On-demand session · 17 minutes Recorded live at HRMCon 2026

Introducing the next generation of Human Risk Management for incident reduction

A first look at new platform capabilities for identifying, prioritizing and reducing workforce risk across modern attack surfaces.

Kelly walks through what’s new in the Living Security Platform — and how it turns behavioral signals into incident reduction, not just reporting.

Kelly Harward speaking at HRMCon 2026
Kelly HarwardLiving Security
Full session · 17 min
Why watch

Your workforce now includes AI agents. Your risk platform has to see both.

People and AI agents share identities, permissions and data. Risk that used to live in one place now moves across both.

Kelly walks through what’s new in the Living Security Platform — and how it turns behavioral signals into incident reduction, not just reporting.

What you'll learn

In 17 minutes, you'll walk away knowing:

The capabilities unveiled at HRMCon, and the problems each one is built to solve.

Where the signals come from, and how they’re correlated into one view of workforce risk.

Focusing effort on the small share of the workforce driving most of the risk.

Measuring outcomes instead of training completion.

Speakers

The team building what comes next

Kelly Harward

Kelly Harward

Living Security Follow on LinkedIn
Transcript

Read the full session

Auto-generated from the live recording. Click a timestamp to jump to that moment in the video.

Show transcriptHide transcript

0:07 So, Ashley just told us that the workforce changed, and she set the standard for the rest of today. Not trust us, not take our word for it. But to promise an outcome. Then, prove that you delivered it. That's the whole job of this next 20 minutes. So, we're not gonna give you a philosophy, we're gonna give you 3 proofs. AI is a threat. AI is also your new workforce. Knowing the difference is critical. Kelly's gonna show you the proof. So you all know this. We've spent years teaching people the same basic things. Make sure you know the person who sent the message. Check the link. If something feels off, call them. And that was really good advice. The problem is, AI is now really good at removing the stuff that used to feel off.

1:06 As Ashley mentioned earlier this morning, the grammar's now perfect. The message content seems to know legitimate things about you. It can sound like someone you know, and it can even look like them. And it shows up in the channel where you're already used to communicating with that person. So the old instinct Just doesn't cut it anymore. Trust but verify alone is no longer enough. And asking our entire workforce to become experts in all the nuances that can differentiate a legitimate business request from a carefully constructed AI-enabled attack It's just not realistic. With all the talk about the human being the last line of defense, we simply can't put all that on the employee alone. Nobody's gonna know every possible tell. And when people aren't sure, they need somewhere to go for help. A trusted expert, an advisor who can provide the needed guidance and expertise in the moment of uncertainty.

2:08 And that's why we're building Ask Libby. So you get an email from the CFO about a, you know. But something's off, you can't tell exactly what, so rather than guess, Ask Libby And she shows her work, right there, 3 reasons, right in the thread. So now, you can report it, or check back with the sender. Good stuff. Real-time guidance and coaching absolutely helps when the message is real, but we can't sit around waiting for the real attack to be the training. We have to test that same decision ahead of time in the channels where it's actually going to show up. So yes, we're building AI-generate… an AI-generated phishing simulation natively into the living security platform.

3:09 Multi-channel phishing isn't new. Plenty of people are doing that. What's different with running phishing out of your HRM platform is how you decide who gets targeted and with what. A risk-driven approach demands that we don't start with an empty campaign and find out afterwards who was risky. The Living Security platform already knows that and can answer that question for you. Who's being targeted by real attacks? What assets those users have access to, how they've behaved in the past. All of that goes into shaping the test before it ever goes out. With that risk-driven approach in mind, we're launching support for phishing simulations via email and Teams now. SMS, voice, and video follow shortly as part of our near-term roadmap. What you're about to watch is the whole playbook in action.

4:06 So we start out with… Who do you decide to test? I'll give you a hint, it's not last year's training completion. We start with a real incident. We pull the life signal from multiple channels. That gives us 34 people in fin… finance, who's gonna… Improve wires, in this case, starting with a text message. Leading to a meeting with a deepfake avatar, where then it starts to get really interesting. Then, a simulated phone call to maintain urgency.

5:20 And finally, the email that ties it all together. And, of course, Jordan clicks. 34 targeted, 6 clicked, 9 reported. And what happens next? Depends on which of those you are. Everybody who clicked gets training. The whole team gets a nudge, giving them a heads up. For those 6 who clicked, access tightens on its own. Step up off before they can authorize the next payment. So, obviously, the CAIC isn't just the thing that you report on. It's just one data point in a broader story that you need to be able to articulate, as well as be able to act on.

6:24 The employee's score moves, and what you do about it moves along with it. Sometimes that's coaching, sometimes it's tightening up their auth, and changing what they can get access to at all. And that's the point for the people in the room, and those listening on livestream today. Who own this decision. You're finally testing your workforce's susceptibility to attacks based on the way they are actually going to arrive to your end users. And every result is a potential learning moment, and which makes your workforce smarter for the next one. But AI didn't only upgrade the attacker, Kelly, it joined your workforce. Human risk management was built on an assumption. The identity taking the action is a person. That assumption, as we know, no longer holds. AI agents have credentials. They have permissions. They touch data. They take action.

7:21 Those tasks can change, their access can change, and their behavior can change. If it can create an incident, we have to be able to measure it, Kelly. That's right, Mike. An agent is an identity, full stop. It's got credentials, it does things we can't fully predict, and it can move risk every bit as fast and as much as a person can. That's the environment we're in today. Managing human risk and governing identity have stopped being two different jobs. It's one workforce, and you can't govern the part of it you can't see. We're going to take a quick look at the AI governance capabilities that we're building into the Living Security platform. This is real-world data, an organization of 18,000 people, and this is the agent side of their workforce.

8:23 So we're starting out with an NHI dashboard that reveals 600 related identities. 31 are AI you'd recognize. But the rest? Nobody can tell you what they are. Including 9 AI tools that your own people bike-coded. Beautiful. One vendor shows up registered 6 different times. And a lot of this has no discernible owner. Let's double-click and open up one. What it reaches, what it does, who it talks to. So the question is, is it… what can it reach? How risky? So we score it. Fame index as your people. And you can actually defend this one, because it's built from how things… the things actually run. People have behavior patterns. Agents have execution patterns.

9:19 It's job changed, it's permissioned through, you're seeing where it's headed, not just where it is. And all of it comes back to one person. Who built it? Who owns it? Who picked up the phone when the risk changes? So you go ahead, and you assign an owner. You go and review the asset. Very good.

10:15 That's what we're announcing today. Your people and the AI they're using and building, approved or not, in one risk picture. Tied back to the humans behind it. And yes, there's a score. But honestly, the number isn't the only interesting part. Yes, it's knowing the number, but it's also about what you can do with it then. So what can you do with it? Well, two things. First, shadow AI. Every tool and agent in use, whether you approved it or not, including the stuff your own people built. And never mentioned to you. Second, risky usage. Who's putting sensitive data into which model? Your riskiest people and your riskiest tools, side by side, tied back to a name. So, Kelly just showed you a workforce that we can finally see, right? But a score is not an outcome.

11:15 Moving the score to a less risky state is actually the outcome that we desire. We don't prove that with activity alone. We prove it by showing risk actually moved for one person, for a team, or for an entire organization.

12:56 So, the numbers really speak for themselves. Those are actual outcomes that our customers are actually getting from our product today. That report that was referenced is actually available now. I think we had a press release that went out this morning, and I encourage everyone to read it. This is the follow-up to last year's SciANTRA report. Amazing data here. But I… As you saw from that, one person can make a better decision, and a team can close an entire attack path. Entire cohorts spent 52, 77, even 90% less time in a risky state. And those are defensible outcomes. But here's what you didn't see. Who was doing this work? Last year, on this stage, Kelly and I announced Livy, and we're showing you the results of Livy's work. Livy runs continuously, in the background of your program. trained on your policies, your risk data, and adapts to the threat landscape targeting your organization. She watches the signals.

13:59 She sees when risk changes. She identifies who needs intervention, and what is the action that is most likely to work for that given person or cohort with their risk. So, you keep the judgment, human in the loop, Livy takes the execution. That's autonomous AI with human oversight. This is not a chatbot that I'm describing to you right now.

14:56 And this is not a staged product story that we have just described to you. In the moving target, this is the research report that was launched today, we measured hundreds of anonymized action plans across thousands of anonymized users. After an action plan, they spent 68% less time in a risky state that triggered it. The improvement held. We opened with one standard, right? Promise an outcome, then prove you deliver it. The risk moved. Livy moved with it, and it's provable. And that outcome starts before the incident ever happens. When a real request creates doubt, employees can now ask Libby. And before the real attack arrives, you can test that decision across email, Teams, with SMS, voice, and video on the way. Help in the moment, preparation for the moment.

15:53 It continues across every identity that can create the incident. Your people, your agents, your workforce, one continuous view of risk. And Livy? Well, she connects it all. She helps your people make the right decisions. She makes every simulation smarter. She watches risk across both humans and agents. And when risk changes, she brings you the action. Asks for your approval, and then does the work. The people, the agents besides them, the risk moving between them, risk doesn't stand still, and neither should your defense. This is human risk management built for what's next. Thank you.

Watched the session. Ready to run the program?

Thirty minutes with a Human Risk Management specialist. Bring your stack and one incident you want to stop repeating — we’ll show you where the risk concentrates and what to do first.