How does Intelligence work?
Intelligence is the second layer in the Human Risk Intelligence closed loop. It takes the signals Moxso collects and turns them into a structured risk calculation for each employee.
The Intelligence layer is where raw signals become structured risk data. Every signal Moxso collects is classified, weighted, and put in context before any action is taken.
What the Intelligence layer does
On its own, a signal doesn't tell you much. A user clicking a link could be routine or it could be a serious risk event. It depends on who the user is, what they have access to, what your organization needs to comply with, and what threats are active right now.
The Intelligence layer works in three steps: signals are collected, risk is calculated using the Moxso Risk Framework, and the result is used to determine what should happen next. Three components contribute to that calculation: Human, OSINT, and Organization.
The Moxso Risk Framework
The Moxso Risk Framework is the classification layer that sits underneath the entire Intelligence layer. Every incoming signal is mapped to one of 16 risk categories, each covering a distinct area of human security behavior.
|
Code |
Category |
|
AAI |
Agentic AI |
|
CS |
Communication Security |
|
DP |
Data Protection |
|
DER |
Digital Exposure |
|
EDS |
Endpoint & Device Security |
|
EA |
Engagement & Awareness |
|
HUAI |
Human Use of AI |
|
IAR |
Identity & Access Risk |
|
IRR |
Incident Response Readiness |
|
MS |
Mobile Security |
|
PS |
Physical Security |
|
PRC |
Policy & Regulatory Compliance |
|
RWR |
Remote Work Risk |
|
SER |
Social Engineering Risks |
|
TPR |
Third-Party Risk |
|
WCU |
Web & Cloud Usage |
Mapping every signal to one of these categories is what allows Moxso to compare risk consistently across employees, teams, and over time. It's also what makes the Resilience Score auditable: because every category maps to ISO 27001, NIS2, and SOC 2, risk levels can be reported directly against the compliance frameworks your organization is accountable to.
The framework is aligned to MITRE ATT&CK and the NIST Cybersecurity Framework (CSF).
You can view the full Risk Framework under Human risk intelligence > Risk Framework. Each category shows a description, the indicators that map to it, and the specific clauses in ISO 27001, NIS2, and SOC 2 that it aligns to. Clicking into a category shows the individual indicators and how many signals have been recorded against each one.
The three intelligence components
The three components below describe how the Intelligence layer processes different types of input. They run in the background automatically – you won't find them as separate screens in Moxso, but understanding what each one contributes helps explain why the risk calculations look the way they do.
Human
The Human component builds a risk profile for each individual employee across three dimensions: culture, competence, and threat detection.
- Culture measures how actively the organization as a whole engages with security training, based on videos watched, simulations passed, and simulations failed.
- Competence measures knowledge at the individual level: correct and incorrect quiz answers, and simulations reported.
- Threat detection measures how effectively employees identify phishing threats: correct and incorrect phishing quiz answers, and simulations reported.
The profile draws on the employee's risk scores across the 16 Risk Framework categories and their behavior over time, not just isolated events but trends. This allows Moxso to distinguish between a user who clicked a suspicious link once and a user who consistently shows risky behavior across multiple categories.
OSINT
The OSINT component maps what's happening in the outside world to your organization. It continuously collects and classifies open-source intelligence, including:
- Active attacks relevant to your industry and country
- Data breaches that may affect your employees or organization
- Cyber news that signals emerging threats
This feeds two outputs you can see in Moxso: trending risk indicators (ranked signals with volume and direction), and a risk level view by country and industry.
OSINT data is refreshed nightly, immediately before Moxso plans new training assignments. This means every assignment decision is based on the most current available threat data.
Organization
The Organization component adds the strategic and compliance context that shapes what risk means for your specific organization. It takes into account:
- Your industry and country
- Your compliance requirements (ISO 27001, NIS2, SOC 2)
- Your business goals
- Your configured training strategy
For each employee, the Organization component also takes their organizational role into account. Roles are standardized across Moxso, which allows the engine to apply consistent risk context regardless of how your organization names its internal positions. Read more about organizational roles in this article: What are organizational roles?
Training strategy
Your training strategy is the key configuration that tells the Intelligence layer what to optimize for. It shapes how signals are prioritized and what actions are started as a result.
Moxso offers three strategies:
|
Strategy |
What it prioritizes |
|
Risk-based training |
Assigns training based on job role, access level, and responsibility. Aligned with NIS2 expectations. Risk first, compliance second. |
|
Compliance-based training |
Assigns training to meet documented requirements in ISO 27001, SOC 2, and related frameworks. Compliance first, risk second. |
|
Group-based training |
Adjusts training using behavior trends across teams and departments, without targeting individuals. |
You can select one or more frameworks. Selecting both ISO 27001 and NIS2, for instance, will align training assignments to cover both.

