Skip to content
English
  • There are no suggestions because the search field is empty.

What are Signals?

Signals is the first layer in the Human Risk Intelligence closed loop. Every risk calculation, training assignment, and intervention starts with a signal.

Signals are the data points Moxso collects about your employees and their environment. They're the starting point for everything the Human Risk Intelligence engine does. Without signals, there's no risk picture, no training assignment, and no intervention.

How signals work

Moxso collects signals continuously from three sources: your employees' behavior, your organization's context, and active threats in your industry and country. Every signal is fed into the Intelligence layer, where it's classified, weighted, and turned into a risk calculation.

Signals don't trigger actions on their own. A single event, such as an employee clicking a link, is only meaningful when the Intelligence layer puts it in context. That context includes who the employee is, what they have access to, and what's currently happening in the outside world.

You can see behavioral signals recorded for your organization under Human risk intelligence > Signals. Each entry shows the signal type, its sentiment, the employee it relates to, and when it was recorded. You can filter by employee, group, signal type, severity, sentiment, risk matrix, and date.

Moxso HRI Signals Screen

 

Clicking on an individual signal opens a detail panel showing the employee's role and access level, the signal type, sentiment, and severity, and the Risk Framework categories associated with it. Where applicable, it also shows a preview of the content that triggered the signal.

Moxso HRI Signals Individual Signals

The three signal sources

Human behavior

Human behavior signals come from how your employees interact with security-related events and systems. Moxso monitors these continuously across your organization.

The full list of behavioral signals is:

Signal

Sentiment

Assigned training completed

Positive

Assigned training completed on time

Positive

Breach found

Negative

Completed optional training

Positive

Email simulation clicked

Negative

Email simulation credentials submitted

Negative

Email simulation delivered

Neutral

Email simulation reported

Positive

Email simulation reported without clicking

Positive

Multiple choice question answered correctly

Positive

Multiple choice question answered incorrectly

Negative

Opened real phishing email

Negative

Participates in cybersecurity initiatives

Positive

Post-deadline completion

Negative

Repeatedly answered phishing quizzes correctly

Positive

Repeatedly answered phishing quizzes incorrectly

Negative

Reported real phishing email

Positive

Reports legitimate emails as phishing emails

Negative

SMS simulation clicked

Negative

SMS simulation delivered

Neutral

Targeted in real phishing emails

Neutral

Threat reported

Positive

Training video watched

Positive

Each signal is classified by severity (Critical, High, Medium, Low, or Neutral) and by sentiment (Positive, Negative, or Neutral). Severity reflects how serious the behavior is. Sentiment reflects whether the behavior moves risk up or down: a phishing simulation failure is Negative, while reporting a real phishing email is Positive.

Signals are also weighted against a risk matrix that combines two dimensions: impact (High, Medium, or Low) and likelihood (Very likely, Somewhat likely, or Very unlikely). A signal that is both high impact and very likely carries significantly more weight than one that is low impact and very unlikely. This weighting happens automatically in the Intelligence layer and feeds directly into each employee's risk profile.

Organizational context

Organizational context tells Moxso who each employee is within your organization. Unlike behavioral signals, this isn't event-based. It's a continuous background input that shapes how every other signal is interpreted, and what allows the Intelligence layer to treat a risky action by a high-privilege user differently from the same action by someone with limited access.

Organizational context includes three inputs.

1) Organizational role is a standardized Moxso role that reflects the type of work an employee does, independent of their job title. Because roles are standardized, Moxso can compare risk consistently across departments and companies. The available roles are:

Administration, Customer support success, Data analytics, Education training, Engineering development, Executive leadership, Facilities services, Finance, Human resources, IT systems, Legal compliance, Management team leadership, Marketing communications, Operations, Product design, Project program management, Quality process, Research science, Sales, Security, and Supply chain logistics.

Moxso can automatically assign an organizational role to employees that don't already have one, based on their department and group data. This requires the employee data enrichment setting to be enabled in your workspace settings. The process runs once per day and existing roles are never overwritten automatically. Read more about organizational roles in this article: What are organizational roles?

2) Access level and responsibility tier are mapped to a risk weighting between 1 and 10. An employee with high system access and broad organizational responsibility carries a higher baseline risk weight than someone with limited access, which means the same behavioral signal can result in a different risk calculation depending on who triggered it.

3) Compliance requirements that apply to the employee. This data comes from your active directory integration, typically Microsoft Entra ID or Google Workspace.

External threats

External threat data comes from OSINT (open-source intelligence), which continuously monitors open sources for threats relevant to your organization. This includes active attacks in your industry and country, and data breaches that may affect your employees.

You can see what Moxso is currently tracking in Human risk intelligence > OSINT.

What happens after a signal is collected

Every signal is passed to the Intelligence layer, where it's classified against the Moxso Risk Framework and weighted based on your organization's context and training strategy. The resulting risk calculation is then passed to the Action layer, which determines the appropriate response.