The Six-D Scorecard
Featured Article

The Six-Dimension Scorecard: A proposed framework for assessing cyberfraud risk

By DeAndre Redd, DBA, CFE
Date: July 1, 2026
Read Time: 14 mins
Please sign in to save this to your favorites.

The Six-Dimension Scorecard offers an expansion of the Fraud Triangle for the digital age by helping fraud examiners classify fraud as behavioral, technical or hybrid and tailor investigative resources accordingly. The author explains how to use the scorecard to triage cases, align controls across human and technical risks, and communicate clearly to leadership why certain incidents might require specialized cyber expertise.

A note from the author: The Six‑Dimension Scorecard is a practitioner‑developed assessment tool, not a validated predictive model. It reflects professional judgment, investigative experience and application to publicly documented cases. The framework hasn’t been formally validated through independent testing, external review or inter‑rater reliability studies. Accordingly, the framework should be used as a structured aid for organizing analysis, communicating risk characteristics and guiding resource allocation, not as a definitive method for proving fraud, predicting misconduct or classifying legal violations.

In May 2021, a single compromised password rendered the largest fuel pipeline in the U.S. on the brink of collapse. The Colonial Pipeline ransomware attack (discussed later in this article) forced a five-day shutdown, triggered panic buying at gas stations across the East Coast and cost the company a $4.4 million ransom payment. The perpetrators, a Russia-linked cybercrime group called DarkSide, weren’t driven by an isolated financial problem. They didn’t need to rationalize their actions. They were a sophisticated criminal enterprise with the technical capability to cripple critical infrastructure from thousands of miles away.

For 70 years, the Fraud Triangle has been the bedrock of the fraud examination profession, providing an indispensable lens for understanding the human element of fraud. But cases like Colonial Pipeline highlight a new reality: Many of the tools and techniques of fraud have fundamentally changed. How do we, as fraud examiners, build upon the timeless wisdom of the Fraud Triangle to address the unique challenges of the digital age?

This article introduces the Six-Dimension (Six-D) Scorecard, a practical tool that complements the Fraud Triangle by integrating the technical dynamics of modern cybercrime. A note on terminology: I use “fraud” throughout for familiarity, but the scorecard is designed to assess cyber-enabled financial crime broadly, including extortion, intrusion and theft. The technical character of a scheme, rather than its precise legal label, drives the investigative response. The scorecard is designed for assessment and triage, not detection. Detection still requires the traditional mechanisms: tips, data analytics, internal controls and vigilant management. The scorecard helps fraud examiners understand the nature of fraud once they’re investigating it or evaluating a risk. I’ll explain the conceptual foundation of the Six-D Scorecard, show you how it works with detailed case studies and provide scoring rubrics you can use in your own investigations.

Updating the Fraud Triangle for the digital age

Donald Cressey’s insight that fraud requires the convergence of pressure, perceived opportunity and rationalization remains as relevant today as when he first articulated it in 1953. His research with incarcerated embezzlers revealed a consistent pattern: An individual faced a financial problem they felt they couldn’t share, perceived an opportunity to resolve it through a violation of trust and justified their actions to preserve their self-image.

The Six-D ScorecardHowever, Cressey’s framework emerged from studying individuals operating within organizations, abusing positions of trust. Many of today’s cyber fraudsters have no relationship at all with their victims. They operate externally, exploiting technical vulnerabilities rather than organizational roles. Ransomware operators across the globe may have no fiduciary connection to a target organization, yet they can still inflict significant financial and operational harm.

To account for this evolution, the Fraud Triangle can be extended beyond its behavioral roots. Although human motivations still drive fraud, modern risk also depends on the technical conditions that enable widespread fraud to occur and with reduced accountability. By pairing Cressey’s three behavioral dimensions with three complementary technical dimensions, we may gain a framework for better understanding financial crime in the digital age.

Behavioral dimensions

For fraud examiners, the core elements of the Fraud Triangle require little elaboration, but they remain essential as the foundation of any expanded model.

Pressure: The motivating force behind the act, whether personal (financial strain, lifestyle pressures), organizational (performance expectations, cultural incentives) or geopolitical in the case of state-sponsored activity.

Opportunity: The perceived ability to commit and conceal fraud. As Cressey emphasized, opportunity is subjective. What matters isn’t just the existence of a control gap but whether it’s recognized and deemed exploitable by the actor.

Rationalization: The cognitive framing that allows the perpetrator to proceed without abandoning their self-concept. Although the narratives are familiar, digital environments often amplify moral disengagement through distance and abstraction.

Technical dimensions

These extend the Fraud Triangle to reflect how perpetrators may carry out their schemes today.

Technical capability: The tools and skills used to exploit systems. This ranges from basic phishing kits to highly sophisticated exploits. Importantly, the rise of “as-a-service” cybercrime models has lowered the barrier to entry, meaning advanced attacks no longer imply advanced actors.

Digital anonymity: The ability to obscure identity and location. Unlike traditional fraudsters who leave audit trails tied to their identity, cyber criminals can operate through layered obfuscation — proxy systems, encryption, jurisdictional complexity and cryptocurrencies — making detection and attribution significantly more difficult.

Viral amplification: The capacity for fraud to expand rapidly and automatically. Traditional fraud tends to grow linearly with effort; cyberfraud grows exponentially. A single intrusion can propagate across networks, supply chains or global systems in minutes, magnifying impact far beyond the initial act.

A unified model

I didn’t set out to build a model but to understand why some cases yielded to traditional examination while others required a forensic lab. In working backward from digital cases, a consistent pattern emerged: Three technical properties shaped how an investigation unfolded, extending the Fraud Triangle’s concept of opportunity beyond internal control weaknesses to include compromised credentials, unpatched systems, anonymous infrastructure and adaptable attack tools. These dimensions — technical capability, digital anonymity, viral amplification — don’t replace opportunity; they clarify its technical character and make it more actionable. Technical capability determines the level of expertise required, digital anonymity defines the difficulty of attribution, and viral amplification signals the potential speed and scale of impact.

Each dimension earns its place by altering a concrete investigative decision. The result is a unified model in which behavioral dimensions describe the actor and technical dimensions describe the method. Together they provide a more complete view of fraud risk in an environment in which technological capability increasingly shapes scale, speed and anonymity.

The Six-D Scorecard: A practical assessment tool

By scoring each dimension on a 1–10 scale and calculating a weighted average, examiners can quickly assess whether a fraud scheme is primarily behavioral (traditional) or primarily technical (cyber-enabled). This distinction matters because it determines which investigative resources and controls are most appropriate.

The formula weighs behavioral and technical factors roughly equally: Risk score = (behavioral average x 0.5) + (technical average x 0.5). The score is a way to organize judgment, not a measurement. It estimates nothing about the likelihood that fraud has occurred or who is responsible. It summarizes how a known scheme is distributed across behavioral and technical dimensions so that investigative resources can be matched to it. The decimal precision of the formula shouldn’t be mistaken for diagnostic precision.

Applying the scorecard across a range of documented fraud cases — from small fraud cases to more complex ransomware and supply chain compromise — a midpoint of approximately 5.0 has proven to be a useful divider in practice. Scores above 5.0 have generally corresponded to schemes that required technical investigative capabilities, and scores below 5.0 have generally corresponded to schemes resolved through traditional examination. This 5.0 mark is a heuristic anchor for triage, not an empirically optimized cutoff, and it should be treated as a starting point for professional judgment rather than a decision rule. The real value of the scorecard lies not in the final number but in the structured analysis that produces it.

By scoring each dimension on a 1–10 scale and calculating a weighted average, examiners can quickly assess whether a fraud scheme is primarily behavioral (traditional) or primarily technical (cyber-enabled).

 

Scoring rubric: Anchoring your assessments

Consistent scoring requires explicit anchors. Without defined criteria, different examiners might score the same case three or four points apart on a single dimension, rendering the framework useless for comparison or communication. The following rubrics provide guidance for the three technical dimensions, which are most likely to be unfamiliar territory for examiners trained in traditional fraud investigation. The behavioral dimension follows Cressey’s original conceptualization and can be scored using established fraud examination principles.

Technical capability scoring guide

Score  Indicators
1-2 No specialized skills. Uses only standard business tools. Paper-based or simple manipulation of existing systems without technical sophistication.
3-4 Basic phishing using purchased kits. Simple social engineering that requires minimal technical knowledge. Uses publicly available exploit tools without modification.
5-6 Customized social engineering campaigns and moderate code modification or scripting. Can chain multiple exploits together. Uses cryptocurrency competently for payment and money movement.
7-8 Original malware development. Multistage attacks with persistence mechanisms. Can maintain long-term covert access to compromised systems. Employs sophisticated detection evasion techniques.
9-10  Nation-state level capability. Zero-day exploit development or acquisition. Supply-chain compromise affecting multiple organizations. Critical infrastructure targeting has the potential for physical impact.

Digital anonymity scoring guide

Score Indicators
 1-2 No attempt to conceal identity. Uses own name, credentials and accounts. Clear, recoverable audit trail exists throughout the fraud.
3-4 Basic obfuscation. Uses personal devices but varies access locations and makes minimal effort to hide a digital footprint. Identity recoverable with moderate investigative effort.
5-6 Throwaway accounts and prepaid devices with basic virtual private network (VPN) usage. Cryptocurrency for payments without advanced mixing or tumbling techniques.
7-8 Multilayered anonymization (Tor, VPN chains, compromised proxies). Sophisticated money mule networks. Operations deliberately span multiple jurisdictions to complicate investigation.
9-10 Near complete attribution resistance. State-sponsored infrastructure or protection. Privacy coins with advanced tumbling. No realistically recoverable identity without intelligence agency resources.

Viral amplification scoring guide

Score  Indicators
1-2 Each fraudulent act requires manual effort. No automation whatsoever. Linear relationship between perpetrator effort and fraud impact.
3-4 Some template reuse. Semiautomated processes. Same scheme can target multiple victims sequentially with modest additional effort per victim.
5-6 Significant automation. Campaigns can scale to thousands of targets simultaneously. Exploitation scripts can be reused across similar systems.
7-8  Self-propagating capability. Network worm behavior spreading without perpetrator intervention. Can compromise entire organizations from a single entry point.
9-10 Global propagation potential. Supply chain attacks affect thousands of organizations. Exponential spread with minimal perpetrator involvement after initial deployment.

The Six-D Scorecard

Developing and testing the scorecard

The rubrics and the 5.0 anchor were applied to 142 publicly documented cases of cyberattacks and fraud, drawn from the U.S. Department of Justice and IRS Criminal Investigation announcements, court records, regulatory actions and reputable security reporting. I selected them to span the full behavioral-to-technical spectrum. This is not a random or representative sample, and I didn’t use the data to train a statistical model. It’s a structured set of worked examples for evaluating whether the dimensions behave sensibly across a wide range of offense types. Because the sample was developmental rather than representative, the 5.0 threshold should be interpreted as an illustrative triage midpoint rather than an empirically validated classification boundary.

A single examiner using the published rubrics conducted scoring in this study. This shows that a single trained analyst can apply the framework across a range of documented cases, but it doesn’t establish scoring consistency over time or among multiple analysts. Confirming this through a formal inter-rater reliability study involving multiple fraud examiners and investigators is an important next step in the framework’s development.

The current scorecard also uses equal weighting for the behavioral and technical dimensions. This was a deliberate design decision intended to emphasize the importance of human and technological factors in cyber-enabled offenses while maintaining transparency and ease of application. Exploratory analyses evaluated whether alternative weighting approaches might materially improve the framework. Although different weighting schemes produced modest variations in individual case scores, the results were sensitive to sample composition and didn’t provide sufficient evidence to justify replacing the equal-weight approach. Accordingly, equal weighting was retained as the most transparent, practical and defensible option for the framework’s initial implementation. Future research using larger datasets, multiple raters and external validation samples may provide a basis for refining the weighting methodology.

The scorecard in action

The following four case studies demonstrate how the Six-D Scorecard helps distinguish among different types of fraud and guides investigative strategy. Each case represents a different point on the behavioral-technical spectrum.

Case study 1: An unexpected discovery at a nonprofit organization

While assisting an organization, I noticed payroll discrepancies and unexplained variances that management initially dismissed. When a finance leader abruptly left, the team and I performed reconciliations and uncovered serious irregularities. The finance function had operated for decades with complete autonomy and no oversight.

Scoring analysis

Dimension  Score  Rationale
Pressure Confirmed personal/organizational pressure indicators.
Opportunity  Full control with no segregation of duties or oversight. 
Rationalization  Dismissive responses and long-term unchecked authority.
Technical capability Standard accounting manipulation.
Digital anonymity 1 Activities conducted under own identity.
Viral amplification 1 Manual, non-scalable activity. 

Calculation: Behavioral average: 7.67 | Technical average: 1.33

Risk score: 4.5

Interpretation: The case reflects a concentrated control failure driven by behavioral factors, particularly unchecked opportunity. The scorecard indicates this case calls for traditional fraud examination techniques, including document review, bank record analysis, timeline reconstruction and interview preparation.

The lesson: Long-term trust without verification creates high-risk conditions. Strong controls and independent oversight remain foundational to fraud prevention.

The Six-D Scorecard
The case reflects a concentrated control failure driven by behavioral factors, particularly unchecked opportunity.

 

Case study 2: Colonial Pipeline ransomware attack

As referenced earlier, DarkSide, a Russia-linked cybercrime group operating on a ransomware-as-a-service model, deployed a ransomware attack that exploited a compromised VPN password lacking multifactor authentication. The incident led to a five-day shutdown of a major U.S. fuel pipeline and a $4.4 million ransom payment. Although ransomware itself isn’t fraud, it’s a method of extortion and, more broadly, a tool used to commit financial crime rather than the deception-based theft that generally defines fraud. I include the Colonial Pipeline incident because the Six-D framework is designed to assess the risk characteristics of cyber-enabled offenses across a broad spectrum of digital victimization events. The framework’s technical dimensions — technical capability, digital anonymity and viral amplification — were specifically developed to capture factors that traditional behavioral models often overlook. These dimensions help distinguish a sophisticated ransomware operation from a conventional embezzlement scheme, which is precisely the framework’s analytical purpose.

Scoring analysis

Dimension  Score  Rationale
Pressure  Profit-driven criminal enterprise.
Opportunity  Weak authentication and network exposure.
Rationalization  Organizational detachment from victims.
Technical capability Sophisticated ransomware deployment.
Digital anonymity Cryptocurrency and anonymized infrastructure.
Viral amplification Rapid internal system spread.

Calculation: Behavioral average: 4.67 | Technical average: 8.33

Risk score: 6.5

Interpretation: The case is defined by high technical sophistication, anonymity and growth capacity, which drive impact.

The lesson: Colonial Pipeline reinforced a critical reality of modern cyber-enabled offenses: Traditional behavioral factors alone don’t explain the scale of harm that technically sophisticated actors can inflict. The compromised VPN credential represented a familiar opportunity, but the severity of the incident was driven by factors outside the scope of the traditional Fraud Triangle. Technical capability, anonymity and propagation can magnify the consequences of a single control failure, making technical risk factors central to modern investigations.

The Six-D Scorecard
Colonial Pipeline reinforced that traditional behavioral factors alone don’t explain the scale of harm that technically sophisticated actors can inflict.

 

Case study 3: Classic embezzlement scheme

A controller embezzled $1.2 million over five years through fraudulent checks, enabled by sole control over disbursements and reconciliations and driven by gambling debt.

Scoring analysis

Dimension  Score  Rationale
Pressure  8   Significant financial distress from gambling.
Opportunity No segregation of duties. 
Rationalization  “Borrowing” evolved into entitlement.
Technical capability Basic accounting system use.
Digital anonymity Direct traceable transactions.
Viral amplification Manual, one-by-one activity.

Calculation: Behavioral average: 8.0 | Technical average: 1.33

Risk score: 4.67

Interpretation: This is a traditional, behavioral-driven fraud. The investigation should focus on interviews, document analysis, bank record subpoenas and lifestyle audits.

The lesson: This case study underscores a fundamental lesson for fraud examiners: Sustained fraud often stems from pressure combined with simple control failures. Early detection depends on addressing both.

The Six-D Scorecard
Sustained fraud often stems from pressure combined with simple control failures.

 

Case study 4: Business email compromise (BEC)

An international group used spoofed executive emails and social engineering to induce wire transfers, routing funds through money mule accounts and cryptocurrency.

Scoring analysis

Dimension  Score 
Rationale
Pressure

Profit-motivated group.
Opportunity 
Exploits weak verification and trust.
Rationalization

Impersonal, deception-based activity.
Technical capability 5   Email spoofing and money mule networks.
Digital anonymity
6
Layered obfuscation via accounts and transfers.
Viral amplification

Repeatable but semi-manual campaigns.

Calculation: Behavioral average: 5.33 | Technical average: 5.00

Risk score: 5.17

Interpretation: Right at the threshold, this represents a true hybrid fraud combining social engineering and technical concealment.

The lesson: BEC illustrates why modern fraud investigations can’t be viewed exclusively through either a behavioral or a technical lens. Unlike traditional occupational fraud, BEC succeeds by exploiting human and technological vulnerabilities. Effectiveness of the scheme comes from blending human manipulation with technical enablement, requiring controls that address both.

The Six-D Scorecard
BEC illustrates why modern fraud investigations can’t be viewed exclusively through either a behavioral or a technical lens.

 

Putting the scorecard to work

The Six-D Scorecard isn’t a replacement for professional judgment; it’s a tool to structure and communicate that judgment. Here’s how to apply it in practice.

Integration with response plans and triaging cases

The scorecard is most effective during the assessment and escalation phase of a case. It complements existing incident response plans by helping practitioners quickly determine the nature of an event, the expertise required and the appropriate level of response. A rapid Six-D assessment can guide early decisions. Higher technical scores may indicate the need for specialized resources, such as digital forensics or threat intelligence, while higher behavioral scores suggest prioritizing interviews, document review and control analysis. Rather than changing how organizations respond operationally, the scorecard helps clarify what kind of problem they’re dealing with and how to allocate appropriate resources from the outset.

Guide control design and resource allocation

The balance between behavioral and technical dimensions highlights the need for people-focused controls (training, oversight, segregation of duties, tone at the top) and technical safeguards (multifactor authentication, patching, monitoring and segmentation). Viewing risks through all six dimensions helps identify control gaps and align investments more effectively.

Communicate risk to leadership

The scorecard translates complex investigative assessments into a clear, structured format that supports decision-making. Breaking risk into behavioral and technical components helps leadership understand not just the severity of an issue but its nature, whether it’s driven by internal control weaknesses, external technical threats or a combination of both. The dimension-level scores often provide as much insight as the overall score, enabling more informed decisions about resource allocation, response strategy and control improvements.

Enhance fraud risk assessments

Applying the scorecard during periodic risk assessments enables more consistent comparison across scenarios. This helps organizations distinguish between behavioral, technical and hybrid risks and design more targeted mitigation strategies.

The scorecard is most effective during the assessment and escalation phase of a case. It complements existing incident response plans.

 

Limitation and considerations

The Six-D Scorecard is an investigative aid, not a predictive instrument, and should be judged by whether it improves triage, resource allocation and communication. Its application relies on professional judgment, and although rubrics promote consistency, variation across examiners is inevitable. In high-stakes cases, independent scoring and discussion can improve outcomes.

The Six-D ScorecardCertain dimensions, particularly rationalization, may require inference when direct insight into a perpetrator’s mindset is unavailable, as is often the case in cyber investigations. In addition, the six dimensions aren’t fully independent, and their interactions aren’t captured by the framework’s simple weighted-average approach. More complex modeling could address these relationships. The current design prioritizes clarity and practical usability.

Evolving our tools for the evolving threat

The Fraud Triangle has served our profession well for seven decades, and it will continue to do so. Cressey’s insight into the human psychology of fraud remains foundational. But as perpetrators gain access to powerful technical tools, unprecedented anonymity and the ability to scale their schemes globally, our analytical frameworks must evolve alongside them. 
The Six-D Scorecard is not a replacement for Cressey’s work; it’s an extension of it, a recognition that 21st century fraud is a multidimensional problem requiring multidimensional analysis. By integrating technical dimensions with behavioral dimensions, we already understand that we can become more effective fraud examiners, better protect our organizations and continue to uphold the integrity of our profession.

DeAndre Redd, DBA, CFE, is a forensic accounting researcher, data scientist and public-sector executive with experience spanning law enforcement, cyber investigations, procurement oversight, public finance and nonprofit financial management. Contact him at deandre.redd@gmail.com or on LinkedIn.

Begin Your Free 30-Day Trial

Unlock full access to Fraud Magazine and explore in-depth articles on the latest trends in fraud prevention and detection.