The Phosphor Doctrine

Calibrated, not contrived.

Cyber IQ Score is an evidence model — calibrated against real player behaviour over 90 days, weighted by domain and recency, designed to be defensible under audit. Not a marketing metric. An audit-grade record of competency, per employee, per threat domain, per quarter.

Audit-defensible by design Weighted by domain & recency 90-day rolling calibration
The Scale

300 to 850. Five tier bands.

The Cyber IQ Score runs on a familiar 300-to-850 scale. Five bands describe what an employee in each band can be trusted to do under pressure — not what they have read, not what they have completed, but what they can be expected to recognise and decide correctly today.

300 500 600 700 800 850
Novice
UNDER 500
Still building foundations. High-frequency exposure to phishing and credential cues without reliable recognition.
Aware
FROM 500
Recognises the common threat patterns when prompted. Decision-making under time pressure remains inconsistent.
Proficient
FROM 600
Reliable on familiar threats. Mid-confidence on novel variants. Asks the right question before acting.
Expert
FROM 700
Reads tactics, not just artefacts. Maintains decision quality across stress, fatigue and unfamiliar framing.
Guardian
FROM 800
A trusted second pair of eyes. Routinely catches what the rest of the team misses and explains why.

Band floors shown. Internal weights and calibration constants reviewable under engagement.

The Eight Domains

Where the score gets its weight.

Every Cyber IQ Score is a weighted aggregate across eight threat domains. A player who excels at phishing recognition but folds on credential hygiene reads differently from one who is steady across all eight. The composition is part of the evidence.

Phishing

DOMAIN 01

Recognising deceptive lures across email, SMS and adjacent channels under live time pressure.

Malware

DOMAIN 02

Identifying malicious payload behaviour and the everyday delivery vectors employees actually encounter.

Credentials

DOMAIN 03

Password hygiene, MFA discipline and the social-engineering attempts that target both.

Data Handling

DOMAIN 04

Classifying sensitive data correctly and choosing the right channel for transmission and storage.

Social Engineering

DOMAIN 05

Spotting pretext, urgency and authority-spoofing in voice, chat and in-person interactions.

Incident Response

DOMAIN 06

Knowing the first three moves when something has gone wrong — report, contain, preserve.

Physical Security

DOMAIN 07

Tailgating, device handling, clean-desk discipline and the analogue gaps that bypass the firewall.

Cloud Posture

DOMAIN 08

Sharing controls, third-party app authorisation and the everyday SaaS decisions that change the blast radius.

Behavioural Metrics

Beyond right and wrong. How the answer was reached.

A correct answer at the end of a thirty-second deliberation reads differently from a correct answer at four seconds. Three behavioural signals run alongside accuracy on every session — and they are what separate a player who has been taught from a player who has been trained.

SIGNAL 01

Stress Resilience

How well decision quality holds up when the clock is running. The signal looks for the players whose answers don't deteriorate when the pressure rises — the ones you'd want on the call at 4am.

Stress BandHOLDING
LOW STEADY PEAK
SIGNAL 02

Decision Velocity

Time-to-correct-answer over the session, weighted to reward speed only when it arrives with accuracy. Faster is better — but only if the answer is still right.

Time to CorrectTRENDING
SESSION 1 NOW
SIGNAL 03

Recall Consistency

Retention of correct decisions across a 90-day window. The signal flags the difference between someone who learned the answer in October and someone who still knows it in January.

90-Day RecallSTABLE

Each signal is a directional indicator on the dashboard, not a published number on the public score. The signals compose into the Cyber IQ aggregate — the aggregate is what the auditor sees.

The Calibration Model

Today's score reflects today's competency.

Three principles govern how raw session evidence becomes the score that lands on an audit page. None of them are clever. All of them are deliberate.

01

Every session writes evidence.

Weighted by domain. Decayed by recency. Reviewable under engagement. Each play is a stamped, timestamped record of a decision under pressure — not a completion log, not a quiz score, but a behavioural artefact that adds to the employee's competency record.

02

The model is calibrated against real player behaviour.

Not synthetic benchmarks. Not a theoretical curve. The score thresholds are anchored on the live distribution of player performance across the eight domains — and recalibrated as the population shifts so the bands stay honest as the cohort grows.

03

Calibration trims old evidence.

Today's score reflects today's competency — not last year's training session. Recent evidence carries more weight than legacy evidence; legacy evidence is not erased, but its contribution recedes on a calibrated schedule. The audit page never asks an employee to vouch for a decision they made eighteen months ago.

Exact weights, decay constants and threshold maps are reviewable under engagement.

Audit-Defensibility

One page. Per-employee. Per-domain. Per-quarter.

The hand-to-auditor moment is the thing the whole model is designed for. When the external assessor asks "show me", the answer is a single export — readable in ninety seconds, defensible in ninety minutes.

Competency Evidence Pack
REF CIQ-2026-Q1-44829
ISSUED 2026-04-30
PAGE 1 OF 1
Employee competency record
Q1 2026 · Per-domain breakdown
Employee Redacted (E-44829)
Cyber IQ Score 742 Expert
Quarterly delta +38
Phishing 764 Expert
Malware 718 Expert
Credentials 812 Guardian
Data Handling 692 Proficient
Social Engineering 748 Expert
Incident Response 704 Expert
Physical Security 681 Proficient
Cloud Posture 609 Proficient

What this page answers

The export folds the calibration model into a single, readable artefact. It is the document a control owner hands to an auditor and a manager hands to a board. Three frameworks, one page.

NIS2 Article 20(1)

Management-body training evidence with auditable competency progression by individual and by domain.

ISO 27001 A.6.3

Information security awareness, education and training — evidenced as competency outcomes, not enrolment counts.

Cyber Essentials

Workforce-awareness alignment with quarterly trend lines to evidence ongoing competency, not point-in-time attestation.

NIS2 ISO 27001 Cyber Essentials
Talk to Sales

Layer it on top of what you already run.

Keep the awareness platform you already trust. Add the competency-evidence layer you can hand to an auditor. We'll walk you through the model, the calibration and the export — on a single call.