Cybersecurity
Human Risk Assessment
Measure how your people and processes hold up against phishing, phone fraud and impersonation, then reduce the risk.
Scope
What the assessment covers
Most breaches still begin with a person: a convincing e-mail, a phone call to the help desk or a password reused on a leaked site. We measure how your people and processes respond to these situations, without blame, and turn the results into a clear plan to reduce the risk.
E-mail phishing
Realistic campaigns that measure reporting as well as clicks.
SMS and messaging
Text and messaging app scenarios on company devices.
Voice calls
Calls that test how staff verify a caller.
Help desk and MFA reset
Whether password and MFA resets can be obtained by impersonation.
Public exposure
What anyone can learn about your staff and structure online.
Targeted training
Short sessions for the teams that need them most.
From baseline to lasting habits
Run once to get a baseline, or quarterly to show progress to management and auditors.
-
1
Agreement
Scope, channels and limits approved by management.
-
2
Exposure review
Public information that makes attacks credible.
-
3
Simulations
Agreed scenarios across the chosen channels.
-
4
Risk score
Results by department and process.
-
5
Improvement
Training and process changes, then re-measure.
What you receive
- 01 Human risk score by department
- 02 Report rate and time to report
- 03 Help desk and verification findings
- 04 Public exposure summary
- 05 Training plan and process fixes
Questions we often hear
How is this different from red teaming?
Red teaming pursues one objective with every technique. A human risk assessment measures behaviour across the whole organisation and tracks improvement over time.
Will individual employees be named?
No. Results are reported by team, role or process. The goal is to improve processes and training, not to blame people.
Is it compliant with GDPR?
Yes. We process the minimum data needed, under a written agreement, and delete it at the end of the engagement.
Related
Web Application Penetration Testing
OWASP-aligned manual and automated testing of web apps, APIs and authentication flows.
Learn moreNetwork & Infrastructure Testing
Internal and external network assessments, Active Directory and cloud perimeter reviews.
Learn moreMobile Application Security
iOS and Android testing based on OWASP MASVS, including reverse engineering.
Learn more