For the security team. Available from day one of a subscription.
Three things a security team needs from a Champions programme, in one module: a way for the whole workforce to raise the risks they see, a way to learn which behaviours your incidents keep pointing at, and a way to get threat intelligence to the people who can act on it. What happens on the ground becomes what the programme works on next.
Every Champion and every member of staff can raise a risk in plain language from the platform or their phone. Your security team triages, owns and closes them, and a live heatmap shows where the exposure is.
Record what happened, attribute it to the behaviours involved, and let the pattern across teams and quarters tell you whether the answer is a priority, a campaign or a targeted intervention.
Your security team writes it once, in plain language. Champions read the items relevant to their teams, brief their colleagues, and you can see who read and who acted.
Security teams find out about most risks late, because the people who notice them have nowhere obvious to put them. Risk Management gives every Champion, and anyone else in the organisation, a two-minute way to raise a risk, and gives your team a single register to run it from.
A report is a title, a category, a short description and a likelihood and impact rating on a five-point scale. The platform scores it, sets the level from low to critical, and puts it in front of your security team. Champions earn recognition for reporting, see the open risks for their own team, and can post updates as things change. Triage, ownership, notes and closure stay with your security and programme team, and every change is logged in plain English.
Risk handling counts towards Programme Strength. How quickly risks are closed against a target for their severity, and whether open risks are being actively worked, both feed the Programme Strength measure, so a well-run register shows up in the score your board sees.
An incident register that only counts incidents tells you how many there were. This one is tied to your behaviour catalogue, so each incident is attributed to the behaviours involved, and the pattern across teams and quarters tells you what to do about it.
When an incident is opened for review, the platform looks at the last twelve months for that behaviour and recommends a response: if the behaviour is not yet a priority, that comes first; if a campaign already covers the affected team, add the work to it; if incidents span several teams or keep returning across quarters, start a campaign; if it is one team in one quarter, design a targeted intervention. It shows the likely COM-B barrier and suggests techniques to match.
Private by design. Champions never see the incident register, because an incident in a small team identifies a person. Incident figures are shown as a criterion alongside your three measures, never folded into them, so a rise in reporting is read as a programme working, not a score falling.
Most threat intelligence never reaches the people who need it, because it is written for analysts. Heroes turns it into something a Champion can take to their team on a Tuesday morning.
Your security function writes each item in plain, non-technical language, with a summary, the detail and a recommended action, and assigns it one of four classifications. A live checklist keeps the writing clear before it is published. Champions choose the classifications relevant to their teams, so they see what matters to them and not a firehose of everything. From there, a Champion logs a briefing to record that they took it to their colleagues, and your team can see who read and who acted.
Security function led, not automated ingestion. Nothing is scraped from a feed and pushed out unread. A person in your security team decides what is worth your colleagues' attention and writes it for them, which is why it lands as guidance rather than noise.
Priced at +30% of your Base subscription, available on any subscription from day one, and included in the 28-day free trial.
Already in Base. Priority behaviours, the behaviour catalogue, campaigns, tasks and the guided intervention designer are all part of the base platform. This module adds the risk, incident and threat intelligence records around them, so the things you learn on the ground feed the work you already run.
Risk & Incidents is available now, on any subscription, from day one. Start a trial and turn it on.