Skip to content
English
  • There are no suggestions because the search field is empty.

How does Intelligence work?

Intelligence is the second layer in the Human Risk Intelligence closed loop. It takes the signals Moxso collects and turns them into a structured risk calculation for each employee.

The Intelligence layer is where raw signals become structured risk data. Every signal Moxso collects is classified, weighted, and put in context before any action is taken.

What the Intelligence layer does

On its own, a signal doesn't tell you much. A user clicking a link could be routine or it could be a serious risk event. It depends on who the user is, what they have access to, what your organization needs to comply with, and what threats are active right now.

The Intelligence layer works in three steps: signals are collected, risk is calculated using the Moxso Risk Framework, and the result is used to determine what should happen next. Three components contribute to that calculation: Human, OSINT, and Organization.

The Moxso Risk Framework

The Moxso Risk Framework is the classification layer that sits underneath the entire Intelligence layer. Every incoming signal is mapped to one of 16 risk categories, each covering a distinct area of human security behavior.

Code

Category

AAI

Agentic AI

CS

Communication Security

DP

Data Protection

DER

Digital Exposure

EDS

Endpoint & Device Security

EA

Engagement & Awareness

HUAI

Human Use of AI

IAR

Identity & Access Risk

IRR

Incident Response Readiness

MS

Mobile Security

PS

Physical Security

PRC

Policy & Regulatory Compliance

RWR

Remote Work Risk

SER

Social Engineering Risks

TPR

Third-Party Risk

WCU

Web & Cloud Usage

Mapping every signal to one of these categories is what allows Moxso to compare risk consistently across employees, teams, and over time. It's also what makes the Resilience Score auditable: because every category maps to ISO 27001, NIS2, and SOC 2, risk levels can be reported directly against the compliance frameworks your organization is accountable to.

The framework is aligned to MITRE ATT&CK and the NIST Cybersecurity Framework (CSF).

You can view the full Risk Framework under Human risk intelligence > Risk Framework. Each category shows a description, the indicators that map to it, and the specific clauses in ISO 27001, NIS2, and SOC 2 that it aligns to. Clicking into a category shows the individual indicators and how many signals have been recorded against each one.

Moxso HRI Risk Frameworks Screen

Moxso HRI Risk Frameworks Single Framework Detail

The three intelligence components

The three components below describe how the Intelligence layer processes different types of input. They run in the background automatically – you won't find them as separate screens in Moxso, but understanding what each one contributes helps explain why the risk calculations look the way they do.

Human

The Human component builds a risk profile for each individual employee across three dimensions: culture, competence, and threat detection.

  • Culture measures how actively the organization as a whole engages with security training, based on videos watched, simulations passed, and simulations failed.
  • Competence measures knowledge at the individual level: correct and incorrect quiz answers, and simulations reported.
  • Threat detection measures how effectively employees identify phishing threats: correct and incorrect phishing quiz answers, and simulations reported.

The profile draws on the employee's risk scores across the 16 Risk Framework categories and their behavior over time, not just isolated events but trends. This allows Moxso to distinguish between a user who clicked a suspicious link once and a user who consistently shows risky behavior across multiple categories.

OSINT

The OSINT component maps what's happening in the outside world to your organization. It continuously collects and classifies open-source intelligence, including:

  • Active attacks relevant to your industry and country
  • Data breaches that may affect your employees or organization
  • Cyber news that signals emerging threats

This feeds two outputs you can see in Moxso: trending risk indicators (ranked signals with volume and direction), and a risk level view by country and industry.

OSINT data is refreshed nightly, immediately before Moxso plans new training assignments. This means every assignment decision is based on the most current available threat data.

Organization

The Organization component adds the strategic and compliance context that shapes what risk means for your specific organization. It takes into account:

  • Your industry and country
  • Your compliance requirements (ISO 27001, NIS2, SOC 2)
  • Your business goals
  • Your configured training strategy

For each employee, the Organization component also takes their organizational role into account. Roles are standardized across Moxso, which allows the engine to apply consistent risk context regardless of how your organization names its internal positions. Read more about organizational roles in this article: What are organizational roles?

Training strategy

Your training strategy is the key configuration that tells the Intelligence layer what to optimize for. It shapes how signals are prioritized and what actions are started as a result.

Moxso offers three strategies:

Strategy

What it prioritizes

Risk-based training

Assigns training based on job role, access level, and responsibility. Aligned with NIS2 expectations. Risk first, compliance second.

Compliance-based training

Assigns training to meet documented requirements in ISO 27001, SOC 2, and related frameworks. Compliance first, risk second.

Group-based training

Adjusts training using behavior trends across teams and departments, without targeting individuals.

You can select one or more frameworks. Selecting both ISO 27001 and NIS2, for instance, will align training assignments to cover both.