“We did the training” is a receipt. What leadership, clients, and insurers increasingly want is a reading — a human risk score that says how exposed the organization is right now and which direction it’s heading. If human risk isn’t a number that moves month over month, it isn’t being managed; it’s being documented. Here’s how to build that number: what goes into it, how to baseline it, and how to make it move.
Why does human risk need to be a number?
Because numbers get managed and narratives get filed. Every other risk the business runs — uptime, revenue, pipeline, patching — lives on a dashboard as a metric someone owns. Human risk alone gets reported as an activity (“annual training: complete”) rather than a state (“how likely is our next incident to start with a person, and is that likelihood shrinking?”). That’s the theater problem we took apart in Why Annual Security Training Is Theater — and the exit from theater is measurement.
A score does three jobs at once: it makes the risk visible to leadership, comparable across teams and time, and provableto the people who now ask — clients running security reviews and insurers writing applications.
What signals feed a human risk score?
Behavior, not attendance. The inputs worth weighting:
Phishing outcomes — both directions. Click rate on simulations is the famous one, but report rate and report speedmatter more: a workforce that flags a suspicious email in minutes is a detection system. Weight reporting positively; don’t just penalize clicks.
Credential hygiene. Exposed credentials appearing in breach data, password reuse where it’s detectable, and MFA coverage across accounts — the single highest-leverage control on the list.
Data handling. Misdirected sends, risky sharing, unsanctioned tools — the quiet, unglamorous incidents that never make the threat reports but generate real exposure.
Role and access weighting. A click from someone with wire authority or admin access is not the same score event as a click from someone without. Weight people by what their compromise would reach — blast-radius thinking applied to humans.
Trend, not snapshot. The score’s movement is the product. A 72 means little; “72, up from 58 two quarters ago” is a managed risk.
How do you build and run the score? Five steps.
- Baseline silently. Measure a full cycle — simulations, credential scans, reporting rates — before any new training or announcements, or you’ll never know what moved the number. This is the baseline-before-you-train rule from What Is Human Risk Management.
- Compose the score simply. A weighted blend of the four signal families above, normalized to 0–100, computed per person, rolled up per team and organization. Resist sophistication; a simple score consistently measured beats an elegant one nobody maintains.
- Set the cadence monthly. Quarterly is too slow to connect cause and effect; weekly is noise. Monthly readings, quarterly reviews.
- Intervene where the score points. The number’s purpose is targeting: the team trending down gets attention, the individual with repeat clicks gets a different conversation than the one who reports everything. Interventions triggered by data — training included, demoted to a tool.
- Publish the trend. Leadership sees the org line monthly. Teams see their own. Individuals see theirs privately. What’s watched, moves.
What are the traps?
- Punishing the score down. If clicking a simulation gets people shamed, they stop reporting real phish — you’ve optimized for hiding, the worst possible outcome. Score events must be safe to generate.
- Gaming by easy sims. Softball simulations make everyone look great and measure nothing. Difficulty should mirror what’s actually arriving in inboxes.
- Completion creep. The old metric sneaks back in (“95% finished the module!”). Completion can feed the score at low weight; it can never be the score.
- Snapshot worship. One good month is weather. The trend is climate — manage the climate.
Why should providers care doubly?
Because for agencies, MSPs, and consultants, the score is sellable twice. Once internally: your own team’s score is your answer when a client’s security review asks how you manage the humans holding keys to their environment. And once as a service: “your organization’s human risk score, measured monthly, trending down” is a line item clients understand instantly and renew reliably — the exact shape of recurring, provable value we described in Add Recurring Revenue Without Hiring Engineers. Continuous measurement across many environments is platform work, not analyst work — it’s the layer Centry Smart runs, scored in language clients can read.
“We did the training” answers a question nobody’s really asking anymore. The question now is “what’s your number, and which way is it moving?” Build the score, baseline it honestly, make it move, and put the trend in front of everyone who needs to trust you. The full program around it: What Is Human Risk Management.
Was this article helpful?
Thanks for your feedback.
Have a question about this topic?
