Cofense PhishMe is a cyber threat and phishing simulator meant to be of use in training employees to be wary against threats and also to gain information about general employee threat knowledge and preparedness. A free trial is available for small business.
N/A
NINJIO
Score 8.9 out of 10
Small Businesses (1-50 employees)
NINJIO is a Security Awareness Company headquartered in Los Angeles that via its NINJIO AWARE platform aims to educate employees of organizations how to become more secure by using short "micro-learning" animated and engaging security stories that are, according to the vendor, based on or inspired by real companies who have suffered actual significant security breaches.
N/A
Pricing
Cofense PhishMe
NINJIO
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
Cofense PhishMe
NINJIO
Free Trial
Yes
Yes
Free/Freemium Version
No
No
Premium Consulting/Integration Services
Yes
No
Entry-level Setup Fee
No setup fee
No setup fee
Additional Details
—
Priced on per seat basis with components including simulated phishing, compliance tracks (HIPAA, GDPR, PCI, etc.), NINJIO's platform or customers LMS, etc.
Cofense was selected as a vendor before I was in this role. Another vendor was evaluated for additional security awareness training but not to replace the Cofense PhishMe program. We also looked at Ninjio to supplement our phishing education program.
Cofense PhishMe is an excellent solution for scenarios where it will be sold as a managed service. I believe that PhishMe is too expensive for many clients and instead would benefit from the economies of scale where an MSSP sells it as part of a whole service, which offers the analysts and reporting included. PhishMe is excellent for training and awareness of Phishing, but shouldn't replace mandatory training for new joiners or yearly refreshers, it should only be used as an additional training option.
The cyber security training, paired with the phishing simulator will reduce your company's vulnerability, at the same time that it flags the localized issues, so specific groups can be targeted later on. Phishing and scamming have become less of a problem once the users were better educated on how to prevent and identify scams/phishings.
It gives clear-cut segregation of different parts of an email, header, text and HTML body, URL, attachments, HTML preview and some analytical insight like "similar reports." This distinctive approach actually helps reduce data overload during an analysis.
The URLs captured here pass through an automatic reputation check [in our case VirusTotal] and add a tag of the reputation. If it is a well-known bad URL the tag helps us take the decision fast.
For creating automation rules on the reported emails the "Recipes" section is really helpful. We can create easy recipes [or rules ] to handle a huge flow of reports and also we can create more sophisticated rules depending on the Cyber intelligence feed to catch the really bad currently less known attack attempts by malicious emails.
The "Threat Indicators" section is also useful to use as a threat intelligence source to check the URLs for their maliciousness.
Engages - People enjoy the videos, they are fun and interesting and they get people talking.
Customer Service - NINJIOs customer service is some of the most amazing I have ever experienced in any industry.
Simplifies - Information Security and the way breaches happen can be very complicated and technical, NINJIO manages to distill this down to easily understandable situations and ways the issue could have been avoided.
Great Value - NINJIO offers additional peace of mind for your information security at a very reasonable cost.
Its built with UX in mind and is aimed at non-tech people, to ensure that almost everyone can run the campaign. But if we go deeper - sometimes you will need an HTML editor or support in order to figure out some advanced edits you might want to add in your scenarios.
NINJIO has an overall easy platform to use. I'm not a fan that I have to use one hub and the Dojo to access different things. The platform does lack a few things, like timestamps of training completion and a schedule of what videos are going to come. The Dojo platform is good, overall.
I have not had to use their support for pretty much anything. The software works well, and is very intuitive. I would imagine their support would be rather basic as there is not too much that can go wrong with a report phishing button, and if it were I would probably consider a different software.
Great support. Support is always there to help you whenever required. They have the quickest response to your request. They also keep monitoring the campaign launches and will notify you if you have missed any month
Cofense PhishMe was the first choice for us as the user interface as well as their bundle package with Cofense Triage and Vision has helped the organisation to alleviate the overall security awareness posture. The other vendors did not provide a vast range of phishing scenarios as compared to Cofense PhishMe platform.
Pricing is great but, if you automate the connection of new user accounts through systems like MS Azure, keep in mind that you will have to make sure to remove service accounts since they charge by a number of users connected to it. The pricing is really good and they offer a ton of features if you are willing to spend a few extra bucks.
Professional services are good. After the purchase, they helped us quickly to set up the account and implement it in the org to we don't waste any time
Recipes in the system are capable of handling almost 2x what an analyst does, which cuts down the efforts [of] an analyst and provides more time for accurate strategies.
With roughly 90% false positives coming through, the remaining 10% of true positives need as much attention as they can get for the full investigation and analysis.
1,500 or more phishing messages can come through in a given week and the amount of time/employees required to review this without a tool like Cofense is surely beyond [the] expected/anticipated budget.
Employees have recognized dangerous emails as a result of Ninjio cyber training videos.
Employees understand the importance and reason for our cyber security policies and adhere to them.
Employees have learned to question the validity of emails before responding and have forwarded any suspicious emails for review by IT and most generally we correct in doing so.