Concepts

ShieldScore

How the 0-100 human risk score is built, and what moves it.

Public

ShieldScore is a 0-100 score where higher means riskier. That direction catches people out, so the product repeats it: lower is safer.

Per person

Each person's score is computed from their own recent behaviour. The contributing categories are:

  • Phishing susceptibility — clicked, submitted credentials, repeat clicks.
  • Training debt — assigned learning that is incomplete or past due.
  • Reporting gap — receiving a simulation and neither clicking nor reporting it.
  • Policy acknowledgement — published policies not yet accepted.
  • Data handling — signals from exposure and connected tools.

Reporting a phishing simulation is a positive signal. A person who reports every lure scores better than one who simply never clicks, because ignoring an attack and catching an attack are not the same thing.

Per organisation

The organisation score is the mean of the active learner ShieldScores. It is not a separate model laid over the top: roll the people up and you get the number.

That means it is dragged by the population, not by the worst case. Ten very risky people in a thousand barely move it, which is why the overview leads with ranked individuals as well as the headline.

Bands

  • 0-39 low
  • 40-69 medium
  • 70-89 high
  • 90-100 critical

What moves it, and how fast

Snapshots are written nightly. A completed module or a reported simulation shows up the next day, not instantly. A score that has not moved after an afternoon of activity is normal.

Missing days are never plotted as zero. If snapshots did not run, the chart breaks the line rather than drawing a cliff that did not happen.

Seeing the working

Open Decision audit for the full derivation on live data: the exact points each category contributed and where the population sits.

Still stuck?Contact support