Vendor comparison · Updated August 2026

OutThink vs Living Security: same acronym, different products

Start with the confusing part, because it is genuinely confusing.

Living Security has a product called Human Risk Index. We have a product called Human Risk Intelligence. Both get abbreviated to HRI, and if both platforms are in your evaluation you have probably already written “HRI” in two cells of a spreadsheet meaning two different things.

And the distinction the words are pointing at is real. An index is a number. An intelligence layer is the thing that produces the number, explains what sits behind it, surfaces the organizational patterns underneath, and tells you what to fix first. Those are different products doing different jobs, and the shared abbreviation hides it.

Which is a fair summary of this whole comparison, and why this page skips the category argument entirely. Both of us are building for behavior change and risk quantification rather than compliance records.

It goes instead to mechanism, evidence and product coherence – which is where two similar-sounding platforms actually separate.

Living Security

What the platform is built around

  1. Aggregation layer. Human Risk Index consolidates signal from a broad set of security-tool integrations.
  2. Scoring and cohorts. People are scored and grouped so campaigns can be targeted at the highest-risk cohorts.
  3. Training and simulation are delivered against those cohorts.
  4. Published weighting. How the index is composed is documented and adjustable.

OutThink

What the platform is built around

  1. Per-person generation. Training is generated for the individual, not selected for a cohort.
  2. Intervention at the moment of risk. Nudges fire from live stack signal into Teams or Slack while the person is active.
  3. One product, not several joined up. Motivate, Educate, Activate and Correct run on the same behavioral record.
  4. Attitudinal layer. The model carries why each person behaves as they do, not only what they did.

Both platforms are real, and both are more than a phishing simulator. They are built around different mechanisms, which is what actually decides which one fits your program. The differences below are mechanism differences, not scores.

Before you build the comparison grid

  • The acronym clash is real and it matters in your notes. Their Human Risk Index is a scored index. Our Human Risk Intelligence is the layer that produces the score, the explanation behind it and the prioritized actions. Write both out in full in your evaluation grid.
  • Both platforms ship a lot. They have first-party training and simulation, nudges in Slack and Teams, automated remediation and control actions. Do not evaluate them as a dashboard vendor; that characterization is out of date.
  • The separation is coherence and evidence, not breadth. Ask what is one product versus what is being integrated, ask what the risk model is built from and whether it can be inspected, and ask for the cohort, timeframe and baseline behind every headline figure – ours included.
  • What changing looks like: RelateCare’s click rate fell from 8% to 1%, reporting doubled from 17% to 34%, and credential submission halved.1
  • On analyst validation: they hold a Forrester Wave Leader placement in Human Risk Management. Read the report rather than either vendor’s summary of it, and hold what it tells you precisely – an assessment against one firm’s criteria on one date, not a fit for your program.
  • Who we are: founded in 2019 by CISOs who lived this problem, seven years of purpose-built HRM engineering, 100+ enterprise deployments.

First, what Living Security does well

Heaviest concession section in the set, alongside the CybSafe page, and the first item is the one buyers raise with us.

  • They are a Leader in the Forrester Wave for Human Risk Management. We do not hold an equivalent placement and we are not going to talk around it. If analyst validation is a procurement requirement for you, that is a point in their favor and you should weight it. What we would ask is that you read the report rather than either vendor’s summary of it, and hold what it establishes precisely: they were assessed well against that report’s criteria on that date.
  • They have been in this category longer than most and helped define its vocabulary. Founded 2017, and they were using “human risk management” when the rest of the market was still selling awareness training.
  • The product is broad and it is first-party. Their own training content library, their own phishing, vishing, smishing and deepfake simulation, nudges in Slack and Teams, automated remediation including triggered coaching, and an upper tier that takes control actions such as access restrictions and MFA re-enrolment. Anyone telling you they only build dashboards is working from old information.
  • Their integration footprint is substantial across endpoint, data loss, identity, SIEM and service management, and they can ingest results from incumbent awareness platforms as well.
  • Named enterprise logos across consumer goods, healthcare, financial services and manufacturing.

If your evaluation weights analyst validation and breadth of first-party capability above all else, they are a strong answer and we would rather say so.

The question this page exists to answer is what differs underneath the shared category and the shared acronym.

What actually differs

Three differences, in the order that matters.

Difference 1The two HRIs are different objects

Theirs is an index: a score per person on a defined scale, computed across behavior, threat and identity dimensions and weighted by role and access. It is a genuine model and they publish a conceptual description of it.

Ours is an intelligence layer: it produces a score, the behavioral explanation behind it, the organizational patterns underneath it, and a prioritized set of improvement actions across people, process and technology – some executed automatically, some for approval, some for your team to action.

Both are useful. They answer different questions. The one to ask is not “what is your score” but “what does the platform tell me to do next, and how did it decide that.”

And for both of us: ask what the model specification is, whether the weightings are published or only described, and whether any validation or back-testing evidence exists. Where we cannot point to public documentation we will say so rather than call ourselves transparent.

Difference 2One product, or several being brought together

This is the sharpest distinction available and it is checkable in an afternoon.

They relaunched their platform in 2026 as an AI-native product. In their own integration catalog, their legacy training and phishing modules appear as data-source connectors into the new platform rather than as rebuilt components, and they maintain public migration support material for customers moving between the two estates.

That is not a scandal; every vendor that has been going a while has a migration story, and ours is not perfect either. But it is a fair question to ask, and it has consequences you can test: ask which parts of the platform were rebuilt and which are integrated, ask what your migration path looks like and who pays for it, and ask whether the feature you are being shown lives on the new estate or the old one.

Two related questions worth asking in the same breath: their AI agent risk capability was announced generally available in early 2026 and their published packaging still labels it as beta, so ask what it discovers today. And phishing simulation is an add-on across their tiers rather than included, so ask for the all-in price of the program you would actually run, not the platform license.

Difference 3What the evidence base looks like

Both of us publish outcome claims, and both should be interrogated.

Theirs include a substantial reduction in risky users attributed to third-party research, and figures for faster remediation and reduced exposure. Ask what cohort, timeframe and baseline definition sit behind each one, and ask whether the third-party validation covers the model itself or the underlying research the model draws on. Those are different claims.

Then look at the independent customer evidence. Their public review corpus is small and predates the platform they now sell – worth knowing not as a criticism of the product, but because it means peer validation is not available for the 2026 release, on either side of this comparison. Ours is not large either. If your process includes a peer-validation step, plan to get references directly rather than relying on review sites for either vendor.

Where the maturity model does and does not help

Short, and honest about the limits of our own framework.

The HRM Maturity Model usefully separates platforms built for compliance from platforms built for behavior change. It does not separate these two platforms. Both credibly operate at Level 2 and both are building toward Level 3, and using the model to claim otherwise would be using it as a marketing device.

Where it still earns its place is the sequencing argument. The four L2 jobs – Motivate, Educate, Activate, Correct – are a system rather than a menu, so check each one separately on both platforms rather than accepting a platform-level claim.

One honest note on the third L2 job. Activate – rehearsing behaviors beyond phishing as practice rather than delivering content about them – is where we think the clearest daylight sits, and our Cyber Ranges deploy the first eight ranges in late 2026. Today that job is covered through adaptive training and stack-triggered nudges. Ask both vendors what is shipping and what is roadmap, and hold us to the same answer.

THE L1 TEST

There isn’t one. If the program is built around phishing simulations, generic training campaigns, newsletters, posters and Cybersecurity Awareness Month activities, it is L1.

THE L2 TEST

Can the platform execute all four L2 critical jobs – Motivate, Educate, Activate and Correct – autonomously, across the entire organization, and across the full spectrum of security behaviors?

THE L3 TEST

Is the risk quantification built on actual behavioral data from security systems, or on simulation results and training completion?

Does it surface actionable intelligence from user interactions, generate prioritized improvement actions across people, process and technology, and feed human risk intelligence into SOC, GRC, ticketing and identity systems?

THE L4 TEST

Can the platform adjust access controls from human risk scores, integrating directly with identity providers? Can it enable user self-remediation that shifts responsibility from the SOC to the individual? Is it architected to extend behavioral governance to AI agents, not just human users?

OutThink and Living Security, side by side

The Living Security column contains only statements traceable to their own public material or published third-party sources. Where we cannot verify something, the cell says so and tells you to ask them.

What to askOutThinkLiving Security (public information, August 2026)
Analyst validationNo equivalent Human Risk Management placement.Leader in the Forrester Wave: Human Risk Management Solutions. Independent and third-party. Read the report rather than either vendor’s summary, and note that a placement describes an assessment against one firm’s criteria on one date rather than a fit for your program.
What “HRI” meansHuman Risk Intelligence: the layer that produces the score, the behavioral explanation behind it, organizational risk patterns, and prioritized improvement actions across people, process and technology.Human Risk Index: a scored index per person across behavior, threat and identity dimensions, weighted by role and access. Write both out in full in your evaluation grid. Different objects, same acronym.
Category vocabularyBoth platforms describe themselves in very similar terms.on seniority – they were using this language first. This is why the rest of this table is mechanism rather than positioning.
Breadth of first-party capabilityTraining, simulation, nudges, gamified competence scoring, ranges from late 2026, and a risk intelligence layer, on one platform.Broadly comparable, and worth saying so. Their own training library, their own phishing, vishing, smishing and deepfake simulation, nudges in Slack and Teams, automated remediation, and control actions in the upper tier. Do not evaluate them as a dashboard.
One product or several integratedOne platform, one roadmap, one estate.Ask which components were rebuilt for the 2026 platform and which are integrated as data sources from the previous estate, what your migration path is, and whether the feature being demoed lives on the new estate or the old one. Their own integration catalog and public migration material are the place to start.
What the risk model is built fromBehavior from EDR, DLP, web, email and IAM, plus attitudes, level of access, how targeted someone is, device security, and workplace factors such as email fatigue and collaboration networks.A model across behavior, threat and identity, fed by a large integration footprint. Ask what proportion of the score originates outside their own products. Put the same question to us.
Model inspectabilityWhere our documentation is not public we will say so rather than call it transparent. Ask what an IAM or GRC reviewer can inspect.A conceptual description is published. Ask whether the full specification, the weightings and any validation evidence are available, and whether third-party validation covers the model or the research behind it. Same questions to us.
From risk view to actionPrioritized improvement actions across people, process and technology, with evidence attached – some automatic, some for approval, some for your team.They ship guided remediation and automated actions including triggered coaching and access changes. Ask specifically what it recommends when the right fix is a process or control change rather than training a person.
What adaptsThe training content itself, generated per person from role, behavior, motivational driver and in-flow choices, plus the nudges. One system.Adaptive campaigns and AI-generated personalized training. Ask both vendors to show the same module rendered for two different people, live, side by side.
Practice beyond phishingCyber Ranges across deepfake CEO video, vishing, smishing, data handling, secure browsing, endpoint, social media and physical security, adapting per person and feeding the risk portrait. First eight deploying late 2026.They ship deepfake, vishing, smishing and quishing simulation today. Ask what is rehearsed as adaptive practice you can fail and retry, as opposed to simulated once, and hold us to the roadmap date above.
AI agent riskRoadmap, sequenced behind L2 and L3, with no date to give you today.Announced generally available in early 2026; their published packaging still labels it beta. Ask what it discovers today.
Motivation and the manager layerCyberQ: a personal cyber-competence score people own and improve, a manager view for line managers, and an HR feed where governance allows.Employee and manager scorecards, gamification and executive reporting. Ask what an individual sees about their own progress and what a line manager can act on.
Commercial shapeNo public list price. Packaging mirrors the maturity model, so expansion follows your own journey. L1 includes phishing simulation rather than gating it as an add-on. See Plans. Human Risk Intelligence, the Real-Time Threats Engine and CyberQ are available from 2,001 licensed users.No public list price. A platform license plus one action package, with phishing simulation, multi-channel simulation and AI content generation priced as add-ons across tiers. Ask for the all-in cost of the program you would actually run.
Independent customer evidenceA smaller review corpus than the largest platforms in this category. Ask us for references at your scale and sector.Their public review corpus is small and predates the platform they now sell. Not a criticism of the product; it means peer validation is unavailable for the 2026 release. Plan to take references directly from both of us. See Living Security on G2.
Implementation and supportDirectory and SSO in week one, first campaign and baseline inside week four. Stack integrations that feed L3 are scoped separately. Named CSM and HRM program expertise.Ask how long to first campaign, how long until stack signal is flowing, and who supports the program day to day.

Sources for the Living Security column. Living Security product, platform, plans and integrations pages, their 2026 platform and reporting release announcements, their published risk-model documentation, and G2 and Gartner Peer Insights listings. All accessed August 2026.

VINCI

Building a Culture of Cyber Resilience Across a Global Workforce

VINCI partnered with OutThink to move beyond tick-box compliance, deploying adaptive, role-based security awareness across 270,000 employees in 120 countries - reducing human risk at enterprise scale.

How to design an evaluation that separates them

Five steps, and they apply to us as much as to them.

  1. Write both product names out in full, always. “HRI” in your notes will mean two different things by week two. Index and intelligence layer are different objects and the ambiguity favors whoever the reader already trusts.
  2. Ask both vendors for the same artifact, not the same story. One module rendered live for two different people. One real alert from your own stack triggering an intervention on a named person. One risk score explained down to its inputs, with the model documentation you would be allowed to review.
  3. Establish which estate you are buying. Ask which components were rebuilt and which are integrated from a previous platform, what the migration path is, what it costs, and whether the feature you were shown is on the new estate. Ask us the equivalent question about our roadmap items.
  4. Apply one evidence standard to both. Cohort, timeframe, baseline definition on every headline figure, and whether third-party validation covers the model or the research behind it.
  5. Price the program, not the platform. Ask both vendors for the all-in cost of everything you would actually run, including simulation, and compare that number rather than the license.

If you run that process and choose them, you will have chosen well and for defensible reasons. We would rather lose that evaluation than win a vaguer one.

Frequently asked questions

Yes, and it is one of the closest comparisons in the category. Both platforms are built for behavior change and risk quantification rather than compliance records.

Category convergence on a natural-sounding phrase. The products behind the abbreviation are different: their Human Risk Index is a scored index, and our Human Risk Intelligence is the layer that produces a score, explains it and recommends what to do next. Write both out in full while you evaluate, because “HRI” in a comparison grid stops meaning anything by week two.

It is a genuine independent assessment and we are not going to argue it away. What it establishes is that they were evaluated well against that report’s criteria on that date. What it does not establish is which platform fits your program, which is what the questions on this page are for. Read the report, then run the evaluation.

No, and anyone telling you that is working from old information. They ship first-party training and simulation, nudges, automated remediation and control actions. Evaluating them as an analytics overlay would be a mistake.

There is no good reason to. Both platforms want the same behavioral signal and splitting it degrades both.

Pricing follows the maturity model, L1 Reactive through L4 Predictive, and depends on seat count, level and term. Phishing simulation is included at L1 rather than sold as an add-on. See Plans, or talk to us for a quote at your seat count.

Run the evaluation

You do not need to take a position on OutThink versus Living Security from a web page. You need a method that separates two platforms making similar claims, and the section above gives you one you can run without us.

If you run the program: ask both vendors for the artifacts in step two, and bring us into that conversation on the same terms as anyone else. If you would rather establish your own baseline first, take the HRM Maturity Assessment.
If you answer to the board: get your IAM and GRC colleagues into the risk-model conversation early. They will either consume the output or ignore it, and that decides whether any of this was worth buying.

Two platforms describing themselves the same way is not a stalemate. It means the description is the wrong instrument.

Footnotes

  1. Outcome figures are each organization’s own results, measured against their own starting point, and are not a benchmark to expect. Starting maturity, sector, workforce profile and program design change the result materially.

Disclaimer

This comparison is an independent analysis by OutThink. Statements about Living Security are drawn from their own public material and published third-party sources, current as of August 2026. Product capabilities change, and you should confirm anything decision-relevant with the vendor directly. Where we could not verify a capability from public sources, we have said so rather than guessed.

OutThink competes with Living Security in human risk management. This is a close comparison and we have a commercial interest in your conclusion, which is why the page gives you an evaluation method you can apply to both of us equally.

This page is informational and is not legal, financial or professional advice.