Your security stack is governed.
Your human layer isn't.
Walk into the board meeting with a number. Walk into the audit with a methodology. Walk into the next customer security questionnaire with answers that already exist.
The Human Resilience Score: sixteen risk categories. Pre-mapped to ISO 27001, NIS2 21(2)(f), SOC 2, and DORA. At the calculation level.
Every layer ships evidence.
Now the human
layer does too.
Compliance is an output of the engine, not its purpose. The Risk Framework structures every signal. The Resilience Score quantifies the outcome. The audit trail records every intervention and the signal that triggered it. The board pack assembles automatically.
When the auditor asks how risk reduction was measured, you answer with a methodology, a time-series, a per-department breakdown, and a drill-down to the individual.
That is what NIS2 21(2)(f) is asking for.
Read the NIS2 mapping
Per-user click and reporting rate plus the Resilience Score with methodology and historical comparison — role-mapped, time-series.

Awareness coverage by job role, traceable to source signals.

Policy acknowledgment per user with version control.

Phishing-driven incident reporting with classification and time-stamp.
A risk number you can defend.
The Human Resilience Score is the board-grade output of the engine. Calculated from sixteen risk categories, weighted for stacking, normalized across the organization.
Defensible to the auditor. Quotable to the CFO.
Drill into any department, any cohort, any individual. The history is preserved. The methodology is documented.
The trend is the answer to did risk reduce.
Organization
Walk in with a number.
Walk out with a budget.
CK Group's Head of IT walked into the board meeting with a Resilience Score of 84, a methodology, and an eight-month historical trend.
The board's question moved from "Are we doing enough training?" to "What does it cost to move this number?"
That is the conversation Moxso enables.
Defensibility. Quantified.
A risk number, with methodology.
The number stands up to the auditor. The methodology is documented. The historical trend is preserved. The board accepts the answer.
NIS2, ISO, SOC 2 structurally connected.
The evidence stack maps to the control sets. Audit cycles get lighter. Customer security questionnaires answer themselves.
From organization to individual.
The Resilience Score drills from organization to department to employee. Risk concentration is named, not implied.
Walk in with a number.
When the board asks where human risk sits, the answer is a number with a methodology, not a percentage with a footnote.
A connected layer, not a parallel program.
The Signal Bus, at Defend tier. Human risk carried into Splunk, Sentinel, XSOAR, CrowdStrike, and the identity layer. The human layer becomes a connected layer of your security stack, not a parallel program with its own dashboard.



