This article explains how to monitor, analyze, and manage your organization's security posture using the Employee Vulnerability Score (EVS) and Hack Records within the TSAT dashboard.
The Employee Vulnerability Score (EVS) provides real-time visibility into the overall and individual risk levels of employees based on their interactions with simulation campaigns.
Total Users: Displays the aggregate number of tracked users across the platform.
AVG EVS: The collective average risk percentage of your entire organization.
Risk Distribution Bar: A color-coded summary categorizing your workforce across four risk tiers:
Low (Green)
Medium (Yellow)
High (Orange/Red)
Critical (Dark Red)
Export CSV: Click the Export CSV button in the top right to download a spreadsheet of all employee EVS metrics.
Search: Quickly locate any employee by typing their name or email into the search field.
Filter Options: Filter user lists by specific risk levels or departments.
Pagination & Rows: Adjust the dropdown to choose how many records display per page (e.g., 10, 25, 50).
View Details: Click the Eye Icon (👁️) on the far right of any user row to open their detailed drawer/profile.
Clicking the Eye Icon (👁️) opens an interactive side-drawer displaying detailed behavioral analytics for that specific user.
Attack Vector Filter: Select specific vectors (e.g., Phishing, Smishing, Vishing) or leave set to Overall.
EVS Score Gauge: A visual dial displaying the user's current EVS percentage and risk severity level (Critical, High, Medium, Low).
Score Analysis Tab:
EVS Score Breakdown: Displays risk scores categorized by attack vector.
EVS Trend Graph: A chronological chart illustrating how the user's vulnerability score has changed over time.
Breach Count: Displays total breaches out of total campaigns assigned (e.g., 2 times out of 3).
Minimum Breach Time: The fastest time recorded for the user falling for a simulation link/prompt.
Repeat Offender & Campaign Summary: Visual charts showing repeat compromise counts and total assigned campaigns.
Campaigns Tab: Switch to this tab to review a full history of specific simulation campaigns sent to the user and their actions (e.g., opened, clicked, submitted data, passed).
Hack Records serve as a central search repository to check if an employee's credentials or email address have appeared in known breach databases or simulation compromises.
Navigate to Security Insights > Hack Record on the left menu.
Enter the employee's email address in the Enter email search bar.
Click Search.
If a breach is found, a table will display specific records.
If a row shows "User not found" under the name field, it indicates that the employee has been deleted or removed from the active user directory in TSAT, but their historical simulation data is retained for risk reporting continuity.
An EVS of 0% means the employee has either not yet been included in any active simulation campaigns or has successfully passed every assigned simulation without failing any security checks.
EVS is an ongoing, dynamic risk score calculated from user responses in phishing simulations.
Hack Record is a historical breach detection tool that searches known dark-web or past leak databases for compromised employee credentials.