Skip to main content
The Human Risk Index is the core metric in the Living Security Platform, providing a comprehensive measure of security risk from human factors.

What is HRI?

HRI is a composite score from 0-1000 that measures an individual’s or group’s security vigilance. Think of it like a credit score: higher scores indicate lower risk (more vigilant, security-conscious behavior).

HRI Components

HRI combines three dimensions:

Behavior (Weight varies)

Actions taken by users:
  • Training completion and timeliness
  • Policy compliance
  • Phishing simulation performance
  • Security tool usage
  • Data handling practices

Threat (Weight varies)

External threats targeting users:
  • Phishing attempts received
  • Malware targeting
  • Social engineering attempts
  • Attack frequency and sophistication

Identity (Weight varies)

Access and privilege factors:
  • Administrative access
  • Sensitive data access
  • Role-based risk
  • Access patterns
Component weights are configured by your organization based on priorities.

Vigilance Levels

Score RangeLevelDescription
800-1000High VigilanceSecurity champions, excellent practices
600-799Somewhat VigilantGood security behaviors
400-599NeutralAverage security posture
200-399Somewhat RiskyNeeds attention and training
0-199High RiskImmediate intervention required

How HRI is Calculated

1

Data Collection

The platform collects signals from integrated systems:
  • Training platforms
  • Security tools
  • Identity providers
  • Communication systems
2

Signal Processing

Raw data is converted to normalized scores for each factor.
3

Component Scoring

Factors are weighted and combined into Behavior, Threat, and Identity scores.
4

Final Calculation

Components are weighted and combined into the final HRI.

Using HRI

For Individuals

  • Identify high-risk users for intervention
  • Track improvement over time
  • Prioritize who needs attention

For Cohorts

  • Compare departments or locations
  • Identify systemic issues
  • Target group interventions

For Organization

  • Track overall security posture
  • Report to leadership
  • Measure program effectiveness
Beyond the current score, track:
  • Direction - Improving, declining, stable
  • Rate of change - How fast is it changing
  • Comparison - Relative to baseline or peers

Factors Affecting HRI

Positive Factors (Increase Score → Lower Risk)

  • Completing training on time
  • Reporting phishing attempts
  • Following security policies
  • Using security tools properly

Negative Factors (Decrease Score → Higher Risk)

  • Clicking phishing links
  • Overdue training
  • Policy violations
  • Risky data handling

FAQs

HRI is updated as new data arrives from integrations, typically within 24 hours of any activity.
HRI is calculated from objective data. Scores improve through genuine behavior change, not gaming.
Most organizations aim for average HRI above 600 (Somewhat Vigilant or higher). The specific target depends on your risk tolerance and industry.
Significant events like clicking a phishing simulation or major policy violation can cause sudden changes. Ask Livvy for explanation of any specific change.

Glossary

All platform terms.

Dashboard Home

Viewing HRI on dashboard.

Cohort Insights

Cohort-level HRI analysis.

Livvy Insights

Ask Livvy about HRI.