“I have been using adaptive for a month now, after using both knowbe4 and mimecast awareness training for a few years. The adaptive stuff is really intuitive and easier to admin, but when users forward a test email to someone in IT (this is common, "is this email safe for me to open?") it triggers a fail.”
“Tools like KnowBe4 send out emails that are OBVIOUS phishing. Their training modules focus on OBVIOUS phishing. Nobody with two brain cells to rub together is going to click on an email that says "Your Untied Airfare Flight Has Been Resurfaced", but those are the level of emails that platforms like KnowBe4 send out.”
“Knowbe4 training is beyond useless, it may as well be AI slop. You're better off sending links to security recommendations and making everyone sign off they've read it.”
“We just dropped KnowBe4 and moved to using Avanan's built-in phishing simulations and training. Barracuda had the same offering when we used them, and both were included as part of our plans.”
“Here to follow the thread because we are also looking into other options; although more so to replace Microsoft Defender and the KnowBe4 PhishER product. Senior leadership (non-IT folks) are fond of KnowBe4 training…”
“Adaptive! The content is fresher than Knowbe4. We pushed out training and I’ve gotten lots of positive feedback on content compared to the past when I’ve received complaints. Their team is also very responsive when we have any issues or questions.”
“If You have the same budget that currently you're paying to knowbe4 then go with any vendor who covered ai powered security threats awareness training. Take refrence from gartner latest SAT vendors report, choose & compare your budget then try their poc.”
“In fairness Knowbe4 training is great for training on the basics, but sucks with not having cheesy, baby feeling training modules which I feel is their greatest weakness.”
“I don't think they do a ton of video (more bite sized training), but I typically try to find an outside partner to do our annual training (I've had a lot of comments from users that they find those a lot more interesting than the built in KnowBe4). Another company we looked at that I liked was Pistachio, I liked working with them as well.”
“We moved from KnowBe4 to a PhishFirewall, which provides freqent short micro-training videos directly to a user's inbox. What i like about it is that it keeps up on new phishing trends and methods better than these annual or semi-annual SAT modules that are somewhat monolithic.”
“The bigger issue isn’t which platform you switch to, it’s that almost every awareness vendor including KnowBe4 is selling the same product: simulated phishing emails + a video library + a click-rate dashboard. If your click rates aren’t budging, switching to a different version of the same model probably won’t move them either.”
“If you use knowbe4 and are in azure with ATP - defender for office365 plan 1 … you will get false info that users are clicking and opening attachments because defender does all that to check the messages. You can modify office 365 to specify that you have external fishing coming in with specifics on who sending messages what domains, etc.”
“Looking to move off KnowBe4, what are people actually using these days? Our renewal is up in two months and leadership wants options. the training content feels stale and our click rates aren't budging.”
“KnowBe4 being the market leader is mostly a legacy thing at this point. They got big when the bar was low and the content library is genuinely massive, but the platform feels dated. Cofense is for the phishing simulation side specifically.”
“One thing I don’t see mentioned much is that KnowBe4 has tied email security pretty closely into their training side. So you can actually base user training/phish sims off the types of threats that are hitting your org (sanitized obviously), instead of just generic templates.”
“KnowBe4 is strong for training and simulations, but it is not the same control as an inbox layer that can remediate messages after delivery. Abnormal and Sublime both live in that detection and response space, so I would judge them on how quickly they pull messages back, how noisy the alerts are, and how well they handle BEC and vendor impersonation.”
“KnowBe4 being the market leader is mostly a legacy thing at this point. They've been around forever and got embedded into compliance checklists before better options existed. Worth looking at Cofense if phishing simulation depth matters to you, and Riot if you want something that takes a more behavioral approach.”
“KnowBe4 supports smart group logic based on custom fields, so you can differentiate new joiners from existing employees who just got email by checking account creation date against email activation date.”
“What sucks is you can’t remove someone from a “new hire” group if it’s synced by AD, so it makes it tough to shift them via KnowBe4 automation from the training pipeline to the quarterly. Bee there and never really found a solution.”
“we just trigger KnowBe4 onboarding off the HR system hire date rather than email creation now, keeps things way cleaner than trying to sort it out after the fact.”
“The generic template problem is real with KnowBe4. We moved away from it partly for that reason. If your main gaps are around personalization and covering non-email vectors, Riot handles the simulation side differently.”
“knowbe4 was built for a different era of threats tbh. if youre looking at modern options, Doppel handles the social engineering and brand impersonation side well.”