
A high-risk score can reveal where cybersecurity needs attention, but it doesn't define an employee. Discover why organisations should use risk indicators to encourage learning, guide training, and strengthen security rather than assign blame
A red flag on a dashboard should start a conversation, not a disciplinary process. Hereâs how to use risk scores to help people rather than blame them.
Two employees end up with the same high-risk score.
One clicked a simulated phishing link because the email looked exactly like it came from their manager. The other clicked because they were rushing to hit a deadline, halfway through a sandwich, with three tabs open and a meeting starting in four minutes.
The number is identical, but the stories have almost nothing in common. If you treat both people as careless, youâll learn very little, and youâll teach two people to dread your next security email.
Thatâs the risk with reading a score as a verdict. It looks like an answer when itâs really the start of a question, and the organisations that get the most out of security awareness tend to treat it that way.
What the score can and canât tell you
Dashboards love a label. High risk, red, problem found. It feels decisive, and thereâs a certain comfort in it: find the problem, fix the problem, get on with your afternoon.
People donât work like that, though. Employees arenât software with a bug waiting for a patch. They make decisions under pressure, skim when theyâre busy, and trust things that look familiar. Attackers know this well. Playing on trust, urgency and routine is how they make a living, and plenty of seasoned professionals have been caught out by it.
A risk score reflects patterns in recorded activity, which is useful. What it canât do is tell you why. Maybe someone misread a warning. Maybe theyâd never seen that particular trick. Maybe it was just a bad Tuesday. Each of those calls for a different response, and you only find out which one youâre dealing with by looking a little closer.
A smoke alarm is a fair comparison. It tells you something needs attention, but not whether youâve burnt the toast or the kitchenâs on fire. Somebody still has to go and look.
Nobody is their worst moment
Take someone whoâs been at the company for years. Theyâre reliable, careful and good at their job. One afternoon they click a link in a very convincing simulation.
That click points to a gap in spotting one kind of threat. It says nothing about their experience, their effort or their competence overall.
It works the other way too. A spotless simulation record doesnât make anyone untouchable. A well-built attack can fool the confident just as easily as the nervous, and sometimes more easily, since confident people tend to move quickly.
People get better with practice, circumstances change, and attack techniques shift every few months. Thatâs why awareness works best as an ongoing habit, much more than as an annual exam you sit, pass and promptly forget.
If you label someone and stop looking, you lose the story. If you look at the pattern, offer help that fits and see what changes, you end up with something you can actually learn from.
Fear makes everyone worse at security
Picture an employee whoâs been quietly branded a âriskâ after a simulation. A week later a slightly odd email lands in their inbox. Something feels off, but they canât say what.
Do they report it, knowing it might remind everyone of the last time? Or do they delete it and hope it goes away?
You want them to report it. Early reporting is one of the strongest defences an organisation has, and blame is the quickest way to switch it off. People who fear judgement stop asking questions and stop admitting mistakes, and eventually they stop putting their hand up at all.
The damage spreads beyond that one person, too. Colleagues watch how mistakes get handled. If the lesson they take away is to keep their heads down, youâve built a workplace thatâs very good at avoiding blame and no better at avoiding breaches.
None of this means ignoring deliberate misconduct or serious policy violations. Accountability matters, but it should rest on evidence, circumstances and the relevant policies, rather than on a number that happens to be coloured red.
What to do when someone gets a high score
A high score is a good reason to ask better questions. Four habits make that easier.
Look for patterns before drawing conclusions. A single result is one data point. Check activity over time and see whether similar outcomes keep turning up, or whether this was a one-off on a busy afternoon. Mixing those two up is how you end up solving the wrong problem.
Match the support to the gap. Not everyone needs the same training. Someone who keeps missing suspicious senders will benefit from practice with senders, unusual requests and misleading links, while someone who handles those well but slips elsewhere needs something different. It also changes the question you ask. âWhatâs wrong with this person?â leads nowhere useful, whereas âWhat would help them make a safer decision next time?â gets you a plan.
Watch what happens after training. Finishing a course is good, but completing it doesnât prove anyone has improved. Look at what follows: whether theyâre spotting suspicious messages more consistently, and whether old patterns fade in later simulations. Progress takes time and one good result doesnât guarantee the next, so aim for steady improvement instead of instant perfection. Passing the theory test doesnât make anyone a confident driver. The hours behind the wheel do that.
Keep a human in the loop. Scores should inform decisions, and they shouldnât make them alone. Before acting on someoneâs result, weigh the evidence, the circumstances and anything else you know. Keep individual results visible only to the people who genuinely need them, because nobody enjoys finding out their security record has been doing the rounds.
What a good conversation sounds like
Say a manager notices an employee has a high-risk indicator. That conversation can go two ways.
In the first, the manager says: âYour score is red. Youâre one of the highest-risk people in the department. You need to take this more seriously.â
The employee goes quiet, feels singled out and starts hoping nobody ever mentions email again. Theyâve also learned to associate security with embarrassment, which undoes a lot of good work.
In the second, the manager says: âI noticed a couple of the recent simulations caught you out. Theyâre built to be sneaky, so thatâs not unusual. Was anything about them confusing? Thereâs some training that might help, and we can see how the next round goes.â
The information is the same in both, and the results are very different. The second version gets honest answers, and honest answers are what improve security. That manager described what theyâd seen without turning it into a charge, treated the employee as someone with useful insight, and finished with a plan. You donât need a script for that, just some curiosity before criticism.
Habits that backfire
Good intentions can still go sideways, and a few habits are worth steering clear of.
Public rankings are the obvious one. A leaderboard of âriskiest employeesâ might feel motivating in a meeting, but in practice it turns a learning tool into a pillory and teaches people to hide their mistakes.
Automatic penalties cause similar trouble. Tying a score directly to a consequence skips the step where you find out what happened.
Blanket retraining feels fair, since everyone gets the same course, but it rarely helps and people can tell it wasnât chosen with them in mind.
Finally, a good score can lull you. A clean record is encouraging, but itâs a snapshot, and threats keep moving.
Questions worth asking first
Before a score turns into a decision, run through a few questions:
- Is this a one-off or a pattern over time?
- What was going on when it happened: deadlines, new tools, an unusually convincing lookalike?
- Has this person had training on this kind of threat yet?
- Would a conversation tell me more than the number does?
- Who actually needs to see this result?
If you canât answer most of these, youâre not ready to draw conclusions, and thatâs fine. It simply means the next step is to find out more.
Building a culture where people speak up
Policies on paper only go so far. What people believe about how mistakes get treated shapes what they do.
Leaders set the tone here. When a senior manager admits to nearly falling for a scam, everyone else gets permission to be honest. When the security team thanks people for reporting suspicious emails, false alarms included, reporting starts to feel normal instead of risky.
Being upfront helps as well. Tell employees why simulations run, what the results are used for and who can see them. People relax a lot when they know the aim is to help them rather than catch them out. Celebrate the report as well as the clean record, and simulations start to feel less like pop quizzes and more like practice.
Where Encrisoft fits in
Understanding human cyber risk takes more than a number on a dashboard. You also need to know what the number represents.
The Risk section in Encrisoft brings together risk scores, breakdowns, and individual and department views, all based on activity recorded in the platform. That helps you spot patterns, decide where extra attention might be needed and track how risk changes over time. Combined with phishing simulations and security training, it supports a cycle of testing, learning and measuring, which suits ongoing awareness better than a once-a-year tick box.
What you do with that picture is where the value lies. A high score is a reason to look closer, and it says nothing certain about someoneâs skills, intentions or character. A low score doesnât guarantee safety either, because no score captures every situation or stops every threat.
The bottom line
Cybersecurity does need measurement. You canât fix what you canât see, and you need ways to spot concerning patterns and decide where your effort will count most.
Numbers without context lead to poor decisions, though. A score is a reason to look more closely, and itâs never proof that someone is careless, incompetent or to blame for an incident.
So measure behaviour, investigate patterns, offer support that fits and check whether things improve. Treat your people as part of the solution, because the ones who feel safe enough to say âthat email looked weirdâ are the best security tool you have.
The real return on a risk score is a team that knows what to do when something looks wrong, whatever the dashboard looks like.
