Human risk management metrics: turn CyberSense into a coaching plan

Read coverage, CyberSense and learning priorities by department. Use a worked example to choose employee coaching, assign practice and review the evidence.

CyberPlay editorial team · Published · Updated · 7 min read

Guide and exercises in English

CyberPlay organisation view showing learning bands beside distinct coaching priorities.

Expand image · Platform screenshot · Example data · English interface

Use the distribution to see missing evidence and the priorities to choose a follow-up. Actual platform screen with fictional data and English labels.

Useful human risk management metrics help an organisation decide who needs support, what to practise and what to check next. Start with the people represented in the data, then interpret their learning evidence. An attractive average can conceal an entire department with no measured practice.

This guide follows the CyberPlay organisation workflow from department coverage to a learning profile, an assignment and a review. CyberSense describes game-informed learning progression. It is not an incident probability or independently validated proof of workplace competence. The guide and its exercise are available in English; illustrated organisation screens use English labels and example data.

What you’ll take away

  • Report measured people and active members alongside every average.
  • Keep missing evidence separate from a low score.
  • Use the priority rules to start a conversation and choose practice.
  • Review learning evidence and workplace procedures as separate questions.

1. Define the decision before choosing the KPI

A useful question is: “Which finance colleagues need support checking a supplier’s changed bank details?” It names a work decision, a group and an action. “Raise our human risk score” leaves the manager guessing what to do tomorrow. NIST SP 800-55 provides guidance for selecting and evaluating security measures.

Write down the decision owner, the population and the review date. For this example, the finance lead owns the payment procedure, the learning coordinator arranges practice and authorised security staff interpret additional incident evidence. CyberPlay contributes learning information; it does not observe every payment approval or every security control.

Section sources: NIST SP 800-55 Volume 1

2. Read coverage before the average

The following organisation is entirely fictional. It has 100 active members: 20 in Finance and 80 in Operations. Finance has 10 measured people averaging 84; Operations has 60 averaging 66. The overall mean is 68.6 across 70 measured people, with 70% coverage. It is not the unweighted average of the two department means.

Finance’s higher mean covers only half its active members. It cannot describe the other ten. Check access, onboarding, language and time to practise before interpreting missing evidence. In the insights view, active organisation members form the denominator; an invited or suspended account is outside that population. An unmeasured active member remains in coverage but is excluded from the mean.

2. Read coverage before the average
Illustrative groupMeasured / activeCoverageMeasured mean
Finance10 / 2050%84
Operations60 / 8075%66
Whole organisation70 / 10070%68.6
CyberPlay Finance view: six of eight example members measured, 75% coverage and a measured mean of 69.7.

Expand image · Platform screenshot · Example data · English interface

  1. Measured mean

    69.7 describes six scored members, not all eight active members.

  2. Coverage

    Six of eight have a score: 75% coverage. The other two remain unknown.

Read the mean together with coverage. This separate eight-member screenshot example is different from the 100-member worked example in the text; neither represents customer results.

3. Know what CyberSense does and does not measure

CyberSense combines game performance with breadth and sustained practice signals. Its calculation also considers quality-adjusted repetition, time, game XP and achievements. No eligible completed scored run means no score. Repeating a game or accumulating time is not, by itself, proof that someone understands the corresponding work procedure.

A person’s current result can change when new performance or catalogue evidence enters the calculation. The score does not simply decay after 30 days without practice: recency is a separate coaching signal. A score of 84 does not mean an 84% chance of resisting phishing. Nor should one colleague’s score become a public label about their character or trustworthiness.

4. Apply the five coaching priorities in order

CyberPlay assigns exactly one priority per person using the following order. These transparent product rules organise follow-up; they are not externally validated risk thresholds. “Baseline” means establish learning evidence through suitable practice, not a separate diagnostic test before training or a shortcut to skip it.

The order matters. Someone scoring 52 whose last practice was 45 days ago receives coaching, not refresh. Someone scoring 84 with the same practice age receives refresh. Missing dates remain visible gaps; they are not invented recent activity. Discuss practical circumstances before treating an assigned priority as the complete explanation.

4. Apply the five coaching priorities in order
First matching conditionPriorityReasonable next step
No scoreBaselineEnable suitable initial practice.
Score below 60CoachDiscuss the difficulty and practise a relevant decision.
Otherwise, last practice missing or at least 30 days oldRefreshArrange a fresh, relevant practice opportunity.
Otherwise, score from 60 to below 80PracticeBuild confidence with another scenario.
Otherwise, score at least 80SustainMaintain varied practice and check the real procedure.
Coverage: Who has learning evidence, out of all active members? Measured mean: Describe scored people; keep unknowns separate. Priority: Apply the first matching rule and inspect context. Follow-up: Assign suitable practice and review the work procedure.

Expand image

Original CyberPlay decision diagram. The workflow uses learning evidence, not incident probabilities.

5. Move from a department to an individual learning profile

Open the organisation insights area with an authorised administrator or manager account and the required analytics entitlement. Select Finance and read its coverage, measured average and priority counts. Department selection changes the summary population. Searching for a name or selecting a coaching priority filters the people list without changing those headline denominators.

Individual profiles additionally require roster permission. Where available, inspect the person’s learning domains, missing domain evidence and practice history. Ask which work decision needs support. Opening assignments from the profile leads to the existing assignment workflow; it does not automatically enrol that person. Check the selected audience, game and timing before confirming an assignment.

Example CyberPlay profile with phishing score 42, identity score 57 and two unmeasured learning domains.

Expand image · Platform screenshot · Example data · English interface

  1. A focused question

    Phishing evidence is 42 here. Discuss the decision and suitable practice, not an assumed incident probability.

  2. Missing evidence

    Incident reporting has no measurement. That is a learning-data gap, not proof of unsafe reporting.

Inspect a relevant learning domain before choosing support. The fictional profile separates lower scores from missing evidence; it does not diagnose real workplace behaviour.

6. Assign a decision to practise, not a score to chase

For the fictional finance team, use this objective: verify a supplier bank-detail change through an independently known channel before approval. Choose a relevant exercise, then ask the learner to explain which contact route they would use at work. The organisation’s actual payment policy remains the authority; a game scenario cannot approve a real transfer.

NCSC advises looking beyond training when the underlying problem persists. If staff already know the rule but cannot find an approved supplier contact, give the process owner that problem. Another game session cannot repair an inaccessible directory. Offer appropriate learning language, accessible instructions and time during work. The article translations do not imply every organisation-dashboard label is translated.

  • Objective: one observable decision in a named work process.
  • Practice: a relevant scenario with an explained debrief.
  • Owner: a person who can resolve the practical obstacle.
  • Review: a date and the evidence to inspect.

Section sources: Putting people at the heart of an organisation’s approach to cyber security

7. Review the result without inventing a trend

At the agreed review, check whether the intended people practised, what learning evidence is now available and whether the procedural obstacle was resolved. A coordinator can record an authorised review note in the organisation’s existing documentation. The insights screen presents a current snapshot, not a historical CyberSense chart.

NIST SP 800-50 includes evaluation methods for improving learning programmes. Keep your conclusion narrower than your data: new practice and a changed score describe platform evidence. Proving that invoice approvals improved requires separately collected workplace evidence. Also recheck membership and catalogue changes before comparing two snapshots; a different denominator can move an average without any individual improving.

Section sources: NIST SP 800-50 Revision 1

8. Practise interpreting a misleading headline

Use this fictional example in a short team discussion. No customer result is represented. Ask participants to state both the next action and the fact that remains unknown.

9. End with a short management decision

A useful update reads: “Our fictional Finance team has evidence for 10 of 20 active members. The measured mean is 84; ten colleagues still need an initial learning opportunity. We will support relevant payment-verification practice, resolve contact-directory access and review participation and the procedure on the agreed date.” This gives management a population, a limitation and an action with a named owner.

Use aggregate reporting for broad audiences and authorised individual detail for support. Avoid public rankings or treating learning data as an employee conduct verdict. Human risk management helps the organisation when an observation leads to a practical improvement, with clear limits on what the observation can establish.

Plan learning for your organisation

Explore CyberPlay for organisations and connect game-based practice to a clear learning objective. This guide and exercise are in English. Organisation analytics and individual profiles depend on your access and plan.

Explore CyberPlay for organisations

Sources and further reading

  1. NIST SP 800-55 Volume 1 — NIST. Accessed 2026-09-13
  2. NIST SP 800-50 Revision 1 — NIST. Accessed 2026-09-13
  3. Putting people at the heart of an organisation’s approach to cyber security — UK National Cyber Security Centre. Accessed 2026-09-13

Keep exploring

All articles

Contact · About