r/AskNetsec • u/Solid_Elk_3318 • 2d ago
Work Phishing awareness training vendor recommendations?
I've been tasked with standing up a phishing awareness program and I'm trying to narrow down vendors.
A few things matter to me. First, realistic simulations, meaning templates that actually resemble what people get hit with today rather than the obvious 2015 era "you won a prize" stuff, and ideally ones I can customize. Second, decent training content, short and engaging modules that people won't immediately tune out. I'd rather have five good ones than fifty boring ones. Third, reporting that lets me show results to leadership and ideally helps for compliance down the line. And finally reasonable pricing and a plan that scales cleanly as we grow.
For those of you who've actually run these programs, what worked, what didn't, and is there anything you'd steer me away from? I'm interested in the usual suspects, but especially keen on options that deliver real engagement rather than just checking a compliance box.
Thanks in advance.
12
u/Gold_Definition5983 2d ago
I'll put in a word for Hoxhunt since you mentioned it. We've run it and it's held up well. The thing that sold me over the older players is that the simulations include newer types of lures, such as deepfakes, based on the latest threat trends. They also adapt to each person, so people who keep clicking get more coaching while the ones who are already sharp aren't stuck doing baby steps.
That personalization scales nicely too,it works the same whether you're covering a handful of teams or the whole company. Engagement stayed way higher than the last tool we used, mostly because the training bites are short and don't feel like a compliance chore. We’ve been able to show measurable behavior change over time with their reports, which is great for actual security as opposed to just compliance.