Behavioral Risk Score
One number your board reads, with the maths shown
Most programmes report training completion, which measures attendance. The Behavioral Risk Score measures resilience: ten named factors resolved into a single A–F grade per person, team, department and organisation, benchmarked against your industry and traceable to the event that moved it.
- 10
- graded factors
- 4
- scope levels
- A–F
- band, not a percentage
Anatomy
Susceptibility, resilience and exposure
Susceptibility is what people fall for. Resilience is what they do about it. Exposure is how much attack surface their role carries. A programme that tracks only the first will always look worse than it is, and will never give credit to the team that reports fastest.
- Each factor independently graded and drillable
- Resilience is weighted, so reporting moves the grade
- Exposure normalises for role, not for convenience
- Susceptibility rate10
- Credential-submit rate8
- Repeat-clicker rate8
- Time-to-click6
- Report rate9
- Real-threat response7
- Training completion6
- Multi-channel exposure7
- Department risk5
- Tenure / onboarding risk5
Trend
Movement, with a reference point
A score with nothing to compare it against is a vanity metric. Every grade ships beside your industry percentile and your own prior quarters, so the board conversation becomes what changed rather than whether the number is good.
- Quarter-over-quarter deltas per department
- Industry and organisation-size percentile
- Written commentary generated with the export
Why letters
Design decisions we will defend
Each of these cost us something, and each one exists because the alternative produced worse behaviour.
We grade resilience, not risk
Higher always means better. Competitor scales run higher-is-riskier, which reads backwards the moment a letter grade is attached to it.
A band absorbs noise
A percentage invites an argument about a two-point move that means nothing. A band moves when behaviour moves.
Every grade drills to an event
No black box. A department's C resolves to the people, the campaigns and the timestamps that produced it.
Person to organisation
The same computation at four levels, so a manager and a CISO are looking at consistent arithmetic rather than two reports.
Individual results stay contained
Nothing publishes a person's failures to their colleagues. Manager scope is configurable and every cross-record view is logged.
The score leaves the platform
Read it over the API into your GRC tool or risk register, with the factor breakdown intact.
The ten factors
What goes into a grade
| Factor | Group | What it measures |
|---|---|---|
| Susceptibility rate | Susceptibility | Share of simulations that resulted in a click |
| Credential-submit rate | Susceptibility | Clicks that went on to submit data |
| Time-to-click | Susceptibility | Latency between delivery and first interaction |
| Repeat-clicker rate | Susceptibility | Failures by people who already failed once |
| Report rate | Resilience | Simulations reported rather than ignored |
| Real-threat response | Resilience | Genuine threats reported through the add-in |
| Training completion | Resilience | Assigned modules finished within the window |
| Multi-channel exposure | Exposure | Breadth of channels the person is reachable on |
| Tenure / onboarding risk | Exposure | Elevated risk in the first 90 days |
| Department risk | Exposure | Role-level targeting attackers actually apply |
Bands: A 90–100 · B 80–89 · C 70–79 · D 60–69 · F 59 and below, computed on the resilience score.
Questions
Asked on every first call
The ones that decide whether a first call turns into a second one.
3 questions
How is the Behavioral Risk Score calculated?
Ten factors across three groups — susceptibility, resilience and exposure — are each graded, weighted and combined into a resilience score from 0 to 100, which maps to an A–F band. It is computed identically at person, team, department and organisation level, and benchmarked against organisations of similar industry and size.
Why an A–F grade instead of a percentage?
Because a percentage invites arguments about noise. A band only changes when behaviour changes, and it reads correctly to a non-technical audience without a legend. We grade resilience rather than risk so higher is always better.
Can managers see individual scores?
Only within their own scope, and only if you enable it. Roles are organisation admin, department-scoped manager and employee. Every view of another person's record is written to the audit log, and the whole programme can run with individual results visible to the security team alone.
Keep reading
Related
Get a provisional score on your own people
One campaign against a test group produces a real grade and the factor breakdown behind it.