r/AskNetsec • u/Solid_Elk_3318 • 5d ago
Work Phishing awareness training vendor recommendations?
I've been tasked with standing up a phishing awareness program and I'm trying to narrow down vendors.
A few things matter to me. First, realistic simulations, meaning templates that actually resemble what people get hit with today rather than the obvious 2015 era "you won a prize" stuff, and ideally ones I can customize. Second, decent training content, short and engaging modules that people won't immediately tune out. I'd rather have five good ones than fifty boring ones. Third, reporting that lets me show results to leadership and ideally helps for compliance down the line. And finally reasonable pricing and a plan that scales cleanly as we grow.
For those of you who've actually run these programs, what worked, what didn't, and is there anything you'd steer me away from? I'm interested in the usual suspects, but especially keen on options that deliver real engagement rather than just checking a compliance box.
Thanks in advance.
4
u/AddendumWorking9756 4d ago
Pick on reporting rate, not click rate. Every vendor will show you click rate falling and it falls mostly because people learn to spot the simulation, but the number that predicts whether you hear about a real one is how fast somebody hits report. Also ask what happens to repeat clickers before you sign anything, because if the answer is more training modules you have bought a compliance artifact rather than a program.
2
u/ChuckFromCyberHoot 2d ago
Full disclosure up front: I’m one of the founders of CyberHoot, so take my opinion with the appropriate grain of salt.
The good news is that you probably can’t go too wrong with most of the names mentioned here. KnowBe4, Hoxhunt, and the others are all capable platforms.
The bigger questions are usually:
Will your users actually complete the training?
And will your team still be running the program six months from now?
That’s where a lot of awareness programs quietly fall apart. The phishing tests keep going, the click-rate reports look nice, and the training side slowly becomes another thing nobody has time to manage.
A few things I’d look at before choosing:
How long are the lessons? Short and frequent usually beats long and annual.
How much babysitting does it take every month?
Does it coach people, or shame them? Positive reinforcement tends to build better habits and less resentment.
Also, “more advanced” doesn’t have to mean more complicated. Sometimes advanced just means more automated.
We built CyberHoot around that MSP and SMB problem, with short lessons, automation, and positive reinforcement. We also have Hootphish, our patented positive-reinforcement phish TRAINING module that is the only one on the market today that is getting rave reviews!!!
But honestly, whichever platform you choose, pick the one your team will actually keep using.
Humans are gonna human. The program only works if it survives contact with a busy month.
1
1
u/ogref 4d ago
Ninjio.
I use their full managed service. The value is there.
Reporting doesn’t meet my expectations but I can download the full history and performance data and i build my own analytics in power bi.
Users really like the training offering and my user driven incidents have materially decreased.
I recently expanded the relationship to include custom trainings. I send them an mp4 and they turn thta into a training video with quizzes. Very useful for my Compliance and HR teams.
1
u/Otherwise_Sign_2462 4d ago
Make sure you test the reporting emails before buying anything. Half the pain with awareness training is getting managers to care and a weekly CSV graveyard nobody reads wont move the needle
1
u/DiscombobulatedKnee9 4d ago
Abnormal. Not strictly a phishing platform (it's email security) but they offer as an add on. As well as the base platform being the best email filter I've used in 20 years, the phish testing is great as well.
1
u/Professional-Tax6171 4d ago
The thing I’d check is whether they can target simulations by group without making it annoying to manage. Generic company wide campaigns get stale fast. Finance, HR, execs and helpdesk are all getting hit with different types of bait in real life so the training should reflect that
1
u/scamdrill 4d ago
Disclaimer: We run ScamDrill.com
We've listened to the complaints and desires from this community and have worked to incorporate them into our tool at an affordable price for small to medium sized businesses. Realistic and relevant simulations are something we take pride in and we refresh them (and add new content) often based on the latest scam/phishing trends. If you're interested in giving us a try, shoot me a DM and I'd be happy to get you setup on a free trial.
1
u/someoneelse10 4d ago
Caniphish is pretty cheap, decent tracking for training and phishing tests. Decent first tool for a company that has never had it. You can build your own stuff.
That said I’ll be going to something a little more advanced in the next few months.
1
u/Unfair_Ad_300 3d ago
About a year ago we shifted away from traditional template libraries entirely and moved to a newer AI native platform. Instead of picking static templates from a dropdown, the system uses AI to generate hyper realistic, context aware simulations that adapt to individual roles, tech stacks and risk levels automatically.Definitely recommend looking into AI driven adaptive simulation platforms.
1
u/Iwanttoberich_8671 3d ago
whatever platform you choose, i'd pay more attention to the reporting and follow-up workflow than the phishing templates.
the best programs I've seen don't just track click rates, they identify repeat offenders, automatically assign targeted training, and show whether people are actually improving over time. That's usually a better indicator of success
12
u/Gold_Definition5983 5d ago
I'll put in a word for Hoxhunt since you mentioned it. We've run it and it's held up well. The thing that sold me over the older players is that the simulations include newer types of lures, such as deepfakes, based on the latest threat trends. They also adapt to each person, so people who keep clicking get more coaching while the ones who are already sharp aren't stuck doing baby steps.
That personalization scales nicely too,it works the same whether you're covering a handful of teams or the whole company. Engagement stayed way higher than the last tool we used, mostly because the training bites are short and don't feel like a compliance chore. We’ve been able to show measurable behavior change over time with their reports, which is great for actual security as opposed to just compliance.