Your platform reports what happened. Can it show what changed?
Every platform in this category can tell you who completed training and who clicked a simulated phish. None of them can show whether your people handle real risk more safely than they did last quarter. That gap is now a regulatory one, and this page shows where each kind of platform leaves it open.
Which gap do you have?
We run a training platform and can't evidence effectiveness
You can show the program ran. You can't show it worked. Start with the platform you already use.
See how Praxis Navigator works with your platformWe've been told to prove our measures work
NIS2, DORA and GDPR each now ask for evidence of effectiveness, not evidence of existence. The obligation is more specific than most teams expect.
Read what the regulations actually requireWe were going to build this ourselves
The data is in your tenant and the API is documented. Here is what building it actually takes, and where it usually stops.
Build it yourself, or buy itWhat each kind of platform measures
Most organizations run several of these at once. They answer different questions, and only one of them answers whether your people behave more securely than they did before.
| What it's for | What it measures | Where the data comes from | Independent of the vendor running the intervention | What it evidences for effectiveness requirements | |
|---|---|---|---|---|---|
| Security awareness training and phishing simulation | Delivering training content and testing recognition of simulated attacks | Course completions, quiz scores, simulated phishing clicks and reports | Its own learning platform and simulation campaigns | No. The vendor delivering the program also supplies the score for it | Shows the program ran and who took part. Does not show whether behavior changed |
| Human risk management | Adapting training and nudges to each user's measured risk | Behavior inside its own delivery surface — how users respond to its simulations, nudges and reporting tools | Its own platform, plus connected email or identity signals | No. Measurement is produced by, and bounded to, the platform running the intervention | Shows engagement and response improving inside the platform. Does not show behavior in daily work outside it |
| Compliance automation | Continuous control monitoring and audit evidence collection | Whether controls exist, are configured correctly, and stay that way | Integrations with cloud, identity and HR systems | Yes | Strong evidence that a control exists. Not evidence that the human layer of it works |
| Microsoft 365 | Securing the tenant and reporting its posture | Threats, configuration posture, policy violations, identity events | Your own tenant | Yes | Evidence that technical controls are in place and working. Not a measure of how people behave over time |
| Build it yourself | Answering a specific question from data you already own | Whatever you extract and normalise | Microsoft Graph, into your own reporting layer | Yes | As strong as the method behind it — and the method is what an assessor asks about |
| Praxis Navigator | Measuring how people actually behave, and whether that changes | 20+ behavior indicators across email, file sharing, collaboration and identity | Your own Microsoft 365 tenant, read-only | Yes. Measures behavior regardless of who ran the intervention | Behavioral baselines and before-and-after comparison — the trend these requirements ask to see |
Security awareness training and phishing simulation
- What it's for
- Delivering training content and testing recognition of simulated attacks
- What it measures
- Course completions, quiz scores, simulated phishing clicks and reports
- Where the data comes from
- Its own learning platform and simulation campaigns
- Independent of the vendor running the intervention
- No. The vendor delivering the program also supplies the score for it
- What it evidences for effectiveness requirements
- Shows the program ran and who took part. Does not show whether behavior changed
Human risk management
- What it's for
- Adapting training and nudges to each user's measured risk
- What it measures
- Behavior inside its own delivery surface — how users respond to its simulations, nudges and reporting tools
- Where the data comes from
- Its own platform, plus connected email or identity signals
- Independent of the vendor running the intervention
- No. Measurement is produced by, and bounded to, the platform running the intervention
- What it evidences for effectiveness requirements
- Shows engagement and response improving inside the platform. Does not show behavior in daily work outside it
Compliance automation
- What it's for
- Continuous control monitoring and audit evidence collection
- What it measures
- Whether controls exist, are configured correctly, and stay that way
- Where the data comes from
- Integrations with cloud, identity and HR systems
- Independent of the vendor running the intervention
- Yes
- What it evidences for effectiveness requirements
- Strong evidence that a control exists. Not evidence that the human layer of it works
Microsoft 365
- What it's for
- Securing the tenant and reporting its posture
- What it measures
- Threats, configuration posture, policy violations, identity events
- Where the data comes from
- Your own tenant
- Independent of the vendor running the intervention
- Yes
- What it evidences for effectiveness requirements
- Evidence that technical controls are in place and working. Not a measure of how people behave over time
Build it yourself
- What it's for
- Answering a specific question from data you already own
- What it measures
- Whatever you extract and normalise
- Where the data comes from
- Microsoft Graph, into your own reporting layer
- Independent of the vendor running the intervention
- Yes
- What it evidences for effectiveness requirements
- As strong as the method behind it — and the method is what an assessor asks about
Praxis Navigator
- What it's for
- Measuring how people actually behave, and whether that changes
- What it measures
- 20+ behavior indicators across email, file sharing, collaboration and identity
- Where the data comes from
- Your own Microsoft 365 tenant, read-only
- Independent of the vendor running the intervention
- Yes. Measures behavior regardless of who ran the intervention
- What it evidences for effectiveness requirements
- Behavioral baselines and before-and-after comparison — the trend these requirements ask to see
These categories serve different purposes, and Praxis Navigator is designed to sit alongside all of them rather than replace any of them.
Peer-reviewed field research
29–55%
of the variation in phishing susceptibility is attributable to organizational-level factors, not individual ones.
Measured across 83,269 employees in 510 organizations, using their real responses to phishing campaigns.
Petrič, G., & Roer, K. (2022). The impact of formal and informal organizational norms on susceptibility to phishing. Telematics and Informatics, 67, 101766. Licensed under CC BY 4.0.
Industry forecast
Gartner expects that by 2030, the major cybersecurity control frameworks will judge human risk by measurable behavior change rather than training completion.
Gartner, cybersecurity trend guidance.
Peer-reviewed field research
When employees believed their colleagues were already handling security well, they became more susceptible to phishing, not less — a boomerang effect. A clear, salient security policy could likewise increase casual link-clicking.
From the same field study of 83,269 employees across 510 organizations.
Petrič, G., & Roer, K. (2022). The impact of formal and informal organizational norms on susceptibility to phishing. Telematics and Informatics, 67, 101766. Licensed under CC BY 4.0.
Why the measurement should be independent
A platform's risk score is calculated from that platform's own signals. Completions it recorded. Simulations it sent. Nudges it delivered. The score goes up when engagement with the platform goes up, which is a reasonable thing for a vendor to optimize and a difficult thing to submit as proof.
When the vendor running the program also supplies the evidence for the program, the evidence is circular. An assessor asking whether your measures are effective is asking a question circular evidence cannot answer.
Independent measurement reads behavior where the work happens, not where the training happens. It doesn't care which platform ran the campaign, or whether you change platforms next year. The baseline holds, the trend line continues, and the evidence survives the contract.
See how Praxis Navigator works with your platform
Security awareness training and phishing simulation
Praxis Navigator + KnowBe4
The world's largest training platform delivers content and simulations. Praxis Navigator measures whether behavior actually changed.
Read more →Praxis Navigator + MetaCompliance
European awareness and compliance platform, now including Junglemap. Praxis Navigator adds behavioral evidence from Microsoft 365.
Read more →Praxis Navigator + Proofpoint
Enterprise email security and ZenGuide training, built on deep threat intelligence. Praxis Navigator measures what happens between the threats.
Read more →Junglemap is now part of MetaCompliance
If your program is moving platforms, this is the moment to establish a behavioral baseline you keep.
Read more →Human risk management
Praxis Navigator + Hoxhunt
Adaptive training that measures how people respond to it. Praxis Navigator measures how they behave the rest of the time.
Read more →Praxis Navigator + CybSafe
Behavioral science applied to security programs. Praxis Navigator provides the independent measurement layer underneath.
Read more →Compliance automation
Activity metrics count what happened. Behavioral evidence shows what changed. See the full comparison
Baseline, intervene, compare, prove — that loop is how a program becomes measurable. See how the platform works
Questions security leaders ask
Which platform should I compare Praxis Navigator against?
Does Praxis Navigator replace my security awareness training platform?
Can my existing platform's risk score satisfy NIS2, DORA or GDPR effectiveness requirements?
How is this different from the risk scoring in my existing platform?
Which training platforms does Praxis Navigator work with?
What if we don't use Microsoft 365?
What does Praxis Navigator monitor?
How quickly can I see results?
Can I see the price without talking to sales?
Who built Praxis Navigator?
Start measuring
Connect Microsoft 365 in 15 minutes and see your behavioral baseline, built from data you already generate.
Start your free 30-day trialNo credit card. No commitment. Results in 15 minutes, or don't continue.
See the price — published, no sales call required.
Read what the regulations require — NIS2, DORA and GDPR now ask whether your measures work.