Flagship Product
Human Risk Management
TRISA
AI security awareness and human risk intelligence
1 min readLast reviewed July 18, 2026
The Problem
Why TRISA exists
Every control on your network can be patched, rotated, or replaced. Your people can't. Most breaches still start with one person clicking one link — and annual compliance training does almost nothing to change that behavior.
Industry Pain Points
What most teams are stuck with today
- Security awareness training is treated as a once-a-year checkbox, not a measured discipline
- Security teams have no visibility into which employees or departments carry the most human risk
- Generic training content doesn't reflect the specific threats an organization actually faces
- There's no way to prove training investment reduced real-world risk, only completion rates
How Threat ResQ Solves It
Inside TRISA
TRISA replaces the annual module with a continuous, AI-driven readiness loop. An AI mentor assesses each employee's Cyber Knowledge Quotient (CKQ), scores real behavioral risk, and adapts the next lesson to the specific gap — so a finance team member at risk of wire-fraud phishing sees different training than an engineer at risk of credential reuse.
TRISA — Live Overview
Readiness Trend
3.2x
See It In Action
TRISA, up close
TRISA — Overview dashboard
Screenshot placeholder
TRISA — Detail / drill-down view
Screenshot placeholder
TRISA — Reporting & export
Screenshot placeholder
Placeholder mockups — to be replaced with real product screenshots.
Platform Connection
TRISA in the Threat ResQ Platform
No product here works in isolation — every signal it produces or consumes is shared with the rest of the ecosystem.
Receives from
- TRAP
Phishing simulation results per employee
- DomainShield IQ
Active impersonation campaigns targeting your brand
TRISA feeds into
- getTRAC
Training completion logged as compliance evidence
Use Cases
Where teams put this to work
New-hire onboarding
Baseline every new employee's CKQ in week one, before they touch sensitive systems.
Post-incident remediation
After a real phishing click, assign the specific micro-training that closes that exact gap.
Board-level risk reporting
Show the board a department-by-department human risk trend, not a training completion percentage.
Business Outcomes
What changes after adopting it
3.2x
Faster improvement in readiness score vs. annual training
68%
Reduction in repeat phishing susceptibility within 90 days
100%
Of employees on an individually adapted path, not a fixed module
Feature Comparison
What changes, concretely
Traditional approach
TRISA
Security awareness training is treated as a once-a-year checkbox, not a measured discipline
AI-driven security awareness training
Security teams have no visibility into which employees or departments carry the most human risk
Human Risk Intelligence scoring per employee and department
Generic training content doesn't reflect the specific threats an organization actually faces
CKQ (Cyber Knowledge Quotient) psychometric scoring
There's no way to prove training investment reduced real-world risk, only completion rates
Adaptive learning paths, not fixed modules
Industries Served
Where TRISA fits
TRISA measures real judgment under pressure — the Cyber Knowledge Quotient — instead of a completion checkbox, giving BFSI organizations the human-risk evidence RBI and SOC 2 programs increasingly expect alongside technical controls.
TRISA's continuous, adaptive training works around clinical schedules rather than interrupting them, building the human-risk evidence HIPAA and ISO 27001 programs need without slowing down patient care.
TRISA's adaptive training is built for exactly the turnover problem education faces — it doesn't assume a one-time onboarding session covers a population that resets every semester.
Integrations
Fits into what you already run
Pricing is scoped to your environment.
TRISA is priced per organization size and scope — talk to us for a quote, not a generic tier.
Capabilities
What's included
- AI-driven security awareness training
- Human Risk Intelligence scoring per employee and department
- CKQ (Cyber Knowledge Quotient) psychometric scoring
- Adaptive learning paths, not fixed modules
FAQ
Common questions
What is CKQ scoring?
Cyber Knowledge Quotient (CKQ) is TRISA's psychometric model for scoring an individual's real security judgment — not just whether they completed a module, but how they'd actually behave under a live threat.
Does TRISA replace compliance training entirely?
TRISA covers the compliance requirement and goes further — the adaptive model is built to satisfy standard awareness training mandates while also measurably reducing behavioral risk, which a fixed annual module can't do.
How does TRISA connect to the rest of the platform?
TRISA is the flagship of the Threat ResQ platform. TRAP's phishing simulations and DomainShield IQ's external risk signals both feed into TRISA's readiness scoring, and getTRAC logs the resulting training activity as compliance evidence automatically.
See TRISA on your own environment.
30 minutes, no scripted pitch.