KnowBe4 is a security awareness and compliance training and simulated social engineering product. It is used by organizations worldwide to strengthen their security culture and reduce human risk. The product includes a comprehensive suite of awareness and compliance training, real-time user coaching, AI-powered simulated social engineering, crowdsourced anti-phishing defense and an AI suite that enhances human risk management through personalized training and automation. With…
$0.95
per month (billed annually) per seat
KnowBe4 PhishER/PhishER Plus
Score 9.0 out of 10
N/A
PhishER is presented as a lightweight Security Orchestration, Automation and Response (SOAR) platform to orchestrate threat response and manage the high volume of potentially malicious email messages reported by users. And, with automatic prioritization of emails, PhishER helps InfoSec and Security Operations team cut through the inbox noise and respond to the most dangerous threats more quickly.
KnowBe4 offered a significantly more favorable cost-benefit ratio compared to other solutions. Its seamless integration with our existing infrastructure—particularly Active Directory and email systems—was the most compatible with our operational and security requirements.
Initially we were using Mimecast Awareness Training. Mimecast was totally different from KnowBe4 Security Awareness Training. They do not have a proper setup for the awareness training. The training video quality and category was very poor. In Mimecast, you will get only human …
KnowBe4 Security Awareness Training has a lot of good features that Mimecast was missing. Mimecast does not have a proper inventory of videos like KnowBe4 Security Awareness Training. Mimecast does not have animation based videos. Most of the users of my company like animated …
The content of KnowBe4 is updated and well-created, the ModStore provides a lot of ideas to address the Awareness activities in your company, and also you can identify the riskiest users based on their behavior
KnowBe4 is world leader in security awareness training and has a good feature set. We selected KnowBe4 because I had earlier experience with them and know they are always willing to help. The implementation was not complicated, also because of the documentation that describes …
We have never used other security awareness training products but we did do an evaluation 4 years ago and found KnowBe4 to be the best from a deployment, quality, and cost perspective. Within just a few weeks we were able to get our entire staff in the system and with the …
KnowBe4 has a library that is very large with many different content types that allows them to have the diversity that they do. Others may brag about their training but it is only made by them or their library is very limited for training. Also, visibility on what you're …
Without Security Awareness Training, our users would not have been as well equipped to identify threats. Also, with the use of PhishER, we are able to examine phishing attempts and reach out to vendors and customers who may have been compromised. I'm not aware of another …
Cleaner Profile, More Modules. proof point also offers continuous training webinars for Admins to understand scenarios of when to set what types of simulated phishing emails. They also highlight the importance of changing campaigns and using vishing and other social engineering …
Mimecast internal email protection feature offer the capability to detect and block any suspicious emails that has been delivered to the users inbox. But they do not have a phish alert button type plug-ins that users can use to report the email. Mimecast solution only act when …
Arctic Wolf also offers a similar product to PhishER using their Phish Tell engine. However, it was severely lacking in terms of workflow automation. Switching to Arctic Wolf's email reporting and response product would have increased the number of manual hours spent on email …
We chose KnowBe4 based on the variety phish testing templates, variety of training, and ease of use for us as administrators. Plus they present things in a way that a non-technical person can understand when they are taking a training module. The integration with PhishER is a …
We view KnowBe4 PhishER as another piece to the security puzzle. It works well alongside the other security applications and services in use at our organization.
KnowBe4 PhishER is our first "go to" when we have a new security need to fill due to its overall effectiveness, ease of use, and cost it has had in our organization.
PhishER in our organisation works as a second line of defense along side VIPRE and Microsoft Exchange Security. We use all 3 systems together to ensure emails are blocked or identified as spam or threats. VIPRE blocks emails before they reach the user, PhishER allows the user …
You pretty much need the KnowBe4 Security Awareness package for PhishER to be useful. Hands down the Security Awareness package and where it has moved up with Training and testing users is fantastic. PhishER is a great additional tool for the Admin to help to manage the …
I don't have any frame of reference for comparison, but the training that I have used has proved impactful for my staff. Since starting KnowBe4 training, we've seen a great increase in the number of phishing attempts, but also a great increase in the number of attempts that have been recognized by staff, and we have thus not been the victim of phishing or other cyberattact vectors
PhishER comes with some good features, such as PhishML, PhishRIP, PhishFlip, etc. These features help us manage phishing email reporting incidents. From reporting emails via Phish Alert Button plug-in to collecting all reported emails in one place at the PhishER dashboard. Now, the PhishML comes into play, scanning all reported emails and tagging each as clean, spam, or threat. With the help of this machine learning-based algorithm, our investigation process becomes easier. Other features, such as PhishRip, help to search and quarantine phishing emails, and PhishFlip converts a real phishing campaign to a test phishing campaign.
The provided templates for phishing simulations are mainly available in English. There are also some templates available in our native language, but their number is small. We have seen other platforms offer way more phishing simulation templates in our language.
Although there is a really huge number of training videos available, some of them are outdated and no longer have much to offer. Some cleaning up could help in this direction.
Although there a some games / puzzle like trainings available, we have seen other platforms offer more and better ones (on the other platforms had they had almost no videos at all...). It would help significantly to also invest in enriching the provided puzzles / games.
We have seen other platforms offer games, where, for example, employees of the company can compete against each other while working together in groups to achieve a common goal (e.g., eliminate a fictional security threat that has "hit" the company. Plan the steps needed to be taken, take the steps one after another and have a chance to see the impact each action has. At the end the team that has suffered the least cost to end the threat is the one that wins. Just an example. The point is to make this challenging, using gamification and to make the employees part of the prevention force of the company against cybersecurity threats.
PhishRIP info tabs (i.e. if improperly check ripped emails are turned into tests. This has caused issues.) Info tabs or markers allow user to hover and get more information about what action a check box or slider provides.
Between the ease of use, cost effectiveness, functionality and continued improvements Knowbe4 continues to make it would be pretty hard to find another competitive product that wraps it all up like KnowBe4 has. Not saying it couldn't happen, but haven't seen anything that competes at this point.
When we first discovered that KnowBe4 released something like this, we saw a demo of it and were floored at what it could do and how it could help us from a security standpoint. Gone are the days of us in IT sending out a mass email saying please don't click on anything in the email from sender "X", and it allows us to quietly and easily ensure that people don't take any action on malicious emails.
KnowBe4 Security Awareness Training is simple to use, simple to administer, effective, with quality content. It is easy to take the training and we have the reminders set so that the longer a user puts the training off, the more frequently they will receive reminder emails. Eventually they get emailed every day until they take the training. But with a simple click, they can get into the training content.
I give it an eight for the feature set. While I only give it an eight because the complexity and interconnectedness of the tools mean that there needs to be quite a bit of RTFM to get the most out of the products.
There have only been a handful of outages in the 2 years we have had the product. Even during those instances, parts of the system were still operational
Pages load quickly, filter/sort quickly, and don't slow down or freeze. Everything is smooth and very easy to use. There are a places in the UI where you can forget how to get there, but other than that everything is great. We have had no issues using any part of the website.
Tech prod support is great! I did have to ask for a new customer success rep, needed a more experienced person to match my 12 years of experience running Cybersec training programs. Would suggest that more matching of rep level of knowledge to client level knowledge would help.
confusing question. I inherited this application so I didnt get any formal training other than the person who was leaving. The CSM provided some later on when I asked in a zoom call
The implementation went really well and KnowBe4 was there the whole time on setup to make sure things were setup correctly. The only thing we had to figure out on our own was to script users automatically being added to security groups. So that when they sync to knowBe4 from AD they are placed into the same/correct groups.
KnowBe4 offered a significantly more favorable cost-benefit ratio compared to other solutions. Its seamless integration with our existing infrastructure—particularly Active Directory and email systems—was the most compatible with our operational and security requirements.
Harmony does not provide security awareness training or simulated phishing emails like KnowB4. However, it does provide a phish alert button & workflow similar to PhishER & we may stop using PhishER because the Phish Alert reports from PhishER don't feed into Harmony to help train it from phishing emails that go through. We got Harmony after KnowB4 because we needed a tool to PREVENT phishing emails from getting to people's inboxes in the first place, which KnowB4 has very little capability for other than PhishER+ blacklists. It is a shame KnowB4 does not have the anti threat phishing prevention like Harmony considering all the email data it has & its existing AI analytic capabilities.
The product scales greatly. As long as you upgrade the license to support the number of users you are needing, adding in those new users is easy. Also getting those users set up with trainings/campaigns is very easy as well
The team was great to work with and took their time to ensure that we knew what we were doing with the product and that it was set up to meet the specific needs of our organization. This wasn't just a cookie-cutter deployment, but rather they focused specifically on our needs.
With the implementation of KnowBe4 Security Awareness Training, we have reduced a lot of issues of social engineering attacks like Phishing attacks, Smishing attacks, Vishing attacks, and a lot more. After implementing the KnowBe4 Security Awareness Training, we have seen a significant decrease in the clicking on a phishing email. Now users are aware of phishing attacks and they know how to react to them.
With KnowBe4 Security Awareness Training, we got another tool Phish Alert Button that we have installed on the user's outlook and after providing training on these topics, now we are receiving a lot of spam report emails are users are protecting them from clicking and just reporting it to the IT team.
With the Phishing test, we are seeing the growth and analyzing how our users will react in the case of a real phishing attack, and with this, we are providing more training to them and going with them as per the test report. This whole process is making our company more stronger against any type pf social engineering attack.
After implementing KnowBe4 Security Awareness Training, we have seen a lot of improvements in the account compromise case in our company because users are not clicking on fake links now.
Phish/ER & PAD: Identifying email threats more quickly allowed us to send alert to the users' community in a timely manner based on the pattern of the threat.
KnowBe4 Training Campaigns have proven to noticeably increase users' awareness.
KnowBe4 Phishing Campaigns made users realize how dangerous and deceiving hacker can be.