The most attacked surface in your company, finally scored.
Firewalls have dashboards. Endpoints have coverage metrics. Your people — the surface attackers actually target — usually have nothing. The Human Risk Score fixes that: one number your board can read, built on a methodology your security team can interrogate.
Five risk sources, one canonical number
A score you can defend has to come from behavior, not questionnaires. Every source below is measured continuously.
Built to survive board scrutiny
A metric only works if leadership trusts it. The Human Risk Score is designed for the three questions every board asks.
Frequently asked questions
What is a Human Risk Score?
A Human Risk Score is a single, board-readable number that quantifies how vulnerable an organization's people are to social engineering. NOUSEC federates five risk sources — simulation results, training progress, reporting behavior, dark web exposure, and signals from your existing security stack — into one score per employee, per department, and per company.
How is the score calculated?
The methodology is published openly: each risk source contributes weighted signals, normalized against industry baselines, and federated into a canonical score. No black box — bring your security team's hardest questions.
Can we compare our score against other companies?
Yes. Scoring is benchmarked against industry baselines such as the Verizon DBIR, so leadership sees not just an internal trend but where the organization stands against its sector.
How often does the score update?
Continuously. Every simulation result, completed training, reported message, and new exposure signal updates the score — so it behaves like the security metrics your team already trends, not an annual audit artifact.
See a live Human Risk Score built from your industry's benchmark data — in a 20-minute demo.
Book a demo