A human risk score is calculated by combining each employee's phishing simulation results (clicks, reports and reporting speed), training completion records and sometimes policy acknowledgements into a single rating — usually expressed from 0 to 100 or low/medium/high — where a lower score means riskier behaviour. There is no universal standard formula: every platform weights the inputs differently, which is why transparency about the weighting matters more than the number itself. The sections below break down the typical inputs, weightings and uses in 2026.
How is a human risk score calculated?
Most platforms pull from the same small set of behavioural inputs:
| Input | What it measures | Typical signal |
|---|---|---|
| Phishing click rate | Did the person click simulated lures | The heaviest weighted input |
| Phishing report rate | Did they report the simulation | The strongest positive signal |
| Time to report | How fast a reported email was flagged | Seconds to days |
| Repeat-click history | Clicks across consecutive campaigns | Escalates the score |
| Training completion | Lessons finished on time | Pass/fail per module |
| Policy acknowledgement | Policies read and signed | Binary, per policy |
A typical weighting puts click behaviour at roughly half the score, reporting behaviour around a third, and training and policy compliance the remainder. Platform-specific weightings differ — check the vendor's documentation or Cyber Aware's human risk reporting for the exact model before comparing scores across tools.
The output is a per-person rating that updates with every campaign. Because benchmark data shows about 33% of untrained staff click a simulated phishing email, falling to 4-5% after twelve months of monthly training (KnowBe4's published benchmark data), a score should move visibly across the first quarter of a programme. A score that never moves usually means the inputs are thin — too few simulations or no reporting mechanism — not that the person is stable.
What each input contributes
Click data is the negative signal. Every click on a simulated lure raises the score's risk weighting. One click is noise — anyone can be caught by a well-crafted lure. Repeat clicks across three or more consecutive campaigns are the pattern that matters, and most scoring models escalate them deliberately.
Reporting data is the positive signal — and the stronger one. A person who reports a simulated phish they did not click is demonstrating the exact reflex training exists to build. Benchmark report rates sit around 21% across the industry (KnowBe4 2026 benchmark data), so a person reporting above that line is outperforming. Time-to-report sharpens the signal: a report within minutes limits real damage far better than one at end of day.
Training and policy data is the compliance floor. Completion does not prove behaviour change, but non-completion is a reliable risk marker — the person was never exposed to the material. Most models treat overdue training as an automatic penalty and completed training as neutral rather than positive, which is honest: finishing a module should be the baseline, not a reward.
How the score is used
- Targeting coaching. The score ranks who needs the next intervention, so a small team can run repeat-clicker coaching without blanket retraining everyone.
- Executive reporting. Aggregated, the scores become a trend line for leadership: click rates falling, report rates rising, and the residual risk concentrated in a named few.
- Insurance and audit evidence. Cyber insurers in 2026 increasingly ask for training and simulation evidence at renewal — Cyber Aware's human risk reporting covers the evidence pack underwriters expect.
The limitations to know about
A human risk score measures behaviour in simulations, not real attacks, and it can be gamed: a person who reports everything — including legitimate email — inflates their positive signal. Privacy also matters. In Australia, scores should sit behind manager-level access, be framed around coaching rather than discipline, and follow a no-blame programme design; using simulation results for disciplinary action is legally fraught and undermines the reporting culture the score depends on.
Finally, the score is a ranking tool, not an absolute. Two employees with identical scores on different platforms can carry different real-world risk if one platform runs monthly simulations and the other quarterly. Compare direction and velocity, not the raw number.
FAQ
What is a human risk score in one sentence? A per-employee rating that combines phishing simulation behaviour, reporting and training compliance into a single measure of how likely that person is to cause a security incident.
Is a high human risk score good or bad? It depends on the platform's scale — on the common 0-100 model, lower is riskier behaviour, so always read the vendor's legend before comparing.
What data goes into the score? Phishing simulation clicks and reports, reporting speed, repeat-click history, training completion and policy acknowledgements.
How often does the score update? With every simulation campaign and training deadline — monthly programmes produce a fresh score roughly every month.
Can an employee see their own score? On most platforms yes, which is deliberate: self-visibility plus coaching moves behaviour faster than a private manager-only metric.
Does a human risk score replace click rate reporting? No — it aggregates click rate with reporting behaviour and training compliance, which makes it harder to mislead than click rate alone.