Last year we published one uncomfortable statistic: 10% of users drive roughly three-quarters of risky behavior. Security leaders came back with the same question: is it the same 10%? This year we can answer it. We followed the same workforce across two full years, spanning 100+ organizations, nearly 4M verified identities and over 200M risk-signal detections, and watched human risk move.
Complete the form for instant access to all 22 pages. No wait, no follow-up call required.
Living Security is committed to protecting and respecting your privacy, and we'll only use your personal information to administer your account and to provide the products and services you requested. From time to time we would like to contact you about our products and services, as well as other content that may be of interest to you.
You may unsubscribe at any time. For more information, review our Privacy Policy. By submitting this form, you consent to allow Living Security to store and process the personal information submitted above to provide you the content requested.
of risky behavior still traces to the riskiest 10% of the workforce, a second year unchanged.
less time spent in a risky state after an action plan, and it holds for 12 months.
of this year's riskiest 10% are new faces who weren't on last year's list.
Last year we published one uncomfortable statistic. Leaders everywhere came back with the same follow-up: is it the same 10%? This report answers it, by following the same workforce through two full years.
The riskiest 10% isn't a fixed cast of characters. It's a role different people rotate through as jobs, access, threats and habits change. That is exactly why point-in-time programs chase where the target was.
Nearly half of the workforce who were net-risky last year were net-vigilant a year later, and intervention accelerates the exit.
As jobs and access change, vigilant people move the other way. In absolute numbers, the inflow nearly matched the outflow.
Almost all data-loss and endpoint risk traces to a small, identifiable slice of people. The problem has an address.
CISOs and security awareness leaders use this data to defend a program budget, set a realistic baseline, and decide where intervention actually pays back. Every figure comes with its method, sample and window.
Continuous programs track where it is. Get the data behind the shift.
Get the report