Last year we published one uncomfortable statistic: 10% of users drive roughly three-quarters of risky behavior. Security leaders came back with the same question: is it the same 10%?
This year we can answer it. We followed the same workforce across two full years, spanning 100+ organizations, 4.9M verified identities and over 55M risk-signal detections, and watched human risk move.
Complete the form for instant access to all 22 pages. No wait, no follow-up call required.
Living Security is committed to protecting and respecting your privacy, and we'll only use your personal information to administer your account and to provide the products and services you requested. From time to time we would like to contact you about our products and services, as well as other content that may be of interest to you.
You may unsubscribe at any time. For more information, review our Privacy Policy. By submitting this form, you consent to allow Living Security to store and process the personal information submitted above to provide you the content requested.
of risky behavior still traces to the riskiest 10% of the workforce, a second year unchanged.
less time in a risky state after completing action plans, up from 60% last year.
of this year's riskiest 10% are new faces who weren't on last year's list.
Last year we published one uncomfortable statistic. Leaders everywhere came back with the same follow-up: is it the same 10%? This report answers it, by following the same workforce through two full years.
The riskiest 10% isn't a fixed cast of characters. It's a role different people rotate through as jobs, access, threats and habits change. That is exactly why point-in-time programs chase where the target was.
Among employees tracked across both years, 46% of those who were risky in 2024 became net-vigilant a year later.
Real phishing attempts per employee roughly doubled from 2024 to today: a genuine rise in volume. Targeted employees now face about 14 attempts a year, up from 8.
Almost all data-loss and endpoint risk traces to a small, identifiable slice of people. The problem has an address.
CISOs and security awareness leaders use this data to defend a program budget, set a realistic baseline, and decide where intervention actually pays back. Every figure comes with its method, sample and window.
Continuous programs track where it is. Get the data behind the shift.
Get the report