Measure what people do. Not what they completed.
Cyberdise rates each person on what they did when tested: the links they clicked, the data they entered, the trainings they did not pass. When someone reports a suspicious message, it reaches your security team as a case.

Completion tells you a course was consumed. Behavior tells you whether it worked.
Each person gets a risk rating from 0 to 100, built from what they did in simulations and training. Higher means riskier, and every report they make is recorded beside it.
Tells you the content was delivered. Not what happens to the next suspicious message.
Clicked, data entered, file opened or reported. Each is recorded per person and per campaign.
People rate themselves, and the rating and the behavior often disagree.
Clicks, submitted data, opened files and reports. Nobody grades themselves.
No way to see which department or role carries the exposure.
The same score rolls up for the board and drills down for the operator.

Your board report, generated from the campaign.
Pick a campaign, choose a template, the modules and the sections, and generate. The template holds your wording, your logo and your structure. Variables fill in the counts and percentages, so every figure comes from the campaign and none from a spreadsheet. Keep one template for the CISO, another for the risk officer and a third for the auditors.
- A default template in every realm, ready to use or duplicate
- Sections for goals, setup, visit timing, training and phishing results, and a conclusion
- Word or PDF output, with the same data on the dashboard, in CSV exports and through the API
- One layout can serve several realms
Behavior moved. Attitude moved separately.
The distinction matters for what you measure: training shifted how people think, exposure shifted what they did.
Source: AISP study
A reported message becomes a security case.
Reported messages are analyzed inside Cyberdise or passed to the tooling you already run, and your team works them as cases. Repeat reports of the same attack merge into one incident instead of arriving as fifty separate tickets. When the reported message was one of your own exercises, it is labeled as a simulation rather than opened as a threat.
- Cases in one incident dashboard, reviewed by realm or tenant operators
- Case automations that call your own tools through the API
- Reports counted per person in the campaign statistics
- Incident figures ready to drop into the campaign report

Where the signals come from, and what they start.

You choose which steps run on their own.
When thresholds are met the workflow escalates: open a case, pass data into SOAR, block a sender, remove the message from inboxes, or hand enriched context downstream. You automate only the steps you choose to automate. Because repeat reports merge into one case and thresholds are set per realm, a real attack gives your analysts one case to work rather than a queue of duplicates.
- Reported messages forwarded to your SOAR environment or sandbox
- A REST API with full access to the platform, documented in OpenAPI
- Token access limited to the realms each operator can see
- Thresholds configurable per realm
How is the risk rating calculated?
Does reporting a message improve someone's rating?
Who can see individual results?
Can we run campaigns anonymously for the works council?
What personal data does a simulation collect?
What happens to someone's results when they leave?
See your own numbers before you commit to anything.
We show you where the score comes from and what your board report would look like.