CyberPlay editorial team · Published · Updated · 7 min read
Guide and exercises in English

Expand image · Platform screenshot · Example data · English interface
Useful human risk management metrics help an organisation decide who needs support, what to practise and what to check next. Start with the people represented in the data, then interpret their learning evidence. An attractive average can conceal an entire department with no measured practice.
This guide follows the CyberPlay organisation workflow from department coverage to a learning profile, an assignment and a review. CyberSense describes game-informed learning progression. It is not an incident probability or independently validated proof of workplace competence. The guide and its exercise are available in English; illustrated organisation screens use English labels and example data.
What you’ll take away
- Report measured people and active members alongside every average.
- Keep missing evidence separate from a low score.
- Use the priority rules to start a conversation and choose practice.
- Review learning evidence and workplace procedures as separate questions.
1. Define the decision before choosing the KPI
A useful question is: “Which finance colleagues need support checking a supplier’s changed bank details?” It names a work decision, a group and an action. “Raise our human risk score” leaves the manager guessing what to do tomorrow. NIST SP 800-55 provides guidance for selecting and evaluating security measures.
Write down the decision owner, the population and the review date. For this example, the finance lead owns the payment procedure, the learning coordinator arranges practice and authorised security staff interpret additional incident evidence. CyberPlay contributes learning information; it does not observe every payment approval or every security control.
Section sources: NIST SP 800-55 Volume 1
2. Read coverage before the average
The following organisation is entirely fictional. It has 100 active members: 20 in Finance and 80 in Operations. Finance has 10 measured people averaging 84; Operations has 60 averaging 66. The overall mean is 68.6 across 70 measured people, with 70% coverage. It is not the unweighted average of the two department means.
Finance’s higher mean covers only half its active members. It cannot describe the other ten. Check access, onboarding, language and time to practise before interpreting missing evidence. In the insights view, active organisation members form the denominator; an invited or suspended account is outside that population. An unmeasured active member remains in coverage but is excluded from the mean.
| Illustrative group | Measured / active | Coverage | Measured mean |
|---|---|---|---|
| Finance | 10 / 20 | 50% | 84 |
| Operations | 60 / 80 | 75% | 66 |
| Whole organisation | 70 / 100 | 70% | 68.6 |

Expand image · Platform screenshot · Example data · English interface
- Measured mean
69.7 describes six scored members, not all eight active members.
- Coverage
Six of eight have a score: 75% coverage. The other two remain unknown.
3. Know what CyberSense does and does not measure
CyberSense combines game performance with breadth and sustained practice signals. Its calculation also considers quality-adjusted repetition, time, game XP and achievements. No eligible completed scored run means no score. Repeating a game or accumulating time is not, by itself, proof that someone understands the corresponding work procedure.
A person’s current result can change when new performance or catalogue evidence enters the calculation. The score does not simply decay after 30 days without practice: recency is a separate coaching signal. A score of 84 does not mean an 84% chance of resisting phishing. Nor should one colleague’s score become a public label about their character or trustworthiness.
4. Apply the five coaching priorities in order
CyberPlay assigns exactly one priority per person using the following order. These transparent product rules organise follow-up; they are not externally validated risk thresholds. “Baseline” means establish learning evidence through suitable practice, not a separate diagnostic test before training or a shortcut to skip it.
The order matters. Someone scoring 52 whose last practice was 45 days ago receives coaching, not refresh. Someone scoring 84 with the same practice age receives refresh. Missing dates remain visible gaps; they are not invented recent activity. Discuss practical circumstances before treating an assigned priority as the complete explanation.
| First matching condition | Priority | Reasonable next step |
|---|---|---|
| No score | Baseline | Enable suitable initial practice. |
| Score below 60 | Coach | Discuss the difficulty and practise a relevant decision. |
| Otherwise, last practice missing or at least 30 days old | Refresh | Arrange a fresh, relevant practice opportunity. |
| Otherwise, score from 60 to below 80 | Practice | Build confidence with another scenario. |
| Otherwise, score at least 80 | Sustain | Maintain varied practice and check the real procedure. |
5. Move from a department to an individual learning profile
Open the organisation insights area with an authorised administrator or manager account and the required analytics entitlement. Select Finance and read its coverage, measured average and priority counts. Department selection changes the summary population. Searching for a name or selecting a coaching priority filters the people list without changing those headline denominators.
Individual profiles additionally require roster permission. Where available, inspect the person’s learning domains, missing domain evidence and practice history. Ask which work decision needs support. Opening assignments from the profile leads to the existing assignment workflow; it does not automatically enrol that person. Check the selected audience, game and timing before confirming an assignment.

Expand image · Platform screenshot · Example data · English interface
- A focused question
Phishing evidence is 42 here. Discuss the decision and suitable practice, not an assumed incident probability.
- Missing evidence
Incident reporting has no measurement. That is a learning-data gap, not proof of unsafe reporting.
6. Assign a decision to practise, not a score to chase
For the fictional finance team, use this objective: verify a supplier bank-detail change through an independently known channel before approval. Choose a relevant exercise, then ask the learner to explain which contact route they would use at work. The organisation’s actual payment policy remains the authority; a game scenario cannot approve a real transfer.
NCSC advises looking beyond training when the underlying problem persists. If staff already know the rule but cannot find an approved supplier contact, give the process owner that problem. Another game session cannot repair an inaccessible directory. Offer appropriate learning language, accessible instructions and time during work. The article translations do not imply every organisation-dashboard label is translated.
- Objective: one observable decision in a named work process.
- Practice: a relevant scenario with an explained debrief.
- Owner: a person who can resolve the practical obstacle.
- Review: a date and the evidence to inspect.
Section sources: Putting people at the heart of an organisation’s approach to cyber security
7. Review the result without inventing a trend
At the agreed review, check whether the intended people practised, what learning evidence is now available and whether the procedural obstacle was resolved. A coordinator can record an authorised review note in the organisation’s existing documentation. The insights screen presents a current snapshot, not a historical CyberSense chart.
NIST SP 800-50 includes evaluation methods for improving learning programmes. Keep your conclusion narrower than your data: new practice and a changed score describe platform evidence. Proving that invoice approvals improved requires separately collected workplace evidence. Also recheck membership and catalogue changes before comparing two snapshots; a different denominator can move an average without any individual improving.
Section sources: NIST SP 800-50 Revision 1
8. Practise interpreting a misleading headline
Use this fictional example in a short team discussion. No customer result is represented. Ask participants to state both the next action and the fact that remains unknown.
9. End with a short management decision
A useful update reads: “Our fictional Finance team has evidence for 10 of 20 active members. The measured mean is 84; ten colleagues still need an initial learning opportunity. We will support relevant payment-verification practice, resolve contact-directory access and review participation and the procedure on the agreed date.” This gives management a population, a limitation and an action with a named owner.
Use aggregate reporting for broad audiences and authorised individual detail for support. Avoid public rankings or treating learning data as an employee conduct verdict. Human risk management helps the organisation when an observation leads to a practical improvement, with clear limits on what the observation can establish.
Plan learning for your organisation
Explore CyberPlay for organisations and connect game-based practice to a clear learning objective. This guide and exercise are in English. Organisation analytics and individual profiles depend on your access and plan.
Explore CyberPlay for organisationsSources and further reading
- NIST SP 800-55 Volume 1 — NIST. Accessed 2026-09-13
- NIST SP 800-50 Revision 1 — NIST. Accessed 2026-09-13
- Putting people at the heart of an organisation’s approach to cyber security — UK National Cyber Security Centre. Accessed 2026-09-13
Keep exploring
- Human risk management: how organisations turn evidence into action
Learn what human risk management means, how it helps organisations and where CyberSense learning insights fit. A practical guide with examples and an exercise.
EN · 7 min read - Human risk management platforms: what should your organisation compare?
Compare Hoxhunt, KnowBe4, SoSafe, usecure and CyberPlay with an educational HRM buying checklist. Examine signals, coaching, language support and evidence in a demo.
EN · 8 min read - Security awareness training metrics: measure more than completion
Measure security awareness with a practical metric dictionary covering participation, decisions, retention and reporting, plus fair comparisons and clear limits.
EN · 8 min read - Security awareness training plan: a 12-month calendar with practical activities
Use an editable 12-month security awareness training calendar with decision objectives, role-based activities, debrief questions, owners and useful review measures.
EN · 8 min read - Security awareness games for employees: how to choose and use them
Choose security awareness games that teach useful workplace decisions. Compare formats, run a sample session, and use a practical evaluation checklist.
EN · 8 min read - Phishing training games: practise the decisions behind a suspicious message
Use phishing training games to rehearse inspection, independent verification and reporting. Includes a fictional supplier message and a practical session plan.
EN · 8 min read