How the Human Risk Score is calculated
Seven weighted components on a 0–100 scale, identical on every surface. Six add to the score. One — reporting a suspicious message — is the only component that subtracts, so the people who raise their hand lower their own number. Four of the seven are live today: endpoint, data protection and dark-web exposure are marked below, because publishing a weight is not the same as claiming the signal is already flowing.
| Phishing behaviour | Clicks, credential entry and callback engagement across all eight simulated channels. | 30% |
|---|---|---|
| Training discipline | Assignment completion, time on content, and the skipped / fast-clicker rate. | 25% |
| Endpoint | Malware and control-failure signals from the endpoint tooling you already run.not yet connected | 15% |
| Identity hygiene | MFA posture, password practice and directory-visible account hygiene, from directory sync. | 10% |
| Data protection | DLP and data-handling signals from your existing security stack.not yet connected | 10% |
| Dark web exposure | Credentials and employee data surfacing in breach dumps.not yet connected | 10% |
| Reporter contribution | The only component that runs the other way. Report an attack and your own score falls. | −10% |
Breach and dark-web exposure, once it is ingested, is deliberately kept out of personal blame — someone whose address appeared in a 2017 dump did not choose to be there. Where a signal source is not yet connected, the product says so rather than defaulting the score, and so does this page: see what we do not connect to.
Four risk sources, one canonical number
Four sources are measured continuously today, and they are the four NOUSEC observes itself. A score you can defend has to come from behavior, not questionnaires — and not from a connector that has not shipped.
The scoring method itself — which signals to use, how to weight them, and how to report the result to a board — is set out in our guide to calculating a human risk score.
Built to survive board scrutiny
A metric only works if leadership trusts it. The Human Risk Score is designed for the three questions every board asks.
Frequently asked questions
What is a Human Risk Score?
A Human Risk Score is a single, board-readable number that quantifies how vulnerable an organization's people are to social engineering. NOUSEC federates four continuously measured sources — simulation results across eight channels, training activity and completion verified server-side, reporting behavior, and credential hygiene from directory sync — into one score per employee, per department, and per company.
How is the score calculated?
The methodology is published openly. Seven weighted components produce a 0–100 score: phishing behaviour 30%, training discipline 25%, endpoint 15%, identity hygiene 10%, data protection 10%, dark web exposure 10%, minus reporter contribution 10%. Reporting is the only component that subtracts, so employees who report suspicious messages lower their own score. Bands are Champion 0–25, Learner 26–50, At-Risk 51–74 and Critical 75–100. No black box — bring your security team's hardest questions.
Are all seven components live today?
No, and we would rather say so. Four are live: phishing behaviour, training discipline, identity hygiene and reporter contribution. Endpoint 15%, data protection 10% and dark web exposure 10% carry a published weight but no live feed yet — those ingestions are on the roadmap, and the component table marks them as not yet connected. Where a source is not connected, the product says so rather than defaulting the score.
Can we compare our score against other companies?
Yes. Scoring is benchmarked against industry baselines such as the Verizon DBIR, so leadership sees not just an internal trend but where the organization stands against its sector.
How often does the score update?
Continuously. Every simulation result, completed training and reported message updates the score — so it behaves like the security metrics your team already trends, not an annual audit artifact.
See a live Human Risk Score built from your industry's benchmark data — in a 20-minute demo.
Book a demo