Encrisoft
← Back to blog

A High-Risk Score Is Not a Character Reference: Why Cybersecurity Should Guide, Not Judge

People & Culture7 min read9 October 2026Updated 9 October 2026
A manager and employee reviewing information on a laptop during a collaborative workplace discussion.

A high-risk score can reveal where cybersecurity needs attention, but it doesn't define an employee. Discover why organisations should use risk indicators to encourage learning, guide training, and strengthen security rather than assign blame

A red flag on a dashboard should start a conversation, not a disciplinary process. Here’s how to use risk scores to help people rather than blame them.

Two employees end up with the same high-risk score.

One clicked a simulated phishing link because the email looked exactly like it came from their manager. The other clicked because they were rushing to hit a deadline, halfway through a sandwich, with three tabs open and a meeting starting in four minutes.

The number is identical, but the stories have almost nothing in common. If you treat both people as careless, you’ll learn very little, and you’ll teach two people to dread your next security email.

That’s the risk with reading a score as a verdict. It looks like an answer when it’s really the start of a question, and the organisations that get the most out of security awareness tend to treat it that way.

What the score can and can’t tell you

Dashboards love a label. High risk, red, problem found. It feels decisive, and there’s a certain comfort in it: find the problem, fix the problem, get on with your afternoon.

People don’t work like that, though. Employees aren’t software with a bug waiting for a patch. They make decisions under pressure, skim when they’re busy, and trust things that look familiar. Attackers know this well. Playing on trust, urgency and routine is how they make a living, and plenty of seasoned professionals have been caught out by it.

A risk score reflects patterns in recorded activity, which is useful. What it can’t do is tell you why. Maybe someone misread a warning. Maybe they’d never seen that particular trick. Maybe it was just a bad Tuesday. Each of those calls for a different response, and you only find out which one you’re dealing with by looking a little closer.

A smoke alarm is a fair comparison. It tells you something needs attention, but not whether you’ve burnt the toast or the kitchen’s on fire. Somebody still has to go and look.

Nobody is their worst moment

Take someone who’s been at the company for years. They’re reliable, careful and good at their job. One afternoon they click a link in a very convincing simulation.

That click points to a gap in spotting one kind of threat. It says nothing about their experience, their effort or their competence overall.

It works the other way too. A spotless simulation record doesn’t make anyone untouchable. A well-built attack can fool the confident just as easily as the nervous, and sometimes more easily, since confident people tend to move quickly.

People get better with practice, circumstances change, and attack techniques shift every few months. That’s why awareness works best as an ongoing habit, much more than as an annual exam you sit, pass and promptly forget.

If you label someone and stop looking, you lose the story. If you look at the pattern, offer help that fits and see what changes, you end up with something you can actually learn from.

Fear makes everyone worse at security

Picture an employee who’s been quietly branded a “risk” after a simulation. A week later a slightly odd email lands in their inbox. Something feels off, but they can’t say what.

Do they report it, knowing it might remind everyone of the last time? Or do they delete it and hope it goes away?

You want them to report it. Early reporting is one of the strongest defences an organisation has, and blame is the quickest way to switch it off. People who fear judgement stop asking questions and stop admitting mistakes, and eventually they stop putting their hand up at all.

The damage spreads beyond that one person, too. Colleagues watch how mistakes get handled. If the lesson they take away is to keep their heads down, you’ve built a workplace that’s very good at avoiding blame and no better at avoiding breaches.

None of this means ignoring deliberate misconduct or serious policy violations. Accountability matters, but it should rest on evidence, circumstances and the relevant policies, rather than on a number that happens to be coloured red.

What to do when someone gets a high score

A high score is a good reason to ask better questions. Four habits make that easier.

Look for patterns before drawing conclusions. A single result is one data point. Check activity over time and see whether similar outcomes keep turning up, or whether this was a one-off on a busy afternoon. Mixing those two up is how you end up solving the wrong problem.

Match the support to the gap. Not everyone needs the same training. Someone who keeps missing suspicious senders will benefit from practice with senders, unusual requests and misleading links, while someone who handles those well but slips elsewhere needs something different. It also changes the question you ask. “What’s wrong with this person?” leads nowhere useful, whereas “What would help them make a safer decision next time?” gets you a plan.

Watch what happens after training. Finishing a course is good, but completing it doesn’t prove anyone has improved. Look at what follows: whether they’re spotting suspicious messages more consistently, and whether old patterns fade in later simulations. Progress takes time and one good result doesn’t guarantee the next, so aim for steady improvement instead of instant perfection. Passing the theory test doesn’t make anyone a confident driver. The hours behind the wheel do that.

Keep a human in the loop. Scores should inform decisions, and they shouldn’t make them alone. Before acting on someone’s result, weigh the evidence, the circumstances and anything else you know. Keep individual results visible only to the people who genuinely need them, because nobody enjoys finding out their security record has been doing the rounds.

What a good conversation sounds like

Say a manager notices an employee has a high-risk indicator. That conversation can go two ways.

In the first, the manager says: “Your score is red. You’re one of the highest-risk people in the department. You need to take this more seriously.”

The employee goes quiet, feels singled out and starts hoping nobody ever mentions email again. They’ve also learned to associate security with embarrassment, which undoes a lot of good work.

In the second, the manager says: “I noticed a couple of the recent simulations caught you out. They’re built to be sneaky, so that’s not unusual. Was anything about them confusing? There’s some training that might help, and we can see how the next round goes.”

The information is the same in both, and the results are very different. The second version gets honest answers, and honest answers are what improve security. That manager described what they’d seen without turning it into a charge, treated the employee as someone with useful insight, and finished with a plan. You don’t need a script for that, just some curiosity before criticism.

Habits that backfire

Good intentions can still go sideways, and a few habits are worth steering clear of.

Public rankings are the obvious one. A leaderboard of “riskiest employees” might feel motivating in a meeting, but in practice it turns a learning tool into a pillory and teaches people to hide their mistakes.

Automatic penalties cause similar trouble. Tying a score directly to a consequence skips the step where you find out what happened.

Blanket retraining feels fair, since everyone gets the same course, but it rarely helps and people can tell it wasn’t chosen with them in mind.

Finally, a good score can lull you. A clean record is encouraging, but it’s a snapshot, and threats keep moving.

Questions worth asking first

Before a score turns into a decision, run through a few questions:

  • Is this a one-off or a pattern over time?
  • What was going on when it happened: deadlines, new tools, an unusually convincing lookalike?
  • Has this person had training on this kind of threat yet?
  • Would a conversation tell me more than the number does?
  • Who actually needs to see this result?

If you can’t answer most of these, you’re not ready to draw conclusions, and that’s fine. It simply means the next step is to find out more.

Building a culture where people speak up

Policies on paper only go so far. What people believe about how mistakes get treated shapes what they do.

Leaders set the tone here. When a senior manager admits to nearly falling for a scam, everyone else gets permission to be honest. When the security team thanks people for reporting suspicious emails, false alarms included, reporting starts to feel normal instead of risky.

Being upfront helps as well. Tell employees why simulations run, what the results are used for and who can see them. People relax a lot when they know the aim is to help them rather than catch them out. Celebrate the report as well as the clean record, and simulations start to feel less like pop quizzes and more like practice.

Where Encrisoft fits in

Understanding human cyber risk takes more than a number on a dashboard. You also need to know what the number represents.

The Risk section in Encrisoft brings together risk scores, breakdowns, and individual and department views, all based on activity recorded in the platform. That helps you spot patterns, decide where extra attention might be needed and track how risk changes over time. Combined with phishing simulations and security training, it supports a cycle of testing, learning and measuring, which suits ongoing awareness better than a once-a-year tick box.

What you do with that picture is where the value lies. A high score is a reason to look closer, and it says nothing certain about someone’s skills, intentions or character. A low score doesn’t guarantee safety either, because no score captures every situation or stops every threat.

The bottom line

Cybersecurity does need measurement. You can’t fix what you can’t see, and you need ways to spot concerning patterns and decide where your effort will count most.

Numbers without context lead to poor decisions, though. A score is a reason to look more closely, and it’s never proof that someone is careless, incompetent or to blame for an incident.

So measure behaviour, investigate patterns, offer support that fits and check whether things improve. Treat your people as part of the solution, because the ones who feel safe enough to say “that email looked weird” are the best security tool you have.

The real return on a risk score is a team that knows what to do when something looks wrong, whatever the dashboard looks like.

Share this article

Emma Okereke

Cybersecurity researcher, technical writer, and SOC analyst passionate about making cybersecurity clear, practical, and accessible. She explores security trends, workplace awareness, and the evolving threat landscape.