Skip to content

Living Security

Living Security is an Austin-based human risk management platform that quantifies individual and organizational human cyber risk and drives targeted training and phishing simulation based on that risk score.

Visit Website ↗ + Add to Compare
62/100Incremental Innovator

Overview

Living Security is an Austin, Texas-based security company built around the idea that security-awareness programs should be driven by measured human risk rather than blanket, once-a-year training. Its Unify platform ingests signals from an organization’s existing security stack — phishing simulation results, endpoint and email security alerts, identity and access data — and turns them into a per-employee human risk score, which is then used to target training, nudges, and interventions at the highest-risk individuals and departments rather than applying the same generic module to everyone.

Founded in 2017, Living Security occupies the “human risk management” category that has emerged as a more data-driven evolution of the older security-awareness-training market (KnowBe4, Proofpoint’s legacy Wombat business). Its pitch to CISOs is a shift from compliance-driven training completion metrics to risk-reduction metrics that can be tied back to actual security incidents and reported to the board.

The company raised a $14 million Series B in 2021 led by Updata Partners, with participation from Silverton Partners, Active Capital, Rain Capital, and SaaS Venture Partners, bringing total disclosed funding to roughly $23 million. Its publicly named customer list includes large enterprises such as CVS Health, MassMutual, JPMorgan, Target, Verizon, Mastercard, and Biogen, which is a meaningful independent signal given these are named, verifiable logos rather than anonymized case studies.

Living Security competes against both legacy training vendors retrofitting risk scoring onto their platforms and a newer wave of human-risk-management startups (e.g., CultureAI, Hoxhunt); its differentiation is depth of integration with existing security tooling to compute risk scores from real telemetry rather than survey or training-completion data alone.

Innovation Matrix Assessment

Innovation Velocity 6/10

Living Security has continued shipping AI-powered risk-scoring and recommendation features into 2024-2025 per its own press releases, but the company does not publish independent third-party validation of model accuracy or a public research/CVE track record.

Operational Value 6/10

Named enterprise customers (CVS Health, MassMutual, JPMorgan, Target, Verizon, Mastercard, Biogen) spanning healthcare, finance, and retail indicate the platform operates reliably at large-enterprise scale across varied security stacks.

Market Momentum 6/10

The company's most recent disclosed raise was a $14M Series B in 2021 (total ~$23M raised); a 2024 press release described a further $14M raise for its human-risk platform, though the funding cadence overall is modest compared to better-capitalized security-awareness peers.

Category Disruption 6/10

Computing a per-employee human risk score from real security-stack telemetry (phishing sim results, endpoint/email alerts, identity signals) rather than training-completion percentages is a genuine shift from the legacy awareness-training model, though several competitors (Hoxhunt, CultureAI) have converged on similar approaches.

Real-World Efficacy 6/10

The named, verifiable Fortune-500-caliber customer list is a strong independent adoption signal, but Living Security has not published a peer-reviewed or third-party study quantifying actual incident or click-rate reduction that CDMG could independently confirm.

Enduring Relevance 7/10

Human error remains a leading factor in breaches, and boards increasingly want risk-reduction metrics rather than training-completion percentages, making a data-driven human risk platform directly relevant to CISO reporting needs.

Why CISOs Should Care

CISOs get a way to show the board a quantified, trending human-risk metric tied to real telemetry instead of a training-completion percentage that says little about actual exposure.

What Makes It Different

Living Security computes its risk score from integrations with the existing security stack (phishing, endpoint, email, identity signals) rather than relying primarily on training completion or self-reported survey data.

The Matrix Verdict

62/100 — INCREMENTAL INNOVATOR

A credible, well-adopted human risk management platform with genuine large-enterprise traction; its evidence base is strong on customer names but light on independently verified efficacy data, which is typical for the category.

Editorial Note: Claims vs. Verified Findings

The specific named customer list (CVS Health, MassMutual, JPMorgan, Target, Verizon, Mastercard, Biogen) is independently corroborated by multiple press sources (TechCrunch, SecurityWeek, Built In) rather than only vendor marketing. Platform effectiveness claims (risk reduction, engagement improvements) are vendor-sourced and have not been independently verified by CDMG.

Sources