For Security Leaders · Defensibility Fit

Your security stack is governed.
Your human layer isn't.

Walk into the board meeting with a number. Walk into the audit with a methodology. Walk into the next customer security questionnaire with answers that already exist.

The Human Resilience Score: sixteen risk categories. Pre-mapped to ISO 27001, NIS2 21(2)(f), SOC 2, and DORA. At the calculation level.

Evidence

Every layer ships evidence.
Now the human
layer does too.

Compliance is an output of the engine, not its purpose. The Risk Framework structures every signal. The Resilience Score quantifies the outcome. The audit trail records every intervention and the signal that triggered it. The board pack assembles automatically.

When the auditor asks how risk reduction was measured, you answer with a methodology, a time-series, a per-department breakdown, and a drill-down to the individual.

That is what NIS2 21(2)(f) is asking for.

Read the NIS2 mapping
What the audit trail produces
NIS2
21(2)(f) · Behavior

Per-user click and reporting rate plus the Resilience Score with methodology and historical comparison — role-mapped, time-series.

ISO 27001
A.6.3

Awareness coverage by job role, traceable to source signals.

SOC 2
CC1.4

Policy acknowledgment per user with version control.

DORA
Article 17

Phishing-driven incident reporting with classification and time-stamp.

The Number

A risk number you can defend.

The Human Resilience Score is the board-grade output of the engine. Calculated from sixteen risk categories, weighted for stacking, normalized across the organization.

Defensible to the auditor. Quotable to the CFO.

Drill into any department, any cohort, any individual. The history is preserved. The methodology is documented.

The trend is the answer to did risk reduce.

Human Resilience Score
0%

Organization

AreaScore
Finance 91
Operations 78
Engineering 84
NIS2 Controls Covered: 100%
Board-grade

Walk in with a number.
Walk out with a budget.

CK Group's Head of IT walked into the board meeting with a Resilience Score of 84, a methodology, and an eight-month historical trend.

The board's question moved from "Are we doing enough training?" to "What does it cost to move this number?"

That is the conversation Moxso enables.

What lands in the board pack
Section
Output
Headline Number
Resilience Score, organization-wide, with quarter-on-quarter delta.
Departmental Breakdown
Per-department scores, ranked, with movement direction.
Sector Benchmark
Where you sit against the cohort of similar organizations in your country.
Compliance Posture
Coverage on the NIS2 control set, audit findings, evidence map.
Methodology Footnote
How the number is calculated, defended in plain language.
What you actually get

Defensibility. Quantified.

01 · Defensibility

A risk number, with methodology.

The number stands up to the auditor. The methodology is documented. The historical trend is preserved. The board accepts the answer.

02 · Compliance

NIS2, ISO, SOC 2 structurally connected.

The evidence stack maps to the control sets. Audit cycles get lighter. Customer security questionnaires answer themselves.

03 · Visibility

From organization to individual.

The Resilience Score drills from organization to department to employee. Risk concentration is named, not implied.

04 · Authority

Walk in with a number.

When the board asks where human risk sits, the answer is a number with a methodology, not a percentage with a footnote.

05 · Signal Bus

A connected layer, not a parallel program.

The Signal Bus, at Defend tier. Human risk carried into Splunk, Sentinel, XSOAR, CrowdStrike, and the identity layer. The human layer becomes a connected layer of your security stack, not a parallel program with its own dashboard.

Get started

See how your team can reduce human risk

Explore how Moxso helps your team identify employee risk, target training and assess progress. Tell us where you want to reduce exposure.

  • Explore how training, simulations and follow-ups address gaps.
  • See how human risk varies across your organization, departments and employees.
  • Review how your goals automatically steer risk reduction.

By submitting this form, you agree to our Privacy Policy. We will be in touch within one working day. No nurture sequence.

ISO 27001 certifiedEnterprise-grade security across all operations.
EU sovereign by architectureData sovereignty compliance built in.