# Praxis Navigator — Complete Product Information > Human security behavior monitoring platform. See what employees are doing security-wise. Prove what works. --- ## PRODUCT OVERVIEW ### The Problem IT leaders are held accountable for managing human security risk — but they can't see human security behaviors. Current tools measure the wrong things: - **SAT platforms** give completion rates (who finished training) - **Phishing tools** give click rates (who failed a test) - **Neither** tells you whether behavior actually changed The result: Hours spent pulling data from Microsoft portals, building manual reports, using metrics everyone knows are inadequate, and unable to answer the question that actually matters: "Are our people behaving more securely?" ### The Solution Praxis Navigator connects to Microsoft 365 and transforms existing behavioral data into: - **Visibility** — See what employees are actually doing security-wise - **Baselines** — Compare against yourself, not meaningless industry averages - **Proof** — Show before/after behavioral impact of any intervention Setup: 15 minutes. See historic data immediately. No waiting to build baselines. ### Who Should Use It **The Progressive IT Leader:** - IT Manager or IT Director - Works at a non-IT company (manufacturing, logistics, production, telematics) - Small team (1-5 people) - Reports to CFO, COO, or CEO (not a CTO or CISO) - Organization: 100-1,000 employees - Has Microsoft 365 - Responsible for security but frustrated by inability to see or prove human risk --- ## MODULES ### Employee Pulse **Purpose:** Behavior intelligence across your organization **What it does:** - Consolidates Microsoft 365 security data into one dashboard - Provides real-time risk indicators - Enables drill-down from organization → department → team → individual - Pulls historic data on first connection **Problems it solves:** - Data scattered across multiple Microsoft portals - Hours spent manually gathering information - No single view of organizational security health - Follow-up questions you can't answer quickly **URL:** /product/employee-pulse/ --- ### Risk Bearing **Purpose:** Your true direction of travel, based on your own data **What it does:** - Creates rolling baselines at multiple levels (user, team, department, org) - Tracks multiple timeframes (7-day, 30-day, quarterly, annual) - Preserves baseline history to show improvement over time - Builds initial baseline from day one using historic Microsoft data **Problems it solves:** - Forced to use generic industry benchmarks - No internal baseline to compare against - Can't prove improvement over time - Using metrics that don't reflect your reality **URL:** /product/risk-bearing/ --- ### Stakeholder Brief **Purpose:** Right information, right language, right audience — automatically **What it does:** - Generates reports adapted to different audiences - Uses business language for executives, technical detail for IT, compliance summaries for auditors - Schedules automatic distribution - Provides on-demand generation for ad-hoc requests **Problems it solves:** - Manual report creation for each audience - Constant rework when requirements change - Meetings to explain and defend findings - Hours spent on reporting instead of security **URL:** /product/stakeholder-brief/ --- ### Impact Proof **Purpose:** Evidence that your interventions actually changed behavior **What it does:** - Tags interventions (training, policy changes, tool deployments) - Calculates automatic before/during/after behavioral comparisons - Shows multi-dimensional impact across teams and timeframes - Exports evidence for stakeholder presentations **Problems it solves:** - SAT completion rates don't prove behavior changed - Can't demonstrate security investments are working - Leadership asks "is it working?" and you can't answer with data - Vendor claims without verification **URL:** /product/impact-proof/ --- ### Compliance Vault **Purpose:** Audit-ready documentation, always protected, always current **What it does:** - Captures behavioral evidence continuously - Maintains trackable audit logs - Supports annotation for decisions and reasoning - Maps to NIS2, DORA, ISO 27001 requirements - Extends retention beyond Microsoft's limits **Problems it solves:** - Scrambling before audits - Failed audits due to lack of behavioral evidence - Regulatory penalties (NIS2, DORA, ISO 27001) - Personal liability concerns (Uber CISO scenario) **URL:** /product/compliance-vault/ --- ### Partner Lens **Purpose:** Verify what your MSSPs and consultants actually deliver **What it does:** - Shows actual behavioral impact of partner activities - Connects partner work to behavioral outcomes - Reduces coordination overhead - Provides evidence for contract decisions **Problems it solves:** - Relying on partner self-reporting - Can't verify if MSSPs are delivering value - Hours coordinating rather than verifying - Contract negotiations without evidence **URL:** /product/partner-lens/ --- ### Supply Chain Anchor (Coming Soon) **Purpose:** Verified human risk reporting across your entire supply chain **What it does:** - Extends visibility to suppliers and partners - Provides verified behavioral data (not questionnaire responses) - Offers consolidated supply chain security dashboard - Enables evidence-based vendor contracts **Problems it solves:** - Supply chain risk relies on self-assessments - No visibility into partner security practices - Documentation gaps in legal and insurance claims - Questionnaires that nobody verifies **URL:** /product/supply-chain-anchor/ --- ## PRICING Transparent, published pricing — enter your team size at praxisnavigator.io/pricing to see your exact price, no sales call required. Every organization gets the full platform in its own dedicated, isolated environment as standard. Your bill is always two lines, and it never cliffs: - **Platform licensing** — the value price, charged on marginal per-employee brackets (each seat is priced at its band's rate, so adding one employee never jumps the bill). - **Processing** — the Microsoft/Azure cost, passed through at a flat rate per employee, shown as its own line. | Segment | Employees | How it's priced | |---------|-----------|-----------------| | Self-service | 25–500 | Published, calculator-based pricing by team size; billed monthly or annually. Built for teams of 25+ (organizations below 25 are billed at 25). | | Custom plan | 501+ | Private offer with custom pricing, dedicated infrastructure where relevant, and a named contact with an SLA. | **Free Trial:** 30 days, no credit card required, self-service via Microsoft Marketplace. --- ## HOW IT WORKS **Step 1: Connect** - Self-service wizard through Microsoft Marketplace - Read-only Microsoft Graph API permissions - No IT resources required beyond authorization click - Setup time: 15 minutes **Step 2: See** - Behavioral data appears immediately - Historic trends from Microsoft 365 (90-160 days depending on your plan) - Baselines built from day one - Drill-down from organization to individual **Step 3: Prove** - Tag interventions (training, policies, tools) - See automatic before/after comparisons - Generate stakeholder reports - Complete the loop: Baseline → Intervention → Compare → Prove --- ## MICROSOFT 365 DATA RETENTION (Critical Context) ### The Problem Microsoft automatically deletes behavioral data based on license type. Most organizations don't realize their data is disappearing until they need it. ### Retention by License | License Type | Retention Period | What Happens After | |--------------|------------------|-------------------| | Microsoft 365 Business Basic/Standard/Premium | 180 days | Permanently deleted | | Microsoft 365 E1 | 180 days | Permanently deleted | | Microsoft 365 E3 | 180 days | Permanently deleted | | Microsoft 365 E5 (Exchange, SharePoint, OneDrive, Entra ID) | 1 year | Permanently deleted | | Microsoft 365 E5 (other activities) | 180 days | Permanently deleted | | E5 + 10-Year Audit Log Retention Add-on | Up to 10 years | Requires additional license | ### Key Facts - **Retention is per-user:** The retention period follows the license of the user who performed the activity, not the admin reviewing logs - **Cannot recover deleted data:** Once Microsoft removes data, it's gone permanently - **Mixed environments have mixed retention:** Organizations with E3 and E5 users have different retention for different users - **Pre-October 2023 data had 90-day retention:** Microsoft extended default from 90 to 180 days in late 2023 ### Why This Matters Without historic data, you cannot: - Build baselines over meaningful timeframes - Prove year-over-year security improvement - Show before/after impact of interventions from more than 6 months ago - Provide audit evidence for events outside the retention window - Investigate incidents that occurred beyond the retention period ### How Praxis Navigator Solves This 1. **Immediate capture:** The moment you connect, we pull whatever historic data Microsoft still has 2. **Forward preservation:** From connection onward, we preserve behavioral data regardless of Microsoft limits 3. **Extended retention:** Your data stays as long as you're a customer — years, not months 4. **Unified view:** Normalizes retention across mixed license environments **The urgency:** Every day you wait is another day of behavioral history permanently lost. The sooner you connect Praxis Navigator, the more historic baseline you preserve. More information: https://praxisnavigator.io/product/data-retention/ --- ## TECHNICAL SPECIFICATIONS **Integration:** - Microsoft Graph API (read-only) - OAuth 2.0 authentication - Azure AD integration - Zero infrastructure on customer side **Data Sources:** - Exchange Online (email security practices) - SharePoint Online (file sharing behaviors) - OneDrive for Business (personal file security) - Microsoft Teams (communication security) - Azure AD Logs (authentication patterns) **Privacy:** - No PII collection (names, email addresses, identifiers) - No content access (email content, file contents, messages) - Behavioral patterns only - GDPR aligned **Compliance:** - SOC2 Type II - ISO 27001 aligned - GDPR compliant - EU data residency available --- ## COMPANY **Praxis Security Labs** Creator of Praxis Navigator and the Security Culture Framework **Founder & CEO:** Kai Roer - Created the Security Culture Framework (adopted by ENISA) - Former Chief Research Officer at KnowBe4 - Author: "Build a Security Culture" - Co-author: "The Security Culture Playbook" **Director of Research:** Dr. Thea Mannix - Neuroscientist - Behavioral science expertise --- ## COMPARISONS ### Praxis Navigator vs. Security Awareness Training (SAT) | Aspect | SAT Platforms | Praxis Navigator | |--------|--------------|------------------| | Measures | Training completions, phishing clicks | Actual behavior change | | Data source | Training platform | Microsoft 365 behavioral data | | Proof | Activity metrics | Before/after behavioral evidence | | Relationship | N/A | Measures if SAT works | **Key point:** Praxis Navigator is not a competitor to SAT. It's the measurement layer that proves whether SAT (and other interventions) actually work. ### Praxis Navigator vs. SIEM/Security Tools | Aspect | SIEM | Praxis Navigator | |--------|------|------------------| | Focus | Technical threats | Human behaviors | | Data | Security events, logs | Behavioral patterns | | Output | Alerts, incidents | Baselines, trends, proof | ### Comparison hub — how Praxis fits alongside named platforms Praxis Navigator does not replace training, phishing simulation, or compliance platforms; it adds the independent behavioural evidence NIS2, DORA and GDPR now require. It measures whether people behave more securely over time, independently of the vendor running the intervention. Full hub: https://praxisnavigator.io/compare/ - Security awareness training & phishing simulation (KnowBe4, MetaCompliance, Proofpoint, Junglemap) — measure completions and simulated-phishing clicks, not independent behaviour change. - Human risk management (Hoxhunt, CybSafe) — measure behaviour bounded to their own delivery surface, not independent of the intervention. - Compliance automation (Vanta, Drata) — evidence that controls exist and stay configured, not whether the human layer of them works. - Microsoft 365 (Defender, Secure Score, Purview, Entra ID) — report tenant security posture, not behaviour over time. Praxis is a Microsoft Marketplace partner built on Microsoft's own data surface, not a competitor. - Build it yourself (Graph API into a BI layer) — as strong as the method behind it, and the method is what an assessor asks about. Comparison pages: - https://praxisnavigator.io/compare/knowbe4/ - https://praxisnavigator.io/compare/metacompliance/ - https://praxisnavigator.io/compare/proofpoint/ - https://praxisnavigator.io/compare/junglemap/ (Junglemap is now part of MetaCompliance) - https://praxisnavigator.io/compare/hoxhunt/ - https://praxisnavigator.io/compare/cybsafe/ - https://praxisnavigator.io/compare/compliance-platforms/ - https://praxisnavigator.io/compare/microsoft-365/ - https://praxisnavigator.io/compare/build-vs-buy/ - https://praxisnavigator.io/compare/security-awareness-training-platforms/ The regulatory case behind the comparisons — why completion is not effectiveness, and what NIS2, DORA and GDPR each require — lives at https://praxisnavigator.io/security-effectiveness/ --- ## WHITEPAPERS In-depth whitepapers from Praxis Security Labs, free to download with no account required. Index: https://praxisnavigator.io/whitepapers/ **Measuring Security Control Effectiveness: From Attestation to Evidence** — Kai Roer (2026). GDPR (Article 32(1)(d)), NIS2 (Article 21(2)(f) and the Article 20 personal-liability provision) and DORA (Article 13(4)) now require organisations to demonstrate that security controls produce measurable effects — not merely that controls exist. The same evidence standard is spreading beyond the EU (US FTC Safeguards Rule, Australia APRA CPS 234, Canada OSFI B-13, UK GDPR). The paper explains the difference between "being effective" and "having an effect," why point-in-time audits are weak evidence and continuous intervention-linked monitoring is strong evidence, and why the organisational (human behaviour) control layer — where measurement almost universally fails — is now measurable through Microsoft 365 behavioural signals. https://praxisnavigator.io/whitepapers/measuring-security-control-effectiveness/ --- ## FREQUENTLY ASKED QUESTIONS **Q: How is Praxis Navigator different from security awareness training platforms?** A: SAT platforms measure activity (completions, click rates). Praxis Navigator measures actual behavior change by analyzing Microsoft 365 data. We're the proof layer that shows whether training works. **Q: What data does Praxis Navigator access?** A: Microsoft 365 data via Graph API with read-only permissions. We analyze behavioral patterns but never access email content, file contents, or personal identifiers. **Q: How long does setup take?** A: 15 minutes. Self-service wizard, single authorization click. You see your data immediately. **Q: Do I need to wait to build baselines?** A: No. We pull historic Microsoft data (90-160 days), so your baseline exists from day one. **Q: What compliance standards do you support?** A: NIS2, DORA, ISO 27001. Compliance Vault provides continuous evidence documentation. **Q: Is there a free trial?** A: Yes. 30 days, full Core features, no credit card required. **Q: How long does Microsoft 365 retain behavioral data?** A: It depends on your license. Business/E1/E3 licenses retain audit logs for 180 days. E5 retains core services (Exchange, SharePoint, OneDrive, Entra ID) for 1 year, other activities for 180 days. Once data ages out, Microsoft permanently deletes it and it cannot be recovered. **Q: Can I get back Microsoft 365 data that's already been deleted?** A: No. Once Microsoft deletes data past its retention period, it's gone permanently. This is why connecting Praxis Navigator sooner preserves more historic data — we capture whatever Microsoft still has the moment you connect. **Q: How is Praxis Navigator retention different from Microsoft?** A: Microsoft automatically deletes data after 180 days (E3) or 1 year (E5 core). Praxis Navigator preserves your behavioral data for as long as you're a customer, on every plan. --- ## BLOG — THE PRAXIS PRACTICE BLOG Research and insights on security culture, human factors in cybersecurity, behavioral security, and human risk management. Written by the Praxis Security Labs team including Kai Roer, Dr. Thea Mannix, Aimee Laycock, and Jacopo Paglia. Blog index: https://praxisnavigator.io/blog/ ### All Articles (newest first) - **On Measuring the Unmeasurable** — Thea Mannix (2024-10-31): https://praxisnavigator.io/blog/on-measuring-the-unmeasurable - **Meaningful Metrics: The Case for Switch Cost** — Thea Mannix (2024-06-27): https://praxisnavigator.io/blog/meaningful-metrics-switch-cost - **The Internet is a dark room. Your brain thinks the lights are on.** — Thea Mannix (2024-06-12): https://praxisnavigator.io/blog/the-internet-is-a-dark-room-your-brain-thinks-the-lights-are-on - **Meaningful Baselines for Human Factors: Here's How To Do It** — Kai Roer (2024-06-07): https://praxisnavigator.io/blog/meaningful-baselines-for-human-factors-heres-how-to-do-it - **The Problem with Awareness Training Best Practices - and How We Can Fix It** — Kai Roer (2024-05-24): https://praxisnavigator.io/blog/the-problem-with-awareness-training-best-practices-and-how-we-can-fix-it - **Words Matter: Why Human Risk Management is More Than Just a Term** — Thea Mannix (2024-05-06): https://praxisnavigator.io/blog/words-matter-why-human-risk-management-is-more-than-just-a-term - **The Emotional Reality of the Digital World** — Thea Mannix (2024-03-20): https://praxisnavigator.io/blog/the-emotional-reality-of-the-digital-world - **The importance of multidisciplinary collaboration in cybersecurity analytics** — Jacopo Paglia (2024-03-08): https://praxisnavigator.io/blog/the-importance-of-multidisciplinary-collaboration-in-cybersecurity-analytics - **How do you report your security culture progress to the board?** — Kai Roer (2024-02-23): https://praxisnavigator.io/blog/how-do-you-report-your-security-culture-progress-to-the-board - **From Reactive to Proactive Strategies** — Thea Mannix (2024-02-19): https://praxisnavigator.io/blog/reactive-to-proactive-strategies - **Advancing Technology, Static Practices: The Cybersecurity Dilemma** — Thea Mannix (2024-01-23): https://praxisnavigator.io/blog/advancing-technology-static-practices-the-cybersecurity-dilemma - **Looking back on 2023** — Aimee Laycock (2023-12-19): https://praxisnavigator.io/blog/looking-back-on-2023 - **Resilience, human factors and security** — Aimee Laycock (2023-12-06): https://praxisnavigator.io/blog/resilience-human-factors-and-security - **Is digital friction harming your organization?** — Aimee Laycock (2023-11-28): https://praxisnavigator.io/blog/is-digital-friction-harming-your-organization - **The Crucial Role of Effective Data Visualization** — Jacopo Paglia (2023-11-13): https://praxisnavigator.io/blog/the-crucial-role-of-effective-data-visualization - **Transform how you manage human risks** — Aimee Laycock (2023-10-31): https://praxisnavigator.io/blog/transform-how-you-manage-human-risks - **New software to solve cybersecurity's human risk challenge** — Aimee Laycock (2023-10-31): https://praxisnavigator.io/blog/new-software-to-solve-cybersecuritys-human-risk-challenge - **Why invest in a culture of security: Human Detectors** — Aimee Laycock (2023-11-09): https://praxisnavigator.io/blog/why-invest-in-a-culture-of-security-human-detectors - **Intercepting human behavior** — Aimee Laycock (2023-11-03): https://praxisnavigator.io/blog/intercepting-human-behavior - **Why invest in a culture of security: Adaptability** — Aimee Laycock (2023-10-02): https://praxisnavigator.io/blog/why-invest-in-a-culture-of-security-adaptability - **Cyber-security or cyber-biased security?** — Aimee Laycock (2023-09-21): https://praxisnavigator.io/blog/cybersecurity-or-cyber-biased-security - **Director of Research to speak at Cognitive Security Institute** — Aimee Laycock (2023-09-06): https://praxisnavigator.io/blog/director-of-research-to-speak-at-cognitive-security-institute - **Why invest in a culture of security: Resilience** — Kai Roer (2023-08-30): https://praxisnavigator.io/blog/why-invest-in-a-culture-of-security-resilience - **No, ChatGPT does not think like us** — Thea Mannix (2023-08-24): https://praxisnavigator.io/blog/no-chatgpt-does-not-think-like-us - **Attend or request the talk: The Psychology of Security** — Kai Roer (2023-08-24): https://praxisnavigator.io/blog/attend-or-request-the-talk-the-psychology-of-security - **Statistical methods of interest: Sensitivity Analysis** — Jacopo Paglia (2023-08-14): https://praxisnavigator.io/blog/statistical-methods-of-interest-sensitivity-analysis - **Statistical methods of interest: Bayesian Optimization** — Jacopo Paglia (2023-07-18): https://praxisnavigator.io/blog/statistical-methods-of-interest-bayesian-optimization - **The SAT elephant in the room: Part 2** — Kai Roer (2023-07-03): https://praxisnavigator.io/blog/the-sat-elephant-in-the-room-part-2 - **The SAT elephant in the room** — Kai Roer (2023-06-21): https://praxisnavigator.io/blog/the-sat-elephant-in-the-room - **Statistical methods of interest: Data Assimilation** — Jacopo Paglia (2023-06-09): https://praxisnavigator.io/blog/statistical-methods-of-interest-data-assimilation - **The Forgotten Human Factor in Cybersecurity** — Thea Mannix (2023-06-01): https://praxisnavigator.io/blog/the-forgotten-human-factor-in-cybersecurity - **Focus on interesting statistical methods: Value of Information** — Jacopo Paglia (2023-05-16): https://praxisnavigator.io/blog/value-of-information - **Why empathy and emotion are key to modern cyber security** — Thea Mannix (2023-04-27): https://praxisnavigator.io/blog/why-empathy-and-emotion-are-key-to-modern-cyber-security - **You get what you reward: Productivity vs. Cybersecurity** — Thea Mannix (2023-04-21): https://praxisnavigator.io/blog/you-get-what-you-reward - **Collect Data Wisely** — Jacopo Paglia (2023-04-05): https://praxisnavigator.io/blog/collect-data-wisely - **Conquer expert bias in cybersecurity with next level focus** — Kai Roer (2023-03-17): https://praxisnavigator.io/blog/conquer-expert-bias-in-cybersecurity-with-next-level-focus - **Business strategy or cybersecurity? Do you have to choose?** — Aimee Laycock (2023-03-14): https://praxisnavigator.io/blog/business-strategy-or-cybersecurity-do-you-have-to-choose - **Value of human knowledge in artificial intelligence & machine learning** — Jacopo Paglia (2023-03-01): https://praxisnavigator.io/blog/value-of-human-knowledge-in-artificial-intelligence-machine-learning - **Can cybersecurity be an efficiency tool instead of a sunk cost?** — Kai Roer (2023-02-16): https://praxisnavigator.io/blog/can-cybersecurity-be-an-efficiency-tool-instead-of-a-sunk-cost - **Introducing Praxis** — Kai Roer (2023-01-26): https://praxisnavigator.io/blog/introducing-praxis ### Blog Topics - Security culture measurement and improvement - Human risk management (HRM) strategy and terminology - Behavioral security metrics, baselines, and meaningful measurement - Security awareness training (SAT) effectiveness and critique - Cognitive psychology applied to cybersecurity (switch cost, expert bias, empathy) - Statistical methods for security analytics (Bayesian optimization, sensitivity analysis, data assimilation, value of information) - Digital friction and its impact on organizations - Organizational resilience, adaptability, and human detectors - AI and machine learning in cybersecurity (ChatGPT, human knowledge) - Board-level security culture reporting - Data visualization for security insights --- ## CONTACT - Website: https://praxisnavigator.io - Product: https://praxisnavigator.io/product/ - Data Retention: https://praxisnavigator.io/product/data-retention/ - Blog: https://praxisnavigator.io/blog/ - Trial: https://praxisnavigator.io/start-now/ - Pricing: https://praxisnavigator.io/pricing/ - Email: hello@praxisnavigator.io - Support: support@praxisnavigator.io