CyBehave Heroes · Add-on module

Risk & Incidents

Available now

For the security team. Available from day one of a subscription.

Three things a security team needs from a Champions programme, in one module: a way for the whole workforce to raise the risks they see, a way to learn which behaviours your incidents keep pointing at, and a way to get threat intelligence to the people who can act on it. What happens on the ground becomes what the programme works on next.

What you get ↓ Start free trial → Pricing ← All modules
What you get

Three capabilities. One question answered: what should we work on next?

Risk Management

Turn the whole workforce into your early warning system.

Security teams find out about most risks late, because the people who notice them have nowhere obvious to put them. Risk Management gives every Champion, and anyone else in the organisation, a two-minute way to raise a risk, and gives your team a single register to run it from.

A report is a title, a category, a short description and a likelihood and impact rating on a five-point scale. The platform scores it, sets the level from low to critical, and puts it in front of your security team. Champions earn recognition for reporting, see the open risks for their own team, and can post updates as things change. Triage, ownership, notes and closure stay with your security and programme team, and every change is logged in plain English.

Risk handling counts towards Programme Strength. How quickly risks are closed against a target for their severity, and whether open risks are being actively worked, both feed the Programme Strength measure, so a well-run register shows up in the score your board sees.

What you get
  • Report from anywhere. A full-page form, a one-click "Log a Risk" from the dashboard, or a four-step flow on the phone. Nine plain-language categories, from phishing to supply chain.
  • Automatic scoring. Likelihood times impact on a 5 x 5 scale, with the level set for you: low, medium, high, critical.
  • A register your team runs. Status from reported to resolved, ownership in one click, notes, and tasks assigned straight to Champions to work a risk down.
  • A dashboard with a 5 x 5 heatmap. Open risks by likelihood and impact, counts of open, critical, triaged and assigned, risks by category, and the ten most urgent.
  • Champions see their team's risks. What they reported, what they own and what sits in their part of the organisation, with the ability to post updates and move status.
  • Network risk findings. Weak points in your Champion network, such as single points of failure, can be pushed straight into the register as risks.
  • Reporting. Board-ready CSV export, open-risk measures in the report builder, a risk summary in the daily email, and Nudge can answer "what does our risk picture look like?"
What you get
  • A register built for behaviour, not blame. What happened, when it occurred and was detected, how it was detected, its severity and an impact band. Never a person, never a currency figure, and simulations are kept out of every count.
  • Behaviour attribution. One primary behaviour and up to five contributing, each with a confidence grade: assessed, probable or possible.
  • A review queue. Every incident lands in the queue, oldest first. Take it, decide it, and record the outcome. "No action" needs a reason.
  • Four ways to act. Add a task to the campaign already covering that behaviour, start a new campaign against it, design an intervention, or add the behaviour to your priorities.
  • Behaviours ranked by incidents. Every behaviour with incidents over 12, 24 and 36 months, with two flags per row: is it a priority, and is anything running against it.
  • Honest measures. Incident rate per 1,000 people per month and the share reported by staff, with a statistical noise test so a change is only called a change when it is one.
  • Timelines and priorities. Incidents appear on each behaviour's timeline and beside each behaviour when you pick priorities, so the evidence is where the decision is made.
Incident Management

Every incident points at a behaviour. Find the pattern, then fix the cause.

An incident register that only counts incidents tells you how many there were. This one is tied to your behaviour catalogue, so each incident is attributed to the behaviours involved, and the pattern across teams and quarters tells you what to do about it.

When an incident is opened for review, the platform looks at the last twelve months for that behaviour and recommends a response: if the behaviour is not yet a priority, that comes first; if a campaign already covers the affected team, add the work to it; if incidents span several teams or keep returning across quarters, start a campaign; if it is one team in one quarter, design a targeted intervention. It shows the likely COM-B barrier and suggests techniques to match.

Private by design. Champions never see the incident register, because an incident in a small team identifies a person. Incident figures are shown as a criterion alongside your three measures, never folded into them, so a rise in reporting is read as a programme working, not a score falling.

Threat Intelligence

Intelligence your people can actually act on.

Most threat intelligence never reaches the people who need it, because it is written for analysts. Heroes turns it into something a Champion can take to their team on a Tuesday morning.

Your security function writes each item in plain, non-technical language, with a summary, the detail and a recommended action, and assigns it one of four classifications. A live checklist keeps the writing clear before it is published. Champions choose the classifications relevant to their teams, so they see what matters to them and not a firehose of everything. From there, a Champion logs a briefing to record that they took it to their colleagues, and your team can see who read and who acted.

Security function led, not automated ingestion. Nothing is scraped from a feed and pushed out unread. A person in your security team decides what is worth your colleagues' attention and writes it for them, which is why it lands as guidance rather than noise.

Four classifications, Champions choose
TechnicalVulnerabilities, malware, indicators, patching and configuration.
BusinessImpact on people, process, finance, brand or customers.
OperationalDay-to-day handling: what teams should watch for and do now.
StrategicLonger-horizon trends, threat-actor shifts and sector risk.
1Security function writes and publishes the item
2Champions see the classifications they have chosen, on desktop or phone
3A Champion briefs their team and logs it
4You see reads, briefings and a six-month trend, and review items at 90 days
In short

What the module adds to Base.

Priced at +30% of your Base subscription, available on any subscription from day one, and included in the 28-day free trial.

Risk register, dashboard and 5 x 5 heatmap, with reporting open to Champions and the whole workforce
Incident register tied to behaviours, with a review queue and a recommended response for each incident
Behaviours ranked by incidents, with priority and campaign gaps flagged
Incident rate and staff-reported share as honest, noise-tested criterion measures
Threat intelligence written by your team, with a read-only Champion feed and logged briefings
Risk closure pace and active management feeding the Programme Strength measure

Already in Base. Priority behaviours, the behaviour catalogue, campaigns, tasks and the guided intervention designer are all part of the base platform. This module adds the risk, incident and threat intelligence records around them, so the things you learn on the ground feed the work you already run.

Built for programmes that started with an incident.

Risk & Incidents is available now, on any subscription, from day one. Start a trial and turn it on.