CYBER PULSE · WEEKLY THREAT INTELLIGENCE · SCOTT CHILLE
FIELD FRAMEWORK · Updated Sep 2026

The Human Attack Surface Index.

Human-layer attacks rarely look like malware. They look like a normal email, an invoice, a login prompt, a Teams message, an executive instruction. Score your workforce exposure across five dimensions before an attacker does.

The Ratio Nobody Wants to Say Out Loud

Grounded in the 2026 SANS Security Awareness & Culture Report

SANS surveyed over 1,700 security awareness practitioners for this year's report, and the headline finding is the one most security budgets already prove: it is common to see a 50 person security team with 49 people focused on technology and exactly one focused on the human side. Then everyone acts surprised that people remain the primary way attackers get in. SANS suggests a starting ratio of roughly 10 technical security professionals for every one human focused professional. Most organizations are nowhere close.

The same report tracked the top human risks organizations are focused on for 2026, and the order shifted in a way worth paying attention to. Social engineering held the top spot at 77%. What moved was AI, which jumped from the fourth ranked human risk to a strong second at 42%, ahead of sensitive data mishandling (39%) and weak passwords or poor authentication (22%). Two years ago AI barely registered on this list. Now it is the fastest growing line item on the human attack surface, and most training calendars have not caught up.

That is the gap this tool is built to surface. The Human Attack Surface Index scores five dimensions of workforce exposure, phishing readiness, credential and MFA risk, BEC readiness, sensitive data handling, and AI and shadow IT risk, because a technology stack score alone will not tell you where the 49-to-1 problem is actually hiding in your organization.

Your Score
--
Answer all questions
Dimension Breakdown

Executive Interpretation

Answer every question above to see your organization's human attack surface score.