KnowBe4 is a security awareness training and simulated phishing platform. The vendor reports it is the world's largest, used by more than 25,000 organizations around the globe. Founded by IT and data security specialist Stu Sjouwerman, KnowBe4's goal is to help organizations address the human ele...
Security Awareness Training Software
Security Awareness Training Overview
What is Security Awareness Training?
Security awareness training protects enterprises against cyber threats that exploit human nature, or simple inattention. These threats include primarily phishing, and also ransomware or other behavior-based vulnerabilities. Cyber security awareness training services can include instructional materials, live teaching, and realistic phishing simulations. To keep up with evolving attack methods, security training services provide continuous training and updates.
The consensus among cyber experts is that prescheduled classroom training is ineffective on its own. So threat simulation is central to enterprise security awareness training and services. While e-learning libraries are included in many online security awareness training offerings, it is simulations delivered surreptitiously that provide authentic proof of workforce resilience in the face of real cyber attacks. Various kinds of simulated attacks may include spear phishing (e.g. pretending to be a trusted sender), BEC (business email compromise), social engineering attacks, HTTPS spoofing, and drive-by cyber attacks.
After simulations, employees who responded inappropriately can then be trained according to their mistakes via classes and lessons, delivered in-context. Research on attention has led to a preference for microlearning courses: sections that take only 10 minutes or less to complete. After the security awareness testing cycle, service providers offer detailed reports about what simulated attacks were successful, or what if any policies were violated.
Providers of security awareness training may also provide privacy or compliance training, or behavior monitoring and remediation.
Features of Security Awareness Training
Security awareness training offerings may consist of the following:
Pre-assessments, or baseline testing to assess vulnerability
Phishing simulation imitating known attack patterns
Random, asynchronous attack delivery
Phishing reply notification & alerting, reply tracking
Non-email based testing (e.g. Smishing / SMS, or Vishing / voice, found USB drive)
Testing analytics and user attribution (e.g. role, day/time of response, demographics)
Industry benchmarking for security awareness performance
Prebuilt library of Interactive training modules
E-learning delivery with live or self-paced modules
Security awareness materials for distribution
Custom-test building tools for company-specific tests
Reinforcement training, gamification, knowledge retention testing
Auto-assign security awareness training for new or vulnerable employees
Company-wide simulation response analytics and reporting
Certification training for security personnel
Industry-specific certifications (e.g. federal security, banking)
Security awareness training is available on per seat basis. Larger companies with greater pools of employees pay less per seat. Additionally, security awareness training offer tiers of service. Lower tiers of service provide core services like phish testing, and online training. Higher levels of service may include more elaborate testing (e.g. found USB device testing, BEC simulation), and more testing modules, as well as knowledge certifications. Security awareness service providers may also provide cybersecurity suites of software, or security appliances. These vendors offer the option to bundle security awareness training with email security services, threat intelligence, and related services.
Security Awareness Training Products
Listings (1-21 of 21)
Cofense PhishMe is a cyber threat and phishing simulator meant to be of use in training employees to be wary against threats and also to gain information about general employee threat knowledge and preparedness. A free version is available for small business.
Sophos offers security awareness and phishing training and preparation testing via Sophos Phish Threat, the company's phishing attack simulator.
Proofpoint Security Awareness Training (formerly ThreatSim from Wombat Security) is a cloud-based training platform that simulates threat scenarios (e.g. phishing) and also provides assessment testing developed by Wombat Technologies, which was acquired by Proofpoint in March 2018.
Inspired eLearning in San Antonio offers their Security Awareness Training computer-delivered courses and phishing simulations to prepare workforces against possible threats.
Webroot Security Awareness Training provides cybersecurity education to enterprise employees and provides security best practice so employees can avoid phishing attempts, and social engineering cybersecurity attacks.
(ISC)2 offers a variety of computer-based and delivered pre-built security training modules packaged in their offering Official@Work, which is available to enterprises.
SANS Institute offers the SANS Advanced Cybersecurity Learning Platform, a suite of compliance training courses delivered via computer, featuring role-based dynamic training modules.
PhishLine provides a suite of applications supporting phishing social engineering simulations with data analytics for evaluation of results as well as targeted training and education to boost readiness. PhishLine was acquired by Barracuda in January 2018, and is now part of Barracuda's security p...
MediaPro in Bothell, Washington offers a suite of training modules and application supporting security awareness and education, touting an advanced Adaptive Planning Tool to meet the needs of various kinds of enterprises.
Security Innovation in Wilmington offers security awareness and education training modules supporting teaching and evaluation / assessment.
Terranova WorldWide in Quebec offers a wide range of security awareness products and support, notably phishing simulations and e-learning applications and training modules.
Global Learning Systems (GLS) offers a variety of training modules supporting security awareness and compliance training needs.
Security Mentor in California offers computer-delivered training modules supporting employee security awareness, and as well as their phishing simulator: PhishDefense.
Dutch company BeOne Development offers security awareness training modules from pre-packed modules to more customized plans dependent on the needs of the requesting enterprise.
The Security Awareness Company offers a suite of e-learning modules supporting compliance and employee security awareness.
Optiv Security Awareness Training features CyberBOT, their story driven eLearning platform to improve employee security awareness, as well as phishing simulation to present realistic examples and scenarios.
Digital Defense in San Antonio offers SecurED, their security awareness computer-delivered training platform.
InfoSec Institute in Illinois offers SecurityIQ, their security awareness and anti-phishing simulation system featuring PhishSim, their simulator, and AwareEd, which is the company's computer-based security awareness training modules.
Booz Allen Hamilton offers CyberSim, a security training and awareness simulation and service.
Kaspersky Labs offers Security Awareness Training and software learning management tools, gamified teaching, and training modules specific to employees in various industries designed to prepare the workforce against phishing, and other cyber threats.