An open, non-proprietary toolkit for assessing and building a security awareness program using the SEAT model: Strategy, Engagement, Assessment, Training.
This repo is maintained by HumanRisk. It exists so that any practitioner — whether or not they ever become a SEAT customer — can use the underlying methodology to understand where their program stands and what to build next.
- The SEAT four-pillar model and generic maturity level definitions
- A self-assessment question set you can run against your own program
- Prompt templates for using an LLM (Claude, ChatGPT, or an agentic tool like Claude Code / Cowork) to turn your own policy documents and program state into a maturity read and a roadmap
- Templates: RACI, stakeholder map, charter, KPI/KRI starter set
- This is not the SEAT platform. It doesn't include the scored assessment engine, the maintained compliance-framework mappings (NIS2, PCI DSS, CMMC, etc.), the recommendation engine, or continuous tracking.
- Running this toolkit gives you a one-time, self-scored maturity read. The platform (app.humanrisk.com) gives you a validated score, peer benchmarking, framework mapping, and a program that stays current as guidance changes.
- Think of this repo as the paper version of the map. SEAT is the GPS.
- Start with
framework/four-pillars-and-maturity-levels.mdto understand the model. - Pick a prompt from
prompts/based on what you're trying to do (retrofit an existing policy, build a roadmap, draft a business case). - See
guides/using-this-with-an-llm.mdfor how to run these prompts safely with Claude, ChatGPT, or an agentic tool, and what to redact before you paste anything in. - Use
templates/for the artifacts (RACI, stakeholder map, charter) once you know what you're building.
| Free assessment (app.humanrisk.com) | This repo | SEAT platform | |
|---|---|---|---|
| Cost | Free | Free | Paid |
| Output | 21-question maturity snapshot | Self-run maturity read against your own docs | Scored, benchmarked, continuously tracked |
| Compliance mapping | No | Generic methodology only | Maintained mappings (NIS2, PCI DSS 4.0, CMMC, etc.) |
| Best for | A 10-minute gut check | A practitioner who wants to do the work themselves, in their own environment | A program that needs to prove maturity over time |
This is maintained by HumanRisk. Issues and PRs for the generic framework content are welcome. This repo does not accept contributions that reference or attempt to reconstruct the proprietary scoring or mapping logic — that content will be closed without review.
MIT for the prompts, templates, and framework docs in this repo. "SEAT," "HumanRisk," and the maturity model naming are used here as reference material; the SEAT platform and its scoring methodology remain proprietary to HumanRisk.