The scoring model behind the Human-Layer Vulnerability Assessment - what it measures, how benchmarking works, and what it doesn't claim.
The Human-Layer Vulnerability Assessment measures decisions, not knowledge. Your people run short, timed drills built on documented incidents - the deepfake video call, the payment-change email, the poisoned knowledge base - and every choice they make is scored against what actually went wrong in the real event. Nobody passes by watching.
Every decision in every drill carries points set by its real-world consequence. Wiring money to an unverified account costs more than picking a weak password hint. A firm's results roll up three ways:
One number. A Human-Layer Exposure Score from 0 to 100, built as an equal-weighted average of the category scores below. One number to track over time.
Seven categories. Data Handling, Output Verification, Bias & Decisions, Verification Under Pressure, Agent Governance, Vendor & Knowledge Risk, Incident Readiness. Each maps to a family of real attack routes.
The detail. Per-decision misses, how fast the right call came, and whether the same miss repeats on a re-run. This is the layer a CCO works from.
Every firm runs the same drills. That makes comparisons honest by construction - the same instrument, the same difficulty, for everyone. (In phishing-simulation benchmarking, differing test difficulty is the biggest known source of skew, which is why the SANS Institute warns against comparing results across uneven programs.)
Your firm's score is shown against three references:
Your own trend. Baseline run, 90 days, annual - the remediation story, in numbers.
The AIS101 cohort. Once at least 30 firms share your comparison group (industry and size band), we show your percentile against them - and we always show how many firms are in the group. Below that threshold we say so instead of printing a number that looks more precise than it is.
Published external baselines, cited as context. Before any training, about one in three employees fails a phishing simulation (KnowBe4's 2026 benchmark of 42 million simulations across 64,000 organizations). After twelve months of continuous training, that falls to about one in twenty-five. The human element is involved in roughly 60% of breaches (Verizon DBIR 2025). These are phishing-click metrics from other instruments - useful context, never a conversion to our scale.
The SEC's FY2026 examination priorities tell advisers exactly what they'll be asked: the "training and security controls that firms are employing to identify and mitigate new risks associated with artificial intelligence." The report is the documented answer: dated completion evidence per learner, category exposure with benchmark context, the trend since baseline, and the remediation record - which decisions improved on a re-run.
It is an assessment of the human layer. It is not a penetration test, a security audit, or a legal or regulatory determination.
A percentile is a comparison to peers, not a probability of breach.
Research citations on this site describe general findings; they are not evaluations of this course.
KnowBe4, 2026 Phishing by Industry Benchmarking Report - 42M simulations, 14.8M users, 64,000 organizations; baseline Phish-prone Percentage 33.2%, 20.1% after 90 days of training, 4.2% after 12 months.
Verizon, 2025 Data Breach Investigations Report - human element in ~60% of breaches (12,195 confirmed breaches analyzed).
Proofpoint, 2024 State of the Phish - more than 1 in 10 users clicked a simulated phish; 1 in 5 for attachment tests.
SANS Institute, Effectively Benchmarking Your Phishing Awareness Program (2023) - variables that skew benchmarks, and the tiering fix.
SEC Division of Examinations, FY2026 Examination Priorities (Nov 2025) - training and security controls for AI-associated risks.