Your platform reports what happened. Can it show what changed?

Every platform in this category can tell you who completed training and who clicked a simulated phish. None of them can show whether your people handle real risk more safely than they did last quarter. That gap is now a regulatory one, and this page shows where each kind of platform leaves it open.

Which gap do you have?

We run a training platform and can't evidence effectiveness

You can show the program ran. You can't show it worked. Start with the platform you already use.

See how Praxis Navigator works with your platform

We've been told to prove our measures work

NIS2, DORA and GDPR each now ask for evidence of effectiveness, not evidence of existence. The obligation is more specific than most teams expect.

Read what the regulations actually require

We were going to build this ourselves

The data is in your tenant and the API is documented. Here is what building it actually takes, and where it usually stops.

Build it yourself, or buy it

What each kind of platform measures

Most organizations run several of these at once. They answer different questions, and only one of them answers whether your people behave more securely than they did before.

Security awareness training and phishing simulation

What it's for
Delivering training content and testing recognition of simulated attacks
What it measures
Course completions, quiz scores, simulated phishing clicks and reports
Where the data comes from
Its own learning platform and simulation campaigns
Independent of the vendor running the intervention
No. The vendor delivering the program also supplies the score for it
What it evidences for effectiveness requirements
Shows the program ran and who took part. Does not show whether behavior changed

Human risk management

What it's for
Adapting training and nudges to each user's measured risk
What it measures
Behavior inside its own delivery surface — how users respond to its simulations, nudges and reporting tools
Where the data comes from
Its own platform, plus connected email or identity signals
Independent of the vendor running the intervention
No. Measurement is produced by, and bounded to, the platform running the intervention
What it evidences for effectiveness requirements
Shows engagement and response improving inside the platform. Does not show behavior in daily work outside it

Compliance automation

What it's for
Continuous control monitoring and audit evidence collection
What it measures
Whether controls exist, are configured correctly, and stay that way
Where the data comes from
Integrations with cloud, identity and HR systems
Independent of the vendor running the intervention
Yes
What it evidences for effectiveness requirements
Strong evidence that a control exists. Not evidence that the human layer of it works

Microsoft 365

What it's for
Securing the tenant and reporting its posture
What it measures
Threats, configuration posture, policy violations, identity events
Where the data comes from
Your own tenant
Independent of the vendor running the intervention
Yes
What it evidences for effectiveness requirements
Evidence that technical controls are in place and working. Not a measure of how people behave over time

Build it yourself

What it's for
Answering a specific question from data you already own
What it measures
Whatever you extract and normalise
Where the data comes from
Microsoft Graph, into your own reporting layer
Independent of the vendor running the intervention
Yes
What it evidences for effectiveness requirements
As strong as the method behind it — and the method is what an assessor asks about

Praxis Navigator

What it's for
Measuring how people actually behave, and whether that changes
What it measures
20+ behavior indicators across email, file sharing, collaboration and identity
Where the data comes from
Your own Microsoft 365 tenant, read-only
Independent of the vendor running the intervention
Yes. Measures behavior regardless of who ran the intervention
What it evidences for effectiveness requirements
Behavioral baselines and before-and-after comparison — the trend these requirements ask to see

These categories serve different purposes, and Praxis Navigator is designed to sit alongside all of them rather than replace any of them.

Peer-reviewed field research

29–55%

of the variation in phishing susceptibility is attributable to organizational-level factors, not individual ones.

Measured across 83,269 employees in 510 organizations, using their real responses to phishing campaigns.

Petrič, G., & Roer, K. (2022). The impact of formal and informal organizational norms on susceptibility to phishing. Telematics and Informatics, 67, 101766. Licensed under CC BY 4.0.

Industry forecast

Gartner expects that by 2030, the major cybersecurity control frameworks will judge human risk by measurable behavior change rather than training completion.

Gartner, cybersecurity trend guidance.

Peer-reviewed field research

When employees believed their colleagues were already handling security well, they became more susceptible to phishing, not less — a boomerang effect. A clear, salient security policy could likewise increase casual link-clicking.

From the same field study of 83,269 employees across 510 organizations.

Petrič, G., & Roer, K. (2022). The impact of formal and informal organizational norms on susceptibility to phishing. Telematics and Informatics, 67, 101766. Licensed under CC BY 4.0.

Why the measurement should be independent

A platform's risk score is calculated from that platform's own signals. Completions it recorded. Simulations it sent. Nudges it delivered. The score goes up when engagement with the platform goes up, which is a reasonable thing for a vendor to optimize and a difficult thing to submit as proof.

When the vendor running the program also supplies the evidence for the program, the evidence is circular. An assessor asking whether your measures are effective is asking a question circular evidence cannot answer.

Independent measurement reads behavior where the work happens, not where the training happens. It doesn't care which platform ran the campaign, or whether you change platforms next year. The baseline holds, the trend line continues, and the evidence survives the contract.

See how Praxis Navigator works with your platform

Activity metrics count what happened. Behavioral evidence shows what changed. See the full comparison

Baseline, intervene, compare, prove — that loop is how a program becomes measurable. See how the platform works

Questions security leaders ask

Which platform should I compare Praxis Navigator against?
None of them, in the sense of choosing one over the other. Praxis Navigator does not deliver training, phishing simulation or compliance content, so it does not displace anything in your stack. The comparison that matters is between the evidence your current tools produce and the evidence you are being asked for.
Does Praxis Navigator replace my security awareness training platform?
No. Praxis Navigator does not deliver training content, phishing simulations or compliance modules. It measures employee security behavior in Microsoft 365. Organizations run it alongside their existing training platform to see whether that training is producing real behavioral change.
Can my existing platform's risk score satisfy NIS2, DORA or GDPR effectiveness requirements?
Partly, and rarely on its own. Those scores are calculated from the platform's own signals — completions it recorded, simulations it sent. That evidences participation in a program rather than the effectiveness of it, and it comes from the vendor whose program is under assessment. Effectiveness requirements ask for a change in behavior, measured over time and documented.
How is this different from the risk scoring in my existing platform?
Your platform's risk score tells you who is at risk based on activity inside that platform. Praxis Navigator tells you how your workforce actually behaves in daily work — email handling, file sharing, collaboration, identity management. An employee can score well on every assessment and still share files insecurely.
Which training platforms does Praxis Navigator work with?
All of them. Praxis Navigator connects to Microsoft 365 through the Graph API, not to your training vendor. You can tag interventions from any source — a KnowBe4 campaign, a MetaCompliance module, a Hoxhunt cycle, a policy change, an internal awareness push — and measure the behavioral impact.
What if we don't use Microsoft 365?
Praxis Navigator reads behavior from Microsoft 365 data. If your organization runs on Google Workspace or another platform, we are not a fit yet.
What does Praxis Navigator monitor?
More than 20 security behavior indicators across five Microsoft 365 sources: Exchange Online, SharePoint, OneDrive, Teams and Entra ID. It uses a zero-storage architecture, and every customer runs in a dedicated Azure environment with no shared infrastructure or pooled tenant data.
How quickly can I see results?
Within 15 minutes of connecting your Microsoft 365 tenant. Because Microsoft retains historic activity data, you get a behavioral baseline from day one rather than waiting months to build one.
Can I see the price without talking to sales?
Yes. Our prices are published. Use the calculator, see your number, start a trial — no sales call, no qualification, no quote request. Most platforms in this category will not tell you the price without a meeting first.
Who built Praxis Navigator?
Praxis Security Labs, founded by Kai Roer, author of Build a Security Culture and co-author of The Security Culture Playbook (Wiley). Roer created the Security Culture Framework, adopted by ENISA and used by organizations worldwide. Dr. Thea Mannix, a neuroscientist, is Director of Research.

Start measuring

Connect Microsoft 365 in 15 minutes and see your behavioral baseline, built from data you already generate.

Start your free 30-day trial

No credit card. No commitment. Results in 15 minutes, or don't continue.

See the price — published, no sales call required.

Read what the regulations require — NIS2, DORA and GDPR now ask whether your measures work.