Skip to main content
TrustRadius
Cofense PhishMe

Cofense PhishMe

Overview

What is Cofense PhishMe?

Cofense PhishMe is a cyber threat and phishing simulator meant to be of use in training employees to be wary against threats and also to gain information about general employee threat knowledge and preparedness. A free trial is available for…

Read more
Recent Reviews

TrustRadius Insights

Cofense PhishMe is a versatile platform that addresses the growing concern of email-based attacks and helps organizations improve their …
Continue reading
Read all reviews

Awards

Products that are considered exceptional by their customers based on a variety of criteria win TrustRadius awards. Learn more about the types of TrustRadius awards to make the best purchase decision. More about TrustRadius Awards

Return to navigation

Pricing

View all pricing
N/A
Unavailable

What is Cofense PhishMe?

Cofense PhishMe is a cyber threat and phishing simulator meant to be of use in training employees to be wary against threats and also to gain information about general employee threat knowledge and preparedness. A free trial is available for small business.

Entry-level set up fee?

  • No setup fee
For the latest information on pricing, visithttps://cofense.com/pricing

Offerings

  • Free Trial
  • Free/Freemium Version
  • Premium Consulting/Integration Services

Would you like us to let the vendor know that you want pricing?

34 people also want pricing

Alternatives Pricing

What is KnowBe4 Security Awareness Training?

KnowBe4 is a security awareness training and simulated phishing platform used by more than 65,000 organizations around the globe. Founded by IT and data security specialist, Stu Sjouwerman, KnowBe4 helps organizations address the human element of security by raising awareness about ransomware, CEO…

What is CyberHoot?

CyberHoot is presented as a simple, fast and effective employee Security Training Platform from the company of the same name headquartered in Portsmouth. The platform includes 700+ Training Videos, 25+ Policy Templates, and Phish Testing.

Return to navigation

Product Details

What is Cofense PhishMe?

Cofense PhishMe™ is the flagship behavior conditioning, phishing awareness platform from Cofense™ which the vendor states is trusted by over 2500 enterprise customers across all verticals. Using simulated phishing emails, Cofense PhishMe conditions users to identify and report email-based threats that bypass secure email gateways and land in user inboxes. Cofense PhishMe uses experiential learning at the point of failure to reinforce positive security awareness behavior.

A phishing simulation program must reflect the real threat landscape. Cofense boasts a unique perspective on the threat landscape, with insights into threat actors & campaigns in the wild, together with unrivalled visibility of phishing threats that bypass existing security controls to reach the recipient inbox. Leveraging this perspective, Cofense PhishMe operationalizes real, active threats into realistic phishing scenarios to ensure program relevance. The vendor describes Cofense PhishMe as using intelligent automation, advanced algorithms, and embedded best practices to increase user engagement and reduce program planning, management, and execution overhead. Cofense PhishMe’s education library includes content created by its content team, as well as from 3rd party content vendors.

Cofense PhishMe has been rated as a leader in the Gartner Magic Quadrant for Security Awareness CBT Solutions and a Gartner peer insights Customer’ Choice security awareness vendor 2 years in a row.

Cofense PhishMe Features

  • Supported: Real Threat & Secure Email Gateway Miss Templates – increase relevance of programs by simulating real threats observed to bypass common Secure Email Gateways
  • Supported: Responsive Delivery – increase program engagement and eliminate global scheduling challenges by delivering simulation emails only when users are active in their mailbox
  • Supported: Smart Suggest – advanced algorithms and embedded best practice provide program guidance based on industry relevance and program history.
  • Supported: Recipient Sync - automates syncing of recipients from Azure Active Directory to PhishMe. Utilize Recipient Sync and Dynamic Groups for fully automated group management.
  • Supported: Automated Playbooks – automate execution of a 12-month simulation program with just a few clicks.
  • Supported: Comprehensive education catalog including content from leading third-party providers including NINJIO and AwareGo.
  • Supported: Board Reports – executive level insight into program performance and changes in resiliency to phishing.

Cofense PhishMe Screenshots

Screenshot of Image 1 – Board of Directors (BOD) report showcasing results of your phishing defense programScreenshot of Image 2 – Create New Scenario PageScreenshot of Image 3 – Intelligent Program Automation using PlaybooksScreenshot of Image 4 – Organizational Suspicious Email Reporting StatisticsScreenshot of Image 5 – Phishing Scam Announcement Templates

Cofense PhishMe Video

Cofense PhishMe Responsive Delivery – increase program engagement, reduce whitelisting and eliminate global scheduling challenges by delivering simulation emails only when users are active in their inbox.

Cofense PhishMe Competitors

Cofense PhishMe Technical Details

Deployment TypesSoftware as a Service (SaaS), Cloud, or Web-Based
Operating SystemsUnspecified
Mobile ApplicationNo
Supported CountriesGlobal
Supported LanguagesEnglish - American, English – British, English – Australian, Afrikaans, Arabic, Chinese – Simplified, Chinese – Traditional, Czech, Danish, Dutch, Finnish, French, French – Canadian, German, Greek, Indonesian, Italian, Japanese, Korean, Norwegian, Polish, Portuguese, Brazilian Portuguese, Romanian, Russian, Serbian, Slovak, Spanish, Spanish – Latin American, Swedish, and Turkish

Frequently Asked Questions

Cofense PhishMe is a cyber threat and phishing simulator meant to be of use in training employees to be wary against threats and also to gain information about general employee threat knowledge and preparedness. A free trial is available for small business.

KnowBe4 Security Awareness Training are common alternatives for Cofense PhishMe.

Reviewers rate Role-based user permissions highest, with a score of 8.1.

The most common users of Cofense PhishMe are from Enterprises (1,001+ employees).

Cofense PhishMe Customer Size Distribution

Consumers0%
Small Businesses (1-50 employees)4%
Mid-Size Companies (51-500 employees)35%
Enterprises (more than 500 employees)61%
Return to navigation

Comparisons

View all alternatives
Return to navigation

Reviews and Ratings

(49)

Community Insights

TrustRadius Insights are summaries of user sentiment data from TrustRadius reviews and, when necessary, 3rd-party data sources. Have feedback on this content? Let us know!

Cofense PhishMe is a versatile platform that addresses the growing concern of email-based attacks and helps organizations improve their cybersecurity. Users report suspicious emails directly from their email client using the Cofense PhishMe plugin, streamlining the process of identifying potential threats. The information security team then triages and analyzes the reported emails, leveraging the different fields provided by Cofense PhishMe to efficiently categorize and prioritize them for further investigation.

One key use case of Cofense PhishMe is its ability to simulate phishing scenarios, providing valuable insights into users' susceptibility to such attacks. This helps organizations better understand their employees' level of awareness and readiness in recognizing and reporting phishing scams or malicious emails. The platform offers a user-friendly interface that does not require extensive training, making it accessible to users across the organization.

Additionally, Cofense PhishMe helps track phishing attempts and enables users to easily report suspicious emails for further action. By automating the categorization of reported emails, the platform saves time and streamlines the analysis process. It also provides statistics that inform clients about the success of their user training efforts, empowering organizations to continually improve mail security awareness.

Furthermore, Cofense PhishMe plays a vital role in increasing users' recognition of legitimate versus fake or malicious emails. Through experiential learning and continuous training, it educates employees on how to detect phishing emails and utilize built-in reporter tools for effective triage. The platform is part of a comprehensive security awareness program that helps organizations demonstrate their commitment to protecting sensitive information and complying with regulatory requirements.

Overall, Cofense PhishMe is widely used by organizations seeking to enhance their email security defenses by empowering employees to proactively identify and report potential phishing threats. It provides automation, valuable insights, and user-friendly features that contribute to creating a more resilient cybersecurity posture.

User-Friendly Interface: Many users have praised the product for its friendly and intuitive user interface, making it easy to navigate and organize campaigns. It has been described as intuitive and has saved users time by allowing them to report phishing attempts with just a click of a button.

Customizability: The ability to customize the product has been highly valued by users. They appreciate the flexibility in creating automation rules and recipes to handle a large flow of reports. Users also mentioned that the product offers detailed whitelisting instructions and a wide variety of customizable templates.

Excellent Customer Support: Users have consistently praised the customer support provided by the company. They found the support to be great, with an outstanding account manager. Assigned professionals advising and suggesting the best approach for their user base was also appreciated. The availability of multilingual support was mentioned as a positive aspect for global companies.

Laggy Performance: Some users have reported experiencing significant laggy performance with the web version support, resulting in frustratingly slow upload and download rates for results and recipient lists. This issue has hindered their workflow efficiency and affected their overall experience with the software.

Limited Account Management: Users have expressed frustration with the limited capabilities of account management within the software. They feel that it could be improved by offering more automated features, such as user cleanup for inactive accounts. The current manual process is time-consuming and inconvenient for administrators.

Lack of Training Resources: Many users have voiced concerns about the lack of innovative training resources available in the software. They would like to see more options for customization, allowing them to tailor training materials to their specific needs. Additionally, users suggest that Cofense PhishMe should provide templates based on current trends in phishing attacks to enhance the effectiveness of their training programs and keep up with evolving threats in cybersecurity.

Attribute Ratings

Reviews

(1-25 of 28)
Companies can't remove reviews or game the system. Here's why
Score 9 out of 10
Vetted Review
Verified User
Incentivized
Cofense PhishMe is an excellent solution for scenarios where it will be sold as a managed service. I believe that PhishMe is too expensive for many clients and instead would benefit from the economies of scale where an MSSP sells it as part of a whole service, which offers the analysts and reporting included. PhishMe is excellent for training and awareness of Phishing, but shouldn't replace mandatory training for new joiners or yearly refreshers, it should only be used as an additional training option.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
The Cofense PhishMe is well suited in all the scenarios for reporting from the end-user side. It is much easier to report to INFOSEC from the end user. In a small environment or that doesn't have owned domain, in this case, it is less appropriate to use the PhishMe. Otherwise, all the places the Cofense will support.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
Attackers targeting organizations require users to reach out or speak up. When a user is able to easily report via [Cofense] PhishMe, an analyst has all the information they need from the submission to take action in their organization in seconds. Phishing scenario targeting HVTs easily is visible in the tool, mitigating future emails are easily done by correlating information collected. Also, when attachments such as dropper malware are included, it is easily identifiable by the information parsed, and the attachments are available for sandbox detonation or static/dynamic analysis. Original content is preserved and cuts down on time to take action on submitted phishing attacks.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
It's a very apt tool for the scenario where there are multiple users and verticals in an organisation. Phishing Campaigns and recording their response actions is quite easier through this tool. Not suitable for a small organization (less than 500) that can maybe use some open tools or self-made emails for campaigns.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
[Cofense] PhishMe is well suited for [medium] to large organizations with [a] dedicated analyst that [is] continually working the findings, building new phishing campaigns and removing malicious emails from the end users mailboxes.
It is less appropriate for SMB's that have limited resources to manage the day to day usage of the product.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
It's well suited for any type of organization. They have content from different languages and different categories. So if you need your company to send targeted phishing scenarios to Spanish users, then they have templates in that language too. Also, we can use templates to target different departments. We are using different templates to target new hires, oversee people, and so on.
Alexander Bagrov | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User
Incentivized
I am one of the Phishing Simulation ambassadors and I am eager to talk to those who listen. This tool is great at educating people and changing their behavior - although, in some parts, it still uses terminology that incites some senior leaders to use punitive methods (like repeat clickers, etc).
August 15, 2021

PhishMe for Analyst

Score 10 out of 10
Vetted Review
Verified User
Incentivized
Well Suited:
  • Large to small-scale organizations with a dedicated information security team.
  • The admin team will get acquainted with the organization's email trends, user behaviors, false Positive scenarios, and real attack concerns.

Less Appropriate:
  • Service provider companies handling multiple clients.
  • There is no approach for client segregation in PhishMe so this may create some kind of confusion when triaging multiple different organizational client's reported emails on a single pane.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
  • Provides a easy to use platform for running campaigns to employees
  • Includes ability to deploy Reporter - Outlook plugin for employees to report suspicious emails for validation
  • In depth reporting and ability to track all aspects of campaign and answers
  • Provides LMS content and CBT Modules
Great to supplement other trainings or LMS. But in my opinion cannot stand on its own.

Score 8 out of 10
Vetted Review
Verified User
Incentivized
In conducting simulation-related activities, Cofense performs a very good job. Their support system to run the activity from planning to translating the content to local languages and the actual execution was quite good. These simulation exercises have been helpful in raising and maintaining awareness against phishing across our staff. The results also provide us with an insight into the "risky" behavior of certain staff who could be guided accordingly.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
  • Well suited: Seamless integration into our in-house training platform
  • Well suited: Templates for phishing simulations - in particular by geographic region
  • Less appropriate: specific training for software developers/programmers
Score 10 out of 10
Vetted Review
Verified User
Incentivized
Cofense PhishMe is well suited for any environment. Works well on a large scale as we send simulations to over 50,000 users each month. Also, on a smaller scale we send phishing simulations to targeted groups or to our users who click and fail tests often. Also extensive metrics available.
Score 5 out of 10
Vetted Review
Verified User
Incentivized
We are using [Cofense] PhishMe as we have several other Cofense products in our environment, so it's simpler to manage one vendor.
PhishMe would be great for smaller organizations with simpler system architecture and rules.

We're currently working with PhishMe to develop better user pathways and a smoother user experience, particularly in relation to automating user feedback and enhancing the education streams.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
We find that doing our phishing emails a couple of times a year works best and makes sure our users don't get too used to the campaigns. In the past, we used computer based training materials that came for free with our subscription. This was a nice add on and worked well with our LMS systems built on top of SharePoint.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
It works well for any company that wants to be able to measure and subsequently reduce phishing susceptibility rates. It's more suitable at places where users have a ton of free reign, like college professors, medical doctors, or high paid consultants. In locked down places with very little user autonomy, such as a bank, it might not be as helpful.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
Cofense PhishMe sure is a good solution for a global company. For a smaller locally-operated company, you may do well with an internal solution to send simulated emails and collect user feedback, but you'll have to operate it, maintain it, come up with email designs, etc. Cofense already has plenty of emails available and in multiple languages what saves a lot of time. You can also use their benchmarks to compare to their customer base or your industry as well as information (knowledge and experience) they have from other customers.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
In our case, the major selling point and the previous gap we had with another competing product was how phishing email was being delivered to end-users. Previous to Cofense PhishMe, when a scenario would begin, there would be thousands of emails sent in a very short period of time that would put our IT support staff into DEFCON 1 with red lights flashing and alarm bells ringing. The email chains would soon follow and the results of the campaign would be unreliable. Cofense PhishMe has a feature called "Responsive Delivery" that gives us the ability to deliver emails in a more natural way as users log in and interact with their inboxes; emails are queued until the user is active and online, then the phish is delivered. This feature allows for a more organic delivery of email to the population.

We have yet to find a scenario where Cofense PhishMe is less appropriate since we only have our previous solution to compare it to.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
Cofense PhishMe is aimed for businesses where you want to ensure your users know about phishing and have metrics and training to back that up. Environments with strong email rules preventing external email or where the Cofense admin does not have email control will be an issue with keywords or whitelisting.
January 29, 2020

Cofense PhishMe Review

Score 8 out of 10
Vetted Review
Verified User
Incentivized
PhishMe is great at generating some relevant phishing scenarios. Every scenario comes with an educational piece if the user falls victim. This can be completely customized to suit your needs.
Return to navigation