Human Attack & Risk Management

Who can reach
your people?

PlankSec HARM helps security teams see, test and reduce the human attack surface across email, WhatsApp, SMS, QR, voice, deepfake, ClickFix, USB and social engineering.

Multi-channel human risk intelligence. Platform currently in active development.

PlankSec HARM Operations Dashboard in dark mode PlankSec HARM Operations Dashboard in light mode
HARM Score72
Open Risk Signals156
Human Attack Surface
The problem

Attackers don't
stay in the inbox.

Your people can be reached through many paths. The channel changes; the target is still human trust.

SC Sarah Chen Finance Director
01 / Email

A familiar request.

A supplier document, password reset or executive instruction arrives in the channel employees use all day.

02 / WhatsApp

A trusted identity.

An attacker changes the channel and uses urgency, familiarity and a public relationship to make the request feel real.

03 / Voice

Pressure in real time.

Vishing removes the pause people get with email. Verification habits are tested while a caller controls the pace.

04 / Deepfake

Recognition is no longer proof.

Synthetic voice or video can amplify executive impersonation and exploit established trust.

05 / Physical

The path can leave the screen.

USB drops and blended social engineering test curiosity, process and physical handling behavior.

A new security category

Your people are
an attack surface.

Attack surface management protects the technology attackers can reach. HARM focuses on the people attackers can reach.

01

Traditional attack surface

Technology

  • Applications
  • Cloud
  • Domains
  • Servers
  • Endpoints
  • APIs
02

Human attack surface

People

  • Employees
  • Roles
  • Relationships
  • Communication channels
  • Public exposure
  • Behavior
  • Trust
One operational view

See human risk forming.

Signals become useful when security teams can see the people, channels and outcomes behind them.

Approved PlankSec HARM Operations Dashboard showing risk metrics, alerts and Scout recommendations Approved PlankSec HARM Operations Dashboard in light mode showing risk metrics, alerts and Scout recommendations
HARM Score High-Risk Users Open Risk Signals Channel Exposure Human Risk Heatmap Scout Recommendations
01 / Discover

Find the exposure before the attack.

Map the role, relationships, public signals and channels that make a person reachable.

02 / Simulate

Test how attackers actually reach people.

Choose an approved channel and scenario that reflects the pressure the role may face.

03 / Observe

See what happens under pressure.

Capture security-relevant outcomes without turning human risk into productivity surveillance.

04 / Measure

Turn behavior into risk intelligence.

Connect channel outcomes with role criticality, history, training and exposure.

05 / Reduce

Know what to do next.

Target training, verify the improvement and keep the analyst in control of every action.

Human exposure profileHigh potential
SC

Sarah Chen

Finance Director

Finance
R

High-value financial rolePayment authority and supplier access

P

Public phone number exposedFound on a professional profile

C

Executive relationship identifiedFrequently associated with CFO

V

Vendor payment responsibilityHigh-impact operational trust

Potential Human Attack SurfaceHigh
Simulation setupPreview only
VO
Selected scenario

CEO urgent supplier payment

Verification pressure and executive impersonation

Target
Sarah Chen
Role
Finance Director
Channel
Voice
Difficulty
Medium

No message or call is sent from this website preview.

Behavior historyLast 90 days

Email phishingReported

Protected

WhatsApp impersonationIgnored

Protected

QR simulationScanned

Medium

VishingSensitive information disclosed

High

ClickFixNo execution

Protected

TrainingIncomplete

Action
HARM Score72/ 100
Email61WhatsApp48Voice84Deepfake73QR57USB22
Role CriticalitySimulation HistorySocial ExposureTraining StatusBehavioral Signals
Recommended actionsScout reviewed
01

Callback verification trainingTarget the seven users who disclosed information

02

Follow-up vishing simulationVerify improvement after training

03

Manager insightShare the Finance pattern without exposing private content

Current72
to
Projected after action58
Inside HARM

Meet Scout.

Your AI helper for human risk operations.

Scout assists analysts with campaign setup, scenario selection, result summaries and recommended follow-up work. It prepares the work; the user reviews and approves it.

  • Create campaign drafts
  • Recommend target groups
  • Explain HARM Score changes
  • Summarize campaign results
  • Suggest training and follow-up tests

Scout AIOnline inside HARM

Finance / Vishing
Finance currently has elevated voice exposure.

Suggested scenario
CEO urgent supplier payment

Target group
Finance - 48 users

Recommended difficulty
Medium
Create a vishing simulation for Finance.
Scout, PlankSec HARM's in-product AI helper

A phishing simulator reports campaign activity.

HARM explains human attack exposure.

Traditional simulator

Campaign outcomes

Useful for one campaign report, but shallow when leadership needs to understand where human risk is forming.

  • SentDelivery count
  • OpenedEngagement count
  • ClickedFailure count
  • ReportedReporter count
  • Training completedCompletion count
PlankSec HARM

Human risk command context

HARM includes everything a traditional simulator reports, then connects each result to the person, role, channel, pattern and next action needed to reduce real human risk.

  • Everything traditional systems reportSent, opened, clicked, reported and completed
  • Who is exposedPerson and group risk
  • How attackers can reach themEmail, voice, SMS, WhatsApp, QR and more
  • Which channels create riskChannel exposure breakdown
  • How role affects impactBusiness context and blast radius
  • What patterns are emergingBehavior trends and repeat signals
  • What should happen nextScout recommendations and workflows
  • Whether risk is improvingHARM score movement over time
  • Where an adversary could apply pressureRole-led scenarios and attack paths
  • How teams should validate defensesControlled human red-team exercises

From awareness testing to human red teaming

Move beyond isolated email tests with controlled, approved scenarios that model how attackers combine reconnaissance, impersonation, channels and operational pressure.

Spear phishingVishingSmishingQR phishingWhatsAppExecutive impersonationDeepfake scenariosHelpdesk social engineeringMulti-stage attacks
Attack channel explorer

Test the paths attackers use.

Email phishing and spear-phishing scenarios that test credential, attachment, payment and account-access decisions.

Email / available in preview
Platform preview

One platform.
Every human risk signal.

The interface follows one operating model across campaigns, people, profiles and integrations.

Selected screen

Operations Dashboard

HARM Score, channel exposure, high-risk users, risk signals, training status and Scout recommendations in one operational view.

PlankSec HARM / Private build
Operations Dashboard product screen Vishing Campaigns product screen Email Campaigns product screen Sending Profiles product screen Voice / SMS Profiles product screen Users & Groups product screen Integrations product screen
Privacy by design

Human risk without human surveillance.

HARM is designed around configured simulations, exposure and security-relevant outcomes. It is not positioned as productivity monitoring or silent access to private employee content.

01

Role-based access

Limit views and actions to the teams responsible for human-risk operations.

02

Data minimization

Collect the signals needed for security decisions, not unrelated personal activity.

03

Audit visibility

Keep campaign ownership, approvals and operational actions reviewable.

04

Configurable retention

Align simulation records and reporting windows with organizational policy.

05

Secure storage

Protect lead and platform data with controlled access and encrypted transport.

06

Privacy-aware reporting

Give leaders useful patterns without exposing unnecessary private content.

Private platform walkthrough

Know your
human attack surface.

See where your people are exposed. Test how attackers can reach them. Measure what happens. Reduce the risk before it becomes an incident.

Request a walkthrough

Tell us what you need to test.

We will focus the conversation on your channels, teams and human-risk goals.