Consent

This site uses third party services that need your consent. Learn more

Skip to content
Privacy-focused human risk management

Discover the Secure Practice way of learning

What we do

Secure Practice blends immersive experiences, intuitive tools, and engaging learning materials to bolster your team's cyber resilience.

Built on a foundation of guaranteed privacy and robust scientific methods, our platform champions a more sustainable way to develop, refine, and strengthen your team’s cybersecurity skillset.

We’re on a mission to help millions of people develop their cybersecurity abilities and knowledge - and become more confident in using them.

Circle labelled “Cyber exercises, positive reinforcement and instant feedback for suspicious emails”.

Help people with cybersecurity based on their knowledge, interest, and needs

Give your colleagues exactly the kind of support they need - and want - to make better cybersecurity decisions. 

Human risk metrics help you understand, measure, and manage the cybersecurity risks associated with human actions. 

Not because humans are the weakest link, but because it’s much more effective to engage people on their terms. 

password security
file sharing
account sharing
learning motivation
leadership example
access control
smishing risk

How we do it

Cybersecurity exercises

Through this immersive experience for teams, you learn with your colleagues by responding together to simulated cyberattacks. 

Collaborate to decide how to handle live cyber incident scenarios, complete with hands-on activities that mimic real situations.

MailRisk

Using automated analysis for email-focused social engineering attacks, MailRisk gives everyone instantly helpful feedback on the suspicious emails they report.

The data crowdsourced through MailRisk also provides IT and security teams with high-quality information for threat hunting and risk management.

Illustration showing how users are instantly rewarded with points for reporting an email in-app.

Simulated phishing

Train colleagues to respond to unexpected threats with ready-to-use exercises that mirror real-life scams and fraud attempts.

Balance personalized human risk management with privacy with anonymized results that spotlight topics for workshops, webinars, and other types of learning activities.

  • Well designed test!
  • Always nice to have reminders.
  • Super nice to get this instant feedback
  • I'm more careful about opening emails than before :)
  • Fun with the simulation!

Gamified e-learning

Gamified e-learning delivers a rich collection of customizable cybersecurity training content, from quick bites and gentle nudges to in-depth guides, email series, and lots more. 

Create and use personalized learning loops for your team based on anonymized data about your colleagues’ actions, interests, and level of knowledge.

How Human risk metrics work

Human cybersecurity risk metrics collects anonymized insights from every interaction with the Secure Practice toolkit.

Use them to understand the specific challenges your colleagues have and engage them in compelling activities to improve those security KPIs.

Human risk metrics help organizations understand, measure, and manage cybersecurity risks associated with human actions. 

Guarantee privacy while collecting security behavior data

To help people be safe at work and at home, we need data about their actions. But we don’t have to sacrifice their privacy to get it. 

Our unique, privacy-friendly approach doesn’t reveal individual risk scores. 

Instead, it maps risk factors (tags) to anonymous behavioral data and dynamically group people based on their learning interest plus knowledge of specific topics (scams, email security, self efficacy, etc).

Illustration showing how a risk factors contributors can contribute to an overall human risk score.

Understand, track, and improve your total risk score

The total risk score of your organization gives you a helpful KPI to track big-picture progress.

Since you can break down this score into clearly defined risk areas and corresponding risk factors, it’s easy to notice and prioritize areas of improvement.

By making security behaviors measurable, human risk metrics provide powerful arguments for a bigger budget when reporting to executives, and proof for return on investment.

Brightly-coloured pills labelled password security, file sharing, account sharing, learning motivation, leadership example, access control, smishing risk and supplier relationships.

Help vulnerable groups as their needs change

Forcing someone who fails a single phishing test into a generic course feels more like a punishment than a learning opportunity. Outdated and ineffective, these very transactional methods alienate people.

At Secure Practice, we use human risk metrics to observe behavior patterns over time, without compromising privacy. This allows for tailored follow-ups like micro-courses or exercises, ensuring upskilling aligns with evolving needs.

Illustration of a graph showing risk areas trending down.

Customize the Human Risk model for your organization

With 100+ pre-configured risk factors, it’s easy to get started with human risk metrics.

Together, these factors create the Human Risk model, which you can customize for your organization. Rename them, add new ones, and adjust their impact.

Organize them into your security program's key areas such as identity, devices, information and scams, plus compliance and motivation to gauge knowledge and interest.

Illustration showing how a Human Cyber Risk score can be broken down into different elements: accounts, passwords, multi-factor auth, lock devices and sharing are all examples of risk factors.

Win people’s hearts and minds without heartless monitoring

Power up your security awareness program with top-notch data, not surveillance. Make your team feel safe to act and engage - not blamed. 

Our privacy-first data collection approach lets you help vulnerable groups with targeted training without exposing individual behavior.

We’re developing Secure Practice with support from:

A list of logo's from the following companies:: Innovation Norway, European Cybersecurity Competence Centre, The Research Council of Norway, eea-and-norway_grants@2x.png, and Microsoft for Startups.

Co-funded by European Union / European Cybersecurity Competence Centre (ECCC) under grant agreement no. 101128020