Skip to main content

Every exercise is indexed by name, CWE, OWASP, MITRE ATT&CK, CIS, NIST CSF, GDPR and EU AI Act reference.

Try

The human risk loop

Human Risk Management

Most breaches start with a person, not a server. Human risk management is how you measure that risk for every employee and bring it down on purpose: run real phishing simulations, score who is actually at risk, and automate the training that fixes it.

Human risk management loop: phishing simulations feed a per-person human risk score, the score triggers risk-based automation, automation assigns interactive training, and the loop repeats as measured risk falls over time

How human risk management works at RansomLeak

One closed loop: surface real behavior, measure it, act on it, and watch risk fall.

01

Simulate

Run phishing and smishing simulations that put employees inside a realistic attacker pretext. Their decisions, not a questionnaire, become the raw signal.

02

Measure

Every person gets an explainable 0 to 100 human risk score built from how they behaved, whether they reported the lure, and whether their training is current.

03

Automate

No-code rules act on the score: auto-enroll a high-risk person in remediation the moment they fail a simulation, with dry-run, an audit log, and a kill switch.

04

Reduce

Interactive 3D exercises build the instinct, the next simulation re-tests it, and the score moves. You manage a trend line, not a one-off training event.

Score every person from 0 to 100

A risk number nobody can defend is a number nobody acts on. Every score traces back to the behavior behind it.

Risk Score dashboard showing the organization average, the count of people scored, the limited-data count, a banded distribution across Low, Moderate, High, and Critical with per-band counts, and an area chart of the average risk over time

A score per person, grounded in behavior

Each employee is rated 0 to 100 from real simulation outcomes, phish reports, and training status. Higher means riskier, and everyone lands in a Low, Moderate, High, or Critical band.

Four sub-scores, weighted by what predicts failure

Susceptibility from simulation outcomes, remediation debt from overdue follow-ups, training hygiene, and external signals from your own stack. Susceptibility carries the most weight because it tracks real failure.

Recent behavior counts most

Every signal fades on a roughly 90-day half-life, so a slip last week weighs more than one last year and people who improve watch their score fall. Scores recompute nightly, and again in real time after a serious failure.

Confidence, and Limited data instead of a guess

Each score carries a confidence rating, and someone with too little history is labeled Limited data rather than assumed safe. A sub-score with no data drops out of the calculation instead of dragging the total to a false middle.

Every score shows its work

A risk number nobody can explain is a number nobody trusts. Each score opens to the evidence behind it.

Why this score dialog showing a per-person risk breakdown: total score with confidence and band, four weighted sub-scores for phishing susceptibility, remediation debt, training hygiene, and external signals, the risk multipliers applied for elevated privileges, the top factors driving the score, and the signals used to compute it

Top factors, in plain terms

Open any score to see the sub-scores, their weights, and the specific events pushing it up or down, like a clicked credential lure three weeks ago, two overdue lessons, or a true-positive SOC alert on their laptop.

No black box

Managers and admins can trace any score back to the exact simulations, reports, and lessons behind it. There is no hidden model output to take on faith, and admins can tune the weights, bands, and half-life.

No dark web, no OSINT, no profiling

Scores are built only from behavior inside your own program, plus signals you choose to send. Nothing is scraped or bought, so every point is explainable for works-council and privacy review.

Bring the signals you already collect

Most security teams already know who signs in from odd places and whose laptop the SOC keeps investigating. Push that in and the score uses it.

Scoring settings dialog listing the external signal catalog grouped by category, with phishing, identity, security operations, training, and privilege signals each toggled on, and a button to add a custom signal

Push from the stack you have

Send signals over a token-authenticated REST API from your SIEM, your identity provider, or a script, or upload a CSV. A dry run shows exactly what will be recorded, and who it could not match, before anything lands.

Signals we already understand

Risky sign-ins from Entra or AD, true-positive SOC alerts by account and device, accounts disabled for training non-compliance, and privileges like local admin or USB access, which act as multipliers so an admin who slips counts as a bigger exposure than a standard user who slips.

Define your own

Anything the catalog does not cover becomes a custom signal type you define in the console with your own severity, with no work from us. Send nothing at all and every score stays exactly as it is today.

See risk across the whole organization

Roll the score up from one person to a team to the entire workforce, and watch the trend instead of a single snapshot.

Teams-by-risk table with the riskiest team at the top showing average score and band, alongside a People table listing the highest-risk individuals with their team, score, band, and confidence

Org and team rollups

See the average score, the spread across Low to Critical bands, and the trend over time for the whole organization and for each team.

Find who needs attention

A roster sorted riskiest first puts the handful of people who actually move the number at the top, so a program manager knows exactly where to spend time.

Private by default

Managers see only their own direct reports. Individual scores are gated behind a permission, and everyone else sees aggregates, in line with works-council and GDPR expectations.

Act on the score automatically

A risk number is only useful if something happens next. No-code rules turn the score into the right intervention.

Risk-automation rules table with a per-run safety cap, a minimum allowance, and three enabled rules for critical-risk auto-enrollment, a high-risk manager alert, and a repeat-offender escalation, each showing its trigger and action

Auto-enroll the right training

When someone crosses a band or score threshold, enroll them in a remediation learning path with a deadline and a grace period, then track it to completion.

Just-in-time remediation

The moment a person fails a phishing simulation, assign the lesson that drills the exact pattern they fell for, while it is still fresh.

Manager escalation

A daily digest tells each manager which of their direct reports are at elevated risk, with an in-app alert, so the conversation happens close to the person.

Rules follow the score, not a list

A rule re-evaluates the whole workforce every night, so people flow into action as their risk rises and out of it as they improve. You set the threshold once, and a repeat-offender circuit breaker routes chronic failures to a manager instead of an endless loop of nudges.

Automation a CISO can sign off on

Most automation asks you to trust it. This one asks you to check it first, then proves what it did.

Stuck people queue listing failed auto-enrollments next to an action log showing chronological outcomes: enrolled, manager alerted, skipped for cooldown, skipped for low confidence, and a whole run skipped by the safety cap, each labeled as a simulated dry-run entry

Dry-run before live

Simulate any rule against your real population and read the outcome before anything happens. No emails go out and no enrollments are created, and the same run in live mode is the one you already reviewed.

Every action logged

A full audit trail records who was enrolled or escalated, when, and why, with a simulated marker on dry-run entries. It is the evidence trail an auditor asks for.

Guardrails that hold

A blast-radius cap stops a bad rule from actioning the whole company in one run, cooldowns prevent repeat nudges, a recovery check waits for genuine improvement, and a global kill switch halts all automation at once.

Build the human firewall

Measurement and automation only pay off if the training changes behavior. That is where the loop closes.

An interactive 3D training scene where an employee inspects a suspicious email at a simulated Windows desktop inside a rendered office, performing the action rather than watching a slideshow

Interactive 3D exercises

Remediation routes into interactive 3D training where people perform the action under a real lure instead of watching a slideshow, so the instinct sticks.

A full security awareness program

Human risk management wraps your whole security awareness training catalogue: phishing, ransomware, social engineering, privacy, and AI security.

Re-tested, not assumed

After training, the next simulation re-tests the same person, and a falling score is your proof that the behavior actually changed.

Human risk management vs security awareness training

Training is one input. Human risk management is the program that decides who gets it, and proves it worked.

Human risk management

  • Scores every person 0 to 100 from real behavior under a live lure
  • Targets the small group that carries most of the exposure
  • Triggers training automatically when someone crosses a risk threshold
  • Re-tests the same person afterwards and shows whether risk fell
  • Produces a trend line a board can read

Security awareness training on its own

  • Assigns the same modules to everyone on a fixed calendar
  • Measures completion, which says nothing about susceptibility
  • Treats a repeat clicker and a consistent reporter identically
  • Ends when the course ends, with no re-test
  • Produces a compliance record rather than a risk signal

What is human risk management?

Human risk management is a security program that measures how likely each employee is to fall for an attack, then reduces that risk with targeted training and automation. It treats human risk as a number you can track per person, not a compliance box you tick once a year.

The loop

  • Simulate
  • Measure
  • Automate
  • Reduce

Risk is never spread evenly across a workforce. A small group of repeat clickers carries most of the exposure, and the Verizon 2024 Data Breach Investigations Report found a human element in 68% of breaches, so the program only pays off if it can tell those people apart from everyone else.

RansomLeak runs it as one closed loop. Phishing simulations surface real behavior, a human risk score measures it per person, risk-based automation assigns the training that brings the score down, and the next simulation re-tests the same person.

Frequently asked questions

How is human risk management different from security awareness training?

Security awareness training is the content that teaches employees to spot attacks. Human risk management is the program around it: it measures who is at risk, decides who needs which training, and shows whether risk actually fell.

Put simply, training is one input. HRM adds measurement through the score, behavior through simulations, and action through automation, so you target effort instead of assigning the same module to everyone.

How do you measure human risk?

RansomLeak gives every person a 0 to 100 human risk score built from four inputs: how they act in phishing simulations, whether they report suspicious messages, whether their training and remediation are current, and any signals your own security tools push in, such as risky sign-ins or true-positive SOC alerts.

Recent behavior counts most, so each signal fades on a roughly 90-day half-life and people who improve watch their score fall. Higher means riskier, and everyone lands in a Low, Moderate, High, or Critical band.

What is a human risk score?

A human risk score is a number, usually on a 0 to 100 scale, that estimates how likely a specific employee is to fall for a social-engineering attack like phishing. A higher score means higher risk.

RansomLeak builds the score from how each person behaves in phishing simulations, whether they report suspicious messages, and whether their training and remediation are up to date. It is the measurement layer of the wider human risk management program.

How is the human risk score calculated?

Four sub-scores feed the total. Susceptibility comes from phishing-simulation outcomes, from opened through clicked to credential submitted. Remediation debt comes from overdue or failed follow-up training. Training hygiene comes from overdue mandatory lessons, weak quiz results, and failed drills. External signals come from whatever your own security tools push in, such as risky sign-ins and SOC alerts.

Susceptibility carries the most weight because it tracks real failure, and every signal decays on a roughly 90-day half-life so recent behavior dominates. A sub-score with no data drops out of the calculation instead of dragging a score to a false middle, and admins can tune the weights, bands, half-life, and which signals count at all.

Does a higher score mean more or less risk?

Higher means riskier. A score near 100 marks someone who has recently failed simulations and has training debt, while a score near 0 marks someone who consistently spots and reports lures.

People sit in one of four bands, Low, Moderate, High, or Critical, so you can act on a band without arguing over single points.

How often does the score update?

Scores recompute every night, and they also update in near real time after a high-impact event such as submitting credentials to a simulated lure or completing a remediation path.

So a serious failure shows up the same day rather than waiting for the next campaign cycle.

Do you use dark web or OSINT data to score people?

No. We do not pull breach databases, social-media footprints, or any other external profiling, and we never buy data about your people.

The score is built from behavior inside your own program, simulation results, phish reports, and training status, plus any signals you choose to push in from your own security tools, such as a risky sign-in from Entra or a true-positive SOC alert. That is your data, sent deliberately by you, not a profile assembled about your employees.

It keeps the score explainable and defensible. Every point traces back to an action the person took or a signal your own stack raised, which matters for works-council and privacy review.

Can I feed the score with signals from my own security tools?

Yes. Signals are pushed to RansomLeak over a token-authenticated REST API or uploaded as a CSV, so your SIEM, your identity provider, or a small script can send them. No raw logs leave your estate: you send a signal type, a timestamp, and a severity, plus any context you choose to include.

The catalog already covers risky sign-ins, true-positive SOC alerts, accounts disabled for training non-compliance, privileges such as local admin or USB access, and phishing outcomes from a simulation tool you already run. Anything else can be added as a custom signal type with its own severity. Every imported signal shows up in that person’s score breakdown, so an admin can see exactly what arrived and when.

What is risk-based automation?

Risk-based automation triggers security-awareness actions automatically based on a person’s measured risk instead of a fixed calendar. When someone becomes high risk, the platform can enroll them in training or alert their manager without anyone filing a ticket.

Three actions are live today. It can auto-enroll a person in a remediation learning path with a deadline, remediate a failed phishing simulation the moment it happens, and escalate at-risk direct reports to their manager through a daily digest and an in-app alert.

Every action is logged, and an enrollment can be dismissed by a human if the situation calls for it.

What triggers an automation?

A rule fires when a person crosses a risk band, such as reaching High, or a numeric score threshold. You can add conditions: a minimum confidence so the rule waits for enough data, or a factor bypass so a serious event like a submitted credential acts immediately.

Rules are evaluated every night and again in real time right after a serious failure. Because the underlying score can also take in signals from your own security tools, a rule can react to a risky sign-in or a true-positive SOC alert without you building a separate workflow.

Can I test a rule before it affects anyone?

Yes, and you should. Every rule can run in dry-run mode, which shows exactly who it would match and what it would do while sending no emails and creating no enrollments.

When you switch a rule to live, it behaves the way the dry-run showed, so there are no surprises.

What stops it from over-emailing or over-enrolling people?

Several guardrails. A blast-radius cap stops a single run from actioning more than a set share of the workforce, per-person cooldowns prevent repeat nudges, and a recovery check keeps someone from being actioned again until they have genuinely improved.

A global kill switch can stop all automation at once if you need it to.

Does it automatically change phishing difficulty for risky users?

Not today. Risk-based automation focuses on training enrollment, just-in-time remediation, and manager escalation. Adapting simulation cadence per user is on the roadmap, not a current claim.

We would rather ship the automation that is genuinely live than market one that is not.

Do I need phishing simulations for human risk management?

Yes. The program runs on real behavior, and phishing simulations are the primary source. Without them there is nothing to measure, so the score and its automation are part of the simulation add-on rather than basic training alone.

If you already run simulations in another tool, you can import those outcomes instead of re-running campaigns here, and they feed the same susceptibility score.

Is human risk management just another dashboard?

No. A dashboard shows you a number. RansomLeak closes the loop: it measures risk, acts on it automatically, and re-tests the result, so the score is tied to interventions rather than just reported.

It is also built to be defensible. Scores are behavior-based and explainable, automation is governed with dry-run and audit logs, and individual scores stay private by default in line with GDPR and works-council expectations.

See RansomLeak in Action

Try the free exercises or book a demo to see analytics, SCORM export, SSO, and custom content in your environment.