This article answers common questions about the transition from Company Risk Score to Human Risk Score in Engage. For the full change announcement, see the article: Awareness Training to Engage Core Migration - Jul 2026.
Human Risk Score in Engage - Frequently Asked Questions
| Q: | Will I lose my historical company risk score data after migration? |
| A: | No. Historical Company Risk Score data is preserved through the migration and remains available in the Risk Center. You can continue to view the Company Risk Score trend on the Risk Center overview and export detailed data from the user risk page after migration. |
| Q: | Does a lower human risk score mean my organization is at more or less risk? |
| A: | Less risk. Human Risk Score uses a numeric scale from 0 to 10 where lower values indicate lower risk. This is inverted from the company risk score, where "A" was the best grade and "F" the worst. A Human Risk Score of 1.9 (labeled "Very Low"), for example, corresponds roughly to what would have been an "A" grade under the old model. |
| Q: | How do I export my company risk score history? |
| A: | Navigate to Reporting & Insights, then Risk Center. Click View Details on the user risk card, then either Export Raw Data for an XLSX file or Report for a PDF that includes Company Risk Score alongside Employee Breakdown by Grade. This can be done before or after migration. |
| Q: | What happened to the Human Error, Engagement, Knowledge, and Sentiment scores? |
| A: | These dimensions were part of the Company Risk Score model. Human Risk Score uses a different set of five behavioral dimensions: Training, Simulated Phishing, Actual Phishing, Sensitive Data Handling, and Malware. The previous dimensions are no longer surfaced in the Program Overview, though historical data remains available in the Risk Center. |
| Q: | How is the human risk score calculated? |
| A: | Human Risk Score is calculated from observable user behavior across five behavioral dimensions: training performance, simulated phishing outcomes, actual phishing engagement, sensitive data handling, and malware interactions. The score factors in both positive actions (like reporting a phishing email) and negative actions (like clicking a phishing link). The exact calculation formula is viewable through the in-app Human Risk Score Simulator (see below). |
| Q: | Why is one of the Human Risk Score dimensions showing no data or a very low contribution? |
| A: |
Human Risk Score dimensions are populated based on your connected security tools. Data from Mimecast Email Security, Engage phishing simulations, and training assignments flow in automatically for existing Engage and Awareness Training customers. Other categories, like malware or third-party actual phishing telemetry, require the corresponding integrations to be configured. HRCC will indicate which data sources are currently feeding your Human Risk Score and which are not, so you can see at a glance where additional integrations would enrich your scoring coverage. The more integrations you configure, the more accurate and complete your Human Risk Score becomes. |
| Q: | Can I see the exact formula behind a score? |
| A: | Yes. The Human Risk Command Center includes a Human Risk Score Simulator that shows the formula used to calculate both organizational and individual scores. To access it, click the info icon on the organization score or on an individual's score. The simulator also lets you model how your organization's score would change under different employee risk distributions, which is useful for setting realistic improvement targets. |
| Q: | How can I see why a specific user has the score they do? |
| A: | Navigate to the user's Individual Risk Profile in the Human Risk Command Center. The Profile Info tab shows the score breakdown by factor. The Events tab shows the specific behaviors and events that contributed to the score, including actions the user took (like clicking a phishing link or completing training) and events affecting the user (ingested from Mimecast's security integrations). This is a significant expansion of visibility compared to the company risk score, which surfaced only the final grade. |
| Q: | What is the human risk command center and how do I access it? |
| A: |
The Human Risk Command Center (HRCC) is the centralized view for identifying, analyzing, and responding to human risk across your organization. It's where the Human Risk Score is calculated and displayed, and where you can drill into the specific behaviors driving each user's score. Access depends on your current setup:
To access HRCC:
1. Log in to the
Mimecast Administration Console. For full documentation, see Human Risk Command Center Overview. |
| Q: | Who in my organization can access the Human Risk Command Center? |
| A: | HRCC access is available to admins with one of the following roles: HRCC Administrator, Security Awareness Administrator, Super Administrator, or Basic Administrator. Custom roles can also be configured with Human Risk Command Center Read or Edit permissions. Access can be restricted by editing role permissions to remove Human Risk privileges. |
| Q: | Can I still see individual user risk grades (A/B/C/D/F)? |
| A: | Individual user risk detail remains available on the User Risk page. The top-level Program Overview no longer displays the A/B/C/D/F distribution card, but if you use letter-grade breakdowns for targeted training assignments, that data is still accessible. |
| Q: | Do I need to update my existing reports or dashboards to leadership? |
| A: | Yes, if you currently report Company Risk Score to internal stakeholders. We recommend preparing a brief explainer of the new scoring model ahead of your migration so your audience understands the shift, particularly the inversion of the scale (lower Human Risk Score is better). |
| Q: | Will my end users see any change? |
| A: | No. End users do not see Company Risk Score or Human Risk Score. The change is limited to admin-facing views. |
Comments
Please sign in to leave a comment.