KnowBe4

Security awareness training and simulated phishing at scale

KnowBe4 trains employees not to fall for the attacks aimed at them, and measures whether it worked. Simulated phishing campaigns go out on a schedule, anyone who clicks is enrolled in training rather than told off, and the platform reports a risk score per person, per department and per organisation so the trend is visible over time. The training library is large and produced in-house, covering security awareness and the compliance topics an audit asks about, in dozens of languages. Real-Time Coaching intervenes at the moment of a risky action instead of waiting for the next campaign, and AI agents pick the content and difficulty for each person. Around the training sit email security products, an incident response agent and a risk manager. Training is sold at two levels - Foundation and Advanced - priced per seat per month on a three-year term, and the rate falls as seat count rises; above a thousand seats it is quoted.

  • Simulated phishing campaigns on a schedule
  • Anyone who clicks is enrolled in training automatically
  • Risk score per person, department and organisation
  • Large in-house training library in dozens of languages
  • Compliance training alongside security awareness
  • Real-Time Coaching at the moment of a risky action
  • AI agents pick content and difficulty per person
  • Priced per seat, cheaper as seat count rises

Based on what people have said

Every answer links back to the mentions it came from

What do people think of the training content?

Opinions are divided. Some users find the content effective, bite-sized, and a good return on time investment. Others describe the modules as dry, boring, or cheesy, with some labeling the training as AI-generated slop. Several users report that the content feels stale or dated, leading them to look for alternatives with fresher or more modern material.

17 mentions · r/cybersecurity · r/sysadmin · r/cybersecurity · r/msp · r/cybersecurity · r/sysadmin · and 3 more · Aug 2023 – Sep 2026

How effective is the phishing simulation and reporting?

Many users report success in reducing click rates and increasing user awareness. However, others complain that the phishing templates are too generic or obvious, making them easy for employees to identify. Some users also report significant issues with false positives, where security tools like Microsoft Defender flag the simulations, leading to inaccurate reporting of failed tests.

35 mentions · r/sysadmin · r/sysadmin · r/cybersecurity · r/sysadmin · r/cybersecurity · r/sysadmin · and 14 more · Apr 2019 – Jun 2026

What are the common complaints regarding the company's business practices?

A recurring concern involves the company's alleged ties to Scientology, which leads some professionals to refuse to engage with them on principle. Additionally, several users describe the sales team as aggressive or sleazy, citing instances of being hounded, having personal numbers called, or having the company attempt to poach clients directly.

14 mentions · r/sysadmin · r/sysadmin · r/cybersecurity · r/msp · r/sysadmin · r/sysadmin · and 5 more · Jul 2019 – Aug 2026

How does the support and account management experience compare?

Experiences with support are inconsistent. Some users find their Customer Success Managers responsive and helpful, while others describe the support as poor, slow, or lacking in technical depth. There are also reports of difficulty in getting assistance or having issues dismissed as working as designed.

17 mentions · r/cybersecurity · r/cybersecurity · r/sysadmin · r/sysadmin · r/sysadmin · r/sysadmin · and 5 more · Jun 2021 – Sep 2025

Is the platform considered easy to set up and manage?

Many users appreciate the automation features and the ability to integrate with Active Directory for user provisioning, describing it as a set-it-and-forget-it solution once configured. Conversely, others find the initial configuration—particularly regarding email filtering, whitelisting, and avoiding false positives—to be a significant pain point.

17 mentions · r/sysadmin · r/sysadmin · r/msp · r/sysadmin · r/cybersecurity · r/sysadmin · and 10 more · Apr 2019 – Aug 2026

These summarise counts and dates only. Read the quotes themselves under what people are saying.

What people are saying about KnowBe4

39% negative
“We use knowbe4. The videos are like 90 seconds. They’re a pretty good return on time investment in my opinion as their end user. Teaches something small every month.”
atamicbomb · reddit ·
“KnowBe4 hired one and wrote it up. Got through the interviews, the background check, the ID verification. Their EDR flagged it day one, once the laptop shipped.”
infosec_observer · reddit ·
“Yep, had a user send in a ticket because their AV flagged a file(turned out to be a KnowBe4 Phishing email attachment from 4 months prior, but y'know) User left for the day within 10 minutes of sending the email in.”
BCIT_Richard · reddit ·
“Although sometimes I miss the advanced features of Knowbe4.”
cwk9 · reddit ·
“Comes up almost every thread about knowbe4 but I will never engage with them just based on their ties to Scientology, even if they claim to be unaffiliated.”
Blastergasm · reddit ·
“And for what it’s worth, the users like it far better than when we used knowbe4 AND I’ve noticed they’re much better at reporting emails now than ever before.”
Medical-Display-9762 · reddit ·
“Is it half the price of KnowBe4? Yes.”
Craig__D · reddit ·
“KnowBe4 can do that.”
fahque · reddit ·
“I had two clients switch from KnowBe4 to Huntress and both of them said they are fans. Setting up the automatic testing and training is nice; you don't ever have to think about it”
ru4serious · reddit ·
“We moved from KnowBe4 to MetaCompliance 3 or so years ago. It's... fine and perfectly competent, and about half the price.”
FarToe1 · reddit ·
“Reporting is thinner than KnowBe4, so if annual attestation is the real driver it wont carry you alone.”
blud_13 · reddit ·
“We us Cyberhoot after having KnowBe4.”
bradinsd · reddit ·
“Abnormal AI is what we moved to from KnowBe4 and so far are very impressed with it.”
muff_puffer · reddit ·
“We switched from Mimecast to KnowBe4(not my choice). Way better engagement with Mimecast. Very entertaining.”
jslucer · reddit ·
“If you're wanting the vendor to organize and conduct the training, I think KnowBe4 can do that. Or they may be able to provide the training resources, and you organize and conduct the training internally.”
Sasataf12 · reddit ·
“Abnormal ai only used it for a couple weeks with knowbe4.”
agingnerds · reddit ·
“Other platforms end up holed by Knowbe4.”
Successful_One_1000 · reddit ·
“We use Usecure, some hate it, some tolerate it, some don't use it at all, we had a client recently request to go back to knowbe4 so that's what we are doing.”
chocate · reddit ·
“Also had, left, and came back to KnowBe4 ourselves.”
maxxpc · reddit ·
“We are currently using KnowBe4 and are on the Diamond tier.”
Milluhgram · reddit ·
“Looks like a phishing test message sent by IT via something like KnowBe4.”
timewarpUK · reddit ·
“Dam I kinda miss my old Job where I owned the KnowBe4 phishing campaigns. I would copy these examples and make my own pages and get people to fall for it.”
Every-Ad-5267 · reddit ·
“I quit obsessing over “AI-powered” labels and instead measured which PoC actually dropped repeat clickers in a month; Tartan App and one other pilot were the only ones that moved the needle enough to justify the KnowBe4 budget shift.”
Remarkable-Top4601 · reddit ·
“This has been ongoing for about 6 months where Microsoft and KB4 are of little help. This is also having a minor impact to our phishing test reports where users that interact with xlsm payload tests are not marked as a fail.”
nocryptios · reddit ·
“But there are a few reasons it became the default choice for many organizations eg massive content library”
mike_chen_sys · reddit ·
See what people previously said about KnowBe4