Praxis Navigator + MetaCompliance

Praxis Navigator + MetaCompliance: Measure What Compliance Records Can't Show

MetaCompliance delivers human risk management through automated security awareness, phishing simulations, and compliance tools across Europe. Praxis Navigator adds a different layer: independent, read-only evidence of whether employees are actually behaving more securely in Microsoft 365. This page shows what MetaCompliance's reporting can tell you, what it can't, and how the two combine to produce the behavioral evidence GDPR, NIS2 and DORA now ask for.

MetaCompliance: Human Risk Management Across Europe

MetaCompliance is a UK-founded human risk management platform backed by the private-equity firm Keensight Capital. It has grown through three acquisitions in three years — most recently acquiring the Nordic NanoLearning leader Junglemap in December 2025 — to build a comprehensive European human risk management platform.

Source: MetaCompliance / Keensight Capital announcement · Verified July 2026

If your organization runs Junglemap through that acquisition and your program is moving onto MetaCompliance's platform, see what the migration means for the evidence you've already built.

What MetaCompliance delivers:

  • Automated security awareness — Personalized, role-based training with monthly content releases, available in 44+ languages, including Junglemap's NanoLearning methodology for short-form, high-frequency learning

  • Advanced phishing simulation (MetaPhish) — Customizable, role-specific phishing campaigns with a library of templates and point-of-click learning when users interact with a simulated email

  • Risk Intelligence & Analytics — Risk scoring, engagement tracking, Exposure Monitoring that checks employee emails against verified breach data, and Power BI dashboard integration for executive reporting

  • Compliance management — Policy lifecycle management, audit-ready reporting, and regulatory frameworks support for GDPR, NIS2, DORA, and ISO 27001

  • Integrations — Connects with Microsoft Teams, Slack, Azure AD, Office 365, and ServiceNow

  • Gamification — Leaderboards, competitive elements, and Virtual Presenter for AI-enabled content delivery

MetaCompliance is particularly well-suited for mid-market and enterprise organizations across the UK and Europe that need a single platform combining security awareness, phishing testing, compliance management, and risk analytics in 44+ languages.

What MetaCompliance's reporting can't show

MetaCompliance's platform is one of the more comprehensive HRM suites in Europe, combining training, phishing, compliance, and analytics. But there's a structural gap between what the platform measures and what your board needs to see:

MetaCompliance's reporting shows:

  • Who completed their training modules and at what engagement level
  • Who clicked on simulated phishing and how click rates trend over time
  • Individual risk scores based on training activity, phishing results, and breach exposure
  • Compliance status against regulatory frameworks
  • Which employees appear on leaderboards and who needs remedial training

MetaCompliance's reporting can't show:

  • How employees handle file sharing across SharePoint and OneDrive day-to-day
  • Whether collaboration behaviors in Teams are becoming more or less secure
  • How MFA adoption and identity hygiene are trending across the organization
  • Whether a specific training campaign or policy rollout produced measurable behavioral improvement in daily Microsoft 365 usage
  • What your organization's security culture looks like as a quantified, trackable metric over time

MetaCompliance's Risk Intelligence tracks signals within its own platform: training completions, phishing test performance, breach exposure data, and compliance status. These are valuable inputs. But they measure what happens inside the HRM platform. They can't measure what happens when employees close the training module and go back to work in Microsoft 365.

That gap between "risk score improved" and "behavior actually changed" is exactly what Praxis Navigator was built to close. See the difference between activity metrics and behavioral evidence.

Peer-reviewed field research

29–55%

of the variation in phishing susceptibility is attributable to organizational-level factors, not individual ones.

Measured across 83,269 employees in 510 organizations, using their real responses to phishing campaigns.

Petrič, G., & Roer, K. (2022). The impact of formal and informal organizational norms on susceptibility to phishing. Telematics and Informatics, 67, 101766. Licensed under CC BY 4.0.

What MetaCompliance reports — and what GDPR still asks for

MetaCompliance's platform is compliance-workflow-led, which makes the gap sharper: policy attestation and training records are documentation that a measure exists, not evidence that it works. GDPR Art 32(1)(d) is the clause that says so directly.

What MetaCompliance reports — and what GDPR still asks for
What your reports show What the regulation asks for What closes the gap
Policy attestations and training completion recordsGDPR Art 32(1)(d) — a process for regularly testing, assessing and evaluating the effectiveness of security measuresBehavioral evidence that the human layer actually improved, not just documentation that a measure exists
Phishing-simulation results and Risk Intelligence scoresNIS2 CIR Annex §8.1.3 — awareness and training programs must be assessed for effectiveness, not simply deliveredAn independent behavioral baseline and trend, read from Microsoft 365
Compliance status against regulatory frameworksNIS2 CIR Annex §7 — the effectiveness of risk-management measures, technical and organizational, must be evaluatedBefore-and-after behavioral comparison across the workforce

MetaCompliance's records document that the measures exist and that training happened. GDPR asks whether they work — a different measurement, taken from a different place.

See what GDPR asks you to evidence

How Praxis Navigator measures it instead

Praxis Navigator connects to your Microsoft 365 environment via the Graph API and monitors actual employee security behaviors across five data sources: Exchange Online, SharePoint, OneDrive, Teams, and Entra ID.

Instead of measuring training engagement or simulated phishing results, Praxis Navigator measures what employees do — every day, in their normal work.

What Praxis Navigator shows you:

  • Behavioral baselines — how your employees handle security before any intervention, calculated from historic Microsoft 365 data available from day one
  • 20+ behavior indicators — real security behaviors across email, file sharing, collaboration, and identity management
  • Intervention tagging — tag when you roll out a MetaCompliance campaign, update a compliance policy, or make any other change
  • Before/after comparison — automatic behavioral comparison showing whether each intervention produced measurable change
  • Security culture scoring — quantified culture maturity metrics based on the Security Culture Framework adopted by ENISA
  • Stakeholder reports — board-ready evidence that your security investments are working. See how the platform works

Setup takes 15 minutes. No agents, no endpoint software, no data export. You see historic behavioral data from day one — no waiting months to build a baseline.

How MetaCompliance and Praxis Navigator work together

1

Baseline — Connect Praxis Navigator to Microsoft 365 and see your current behavioral baseline.

2

Train & Test — MetaCompliance delivers automated awareness training, phishing simulations, and compliance policies.

3

Tag — Tag MetaCompliance campaigns and policy rollouts as interventions in Praxis Navigator.

4

Compare — See automatic before/during/after behavioral comparison.

5

Prove — Generate stakeholder reports showing whether the program is producing measurable behavior change.

Need to justify the investment to your board? Calculate your security training ROI — free, no email required.

Feature comparison

How MetaCompliance and Praxis Navigator divide the work
Capability MetaCompliance Praxis Navigator Together
Automated security awareness trainingYesMetaCompliance delivers training
NanoLearning (via Junglemap)YesMetaCompliance delivers short-form training
Phishing simulation (MetaPhish)YesMetaCompliance tests awareness
Compliance and policy managementYesMetaCompliance manages compliance
Risk scoring (platform-based)YesMetaCompliance scores risk from platform signals
Training completion trackingYesMetaCompliance tracks participation
Microsoft 365 behavior monitoringYesPraxis measures real daily behavior
Behavioral baseline from historic dataYesPraxis provides an instant baseline
Intervention impact measurementYesPraxis proves what worked
Published pricing, self-serve signupYesPraxis is buyable without a sales call
Dedicated environment per customerYes — dedicated AzureNo pooled tenant data
Evidence independent of the training platformNoYesMeasurement that survives a vendor change
Setup timeDays (depending on scope)15 minutesPraxis operational alongside existing MetaCompliance deployment

MetaCompliance is a human risk management and compliance platform; Praxis Navigator is a behavior monitoring platform. They serve different functions in a security program.

Pricing you can see

Our prices are published. Use the calculator, see your number, start a trial — no sales call, no qualification, no quote request. Most platforms in this category will not tell you the price without a meeting first.

See the price

Questions security leaders ask

Is Praxis Navigator a replacement for MetaCompliance?
No. Praxis Navigator does not deliver security awareness training, phishing simulations, compliance management, or policy lifecycle tools. It monitors actual employee security behaviors in Microsoft 365. Organizations use Praxis Navigator alongside MetaCompliance to add a behavioral measurement layer that proves whether the HRM program is producing real behavioral change.
Doesn't MetaCompliance's Risk Intelligence already measure behavior?
MetaCompliance's Risk Intelligence generates risk scores based on signals within its platform: training engagement, phishing simulation results, breach exposure data, and compliance status. These are valuable indicators. Praxis Navigator measures something different: how employees actually behave across the full Microsoft 365 environment — file sharing patterns, collaboration behaviors, identity management, email handling — regardless of whether a training module, simulation, or breach alert triggered the observation. Risk Intelligence tells you who is at risk based on HRM platform signals. Praxis Navigator tells you how the entire workforce behaves day-to-day.
We use Junglemap through MetaCompliance. Does Praxis Navigator work with that?
Yes. Since MetaCompliance acquired Junglemap in December 2025, organizations using either MetaCompliance's core platform or Junglemap's NanoLearning content can use Praxis Navigator as the behavioral measurement layer. Praxis Navigator doesn't connect to the training platform — it monitors behaviors in Microsoft 365, so it works regardless of which MetaCompliance product or package you're using.
MetaCompliance claims to "prove the impact" — how is Praxis Navigator different?
MetaCompliance measures impact through its own platform: fewer phishing clicks, higher training engagement, improved risk scores, compliance completion rates. These are real metrics. Praxis Navigator measures something they can't: whether employees are actually behaving more securely in their daily Microsoft 365 usage — file sharing, email handling, collaboration, identity management. One measures program performance. The other measures workforce behavior. Both matter.
Do MetaCompliance's policy attestations satisfy GDPR's requirement to test security effectiveness?
Not on their own. GDPR Art 32(1)(d) requires a process for regularly testing, assessing and evaluating the effectiveness of security measures — not just documenting that a policy was read and acknowledged. MetaCompliance's attestations and training completion records evidence that the measure exists and that the workforce engaged with it. They do not show whether behavior in daily work actually changed. Praxis Navigator reads that behavioral evidence directly from Microsoft 365, independent of the compliance platform.
How does Praxis Navigator get behavioral data?
Praxis Navigator connects to Microsoft 365 via the Graph API with read-only access. It monitors security-relevant behaviors across Exchange Online, SharePoint, OneDrive, Teams, and Entra ID. No data is exported or stored outside your environment — Praxis uses a zero-storage architecture for maximum data privacy.
How quickly can I see results?
Within 15 minutes of connecting your Microsoft 365 tenant, you'll see your first Employee Pulse with behavioral data. Because Microsoft retains historic activity data, you get a behavioral baseline from day one — no need to wait weeks or months to start measuring.
Does Praxis Navigator work with other HRM platforms besides MetaCompliance?
Yes. Praxis Navigator is platform-agnostic. It works alongside any training or HRM solution because it measures behaviors in Microsoft 365, not within any vendor's platform. You can tag interventions from any source — MetaCompliance campaigns, KnowBe4 modules, Proofpoint training, policy changes, or anything else — and measure the behavioral impact.
Who built Praxis Navigator?
Praxis Navigator is built by Praxis Security Labs, founded by Kai Roer. Roer is the author of Build a Security Culture and co-author of The Security Culture Playbook (Wiley). He created the Security Culture Framework, which has been adopted by ENISA and is used by organizations worldwide to measure and improve security culture.

Already using MetaCompliance?

Connect Praxis Navigator to your Microsoft 365 in 15 minutes and see whether your MetaCompliance investment is actually changing how employees work.

Start your free 30-day trial

No credit card. No commitment. Results in 15 minutes, or don't continue.

See the price — published, no sales call required.

Read what GDPR requires — effectiveness must be tested and evaluated, not just documented.