Skip to content
Kodvalley

Cybersecurity

Human Risk Assessment

Measure how your people and processes hold up against phishing, phone fraud and impersonation, then reduce the risk.

4 channels: e-mail, SMS, voice, web
By team never by individual
GDPR compliant by design

Scope

What the assessment covers

Most breaches still begin with a person: a convincing e-mail, a phone call to the help desk or a password reused on a leaked site. We measure how your people and processes respond to these situations, without blame, and turn the results into a clear plan to reduce the risk.

E-mail phishing

Realistic campaigns that measure reporting as well as clicks.

SMS and messaging

Text and messaging app scenarios on company devices.

Voice calls

Calls that test how staff verify a caller.

Help desk and MFA reset

Whether password and MFA resets can be obtained by impersonation.

Public exposure

What anyone can learn about your staff and structure online.

Targeted training

Short sessions for the teams that need them most.

From baseline to lasting habits

Run once to get a baseline, or quarterly to show progress to management and auditors.

  1. 1

    Agreement

    Scope, channels and limits approved by management.

  2. 2

    Exposure review

    Public information that makes attacks credible.

  3. 3

    Simulations

    Agreed scenarios across the chosen channels.

  4. 4

    Risk score

    Results by department and process.

  5. 5

    Improvement

    Training and process changes, then re-measure.

What you receive

  1. 01 Human risk score by department
  2. 02 Report rate and time to report
  3. 03 Help desk and verification findings
  4. 04 Public exposure summary
  5. 05 Training plan and process fixes

Questions we often hear

How is this different from red teaming?

Red teaming pursues one objective with every technique. A human risk assessment measures behaviour across the whole organisation and tracks improvement over time.

Will individual employees be named?

No. Results are reported by team, role or process. The goal is to improve processes and training, not to blame people.

Is it compliant with GDPR?

Yes. We process the minimum data needed, under a written agreement, and delete it at the end of the engagement.