← Back to news 03.08.2026

How do you measure people without surveilling them?

Computing a human risk index is technically trivial, the data has long been there. The hard part is what you may do with it afterwards. Why the defaults are the real statement in this metric, and what a minimum group size is for.

Measuring the human security level is not a technical challenge. Training completions, simulation results, two-factor status: it is all there, you only have to add it up. The real question begins afterwards. Who may see the number, at whom may it point, and what happens to the small department whose average is effectively an individual score?

Three dimensions, weighted honestly

The Human Security Index condenses three dimensions into a figure from 0 to 100: knowledge from completed training, behaviour from phishing simulations, and lived culture from two-factor authentication, genuine suspicious-mail reports and acknowledged policies. The weights are configurable per tenant. More important is the rule for missing data: a dimension without a data basis drops out of the weighting instead of counting as zero. Otherwise the index punishes areas for things that never existed there, and nobody trusts the figure any more.

The defaults are the statement

Individual personal scores are switched off by default and become visible only after an explicit release that is subject to co-determination. Evaluations below a minimum group size of five people are suppressed entirely, not blurred, because the average of a group of three is not an average. Index snapshots expire after three years.

That these values sit as defaults in the data model itself is not an implementation detail. The code carries a remarkably honest sentence about it: without the default, the suppression would never take effect, precisely the case it is meant to prevent. Privacy that depends on a setting somebody has to remember to make is not privacy.

The self-view inverts the logic

Every person sees their own score in a dedicated view, even when leadership sees no individual scores at all. That turns the measurement into feedback to the person instead of a report about them.

And where logging does happen

A piece about restraint would be dishonest if it concealed the one place where data accrues. Security notices can be sent with proof of acknowledgement, and that proof stores the IP address of the confirmation alongside the timestamp. That is evidence quality for an audit, but it is personal data, and it belongs in the record of processing activities like any other.

More on the Human Risk module page. Where the behaviour dimension comes from is shown by phishing simulation, the knowledge dimension by e-learning.

Questions about this update?

Talk to us – we are happy to show you this feature in a demo.