Skip to main content

Introducing uHealth

Improve your organisation’s account security with deeper visibility into human risk across your organisation with uHealth, usecure's Human Risk Intelligence capability.

Written by Anna Cunningham

Security awareness training plays a critical role in reducing cyber risk, but user behaviour is only part of the picture. Attackers also exploit weak account security, excessive privileges, dormant accounts, and exposed identities to gain access to organisations. As part of the usecure platform, uHealth combines identity, account, access, and behavioural risk data to provide a complete view of human risk, helping you identify high-risk users, prioritise remediation efforts, and strengthen your overall security posture before issues become incidents.

In this article, you’ll learn:

What is uHealth?

uHealth is usecure's Human Risk Intelligence capability, designed to complement your security awareness programme by providing continuous visibility into user and identity-related risk.

By combining data from Microsoft Entra ID or Google Workspace with security awareness insights from the wider usecure platform, uHealth analyses account hygiene, access privileges, identity exposure, and user behaviour to generate a real-time Health Score for every user, and builds a comprehensive picture of risk across your organisation. This enables security teams to move beyond awareness metrics alone and make informed, risk-based decisions about where to focus their efforts.


What are the key features of uHealth?

With uHealth, you get:

Dashboard and reporting

The uHealth dashboard provides a clear, real-time overview of your overall security posture, helping you quickly track the health trend at company level, identify priority tasks and high-risk users, and prioritise remediation efforts. Key metrics and visualisations make it easy to understand where risk is concentrated and what needs attention first.

User Health Scores

uHealth assesses user risk across four pillars: Target Value, Security Awareness, Account Hygiene and Access and Privilege.

These signals are combined into a single Health Score for each user, giving you a simple and consistent way to measure risk across your organisation. This allows you to quickly compare users, identify those at highest risk, and focus on the actions that will have the greatest impact.

User-level detail

Drill into individual users to understand exactly what is impacting their security posture.

Each user profile provides a breakdown of risk factors, contributing conditions, and relevant insights, so you can clearly see why a user is considered at risk and what actions are needed to improve their score.

Applications

Under the Applications tab, uHealth provides insights for each application used by synched users, helping you understand how the application is used and the level of risk it may introduce. This includes:

  • The number of active and inactive users using the application

  • The overall risk level of the application

  • Whether the application is company-approved

  • The number of breaches associated with the application

These insights help you identify risky or unmanaged applications, monitor user activity, and reduce your organisation’s overall attack surface.

Tasks

The Tasks section helps you quickly identify and prioritise the actions needed to improve your organisation’s overall security posture. Based on detected risk conditions and user account hygiene, uHealth surfaces recommended remediation tasks so you can focus on the issues that require the most attention. This helps streamline remediation efforts, reduce manual investigation, and ensure critical risks are addressed before they become security incidents.

Reports

The uHealth Reports tab provides a company-level view of your Health Score across a selected time period, helping you track whether your security posture is improving, declining, or remaining stable.

This makes it easier to:

  • Monitor trends in overall risk

  • Measure the impact of security improvements

  • Support internal reviews and reporting


What data does the dashboard display?

The uHealth Dashboard gives you a clear overview of your organisation’s security posture and highlights the areas that need the most attention.

Security Health Overview

The uHealth dashboard provides a snapshot of your organisation's overall account security by surfacing key metrics to help you identify and prioritise vulnerabilities across all user accounts.

Critical Risk Users & Toxic Combinations

A user is classified as a Critical Risk User when a toxic combination of risk conditions is detected during sync. A toxic combination is when multiple security weaknesses occur together, creating a significantly higher risk than any single factor alone.

For example:

  • MFA is disabled

  • account is dormant

  • user has elevated privileges

Individually these may be moderate risks, but together they become critical risks.

Urgent Action

Users who have two out of three of the critical risk factors compromised.

At-Risk Users

Users showing a single risk factor, giving you an early warning before issues become critical.

These categories help you focus remediation efforts where they’ll have the greatest impact.


How does uHealth measure user risk?

uHealth evaluates each user across the four core risk pillars: Target Value, Hygiene, Access and Privilege, and Awareness to form the overall Health Score of a user and help you understand why a user is considered high or low risk.

Target Value

Target Value measures how attractive a user is to external attackers based on their role, visibility, and influence within the organisation.

It helps identify users who are more likely to be targeted in social engineering or identity-based attacks.

What it includes:

  • Role and department within the organisation

  • Organisational hierarchy and seniority

  • External visibility and public-facing presence

  • Business function sensitivity (e.g. finance, operations, leadership)

  • Likely attacker interest or threat targeting potential

For example, a user with high organisational visibility has a higher Target Value than a standard internal user.

Hygiene

Hygiene measures how securely a user maintains their account over time.

It focuses on practical security hygiene and configuration choices that directly impact account safety.

What it includes:

  • Account status (active, inactive, or dormant)

  • Password age and strength

  • Use of strong vs weak authentication methods

  • Multi-factor authentication (MFA) adoption

  • Account inactivity or unusual usage patterns

  • Other exploitable account conditions

For example, a user with an old password, no MFA enabled, and limited recent activity would score poorly for Account Hygiene.

Access and Privilege

Access and Privilege measures how much control a user has within your organization and how far their access extends.

Users with higher levels of access represent a greater security impact if their account is compromised.

What it includes:

  • Privileged roles in Microsoft Entra ID or Google Workspace

  • Application ownership and administrative permissions

  • Group memberships and inherited access rights

  • Subscription-level or delegated permissions

  • Potential privilege escalation paths

For example, an IT administrator with global administrator access presents significantly higher risk than a standard employee due to the level of system-wide control.

Awareness

Awareness measures how a user behaves from a security training and threat-awareness perspective.

It connects human behaviour with account-level risk, helping identify users who may be more susceptible to social engineering or phishing attacks.

What it includes:

  • Security awareness training completion and effectiveness

  • Phishing simulation performance

  • Likelihood of reporting suspicious activity

  • Exposure to simulated brand or application attacks

  • Behavioural indicators of security awareness over time

For example, a user who repeatedly fails phishing simulations or ignores security training recommendations will have a lower Awareness score.


Next steps

Did this answer your question?