Human Risk ScoreThe most attacked surface in your company, finally scored.

Every vendor shows you a number. This one shows its arithmetic — seven weighted components, published, with reporting as the only one that subtracts.

GDPR ready · EU data residency (Frankfurt)
SCORE ARITHMETIC48LearnerChampion 0–25 · Learner 26–50At-Risk 51–74 · Critical 75–100Phishing behaviour30%Training discipline25%Endpoint15%Identity hygiene10%Data protection10%Dark web exposure10%Reporter contribution−10%the only component that runs the other wayReport an attack and your own score falls.
SCORE ARITHMETIC48LearnerChampion 0–25Learner 26–50At-Risk 51–74Critical 75–100Phishing behaviour30%Training discipline25%Endpoint15%Identity hygiene10%Data protection10%Dark web exposure10%Reporter contribution−10%the only one that runs the other wayReport an attack and your own score falls.
4
risk sources measured directly today — three more on the roadmap
3
levels of granularity: employee, department, company
100%
published methodology — no black box

How the Human Risk Score is calculated

Seven weighted components on a 0–100 scale, identical on every surface. Six add to the score. One — reporting a suspicious message — is the only component that subtracts, so the people who raise their hand lower their own number. Four of the seven are live today: endpoint, data protection and dark-web exposure are marked below, because publishing a weight is not the same as claiming the signal is already flowing.

Human Risk Score component weights
Phishing behaviourClicks, credential entry and callback engagement across all eight simulated channels.
30%
Training disciplineAssignment completion, time on content, and the skipped / fast-clicker rate.
25%
EndpointMalware and control-failure signals from the endpoint tooling you already run.not yet connected
15%
Identity hygieneMFA posture, password practice and directory-visible account hygiene, from directory sync.
10%
Data protectionDLP and data-handling signals from your existing security stack.not yet connected
10%
Dark web exposureCredentials and employee data surfacing in breach dumps.not yet connected
10%
Reporter contributionThe only component that runs the other way. Report an attack and your own score falls.
−10%
BandsChampion0 – 25Learner26 – 50At-Risk51 – 74Critical75 – 100

Breach and dark-web exposure, once it is ingested, is deliberately kept out of personal blame — someone whose address appeared in a 2017 dump did not choose to be there. Where a signal source is not yet connected, the product says so rather than defaulting the score, and so does this page: see what we do not connect to.

Four risk sources, one canonical number

Four sources are measured continuously today, and they are the four NOUSEC observes itself. A score you can defend has to come from behavior, not questionnaires — and not from a connector that has not shipped.

Source 1
Simulation results
How each employee actually responds to realistic attacks across 8 channels — clicks, credential entry, callback engagement, and resistance over time.
Source 2
Training signals
Progress and decay: adaptive micro-training completion, scenario outcomes, and how quickly knowledge fades without reinforcement.
Source 3
Reporting behavior
The strongest positive signal: who reports suspicious contact, and how fast. A reporting workforce is a detection network.
Source 4
Credential hygiene
MFA posture, password practice and directory-visible account hygiene, read from the identity directory you already sync.
Not connected yet
Endpoint, DLP, dark web
Three components carry a published weight but no live feed: endpoint, data protection and dark-web exposure. They are on the roadmap. Until they ship we name the gap rather than imply a connector — see what we do not connect to.
Output
Federated score
Per user, per department, per company — normalized, trended, and benchmarked against industry baselines like the Verizon DBIR.

The scoring method itself — which signals to use, how to weight them, and how to report the result to a board — is set out in our guide to calculating a human risk score.

Built to survive board scrutiny

A metric only works if leadership trusts it. The Human Risk Score is designed for the three questions every board asks.

“Where are we today?”
One current score, with department-level drill-down that shows exactly where risk concentrates — finance, executive assistants, new joiners.
“Are we improving?”
Continuous measurement makes the score trendable month over month — the difference between reporting activity and reporting outcomes.
“How do we compare?”
Benchmarked against industry baselines, so the answer is a position, not a feeling.

Frequently asked questions

What is a Human Risk Score?

A Human Risk Score is a single, board-readable number that quantifies how vulnerable an organization's people are to social engineering. NOUSEC federates four continuously measured sources — simulation results across eight channels, training activity and completion verified server-side, reporting behavior, and credential hygiene from directory sync — into one score per employee, per department, and per company.

How is the score calculated?

The methodology is published openly. Seven weighted components produce a 0–100 score: phishing behaviour 30%, training discipline 25%, endpoint 15%, identity hygiene 10%, data protection 10%, dark web exposure 10%, minus reporter contribution 10%. Reporting is the only component that subtracts, so employees who report suspicious messages lower their own score. Bands are Champion 0–25, Learner 26–50, At-Risk 51–74 and Critical 75–100. No black box — bring your security team's hardest questions.

Are all seven components live today?

No, and we would rather say so. Four are live: phishing behaviour, training discipline, identity hygiene and reporter contribution. Endpoint 15%, data protection 10% and dark web exposure 10% carry a published weight but no live feed yet — those ingestions are on the roadmap, and the component table marks them as not yet connected. Where a source is not connected, the product says so rather than defaulting the score.

Can we compare our score against other companies?

Yes. Scoring is benchmarked against industry baselines such as the Verizon DBIR, so leadership sees not just an internal trend but where the organization stands against its sector.

How often does the score update?

Continuously. Every simulation result, completed training and reported message updates the score — so it behaves like the security metrics your team already trends, not an annual audit artifact.

Know your human risk. Then lower it.

See a live Human Risk Score built from your industry's benchmark data — in a 20-minute demo.

Book a demo