What is the Workforce Risk Index?
The Workforce Risk Index (WRI) is Right-Hand Cybersecurity's evidence-based model for measuring human risk in your organization. Rather than reporting isolated activities - training completions, phishing click rates, quiz scores. WRI combines the signals your security stack already generates into a single score per employee, on a 0–100 scale, estimating how likely that person is to be the human entry point for a security incident.
Three things define it:
Evidence-based. Every point traces back to a real, observable event - nothing is hidden behind a proprietary algorithm.
Per employee. Each individual is scored, then rolled up to teams, locations, departments, and the whole organization.
Continuously updated. Scores refresh with each ingestion cycle - roughly every 15 minutes - as new evidence arrives.
What feeds the score
WRI sorts every piece of evidence into one of four factors:
Factor | What it means |
Negative behavior | Actions that raise the chance of compromise - clicking a simulated phishing link, submitting credentials, failing an assessment, inserting an unapproved USB device. |
Positive behavior | Actions that lower it - reporting a suspicious email, completing training, disclosing a possible incident. |
Threat exposure | Attacks aimed at the employee, whether or not they responded - targeted phishing volume, anomalous logins, credential-stuffing. |
Role exposure | The structural risk of a person's role and access. Applied as a multiplier, not as an event. |
Evidence is also grouped into six risk categories, so you can see what type of risk is moving:
Social Engineering · Identity & Access · Device Security · Privacy/Data · Web Security · Security Awareness
Risk Score vs. Behavior Score
WRI produces two scores for every employee. They answer different questions and are shown to different audiences.
| Risk Score | Behavior Score |
What it measures | Overall workforce risk | Employee behavior only |
Includes role exposure | Yes | No |
Includes threat exposure | Yes | No |
Who sees it | Admins, security team, leadership | The employee and their manager |
Used for | Executive reporting, prioritization | Coaching, awareness, continuous improvement |
Why the split matters. A CFO with a spotless record can still carry a high Risk Score purely because of their access and the volume of phishing aimed at them - showing them that number would read as a judgment on excellent behavior. The Behavior Score reflects only what the employee controls, which makes it the right number for coaching and for the monthly employee digest.
Switch between the two views at any time with the Risk Score / Behavior Score toggle on the dashboard.
Before you begin: the setup banner
Before you begin: the setup banner
If your organization has not yet configured WRI, the dashboard opens in setup mode, showing:
A banner reading "Introducing the New Risk Dashboard"
A "Read the thought process behind Workforce Risk Index (WRI)" link, which opens the WRI whitepaper
A View New Dashboard button that takes you to the setup screen
Sample data and Setup required labels
Everything shown in this state is sample data, there so you can see how the views work before your own scores exist. No number reflects your organization until you apply a configuration. Once you do, the banner and sample-data labels disappear and the dashboard switches to your live data.
Setting up WRI: the 5-question configuration
Setting up WRI: the 5-question configuration
Where: Settings → Company Settings → Risk Score tab (or click Configure now on the dashboard banner).
WRI isn't a scoring model imposed on you - it's your organization's risk philosophy made measurable. Setup asks five plain-language questions with no math to work through, and takes around 10 minutes. Click Start setup to begin.
The five questions
# | Question covers | What you are deciding |
1 | Behavioral balance | How much weight positive behavior carries against negative — from an equal split through to a negative-dominant model. |
2 | Role exposure | Whether a role and its access should influence the Risk Score at all. Yes or no. |
3 | Threat exposure contribution | How much externally directed threat activity contributes. Select None and only positive and negative behavior count — making Risk Score and Behavior Score identical, unless role exposure is on. |
4 | Event memory | How quickly evidence fades. Short — weight drops off fast. Medium — the default. Long — older evidence keeps close to its original weight. |
5 | Baseline risk value | Keep the recommended industry baseline, or set a custom starting value. |
As you answer, the panel on the right updates to show how your choices shift the model's balance.
Reviewing and applying
After the fifth question, click See my configuration.
Check the summary - each question is listed with the option you chose.
If anything is unclear, click "Need assistance? Talk to our team" to reach Right-Hand Cybersecurity support.
Click Apply configuration.
Your dashboard unlocks immediately and event ingestion begins from all connected integrations.
The Open Whitepaper link explains the reasoning behind each recommendation in full.
NOTE Scores start generating as soon as configuration is applied. The first genuinely useful insights typically appear within two to four weeks, as the evidence window fills.
IMPORTANT NOTE: The Open Whitepaper link explains the reasoning behind each recommendation in full.
Scores start generating as soon as configuration is applied. The first genuinely useful insights typically appear within two to four weeks, as the evidence window fills.
Reading your WRI dashboard
Reading your WRI dashboard
Once configured, the dashboard gives you four layers of insight.
Score trend. Your organization's Risk Score and Behavior Score over time - the view for "are we getting better or worse?"
Factor contribution. The make-up of your current score (for example, 33% positive behavior, 67% negative, 0% threat events). It's a ratio, not a judgment: it tells you which lever to pull. If negative behavior dominates, invest in behavior change; if threat exposure dominates, invest in protecting the people being targeted.
Trending behaviors. Which evidence types are rising or falling across the organization. A type need not be your largest contributor to matter - a category climbing quickly is worth acting on early.
Most vulnerable groups and people. Ranked breakdowns of where risk is concentrated. Use the Office Locations, User Groups and Departments tabs to change the grouping, and the Risk Score / Behavior Score toggle to change the measure.
Drilling into a category
Drilling into a category
Each category has a View details button that opens a drawer with two sections:
"What has contributed to your current score" - the evidence behind the number. For example, a Social Engineering score of 82 might break down into 142 phishing link clicks, 98 reports filed, 64 credential submissions, 14 malware attachment opens and 9 credentials found in a breach dump. This is your list of areas to plan training and coaching around.
"What has changed in the last 30 days" - which evidence types are trending up or down. A behavior that isn't yet a top contributor but is climbing fast shows up here first, giving you time to get ahead of it.
Where does the math come from? Click "How are Risk Score and Behavior Score calculated?" on the dashboard, then Open Whitepaper in the drawer. The full methodology, including both formulae, is published there; nothing about the model is confidential.
Checking your active configuration
Checking your active configuration
Click the gear icon on the dashboard to open the configuration drawer, which shows at a glance:
Risk Factors - which factors are contributing and how they're weighted
Event memory - the decay setting currently in force
Role multipliers- how much a user's role scales their behavior and threat-based risk
Changing your configuration later
Changing your configuration later
Where: Settings → Company Settings → Risk Score tab
Once WRI is live, the Workforce Risk Index option carries an Active label.
Click Edit next to the question you want to change. A drawer opens with the available options.
Select your new option and click Save (or Cancel to close without changing anything).
Repeat for any other questions.
Click Apply configuration.
A recalculation progress bar appears while scores update. When it finishes, use the Go to dashboard link to see the new results.
IMPORTANT: A configuration change applies to future scoring only. It does not automatically rewrite your historical trend chart. To restate past snapshots under the new settings, use Recalculate Historical Trend (section 9).
Recalculating the historical trend
Recalculating the historical trend
Use this after changing your configuration when you want the historical trend chart restated under the new settings, so the whole chart is comparable.
On the Risk Score settings page, click Recalculate Historical Trend.
A confirmation modal appears: "Recalculate historical trend chart?" noting that the action cannot be undone, that it will be logged for compliance, and that it takes a few minutes.
Click Cancel to back out, or Recalculate Historical Trend to proceed.
A progress bar tracks the recalculation.
Because the action is logged and attributed, it forms part of your audit trail - which is what lets you explain a change in the chart to an auditor or your board later.
Frequently asked questions
Frequently asked questions
How often do scores update?
With every ingestion cycle, roughly every 15 minutes.
How far back does WRI look?
Evidence from the preceding 12 months contributes to the current score. Older events are retained in storage but carry no weight. Within that window, recent evidence counts for more than older evidence, at a rate set by your Event memory choice.
Can employees see their Risk Score?
No. Employees see only their Behavior Score, which reflects behavior they directly control. The Risk Score - which includes role and threat exposure- is visible to administrators only.
Why did an employee's Risk Score rise even though their behavior improved? Almost always, a change in role or threat exposure, a promotion or access change, or a spike in phishing targeting them. Check their Behavior Score: if it's stable or improving, their personal conduct is fine and what changed is their exposure.
Is this surveillance?
No. WRI does not read email content, monitor keystrokes, track location, or capture files. It reads security events your existing tools already generate - a phishing simulation click is recorded by your email security platform whether or not WRI exists- and uses them to estimate risk.
Can WRI be used in performance reviews?
No. WRI is a security risk management tool. Use in HR or performance processes is not recommended, and the employee digest states this explicitly.
What if an event has been attributed to the wrong person?
Administrators can review individual events and remove them from an employee's record where appropriate; every such action is logged in the audit trail. You can also reclassify event severities for event types that generate noise in your environment.
Do I need every integration connected for WRI to work?
No. The model works with partial integration - with only phishing simulations and training data connected, scoring still functions correctly, just with less breadth of signal. The more sources connected, the more complete the picture.





















