Human-factor attack surface · measured, not guessed

The people in your organisation
are the attack surface.
Now you can reduce it.

Dirigent shows every employee the attacks an adversary could run on them personally — and gives you the cohort metrics, playbooks and audit-ready evidence your regulator wants. Without ever seeing them as individuals.

Professional Identity Vanity & Recognition Life Transitions Trust Networks Protective Instincts Routine & Predictability Financial Concerns Values & Beliefs LEVERAGE marketing dept · n=18

What your human attack surface enables.

Fraud
wire · CFO impersonation
invoice redirect
$2.9bn BEC losses · FBI IC3 '23 ↗
Cyber breach
phishing · OAuth abuse
credential theft
68% involve people · DBIR '24 ↗
Espionage
recruitment · blackmail
insider cultivation
~70% start social-eng · Mandiant ↗
Reputational attack
exec doxxing · harassment
targeted disinfo
$4.45M avg breach cost · IBM '24 ↗
Fines & liability
NIS2 Art 20/21 · DORA
GDPR Art 32 · CER
€10M / 2% turnover · NIS2 Art 34 ↗
Two views · one assessment

Your employees see themselves as targets.
You see cohort patterns. The two never meet.

Employee debrief · private delivered
👤
Your daughter is named in your LinkedIn About section
strongest protective-instinct leverage an attacker can wield
📍
Strava reveals your commute · Mon–Thu · ~08:18
Transvaalstraat → Zuidas · 200m privacy zone fixes it
🔓
Adobe 2013 breach exposes your DOB
confirmed independently in Bevolkingsonderzoek 2025
findings 3 of 12 →
Aggregate dashboard · k=5 anonymous
Marketing
n=18
78%
Finance
n=24
81%
Engineering
n=38
74%
Legal
n=3 · suppressed
below k-anonymity threshold
OAuth phishing exposure · 4 of 6 cohorts shown
↑ One employee · one private debrief   ·   one dashboard · aggregates only, k ≥ 5 ↑
How it works

Only what any AI could already find.
Two flows out — privacy and data security.

Input · only public data
LinkedIn public press disclosed breaches public records social trails
No special access. No scraping past authentication. Nothing private. All of it is data any AI agent could already collect today — Dirigent's value is in structuring what's already commodity, not unlocking what isn't.
Privacy flow
Who sees what.
Routing and permissioning between subject, employer, and Dirigent.
1
Employee sees their own findings
Detailed, individualised, in their language. The subject is the only person with access to their own debrief.
2
Employer sees aggregates only
Cohort metrics, sentiment averages, threat archetypes. Never individuals. Decline reasons stay private to the subject.
3
k = 5 minimum cohort size
No cohort below five respondents is computed or shown. Structurally, not just hidden.
Data security flow
How the data is protected.
Encryption lifecycle from collection through verifiable destruction.
1
Encrypted in transit and at rest
Standard transport encryption · at-rest encryption tied to a per-assessment key generated at start.
2
Per-assessment encryption key
Each assessment gets its own key, never shared across runs. The key is the only path to the raw data.
3
Key destroyed at closure
24-hour grace window, then the key is shredded. Raw OSINT, transcripts and individual responses become unreadable — including by Dirigent.
Choose your context

Same engine. Your regulator's vocabulary.

EU · all essential and important
NIS2
Directive (EU) 2022/2555
Art 20(1) · 20(2)
Art 21(2) d · f · g · i
Sample attestation
EU · financial services
DORA
Regulation (EU) 2022/2554
Art 5 · 6(8) · 9
Art 13(6) · 28
Sample attestation
UK · NCSC frameworks
CE+ · CAF
Cyber Essentials Plus + CAF
CAF B2 · B4 · B6
CE+ awareness control
Sample attestation
+ CER · EU physical resilience + SOC 2 / NIST CSF + ISO 27001 A.7 Need another? Talk to us.
Threat library

Three archetypes that actually land. Derived per cohort.

Wire fraud · CFO impersonation
Finance ↔ Exec interface
Coercive request, out-of-band channel, signed urgency. Lands hardest where budget authority overlaps with public press exposure.
Top exposure 81% Cohort fit Finance · n=24 Mitigation OOB verify · approval-chain
OAuth consent phishing
Admin-scope creep
M365 / Google / GitHub admin overlap, sales-tool sprawl, long-lived PATs. Phishing-resistant MFA on admin scopes is the lever.
Top exposure 74% Cohort fit Engineering · n=38 Mitigation FIDO2 · scope review
IT impersonation
Helpdesk · password reset
Familiar-pretext password-reset requests, vendor-portal access. Trust-network exploit zone — verification protocol is the fix.
Top exposure 71% Cohort fit Operations · n=38 Mitigation OOB on resets

See what an attacker would derive about your team.

Free sample attestation in your inbox in 10 minutes — no sales call required.