“Since this knowledge is common knowledge this can be abused by a third party to include these headers in their own malicious mails and any organization that has setup this "recommended" config of KnowBe4 will be vulnerable too. The header should have contained a customer specific ID and not a generic value which is currently the case.”
“They have a pricing page unless you have more than 5,000 users. From time to time they have a special like 10% off or so, and a bit of a discount if you do a multiyear vs single year contract.”
“If you engage with a reseller rather than KnowBe4 directly, it might cut down on the spam, and you have to go through a reseller to purchase anyway...”
“I use KnowBe4 to phish and train our users. It's simple for end-users, and a lot of automation can be set up on the backend. There is different types of content to help keep users interested.”
“Genuinely interested in the collective mind's impression of KnowBe4's phishing campaigns and training services. My org's SecureHalo service wasn't renewed and I'm seeing an uptick in staff replying to phishing email.”
“Basically if they hit 50% over the last 4 tests they get an email from HR that they are being enrolled in additional KnowBe4 training on how to ID phishing emails. It's often an education issue on how to spot phishy emails and changing a habit - slow down, read the email.”
“The problem was that I noticed I was suddenly failing my monthly testing as soon as I used the button because of a configuration error on the 365 side. Now I'm on the weekly Phish list and I've told the rest of the IT team that I will never use that button again and will go back to shift deleting the email.”
“I “failed” a knowbe4 attachment when I had never seen the email. Went to junk actually. Turns out google workspace was checking attachments and causing failures.”
“Contact KnowBe4 and find out who your contact there is. Mine updates me regularly on new content and assists with setting up training. And for technical issues they’re support is good.”
“The guy managing our KnowBe4 instance quit suddenly and didn't train anyone on how to use it. So lucky me I get tasked with taking it over and I don't have any idea how to do anything. Is there any good source or materials I can use to get at least a fundamental understanding of how to assigned users...”
“I clicked it going what in the fresh hell is HR doing this is hilarious, using a throwaway secure device that's not going to fall for such attacks (e.g. no Word installed so no macro compatibility), and now I'm going to be put into some crappy remedial training.”
“We use them and have been overall pretty happy with what they offer. The rules you made should just be to ensure the mail is delivered into the users mailbox and not caught by the 0365 malware or junk filters.”
“Knowbe4 is a security awareness training platform - it's used to train users not 'get them'. If they are inspecting email headers - I will say they have been successfully trained.”
“It blew us away with how well the template they made fooled our users. That test was enough to prove to our C level exes to spend the money on the system.”
“I would find them more helpful if they didn't say that they were from KnowBe4. It's painfully obvious when they are attempting a "test" and the email says <garbage address sent via KnowBe4>. Some folks still get tripped up though so I guess it's working.”
“My CEO / compliance officer have forced me to open holes in our security for KnowBe4 to send our users spoofed emails for the purpose of anti-phishing training. This makes me uncomfortable.”
“We experienced false clicks with an open source vendor we used to use but never with Knowbe4. We ran through several other vendors over the years with the occasional whitelist issue, but no matter the vendor, you shouldn't have a problem with Barracuda.”
“I think it's stronger than most folks give it credit because the alternatives are either double the price or using incredibly outdated material. The key is that you really want to ingrain into your users that they should be using the phish alert button frequently and to be able to identify the difference between spam and phishing.”
“Knowbe4 is a really good company for training and monitoring "user errors" of security and safety. :) Three are also a number of open source training programs that can help, like GoPhish.”
“I did the training anyways just in case it's required by my company but now I'm worried I'm going to get an email telling me I fell for it and I am an idiot.”