygiene 10%, data protection 10%, dark web exposure 10%, minus reporter contribution 10%. Reporting is the only component that subtracts, so employees who report suspicious messages lower their own score. Bands are Champion 0–25, Learner 26–50, At-Risk 51–74 and Critical 75–100. Four of the seven components are live today; endpoint, data protection and dark web exposure carry a published weight but no live feed yet.

Which social engineering channels can NOUSEC simulate?

Eight: email phishing, smishing (SMS), vishing (voice), deepfake voice and video, WhatsApp phishing, QR code phishing (quishing), USB drops, and callback scams (TOAD). Attackers don't stop at email — neither do the simulations.

Does security awareness training actually reduce phishing?

Not in the form most organizations run it. A 2025 randomized trial of more than 19,500 employees (Ho et al., IEEE Symposium on Security & Privacy) found no significant relationship between recently completing annual mandated training and failing a phishing simulation. What does move the number is continuous testing paired with training: across 42 million simulations, average phish-prone rates fell from 33.2% at baseline to 4.2% after twelve months (KnowBe4 Phishing by Industry Benchmarking Report 2026). The decisive variable is frequency and measurement, not course quality.

Do we need to install anything on employee devices?

No. There are no endpoint agents and no software installation is required. Deliverability setup is guided, and reporting works through one-click Gmail and Outlook add-ins.

Where is our data stored?

EU data residency in Frankfurt, GDPR native, with tenant-level data export and erasure available.

See your human attack surface for the first time.

A 30-minute walkthrough on your own tenant. No agents to install.

Book a demo