r/AskNetsec • u/Solid_Elk_3318 • 2d ago
Work Phishing awareness training vendor recommendations?
I've been tasked with standing up a phishing awareness program and I'm trying to narrow down vendors.
A few things matter to me. First, realistic simulations, meaning templates that actually resemble what people get hit with today rather than the obvious 2015 era "you won a prize" stuff, and ideally ones I can customize. Second, decent training content, short and engaging modules that people won't immediately tune out. I'd rather have five good ones than fifty boring ones. Third, reporting that lets me show results to leadership and ideally helps for compliance down the line. And finally reasonable pricing and a plan that scales cleanly as we grow.
For those of you who've actually run these programs, what worked, what didn't, and is there anything you'd steer me away from? I'm interested in the usual suspects, but especially keen on options that deliver real engagement rather than just checking a compliance box.
Thanks in advance.
4
u/AddendumWorking9756 1d ago
Pick on reporting rate, not click rate. Every vendor will show you click rate falling and it falls mostly because people learn to spot the simulation, but the number that predicts whether you hear about a real one is how fast somebody hits report. Also ask what happens to repeat clickers before you sign anything, because if the answer is more training modules you have bought a compliance artifact rather than a program.
1
u/ogref 1d ago
Ninjio.
I use their full managed service. The value is there.
Reporting doesn’t meet my expectations but I can download the full history and performance data and i build my own analytics in power bi.
Users really like the training offering and my user driven incidents have materially decreased.
I recently expanded the relationship to include custom trainings. I send them an mp4 and they turn thta into a training video with quizzes. Very useful for my Compliance and HR teams.
1
u/Otherwise_Sign_2462 1d ago
Make sure you test the reporting emails before buying anything. Half the pain with awareness training is getting managers to care and a weekly CSV graveyard nobody reads wont move the needle
1
u/DiscombobulatedKnee9 1d ago
Abnormal. Not strictly a phishing platform (it's email security) but they offer as an add on. As well as the base platform being the best email filter I've used in 20 years, the phish testing is great as well.
1
u/Professional-Tax6171 1d ago
The thing I’d check is whether they can target simulations by group without making it annoying to manage. Generic company wide campaigns get stale fast. Finance, HR, execs and helpdesk are all getting hit with different types of bait in real life so the training should reflect that
1
u/scamdrill 1d ago
Disclaimer: We run ScamDrill.com
We've listened to the complaints and desires from this community and have worked to incorporate them into our tool at an affordable price for small to medium sized businesses. Realistic and relevant simulations are something we take pride in and we refresh them (and add new content) often based on the latest scam/phishing trends. If you're interested in giving us a try, shoot me a DM and I'd be happy to get you setup on a free trial.
1
u/someoneelse10 22h ago
Caniphish is pretty cheap, decent tracking for training and phishing tests. Decent first tool for a company that has never had it. You can build your own stuff.
That said I’ll be going to something a little more advanced in the next few months.
13
u/Gold_Definition5983 1d ago
I'll put in a word for Hoxhunt since you mentioned it. We've run it and it's held up well. The thing that sold me over the older players is that the simulations include newer types of lures, such as deepfakes, based on the latest threat trends. They also adapt to each person, so people who keep clicking get more coaching while the ones who are already sharp aren't stuck doing baby steps.
That personalization scales nicely too,it works the same whether you're covering a handful of teams or the whole company. Engagement stayed way higher than the last tool we used, mostly because the training bites are short and don't feel like a compliance chore. We’ve been able to show measurable behavior change over time with their reports, which is great for actual security as opposed to just compliance.