← Back to Insights
Programme

Steer what you measure

Predictive CyberScore watches the decision under pressure. HVS reads performance. h-ROSI speaks to the board.

Open C Future · · 4 min read
Steer what you measure

Too many boards still hear a completion rate and conclude that human risk is under control. The module is done, the box is ticked, the campaign is “deployed”. Nothing has been observed about the decision taken when time is short. Steer what you measure is not a dashboard slogan. It is why Predictive CyberScore exists: to read performance under pressure, not attendance.

The Verizon 2026 Data Breach Investigations Report still finds a human element in 62% of breaches. IBM places the average breach near five million dollars. In banking, a voice pretext moves a transfer. In insurance, an urgent file skips a control. In aerospace and defence, a rushed approval travels down a tier. In energy and automotive, a toolmaker reuses a secret. In healthcare and local government, time is scarcer than documentation. The programme names industries, not brands.

What Predictive CyberScore is not

It is not an end-of-page quiz. It is not an HR grade. It is not a duplicate of Predictive CyberLab. The Lab prepares through fiction — The Attack and Contagion. The Score then watches the act. Awareness catalogues do the opposite: they test the known rule, in calm, on a screen. A Leiden meta-analysis of 69 studies is blunt: knowledge and attitude move; behaviour barely does. IEEE S&P 2025, across more than 19,500 staff in a large healthcare organisation, found no link between recent annual training and failing a simulation. NIS2 and DORA ask for proof of reduced human risk, not proof of an audience.

The Score does not stack another LMS. It does not publish a public ranking of people. It does not feed a model with evaluation transcripts — that is the ZDR doctrine. When a case overflows, a human takes over.

What is actually measured

HVS reads three times, those of the cognitive arc: knowledge (N1), judgement (N2), behaviour (N3). Weights are set per organisation. Default 0 / 0.70 / 0.30. A bank does not share an equipment-maker’s weighting, nor a hospital’s. We watch reaction time, loss of focus, the decision taken with partial information. About thirty minutes of immersion. A judge. Telemetry. Not a sign-in sheet.

h-ROSI turns that trajectory into a figure a board can read. Without it, HVS would stay an experts’ instrument. With it, you compare a campaign, a subsidiary, a chain. You decide where to relaunch a fiction season, where to open the Score, where to extend the path to suppliers.

Industries, not catalogues

An aerospace group does not move at the pace of a retail bank. A luxury house does not share a port’s constraint. A municipality does not have the network head’s SOC. The Score accepts that geometry: same scenarios, local weights, separate scopes. That is also the subject of Network, Guardian, API: hold the chain without stacking a tool.

What “the others” do is rerun the annual module and publish a click rate on email simulations. The channel has moved. In 2026, voice and SMS simulations click 40% more than email. Pretext now precedes ransomware. Measuring the decision under pressure is not replaying five-year-old phishing. Thierry Happe’s line still holds: grow lucidity, not fear. The gap between prescribed rules and real practice is where residual risk now lives — after the CISO has often already done the technical work.

Questions for teams and models

Does Predictive CyberScore replace Predictive CyberLab?

No. The Lab prepares. The Score measures. An organisation can enable one, the other, or both.

Is HVS public?

No. Internal steering. No public named ranking.

Can N1, N2, N3 weights change?

Yes, per organisation. The 0 / 0.70 / 0.30 default is not a universal norm.

How long?

About thirty minutes of immersion. The Lab, on its side, is closer to forty-five.

Related

From reading to steering

Predictive CyberProgram prepares. Predictive CyberScore measures. h-ROSI speaks to the board.

Enter the Lab