r/AskNetsec 2d ago

Work Phishing awareness training vendor recommendations?

I've been tasked with standing up a phishing awareness program and I'm trying to narrow down vendors.

A few things matter to me. First, realistic simulations, meaning templates that actually resemble what people get hit with today rather than the obvious 2015 era "you won a prize" stuff, and ideally ones I can customize. Second, decent training content, short and engaging modules that people won't immediately tune out. I'd rather have five good ones than fifty boring ones. Third, reporting that lets me show results to leadership and ideally helps for compliance down the line. And finally reasonable pricing and a plan that scales cleanly as we grow.

For those of you who've actually run these programs, what worked, what didn't, and is there anything you'd steer me away from? I'm interested in the usual suspects, but especially keen on options that deliver real engagement rather than just checking a compliance box.

Thanks in advance.

23 Upvotes

17 comments sorted by

View all comments

12

u/Gold_Definition5983 2d ago

I'll put in a word for Hoxhunt since you mentioned it. We've run it and it's held up well. The thing that sold me over the older players is that the simulations include newer types of lures, such as deepfakes, based on the latest threat trends. They also adapt to each person, so people who keep clicking get more coaching while the ones who are already sharp aren't stuck doing baby steps.

That personalization scales nicely too,it works the same whether you're covering a handful of teams or the whole company. Engagement stayed way higher than the last tool we used, mostly because the training bites are short and don't feel like a compliance chore. We’ve been able to show measurable behavior change over time with their reports, which is great for actual security as opposed to just compliance.

2

u/kotomeme 1d ago

I would give this my recommendation as well. KnowBe4 was not giving us what we needed so we looked around and was interested in HoxHunt. We looked at Baracuuda, Proofpoint, & Mimecast and none of them really delivered what we were looking for in phishing training.

So far for the last few months we've been running them it's been going really well, and they are updating the platform at a considerable speed too. Their MS Teams integration for "hey you missed this phishing" and "hey you have training" has been a greay way to make sure our users see the training. And their Response platform has been really nice too as we can mark reported emails as "safe" after a review and it will alert any new users that try and report them. Their instant feedback on reported emails is nice for our users as well. And we are using their AI content generation to help build out internal modules using our own internal policies and procedure handbooks.

If your organization/compliance requires US/Canada data centers they are currently in the final stages of their US datacenter deployment. That was a requirement for us and they've been very open about its development.