Human Risk Score

The most attacked surface in your company, finally scored.

Firewalls have dashboards. Endpoints have coverage metrics. Your people — the surface attackers actually target — usually have nothing. The Human Risk Score fixes that: one number your board can read, built on a methodology your security team can interrogate.

5
risk sources federated — plus signals from your existing stack
3
levels of granularity: employee, department, company
100%
published methodology — no black box

Five risk sources, one canonical number

A score you can defend has to come from behavior, not questionnaires. Every source below is measured continuously.

Source 1
Simulation results
How each employee actually responds to realistic attacks across 8 channels — clicks, credential entry, callback engagement, and resistance over time.
Source 2
Training signals
Progress and decay: adaptive micro-training completion, scenario outcomes, and how quickly knowledge fades without reinforcement.
Source 3
Reporting behavior
The strongest positive signal: who reports suspicious contact, and how fast. A reporting workforce is a detection network.
Source 4
Dark web exposure
Leaked credentials and employee data surfacing in breach dumps — exposure that raises risk before any attack lands.
Source 5
Your security stack
Signals from IAM, email security, endpoint, and DLP feed the score, so it reflects your real environment — not a lab.
Output
Federated score
Per user, per department, per company — normalized, trended, and benchmarked against industry baselines like the Verizon DBIR.

Built to survive board scrutiny

A metric only works if leadership trusts it. The Human Risk Score is designed for the three questions every board asks.

“Where are we today?”
One current score, with department-level drill-down that shows exactly where risk concentrates — finance, executive assistants, new joiners.
“Are we improving?”
Continuous measurement makes the score trendable month over month — the difference between reporting activity and reporting outcomes.
“How do we compare?”
Benchmarked against industry baselines, so the answer is a position, not a feeling.

Frequently asked questions

What is a Human Risk Score?

A Human Risk Score is a single, board-readable number that quantifies how vulnerable an organization's people are to social engineering. NOUSEC federates five risk sources — simulation results, training progress, reporting behavior, dark web exposure, and signals from your existing security stack — into one score per employee, per department, and per company.

How is the score calculated?

The methodology is published openly: each risk source contributes weighted signals, normalized against industry baselines, and federated into a canonical score. No black box — bring your security team's hardest questions.

Can we compare our score against other companies?

Yes. Scoring is benchmarked against industry baselines such as the Verizon DBIR, so leadership sees not just an internal trend but where the organization stands against its sector.

How often does the score update?

Continuously. Every simulation result, completed training, reported message, and new exposure signal updates the score — so it behaves like the security metrics your team already trends, not an annual audit artifact.

Know your human risk. Then lower it.

See a live Human Risk Score built from your industry's benchmark data — in a 20-minute demo.

Book a demo