Skip to content

Behavioral Risk Score

One number your board reads, with the maths shown

Most programmes report training completion, which measures attendance. The Behavioral Risk Score measures resilience: ten named factors resolved into a single A–F grade per person, team, department and organisation, benchmarked against your industry and traceable to the event that moved it.

10
graded factors
4
scope levels
A–F
band, not a percentage
B84 / 100Exposure3 factorsResilience3 factorsSusceptibility4 factors

Anatomy

Susceptibility, resilience and exposure

Susceptibility is what people fall for. Resilience is what they do about it. Exposure is how much attack surface their role carries. A programme that tracks only the first will always look worse than it is, and will never give credit to the team that reports fastest.

  • Each factor independently graded and drillable
  • Resilience is weighted, so reporting moves the grade
  • Exposure normalises for role, not for convenience
A90–100Resilient
B80–89Solid
C70–79Uneven
D60–69Exposed
F≤59Critical
01

Susceptibility

What people fall for

32/40
  • Susceptibility rate10
  • Credential-submit rate8
  • Repeat-clicker rate8
  • Time-to-click6
02

Resilience

What they do about it

22/30
  • Report rate9
  • Real-threat response7
  • Training completion6
03

Exposure

Surface their role carries

17/30
  • Multi-channel exposure7
  • Department risk5
  • Tenure / onboarding risk5
Ten factors, each weighted out of ten. Count the cells — the grade is arithmetic you can check, not a length you have to trust.

Trend

Movement, with a reference point

A score with nothing to compare it against is a vanity metric. Every grade ships beside your industry percentile and your own prior quarters, so the board conversation becomes what changed rather than whether the number is good.

  • Quarter-over-quarter deltas per department
  • Industry and organisation-size percentile
  • Written commentary generated with the export
0%10%20%30%40%Baseline: 33.2% phish-prone33.2%Baseline90 days: 20.1% phish-prone20.1%90 days12 months: 4.2% phish-prone4.2%12 months−87%
Phish-prone rate over 12 months of continuous simulation and training. Source: KnowBe4 2026 Phishing by Industry benchmark (33.2% → 20.1% → 4.2%).

Why letters

Design decisions we will defend

Each of these cost us something, and each one exists because the alternative produced worse behaviour.

Polarity

We grade resilience, not risk

Higher always means better. Competitor scales run higher-is-riskier, which reads backwards the moment a letter grade is attached to it.

Bands

A band absorbs noise

A percentage invites an argument about a two-point move that means nothing. A band moves when behaviour moves.

Traceability

Every grade drills to an event

No black box. A department's C resolves to the people, the campaigns and the timestamps that produced it.

Scope

Person to organisation

The same computation at four levels, so a manager and a CISO are looking at consistent arithmetic rather than two reports.

Governance

Individual results stay contained

Nothing publishes a person's failures to their colleagues. Manager scope is configurable and every cross-record view is logged.

Portability

The score leaves the platform

Read it over the API into your GRC tool or risk register, with the factor breakdown intact.

The ten factors

What goes into a grade

FactorGroupWhat it measures
Susceptibility rateSusceptibilityShare of simulations that resulted in a click
Credential-submit rateSusceptibilityClicks that went on to submit data
Time-to-clickSusceptibilityLatency between delivery and first interaction
Repeat-clicker rateSusceptibilityFailures by people who already failed once
Report rateResilienceSimulations reported rather than ignored
Real-threat responseResilienceGenuine threats reported through the add-in
Training completionResilienceAssigned modules finished within the window
Multi-channel exposureExposureBreadth of channels the person is reachable on
Tenure / onboarding riskExposureElevated risk in the first 90 days
Department riskExposureRole-level targeting attackers actually apply

Bands: A 90–100 · B 80–89 · C 70–79 · D 60–69 · F 59 and below, computed on the resilience score.

Questions

Asked on every first call

The ones that decide whether a first call turns into a second one.

3 questions

How is the Behavioral Risk Score calculated?

Ten factors across three groups — susceptibility, resilience and exposure — are each graded, weighted and combined into a resilience score from 0 to 100, which maps to an A–F band. It is computed identically at person, team, department and organisation level, and benchmarked against organisations of similar industry and size.

Why an A–F grade instead of a percentage?

Because a percentage invites arguments about noise. A band only changes when behaviour changes, and it reads correctly to a non-technical audience without a legend. We grade resilience rather than risk so higher is always better.

Can managers see individual scores?

Only within their own scope, and only if you enable it. Roles are organisation admin, department-scoped manager and employee. Every view of another person's record is written to the audit log, and the whole programme can run with individual results visible to the security team alone.

Get a provisional score on your own people

One campaign against a test group produces a real grade and the factor breakdown behind it.

See your human risk in 20 minutes

Book a demo and we’ll run a sample campaign against a test group.