SELF-ASSESSMENT / 7 QUESTIONS / 90 SECONDS

Which security types dominate your workforce?

No two employees are alike, and there’s no reason to treat them the same.

For twenty years the tooling could only tell you who clicked. Never why. That was an instrument gap, not a judgment gap, and it left a handful of behavioral types driving most of the real risk, invisible inside the aggregate. Two things sort those types: how your people feel about security, and how well they understand it. In 90 seconds, see which ones dominate yours.

What this model is built on
100+

enterprise deployments across financial services, manufacturing, healthcare, energy and the public sector.

10 billion

behavioral data points measured on the OutThink platform.

Peer-reviewed behavioral science

The two-axis segmentation is grounded in academic research co-authored by Prof. Angela Sasse, OutThink’s Chief Scientific Advisor, and is embedded in the platform as psychographic segmentation.

OutThink is recognized by Gartner in Security Behavior & Culture Programs.

Deployment and data-point figures are measured across OutThink enterprise deployments; individual results vary by baseline and deployment maturity. The assessment below is a directional self-assessment, not a measurement of your workforce.

The method

How this assessment works

Two things predict how someone actually behaves under security pressure. Not their job title, and not whether they passed last year’s module.

Vertical axis

Affective Security

How your people feel about security: whether they own it, tolerate it, or experience it as a tax on the real job. Low affective security is what pushes capable people into workarounds.

Horizontal axis

Risk Understanding

How well your people understand the risk: whether they grasp why a control exists, or only that it does. Low risk understanding is what targeted, role-specific training actually moves.

Four quadrants, sixteen types

Each axis bands into four levels: strongly negative, weakly negative, weakly positive, strongly positive. That produces a four-by-four matrix, and the research names all sixteen cells. The four quadrants below are the coarser two-by-two view of the same matrix, named after the Johari Window: Open (positive on both axes), Blind (motivated, under-informed), Hidden (informed, disengaged) and Unknown (negative on both).

Hover or tap any of the sixteen cells to see what that type is, the risk it carries, and what moves it.

Affective Security
how they feel about security
Strongly
negative
Weakly
negative
Weakly
positive
Strongly
positive
Strongly
positive
Weakly
positive
Weakly
negative
Strongly
negative
Risk Understanding  how well they understand the risk

Scroll the grid sideways to see all four columns.

Open
Positive on both axes. Motivated and informed. Harness them.
Blind
Positive attitude, negative understanding. Motivated but under-informed. Train them.
Hidden
Negative attitude, positive understanding. They know the risk and route around the control anyway. Reduce the friction.
Unknown
Negative on both axes. Low buy-in and low understanding together. The highest priority.

The Hidden quadrant rests on the compliance budget, the earlier finding by Beautement, Sasse and Wonham that every person has a finite capacity for security effort. Workarounds begin when a control demands more than that budget allows, which is why the people who understand the risk best are sometimes the ones circumventing it.

Seven questions: three read affective security, three read risk understanding, and one adjusts for how much of your workforce sits away from a desk and corporate IT. Each axis is scored and banded, which places you in one quadrant and on one of the sixteen types. This is a directional read of the environment you describe, not a measurement of your people. Note too that the original research treats the categories as relative rather than absolute. Someone scores as a given type compared with others in their own organization, not against the full range of possible behavior. Answer for your organization as it really runs today; the value is in the gaps it surfaces. If you want the program-level view instead, take the HRM Maturity Assessment.

The research behind this tool

Where the framework comes from

This tool exists to make an academic framework usable. The Behavioral Security Grid, its two axes and all sixteen types were defined in peer-reviewed research at University College London, not by OutThink. We have built an interactive way to explore it, in our own words and design, with the sources below.

  1. [1]Beris, O., Beautement, A. and Sasse, M. A. (2015). “Employee Rule Breakers, Excuse Makers and Security Champions: Mapping the risk perceptions and emotions that drive security behaviors.”Proceedings of the 2015 New Security Paradigms Workshop (NSPW ’15), ACM, pp. 73–84.doi:10.1145/2841113.2841119 · open-access PDF · UCL DiscoveryThe naming source. Defines both axes, the four quadrants and all sixteen types.
  2. [2]Beris, O. (2017). “Risk understanding is not enough: modelling and measuring employee security behavior.”Doctoral thesis, University College London.open-access PDFThe fuller mechanics: quadrant construction, scoring methodology and case studies.
  3. [3]Beautement, A., Sasse, M. A. and Wonham, M. (2008). “The compliance budget: managing security behaviour in organisations.”Proceedings of the 2008 New Security Paradigms Workshop (NSPW ’08), ACM.open-access PDFThe predecessor concept the Hidden quadrant rests on. Every person has a finite budget for security effort, and workarounds begin when it runs out.

The Behavioral Security Grid is built into OutThink’s Human Risk Intelligence, designed with the research of our Chief Scientific Advisor, Professor M. Angela Sasse (FREng), founder of the Research Institute in the Science of Cyber Security at UCL and a co-author of both the 2015 and 2008 papers above.

Framework adapted with credit. The type names and axis names are the researchers’; the descriptions, visual design and this assessment are OutThink’s. No figures or tables from the papers are reproduced here.

Question 1 of 7
Answer for your organization as a whole, not for yourself.
Risk understanding

When your people follow a security rule, do they mostly understand why, or just that they have to?

Know your type. Now find your level.

This assessment reads your people. The HRM Maturity Assessment reads your program: twelve questions to place you on the four levels of the HRM Maturity Model and show what it takes to level up.

Take the HRM Maturity Assessment

Illustrative synthetic data. Not a measurement of any real organization, and not customer data.

The Behavioral Security Grid, its two axes and its sixteen behavioral types were defined in peer-reviewed research at University College London by Beris, Beautement and Sasse (NSPW ’15, doi:10.1145/2841113.2841119), building on the compliance budget of Beautement, Sasse and Wonham (NSPW ’08). Framework adapted with credit. The concepts are presented here in OutThink’s own words and design; no figures or tables from the papers are reproduced. Full sources.

Want to talk it through? Speak to our HRM specialists