CybSafe applies behavioral science. Praxis Navigator measures the outcome — independently.

CybSafe and Praxis Navigator both take behavior seriously, so the distinction matters. CybSafe changes behavior through its own program and measures its own signal. Praxis Navigator measures behavior independently, in the environment where the work happens, regardless of who ran the intervention. This page shows how they fit together.

What CybSafe does well

CybSafe is a serious, research-led human risk management platform. It applies behavioral science to security programs, using data-backed nudges and automation to reduce risky behaviors, and it surfaces behavior, sentiment and risk signals across the stack. Its SebDB — an open research initiative maintained by CybSafe's science team — is the largest catalog of human cybersecurity behaviors, mapping more than 70 behaviors to impacts, threat-actor tactics and frameworks like MITRE ATT&CK and NIST CSF. Few vendors take the science this seriously.

Source: CybSafe product and research documentation · Verified July 2026

What CybSafe's behavior data covers, and what it doesn't

CybSafe's measurement is real and thoughtfully built — this is not a platform measuring nothing. It measures the behaviors it instruments and collects through its own platform, nudges and workflows, mapped to a rigorous taxonomy.

It is also bounded to what its own program touches, and the measurement is produced by the platform running the intervention. Praxis Navigator provides the layer underneath: an independent read of how the same people behave across their whole Microsoft 365 environment, not produced by the program being assessed.

Peer-reviewed field research

29–55%

of the variation in phishing susceptibility is attributable to organizational-level factors, not individual ones.

Measured across 83,269 employees in 510 organizations, using their real responses to phishing campaigns.

Petrič, G., & Roer, K. (2022). The impact of formal and informal organizational norms on susceptibility to phishing. Telematics and Informatics, 67, 101766. Licensed under CC BY 4.0.

Peer-reviewed field research

When employees believed their colleagues were already handling security well, they became more susceptible to phishing, not less — a boomerang effect. A clear, salient security policy could likewise increase casual link-clicking.

From the same field study of 83,269 employees across 510 organizations.

Petrič, G., & Roer, K. (2022). The impact of formal and informal organizational norms on susceptibility to phishing. Telematics and Informatics, 67, 101766. Licensed under CC BY 4.0.

Why the measurement should be independent

When the vendor running the program also supplies the score for the program, the evidence is circular — and an assessor asking whether your measures work is asking a question circular evidence cannot answer. Here is the full case for independent measurement.

Behavior inside the program is not the same as behavior at work

CybSafe can show real behavioral gains inside its own program. The effectiveness regimes ask a wider question: does behavior improve in daily work, measured independently of the program itself?

Behavior inside the program is not the same as behavior at work
What your reports show What the regulation asks for What closes the gap
Behavior scores and nudge outcomes collected inside CybSafeNIS2 CIR Annex §8.1.3 — awareness and training programs assessed for effectivenessBehavioral evidence in daily work, independent of the program
Risk signals surfaced by CybSafe's own instrumentationNIS2 CIR Annex §7 — the effectiveness of risk-management measures is evaluatedA measure not produced by the vendor whose program is under assessment
Behavior tracked within the platform over timeGDPR Art 32(1)(d) — a process for regularly testing, assessing and evaluating effectivenessAn independent behavioral baseline and trend from Microsoft 365

CybSafe's measurement is real; it is simply bounded to its own program and comes from the vendor running it. Independent measurement answers the question circular evidence cannot.

See what NIS2 asks you to evidence

How Praxis Navigator measures it instead

Praxis Navigator reads security behavior from your own Microsoft 365 tenant, not from CybSafe. It builds rolling baselines and before-and-after comparisons across email, file sharing, collaboration and identity — so you can tag a CybSafe intervention and see whether behavior changed in daily work, measured by something other than CybSafe.

The two together

1

Baseline — connect Microsoft 365 and see current behavior, with months of history immediately.

2

Intervene — run your CybSafe program as you normally would.

3

Tag — mark the CybSafe intervention in Praxis Navigator.

4

Compare — see before-and-after behavior in daily work, independent of CybSafe.

5

Prove — evidence the change to auditors and the board, from a source that is not the program.

Feature comparison

How CybSafe and Praxis Navigator divide the work
Capability CybSafe Praxis Navigator Together
Behavioral-science program designYesCybSafe designs the intervention
Science-backed nudges and automationYesCybSafe nudges behavior
SebDB security-behavior taxonomyYesCybSafe maps behaviors to frameworks
Measures behaviors through its own platformYesCybSafe measures its instrumented signals
Microsoft 365 behavior monitoringYesPraxis reads real daily behavior
Behavioral baseline from historic dataYesPraxis provides an instant baseline
Published pricing, self-serve signupYesPraxis is buyable without a sales call
Dedicated environment per customerYes — dedicated AzureNo pooled tenant data
Evidence independent of the training platformNoYesMeasurement that survives a vendor change

Pricing you can see

Our prices are published. Use the calculator, see your number, start a trial — no sales call, no qualification, no quote request. Most platforms in this category will not tell you the price without a meeting first.

See the price

Questions security leaders ask

Does Praxis Navigator replace CybSafe?
No. CybSafe designs behavioral-science-based programs and nudges behavior through its own platform. Praxis Navigator does not run programs; it measures how people behave across Microsoft 365, independent of any platform. Organizations run them together — CybSafe to intervene, Praxis to provide the independent measurement layer underneath.
Doesn’t CybSafe already measure security behavior?
It does, and it does it thoughtfully — CybSafe is built on behavioral science and its SebDB taxonomy maps behaviors to frameworks like MITRE ATT&CK and NIST CSF. But the behaviors it measures are the ones it instruments and collects through its own platform, and the measurement is produced by the same program running the intervention. Praxis Navigator measures behavior independently, from your Microsoft 365 environment.
Can CybSafe’s behavioral data satisfy NIS2 or GDPR effectiveness requirements?
Partly, and rarely on its own. Its data evidences behavior inside CybSafe’s program, produced by the vendor whose program is under assessment. NIS2 CIR Annex §8.1.3 and GDPR Art 32(1)(d) ask for a change in behavior, measured over time and independently of the intervention — which is the layer Praxis Navigator adds.
How does Praxis Navigator get behavioral data?
Praxis Navigator connects to Microsoft 365 via the Graph API with read-only access. It monitors security-relevant behaviors across Exchange Online, SharePoint, OneDrive, Teams and Entra ID, using a zero-storage architecture and a dedicated Azure environment per customer.
How quickly can I see results?
Within 15 minutes of connecting your Microsoft 365 tenant. Because Microsoft retains historic activity data, you get a behavioral baseline from day one rather than waiting months to build one.

Add the independent measurement layer

Connect Microsoft 365 in 15 minutes and see whether behavior is changing in daily work — measured independently of the program running it.

Start your free 30-day trial

No credit card. No commitment. Results in 15 minutes, or don't continue.

See the price — published, no sales call required.

Read what NIS2 requires — training effectiveness assessed, not just delivered.