TrustRadius: an HG Insights company

KnowBe4 Security Awareness Training

Score9 out of 10

1,154 Reviews and Ratings

What is KnowBe4 Security Awareness Training?

KnowBe4 is a security awareness and compliance training and simulated social engineering product. It is used by organizations worldwide to strengthen their security culture and reduce risk.

The product includes a comprehensive suite of awareness and compliance training, real-time user coaching, AI-powered simulated social engineering, crowdsourced anti-phishing defense and an AI suite that enhances risk management through personalized training and automation. With content in 35+ languages, KnowBe4 provides an always-fresh library of engaging content to strengthen an organization's security culture.

KnowBe4 provides:
  • Baseline testing to assess the Phish-Proneā„¢ Percentage of users through a free simulated phishing attack
  • Fully automated simulated phishing attacks, using thousands of customizable templates with unlimited usage
  • AI-Driven phishing and training recommendations based on users' phishing and training history
  • Enterprise strength reporting, showings stats and graphs for both training and phishing, ready for management
  • Artificial Intelligence Defense Agents (AIDA), AI-powered agents that reduce admin burden by automating template generation, training and reporting

Categories & Use Cases

Media

The Phishing Dashboard. This displays how end users are doing at-a-glance and in comparison to peers across industries with Industry Benchmarking.
The Virtual Risk Officer functionality, which helps identify risk to support data-driven decisions about a security awareness plan.
KnowBe4's partners, including The Security Awareness Company, Popcorn Training, exploqii, Twist & Shout, El Pescador, CLTRe, Saya University, and MediaPRO. Together, they create security awareness training content available in the ModStore.
A security training quiz question showing "Security Moments Series: Spot the Bad Link" asking what Lisa should do when receiving an unexpected email with an HTML attachment, with three answer options and Submit/Cancel buttons.
The AIDA Phishing Template Generator interface, which displays a customizable phishing simulation tool with template setup options on the left and a preview of a generated "Annual Bonus Announcement" email featuring a QR code attack vector on the right.
The AIDA Configure Training interface, which displays settings for personalized remedial phishing training, including user enrollment options, completion timeframes, knowledge refresher schedules, and notification preferences, with an "Activate Remedial Training" button to implement the configuration.

1 / 6

Top Performing Features

  • Phishing Simulations

    Administrators can run simulated phishing attacks to test the effectiveness of the training and assess vulnerabilities.

    Category average: 8.9

  • Single sign-on capability

    The software system supports a centralized authentication mechanism allowing the user to access multiple systems with a single, centrally managed password.

    Category average: 9.2

  • Role-based user permissions

    Permissions to perform actions or access or modify data are assigned to roles, which are then assigned to users, reducing complexity of administration.

    Category average: 8.7

Areas for Improvement

  • Integration with Security Tech Stack

    The product integrates with other security tools, such as a SIEM or SOAR platform, and may provide alerts for potential breaches.

    Category average: 8.4

  • Training Gamification

    Training content is available in a gamified format.

    Category average: 7.8

  • Industry-Specific Security Training

    Security training can be tailored based on industry-specific requirements, such as HIPAA, PCI DSS, GDPR, etc.

    Category average: 7.5

Phishing Awareness Software

Use Cases and Deployment Scope

We use KnowBe4 to educate, test, and retrain our staff to go from liability in network security to become a "human firewall". Quarterly testing is completed with phishing campaigns. Users that fall for the emails are assigned short educational videos to help increase their phishing awareness.

Pros

  • Generates phishing campaigns that rank from the obvious to highly sophisticated
  • Provides timely and relevant training to users
  • The dashboard provides a quantifiable risk assessment of our organization. Something that can be difficult to gather with no program in place.

Cons

  • The one thing I would say is that users that are assigned training will forget their passwords and that becomes a bit of a hassle after a campaign
  • The ironic thing is that training emails after a user clicks on a campaign email is often flagged as phishing.

Return on Investment

  • We have created a phishing awareness culture in our organization where staff take pride in making sure potential phish schemes are flagged for review.
  • There are numerous instances where active phishing attempts to gain access to data or to steal funds are flagged and stopped before any real damage to our institution occurs.

Usability

Other Software Used

Adobe Acrobat, Alma SIS, Lightspeed Filter

Industry leading Cyber-Security and Phishing Awareness training content

Use Cases and Deployment Scope

Technology service providers are often faced with the challenege of protecting their own systems and having their own tech staff upskilled on cyber resilience and tech staff awareness uplifted every now and then. KnowBe4 tools help assist in providing ready made material that can be used to support elevate these operational and tactical gaps in awareness training.

Pros

  • Cyber-Security awareness kit: The cyber-security monthly awareness resource kit and strategy guide- Formalized content for weekly deepdive
  • Ransomware hostage rescue manual - Prepare and recover from a ransomware attack-STep by step checklist provided for mitigating ransomware attacks in a methodical manner
  • Cyber-Security awareness wekkly scanner - Weekly planning activities-Planning schedule includes material such as interactive training modules, infographics, awareness posters, awareness tips and arcade villain characters

Cons

  • Too much technology jargon-Has heaps of pdf's text and documentation which could have been further enhanced with graphics, infographics and cartoons and non text material
  • The Human touch-The awareness material could include more real life human related figures in the illustration videos which would give a better look and feel for non tech savvy persons going through the content
  • AI driven gamification-AI driven gamification could be brought into enable innovation such as role playing between the hacker and protector for widen the scope of knowledge and with the objective of teaching to think like the attacker

Return on Investment

  • Overall cyber-security resilience-An overall knowledge gain of atleast 25% on individuals on countering cyber attacks within business as usual
  • Lowered potential of probability of impact-A lowered probability of atleast 25% where a end user would be prone to or succeptible to a phishing attack within normal business and communication
  • Attack mitigation capability- A potential 25% increase in end-users capability to mitigate cyber attacks with self help tools and already provided technology

Usability

Alternatives Considered

NINJIO and Proofpoint Advanced Threat Protection

Other Software Used

Microsoft Defender for Office 365, Microsoft 365 Copilot, Microsoft Visio

KnowBe4 is a Leader in SAT for Good Reasons

Use Cases and Deployment Scope

KnowBe4 is a industry leading security awareness training tool, which can be used to send out cyber security training content, phishing campaigns, and other resources depending on the modules you have purchased. The user is the weakest link in the security chain, and so it is important to educate and raise awareness for different threats that users will encounter. Before I purchased KnowBe4 I had to scrape together different products to send out phishing campaigns, and I was creating my own training material. This took time and meant that I wasn't able to do this as often as I would like. However, with KnowBe4 I have access to a large library of email templates, training modules, and customizable features for educating my staff.

Pros

  • Customizable Phishing Campaigns
  • Excellent Training Modules
  • Multiple Product Integrations

Cons

  • More Content for Non-Diamond Users
  • More Interactive Training Material
  • Customizable Reporting

Return on Investment

  • Lower Click Rates
  • Higher Report Rates

Alternatives Considered

Webroot Security Awareness Training, Microsoft 365 Defender and THRIVE Learning & Skills Platform

Other Software Used

Webroot Email Security Powered by Zix, Webroot Advanced Email Encryption powered by Zix, Microsoft 365 Defender

KnowBe4 - Security Awareness Training that works

Use Cases and Deployment Scope

We perform monthly phishing expeditions of all employees. We also require monthly Security Awareness training videos be completed by each employee. It is part of their annual performance evaluation. We also take advantage of the KnowBe4 Phish Alert button for Outlook. All employees can report suspected phishing messages to IT this way.

Pros

  • Keeps end-users aware of security practices that they should be employing
  • Makes end-users aware of the various ways that security threats can manifest themselves
  • Helps the organization understand how well prepared our staff our to recognize phishing attacks

Cons

  • The only thing we wish was available was a method to email CSV attachments directly to IT staff; rather than having to chase links. This is for report integration.

Return on Investment

  • We've had several reports from employees that claimed that their responses to potential security threats were the direct result of what they had seen on one of the training videos
  • It has actually made staff interested in the security topic. We've had requests to "binge watch" our training videos. At least one department has printed a large The Inside Man banner for their break room.

Usability

Employees gets to know the security attacks and trends before time because of KnowBe4

Use Cases and Deployment Scope

This helps in getting all employees get basic security awareness training and it helped a lot from phishing attacks and many more attacks

Pros

  • Providing information on Latest security trends
  • Providing information on Common attacks

Cons

  • More contents on developers secure code training needed

Return on Investment

  • An attack can cost a huge loss , so comparatively investing on employees training and Knowbe4 is completely worth

Alternatives Considered

Coursera and Mimecast Awareness Training

Other Software Used

Mimecast Awareness Training