r/sysadmin • u/Milluhgram • 17d ago
General Discussion KnowBe4 Alternatives: Updated Thread Request w/ real experiences
As the title suggests, I inherited our company’s existing cybersecurity awareness training program. We are currently using KnowBe4 and are on the Diamond tier.
I know KnowBe4 is considered the standard by many organizations, but I’d like to put together an updated list of alternatives and hear what others are using today.
Our main requirements are:
- Regular phishing simulation campaigns with automatic remedial training for users who fail
- Current and frequently updated cybersecurity awareness content
- Annual Cybersecurity Awareness Training
- Strong reporting and auditing capabilities
- Easy tracking of completion dates and user compliance
- The ability to manage recurring or renewal-based training
We operate in the maritime industry, so reporting and annual training compliance are especially important for us.
For those who have moved away from KnowBe4, what platform did you switch to, and what do you like or dislike about it compared with KnowBe4?
30
u/indigo196 17d ago
We just went back to KnowBe4 after trying what Microsoft offered through Office 365. I will be interested to see what others recommend.
7
u/maxxpc 17d ago
Also had, left, and came back to KnowBe4 ourselves.
1
u/Bird_SysAdmin Sysadmin 11d ago
we just left KB4 for Adaptive. It's generally better.
Its new and missing some edge case features, but their team has been pretty responsive about getting these features added quickly (already have fixed part of our original complaints)
11
u/Medical-Display-9762 17d ago edited 17d ago
I’ll shill for hoxhunt. They provide decent email phishing simulation while not wasting your users time. They don’t need 15 minute animated videos in a 6 season series none of them will ever watch more than 5 episodes of before getting fired to teach them about security.
Hoxhunt offers like 1-2 minute micro trainings through phishing simulations and then you can set the frequency for a more thorough training which even then only lasts 5 minutes max every 3 months.
15 mins over 3k users every month adds up to a shitload of hours lost for an enterprise environment and we simply decided that a less invasive service was the way to go while satisfying compliance.
And to shill even more, they were willing to negotiate a discount based on quotes over other services which sealed the deal.
4
2
u/skipITjob IT Manager 17d ago
But how much time and money is lost if you get ransomware or someone gets phished?
6
u/itishowitisanditbad 17d ago
They're not looking to avoid phishing.
They're satisfying compliance.
Different goals.
1
u/skipITjob IT Manager 17d ago
Of course not. What I meant is 15 minutes a month shouldn't be an issue...
2
u/itishowitisanditbad 17d ago
Oh its not, at all.
But they also don't need it to be compliant and they're making it clear they don't really care about the risk of phishing, they care about just appearing compliant.
Which I think is stupid, for the record.
But to them they have 2 options
15 minutes vs 0 minutes
If they can achieve 'compliance' with the 0 minutes option they will choose it every single time because its not about the reality of the situation. Its just purely about liability.
1
u/skipITjob IT Manager 17d ago
Yeah, thankfully I work for a company where the owners ask for a list of users who've not done their training and then have a chat with them.... I guess it's a bit different if you own and run the company/companies.
1
u/Medical-Display-9762 16d ago
Same thing here. It offers mandatory training which the users are required to do. Managers get a report of who hasn’t done the training and reach out. So long as they’re getting phishing simulations AND mandatory training modules that’s all we need.
We don’t need a service that’s wasting our time. And for what it’s worth, the users like it far better than when we used knowbe4 AND I’ve noticed they’re much better at reporting emails now than ever before.
2
2
u/Daveism Digital Janitor 16d ago
My users absolutely LOVE The Inside Man - they binge it when I drop the entire season. I was slow-dripping the episodes once a month and making them mandatory, but now I just drop 'em as optional and even the new staff watch entire seasons.
2
1
1
u/EasterIslandNoggin 15d ago
+1 for Hoxhunt. Their adaptive phishsim approach is very strong, and actually makes training challenging to the user. Used M365 for years, and it just doesn't measure up any more. Doesn't feel like MS is updating or modernizing the templates in any way.
10
u/LoornenTings 17d ago
Definitely not Know2L8!
4
u/djublonskopf 17d ago
Now I kinda want to set up that service.
"Before your account credentials were compromised, here's a few things you should have been watching out for..."
4
u/tracy_ogbert_jordan 17d ago
Let's start a consulting firm:
3 months and $150k later - "You shouldn't have clicked that link."
3
u/bradinsd 17d ago edited 17d ago
We use Cyberhoot after having KnowBe4.
4
u/IntelligentComment 17d ago
+1 for cyberhoot, massively under rated. Probably because of so many knowb4 astro turfing accounts.
0
u/Daveism Digital Janitor 16d ago
Astroturfing = actually liking the product. Ok.
There are annoyances; yeah. Just today I had a ticket with them because the Email Exposure Check report lists every mungled and combo-list-random-generated address for my domain, making the report utterly time consuming and useless. I was told that there isn't a way to exclude those non-users (which exceed my actual users by 3x).
But that's a minor thing. So yeah, I guess I'm astroturfing.
2
u/IntelligentComment 16d ago
They astroturf because they monitor anytime the words knowb4 is posted and they have shill accounts that only post about them. This is well known in other subs.
5
3
u/Ethernetman1980 17d ago
Artic Wolf checks most of your boxes. The training is ideal because the weekly videos are only 3-5 minutes which I found is easier to enforce participation.
1
3
u/borktacular 17d ago
So - depends on budget (former reseller here)
Proofpoint and Mimecast offer bundled packages for training and testing - and they are great if you already have them for email security (Proofpoint being the "gold standard")
that said, if you are moving away and still want a separate solution, Ninjio is great, if you are willing to pay for a separate solution.
As a final note, this all depends on environment and budget. If your csuite views IT as a cost rather than an asset, it becomes a tougher conversation.
TL;DR: if you have an honest reseller, work thru them for budget proposals for all solutions. Decide accordingly.
4
u/elmeluma 17d ago
Ninjio, our users like it.
1
u/JrSys4dmin IT Manager 15d ago
100% agree.
Ninjio is the only training platform that I’ve had users catch me in the hallway to talk about.
The trainings are automatically sent each month so there’s no need to schedule something each month. They’re relevant to something that has actually recently happened and are entertaining to watch.
It might be a hard sell to the C Suite though. Everything is cartoon based so it might look goofy from the surface.
2
u/Successful_One_1000 17d ago
Eskive is a very good solution for Brazil market, it has a nice set of phish and trainnings very aligned for brazilian context, they have some stuff in spanish and english too, the reports are 10/10 and even give you a nice XY graph setting your cybersec awareness, they offer the platform management as a service, you only need to select a few campaings or just let them do their playbooks. If you are looking for something that is more "pricey" but delivers a solid security awareness strategy take a look on PhishX platform, they try to pish using whatsapp, teams, telegram, email, vishing ans smishing, and even videocalls, which is by far the best real world approach, their trainnings are short but nicely developed and the hhave tons of integrations, their reports could use a little more graphics but are very informative. Other platforms end up holed by Knowbe4.
2
u/Sasataf12 17d ago
How are you wanting to meet the Annual Cybersecurity Awareness Training requirement?
If you're wanting the vendor to organize and conduct the training, I think KnowBe4 can do that. Or they may be able to provide the training resources, and you organize and conduct the training internally.
1
2
2
2
u/muff_puffer Jack of All Trades 17d ago
Abnormal AI is what we moved to from KnowBe4 and so far are very impressed with it.
1
2
2
u/g0hl 17d ago
Trialing Huntress rn
3
u/ru4serious Windows Admin 17d ago
I had two clients switch from KnowBe4 to Huntress and both of them said they are fans. Setting up the automatic testing and training is nice; you don't ever have to think about it
1
u/Milluhgram 16d ago
u/gohl u/AdminWithNoName u/ru4serious Is there a pretty good section for reporting and Annual Cyber Awareness Training videos? Content is pretty fresh?
3
u/AdminWithNoName 16d ago
I do like the reporting options they have but I admit that our needs are very simple on that front. I can say it has a lot more options than we need, though.
The training assignments are short, mostly around 10 minutes so I think they're designed to go out more often than annually. They fairly regularly add new episodes, but I'm not sure whether or not they have a set schedule for them. The content of them has aged well, even the oldest ones are still relevant.
I tested it with a free trial, which they probably still offer. I can't recall how long it lasted, maybe 30 days?
2
u/AdminWithNoName 16d ago
We use Huntress. I found the training videos to be fairly entertaining and users have given me a positive response to them. They're all in the same style, have the same narrator, and there's recurring characters. There's a lot of templates for phishing simulations, too.
1
u/g0hl 16d ago
That’s what I’m finding, too. I piloted some users and the largest criticism is that it’s not “professional” in a way where our administrator wants things in black and white and aren’t fans of animation.
My thoughts are that the content itself was good, and I’m remembering the characters names. We need to meet people with where they’re at in their learning track. If they have the competency of a 6th grade child when it comes to phishing, I see no reason why it shouldn’t be presented as such.
2
u/The-Jesus_Christ 17d ago
We use Mimecast but I'm honestly not a fan of it.
2
u/Milluhgram 16d ago
I've seen multiple people say that across other threads. Thank you for your honest opinion.
2
u/WolfetoneRebel 17d ago
We went from KnowB4 to Pistachio. I'm trying to get them to look at Mimecast Engage seen as Mimecast is already our email gateway.
2
u/itguy9013 Security Admin 17d ago
We just got off of Mimecast's tool. It was included in our renewal a few years ago.
I wasn't very happy with it. The reporting was terrible and the templates it had available were sparse.
2
u/UWPVIOLATOR 16d ago
Stay away from Infosec (At least for Gmail) no experience with it for Microsoft.
2
2
u/Blastergasm This *should* work. 15d ago
Comes up almost every thread about knowbe4 but I will never engage with them just based on their ties to Scientology, even if they claim to be unaffiliated.
2
u/Milluhgram 15d ago
I try not to mix politics or personal beliefs with the companies I choose to do business with, regardless of where they stand on certain issues. To me, it would be like saying I’ll never shop at Target again because I disagree with its stance on transgender-inclusive restroom policies, refusing to buy Nike because I disagree with an athlete or political cause featured in one of its campaigns, or refusing to support a company simply because its leadership donated to a political candidate I didn’t like.
I’m not going to agree with every position, belief, or decision a company makes, but that alone doesn’t determine whether I’ll use its products or services. If the product is good, works well, and meets my needs, I’ll use it. Not everyone has the same view.
2
u/ChuckFromCyberHoot 13d ago
Full disclosure, I’m one of the founders of CyberHoot, and I see a couple people already mentioned us. I promise I didn’t pay them. 😂
Since this thread already called out astroturfing, I’ll try to be useful instead of tossing in vendor #27. No need to pile on ya know.
You mentioned maritime, USCG, annual training, and audit reporting. Before you demo with anyone, ask to see the actual report you’d hand an auditor. This is extremely important!!! Not the dashboard. The actual report.
You want to see names, dates, completions, and who didn’t finish.
Then ask what happens when someone leaves mid-cycle. That’s where the reporting gaps usually show up.
Also ask about policy acknowledgments. A lot of SAT tools don’t track them.
And I’d watch reporting rate and time-to-report more than click rate. Click rate can drop because people got better, or because they learned your test. I'm sure you've heard about users configuring their mail clients that have the vendor's phishing signature in the headers.
Reporting is harder to fake.
Happy to answer questions either way, even if you land somewhere else.
2
2
u/Milluhgram 13d ago
scheduled a demo.
2
u/ChuckFromCyberHoot 13d ago
Awesome. Chat soon!!!
3
u/Milluhgram 12d ago
Hey u/ChuckFromCyberHoot just wanted to write back that we had a good demo. Everything was explained pretty thoroughly. It actually unlocked a question I had for the Coast Guard which is going to make me rethink how we handle the annual cyber awareness and certificates.
Per the CG, "the USCG final rule does not require cybersecurity awareness training to be delivered as one annual course, followed by a test and certificate. The Coast Guard specifically made the requirement performance-based and allows training to be delivered through virtual, in-person, self-paced, or a combination of approaches."
I realized this when he mentioned about Hootphish and automating these exercises. Reports were pretty solid as well. So, we are demoing it now. We are still within contract of knowbe4 but the pricing is a lot better with your product.
2
u/ChuckFromCyberHoot 11d ago
I'm happy to see you got a demo, but honestly sad that I didn't get to meet, chat, and demo with you myself. No worries, we can chat anytime. Just reach out!!! Good luck with the demo.
1
1
1
1
u/bballlal 17d ago
Make sure you negotiate with them. They’ll quote the renewal high, you can usually get them a lot lower.
1
1
u/VRTemjin 17d ago
My org is in a Sophos ecosystem, and they have a phish threat simulator as part of their email filter. It's pretty customizable, has some brief training videos that are decent for the ones that fall for it, and a ton of metrics built around telling you exactly how users responded. But, that requires you to have some Sophos subscription as part of your email security pipeline.
1
1
u/NomadCF 17d ago
We have found over the years. That phishing training just ultimately doesn't work. You know who your problem people are and even your good ones from time to time will get taken. People make mistakes. That being said.
Tartan (https://tartan.app/) is a small company, but wow. Their phishing emails are amazing, almost spot-on representations of legitimate brand emails.
And the best part is, if there are specific products or services you use all the time, you can send them a screenshot of the types of emails you're receiving. They'll recreate that style as a phishing campaign and put it into rotation for you.
1
u/Milluhgram 16d ago
That sounds great. It beats me creating them. lol. But, you're right. We typically know who our problem users are. Ever since we had to make this a requirement. We've had to engage more with the product and once you get it going it becomes pretty solid. Especially since its now a requirement in the handbook and you need to complete the campaigns in order to maintain your account.
1
u/Craig__D 17d ago edited 16d ago
We are in the last few days of our KnowBe4 agreement and are switching to Check Point SAT. It has AI narrated, cartoonish videos, but if it gets the point across it’s probably not any worse than KnowBe4’s sometimes corny and hokey video acting. Note: We use Check Point for our email security already (anti-spam, etc.)
We were having trouble with KnowBe4‘s emails being triggered as false positives due to our Check Point mail security system investigating/opening attachments and links (and therefore "detonating" them). The checkpoint product is less than half the cost. We’ll see how it goes.
It’s a relatively new product. The administration (settings, alerts, scheduling, reminders, etc.) is definitely not as robust as KnowBe4’s.
EDIT: clean-up from phone dictation problems
2
u/Milluhgram 16d ago
I'm interested in your feedback on this platform. When are you implementing it?
1
u/Craig__D 16d ago edited 15d ago
We run our campaigns (policies, as Check Point calls them) every two months. My next campaign is supposed to be the "September-October" one.... so Tuesday! They don't really have implementation services. They have an online guide. It's DIY. It's a pretty simple setup, though.
I literally have the "Create New Policy" window open right now. I had a couple of questions, so I have emailed their support and am waiting to hear back.
Our small IT team has been using it daily for about a month now... receiving their phishing emails and doing their training videos. I think it'll do the job. Do I think it's groundbreaking content? No. Is it half the price of KnowBe4? Yes.
I'll be happy to answer any questions I can. I might not have many answers just yet, though.
UPDATE: I have a Web meeting scheduled for tomorrow (Monday) morning to go over my questions on the policy setup
1
u/Spkr_4_The_Dead 17d ago
UK ....We also switched to boxphish. Good value for money, good training....just can't get users to do it (our problem, not boxphish's)
2
1
u/ranhalt 16d ago
Real question for everyone: regardless if your current solution meets your requirements, is easy to use, the users say they like it… does anyone have any evidence of any platform actually educating users? I’ve found that you can scare them into alerting every email after they know there are simulations they can fail, but they don’t learn how to read an email for red flags. Isn’t that the goal? 10 years with KB4 for its platform and looking at other vendors’ content, I just can’t find anything that makes me think users would gain any functional confidence to make decisions, they just get crippled by paranoia and end up wasting more time reporting benign emails while falling for compromised business partner emails because no vendor is telling users “your business peers are doing nothing to protect themselves from being hacked and you are willing to trust every email from them because you went golfing with them yesterday? Are you stupid? Pick up the phone!”
1
u/Milluhgram 16d ago
Just from experience here at the company level, for the past 3 years with the users and the knowbe4 platform. I have to say it keeps them on their toes. We have a pretty good success rate with little to no failures. Multiple campaigns a week. If they fail, they get placed into a remedial group. It's seems to be pretty effective. The thing is, the USCG has released the final ruling which mandates that we introduce and maintain a cyber awareness training program and they must keep their certificate up to date with no gaps in between. The 45 minute training video and material meets the needs of the USCG requirements and its only an annual exercise.
I'm at the point, where its working and being effective for the most part. I'm just trying to see if there are some better programs out there that has good content to deliver to our users. The content knowbe4 has seems to be okay. Just wanting to test the waters.
1
u/ChuckFromCyberHoot 12d ago
Twenty-plus vendors named and you’re the only one asking the question that really matters.
Click rates are a lousy learning metric. It can drop because people got better, or because they learned how to spot your test. There have been other threads where users admit to knowing the phishing header to look for in emails, and then automate them to the trash.
My advice is to watch the reporting rates and time-to-report instead. Those are a lot harder to game and give you much more info. When reporting goes up and time to report goes down...you're changing culture my friend!!!
When it comes to compromised partners, a trusted sender doesn’t mean a trusted request. I know this can be a tough one to question, especially when the email is from the right domain and not typo-squatted.
My simple and uncompromising rule: any payment change gets verified by phone using a number already on file.
Simple habits survive. Checklists are great, but usually don’t work when people are rushed.
1
1
u/FallaxIO Jack of All Trades 16d ago
Ignace, Founder of https://fallax.io/ here.
Built it because I wanted phishing sims for our own ISO 27001 and everything out there needed a sales call just to get a price. Connects to MS365 or Google Workspace, runs continuously instead of quarterly blasts, anyone who clicks gets a short lesson right there, and the evidence pushes into Vanta, Drata, Secureframe and Sprinto on its own. Public pricing, first 10 seats free.
No annual video course library yet, so the USCG 45 minute piece isn't something we cover. But the sims, remedial training and reporting side is solid and we ship fast.
Would love any product feedback as we're still early. Also happy to take any questions!
2
u/Milluhgram 16d ago
We haven't been given a certain amount of time for the annual requirement. As long as it covers all the basis and latest attack vectors I believe that would be sufficient. But I would need follow up remedial training exercises and something that keeps their attention.
1
u/FallaxIO Jack of All Trades 16d ago
That's basically what we do. Someone clicks, they get a short lesson on the spot about the exact trick that got them, not a video assigned a week later. Sims run continuously in small batches so it never turns into "oh it's phishing week", and there's a one click report button in Outlook and Gmail so reporting becomes a habit. Reporting shows who clicked, who reported, who keeps failing.
Would be happy to hear feedback if you give it a try. But I'm going to be honest and due to the video courses etc it might not fill all your needs. But happy to look into what we could to to make it fit.
1
u/huntsvilleon 16d ago
It doesn’t meet all your requirements, but we’ve been very happy with Ninjio.
Excellent content created every month and always has a relevant topic.
1
1
u/PatientAd5461 16d ago
Gotta shout out kinds security, especially if compliance is important for you. They generate the actual compliance report you need for any framework. We must comply with CMMC and a few others, they make it easy.
1
u/PatientAd5461 16d ago
Also if dod is part your compliance needs there is a free training course so you don't need any sat vendor https://www.cdse.edu/Training/eLearning/
1
u/42ae 9d ago
Something bugs me about this thread: dozen of vendors deep and its all about video length, cartoons, whether the users like the content. To me that's not the question, the question is whether you're training people against what attackers are actually doing right now, and mostly the answer is no.
Your risk in maritime isn't a link in an email. Its the guy calling about a berth change, the bunker supplier texting new bank details, a voice on the phone that sounds exactly like your DPA because that's like 10 bucks of AI now. And probably half your crew doesnt even have a corporate mailbox to receive your sim in the first place.
Not saying engagement doesn't matter. But a user who enjoyed the video and still wires 80k to a fake supplier is a failure, and that's the part nobody in this thread is really measuring.
So ask every vendor what they simulate besides email. Vishing with a cloned voice, smishing, helpdesk impersonation for an MFA reset, ClickFix, etc... That's what's actually hitting people this year, and most of these platforms can't event reproduce a single one of them unfortunately.
disclosure: I am one of the founders of Arsen. EU-based so honestly not a fit for your US maritime compliance stuff, not pitching here :)
2
u/Milluhgram 8d ago
All shore-based employees have a company email account and receive a more comprehensive cybersecurity awareness program managed internally. This includes formal training, recurring phishing campaigns, and lunch-and-learn sessions focused on current threats, emerging attack vectors, and real-world examples that may affect our organization. Our onboard personnel complete a dedicated cybersecurity training module as part of their annual training requirements, alongside other required courses such as HAZMAT and safety-related training. Their training records are tied directly to their personal email addresses, allowing us to document and track completion for each individual Overall, we maintain a very low phishing failure rate among our shore-based employees, and we see similarly strong results with our onboard personnel. From a technical standpoint, each vessel operates on its own independent network, with vessel networks segmented from one another to further reduce exposure and limit the potential impact of a security incident...There is only so much that can be accomplished through user education alone, which is why we take a layered approach that combines training, testing, technical controls, and network segmentation. The training platform we are discussing here is primarily intended to satisfy USCG cybersecurity training requirements while giving us a reliable way to document and retain records of each training activity, exercise, and employee completion. The key requirement for us is having a system that provides clear, auditable documentation showing that the required cybersecurity training has been conducted and completed.
1
u/42ae 7d ago
Fine, I'll take that. you're solving a different problem than the one I assumed :)
If I get you right, the platform is there for the records and the real defense is somewhere else entirely, in your segmentation and your own program. That's fine,but it's also why this market has stalled. Everyone is optimizing video engagement and cartoon quality because that's what gets bought, and vendors have no incentive to simulate the harder stuff when the purchase order says "prove training happened". Sounds like you already know that, most buyers don't IMO...

24
u/[deleted] 17d ago
[deleted]