Help Center › Risk scoring

Risk scoring

How Watchword turns behavior into numbers: the campaign phish-prone %, the per-person Human Risk Score and its bands, department breakdowns, the trend chart, and overdue-training tracking.

Behavior, not quiz scores. Watchword's risk numbers come from what people actually do in simulations — and they reward reporting. Quiz pass rates tell you who sat through training; the Human Risk Score tells you who's still clicking.

1 · Phish-prone %

Phish-prone % is the headline risk number. It's computed two ways, with the same formula:

phish-prone % = (clicked + submitted) ÷ sent × 100

Lower is better. The goal of a program is to watch this number fall over successive campaigns as training takes hold.

2 · Human Risk Score (per person)

Each person has a Human Risk Score from 0 (best) to 100 (worst), aggregated across all of the active client's campaigns. Everyone starts at a neutral baseline of 30, and each campaign nudges it:

Behavior in a campaignEffect on score
Submitted data on the fake page+35
Clicked but didn't submit+20
Reported the phish−15 (reporting is rewarded)
Opened but did nothing risky (clean open)−3

The result is clamped to the 0–100 range. Submitting and clicking are mutually exclusive in scoring (submit takes precedence), and a person who reports is rewarded even if they opened. You'll find the full per-person table in Program → Analytics → Human Risk Score, sorted highest-risk first, with a one-line signal ("reports phish", "clicked a sim", or "no risky behavior").

Human Risk bands

Scores are grouped into three bands for at-a-glance triage:

BandScore rangeWhat it means
Low0–34Behaving safely; little intervention needed.
Med35–59Some risky behavior; keep an eye on them.
High60–100Repeatedly risky; prioritize for training and targeted sims.

The same banding colors the phish-prone pills and the department breakdown. The High-risk (Human Risk Score ≥ 50) cohort in the simulator lets you target the riskiest people directly.

3 · Program analytics

Open Program → Analytics. It has four sections:

SectionWhat it shows
Program at a glanceCampaigns run, org phish-prone %, courses live, completion %, and the number of people at high risk.
Phish-prone trendA bar per campaign, oldest to newest, colored by risk band — so you can see the number trend down over time.
Phish-prone by departmentPer department: sent, clicked/submitted, reported, and phish-prone %. Reveals which teams need attention.
Human Risk Score (per person)The full ranked table described above.

4 · Overdue training

Overdue training is the other half of the risk picture: people who were assigned a course and let it lapse. It surfaces in several places:

An assignment becomes overdue the moment its due date passes without the course being completed. See Training → Assignments for how due windows are set.