Compare Security Awareness Training Providers UK (2026)
Compare Training, Simulations, Reporting, Behaviour Change, Support And Cost
Compare cyber security training for staff in the UK by induction learning, role-based modules, phishing and multi-channel simulations, instant coaching, reporting buttons, behavioural analytics, accessibility, languages, directory integration, administration, privacy, managed delivery, support and total cost. Evaluate providers against the same workforce, risk scenarios and measurable behaviour outcomes before launching a programme.

Train Staff To Recognise, Reject And Report Risk
The objective is safer day-to-day behaviour, not simply a high completion percentage or a punitive list of employees who clicked a simulation.
- Teach the action staff should take in realistic work situations
- Give employees a simple and trusted route to report suspicious activity
- Use simulations proportionately and provide immediate constructive coaching
- Measure reporting, repeated behaviour and risk reduction over time
Security awareness training gives employees practical knowledge and repeated opportunities to make safer decisions when using business systems and data. Programmes commonly cover phishing, business email compromise, password and authentication habits, data handling, social engineering, remote work, removable media, cloud sharing, personal-data incidents, ransomware, mobile devices and the safe use of emerging technologies.
Effective programmes combine induction, short recurring learning, role-specific content, realistic simulations, reporting practice and management follow-up. Training should reflect the organisation’s actual risks and policies. Finance staff need payment-verification scenarios, executives need targeted impersonation awareness, developers need secure-handling guidance and all users need to know how to report a suspected mistake quickly.
This page does not compare penetration testing or managed security service providers. Penetration testing examines technical systems through an authorised point-in-time assessment. An MSSP operates monitoring and other security controls. Security awareness training focuses specifically on workforce knowledge, judgement, reporting and behaviour.
Choose The Right Awareness Delivery Model
Training platforms range from simple compliance libraries to adaptive human-risk programmes. Match the model to the workforce and internal operating capacity.
| Programme Model | What It Usually Provides | Best-Fit Question |
|---|---|---|
| Annual compliance course | Delivers a scheduled course and assessment to demonstrate baseline completion | Does the programme also reinforce behaviour throughout the year, or end after one long module? |
| Continuous microlearning | Provides short, frequent modules and reminders intended to improve retention and reduce training fatigue | Can the cadence adapt to role, risk and previous behaviour without overloading users? |
| Phishing simulation programme | Sends safe simulated messages and provides immediate feedback, reporting practice and targeted follow-up | Are simulations realistic, ethical, technically controlled and connected to supportive coaching? |
| Multi-channel simulation | Extends testing beyond email to messaging, QR codes, SMS, voice or collaboration platforms where appropriate | Which channels match the organisation’s real threat exposure and employee consent expectations? |
| Role-based security learning | Targets finance, executives, developers, customer service, administrators or other groups with relevant scenarios | How are roles assigned, maintained and protected from inappropriate profiling or unnecessary data collection? |
| Human risk management platform | Combines training, simulations and behavioural signals to prioritise interventions by user or group | Which data creates the risk score, how is it explained and what decisions will the organisation make from it? |
| Managed awareness service | A provider plans campaigns, content, simulations, reports and programme reviews for the customer | Which decisions remain with the employer and how are workforce communications, privacy and culture governed? |
| In-house programme using provider content | Internal teams own the strategy and delivery while licensing content, simulations or a learning platform | Does the organisation have enough time, skill and authority to keep the programme current and measurable? |
Eight Areas That Determine Security Awareness Training Fit
Use the same workforce and behaviour criteria for every provider so content-library size and simulation volume do not hide administration or privacy gaps.
Comparison Criterion
Curriculum, Relevance And Role Coverage
Compare induction, refresher and specialist content across phishing, social engineering, payment fraud, passwords, MFA, data protection, ransomware, remote work, cloud sharing, mobile devices and safe AI use. Assess role, sector and policy customisation rather than counting library items.
Comparison Criterion
Phishing And Multi-Channel Simulations
Review email-template quality, custom domains, direct message injection, attachment and credential scenarios, QR codes, SMS, voice or collaboration-channel simulations. Confirm safe delivery, allow-listing, landing pages, immediate feedback, exclusions, seasonal controls and repeat-user treatment.
Comparison Criterion
Personalisation And Adaptive Learning
Assess knowledge baselines, behavioural signals, role, language and previous results used to assign content. Personalisation should reduce irrelevant training without creating opaque employee scores, unfair treatment or unmanaged decisions based on limited simulation data.
Comparison Criterion
Reporting And Positive Security Behaviour
Compare email-reporting buttons, suspicious-message workflows, instant confirmation, triage integration and reinforcement when staff report correctly. The programme should improve early reporting of real concerns, not teach users to hide mistakes because simulations feel punitive.
Comparison Criterion
Accessibility, Languages And Workforce Inclusion
Review WCAG-related accessibility, captions, transcripts, screen-reader support, mobile access, reading level, cultural adaptation, languages, temporary staff, volunteers, contractors, non-desk workers and users without corporate email. Test representative users before purchase.
Comparison Criterion
Administration, Automation And Integrations
Assess directory or HR synchronisation, user lifecycle, groups, scheduling, reminders, manager escalation, APIs, SSO, Microsoft 365, Google Workspace, LMS, SIEM, ticketing and email-security connections. Confirm failure handling, duplicate users and administrative effort.
Comparison Criterion
Analytics, Evidence And Programme Improvement
Compare completion, knowledge, reporting, simulation susceptibility, repeat behaviour, role trends, real phishing reports, incident themes and intervention outcomes. Require denominator, exclusions and trend definitions. Avoid league tables that shame individuals without improving controls.
Comparison Criterion
Privacy, Support And Service Governance
Review employee notice, lawful and fair data use, retention, locations, subprocessors, profiling, manager access, union or employee-relations considerations, support, implementation, content updates, managed-service boundaries, data export and deletion.
Measures To Define Before A Training Contract Is Signed
Translate engagement and human-risk reduction into consistent workforce, reporting and behavioural measures.
| Measure | What It Should Define | Evidence To Request | Common Weakness |
|---|---|---|---|
| Programme coverage | Whether every in-scope employee, contractor and relevant temporary worker receives the correct learning | Workforce source, assigned, active, new starter, leaver, exempt, overdue, role and owner | Completion is calculated only from users successfully synchronised into the platform |
| Induction completion time | How quickly new starters complete essential training before or soon after receiving access | Start date, access date, assignment, completion, manager, exception and escalation | Training is assigned monthly, leaving new users untrained for several weeks |
| Knowledge improvement | Whether users retain relevant knowledge after training rather than only passing immediate quizzes | Baseline, follow-up assessment, question design, role, interval, result and confidence | The same questions are repeated until users memorise answers |
| Simulation susceptibility | The proportion of delivered simulations in which users perform the defined risky action | Delivered users, clicks, credentials, attachments, QR action, exclusions, repeat rate and scenario | The headline rate mixes easy and highly targeted simulations without context |
| Suspicious-message reporting rate | Whether users report simulations and genuine suspicious messages through the approved route | Delivered simulations, correct reports, real reports, time to report, duplicates and false alarms | Click rate improves while staff still do not notify the security or IT team |
| Repeat-risk behaviour | Whether the same users or groups repeat risky actions after feedback and additional learning | User or cohort, scenario, intervention, subsequent result, role, support and trend | Repeat behaviour is used for blame rather than identifying process or role-specific risk |
| Real-incident contribution | Whether staff reports enable earlier investigation or reduce harm from genuine events | Report time, case classification, malicious or benign, action, avoided impact and feedback | The awareness team cannot link training results to operational security outcomes |
| Training fatigue and completion quality | Whether programme frequency and content remain proportionate and engaging | Time spent, overdue rate, drop-off, assessment attempts, feedback, accessibility issue and opt-out | More modules are assigned whenever a risk increases, regardless of relevance |
| Manager and board evidence | Whether leaders receive understandable trends, actions and ownership rather than raw user rankings | Coverage, behaviour trends, incidents, high-risk roles, interventions, unresolved actions and owner | Reports display completion percentages without explaining security decisions |
| Total cost per active learner | The complete licence, implementation, content, simulation, managed service and internal administration cost | Learners, minimums, modules, simulations, service hours, integrations, internal effort and growth | A low user price excludes phishing simulation or requires a large minimum licence band |
Security Awareness Training Providers UK Businesses Can Consider
Shortlist providers whose learning model, simulations, administration and privacy controls fit the workforce. Confirm current packages, availability and pricing directly before award.
Provider Profile
KnowBe4 Security Awareness Training
KnowBe4 provides a broad security-awareness and simulated-phishing platform with a large content library, automated campaigns, reporting tools, user-risk features and optional modules across the wider human-risk portfolio. Include it where a business wants extensive content choice, mature phishing administration and a well-established procurement route. Confirm the exact subscription level, minimum users, phishing and reporting-button rights, languages, AI and risk features, content updates, integrations, data location, customer-success model, managed services and multi-year commercial terms.
Review official KnowBe4 trainingProvider Profile
Hoxhunt
Hoxhunt centres its platform on adaptive phishing simulations, immediate microlearning, positive reporting behaviour and personalised human-risk interventions, with simulations extending across several communication channels. Include it where continuous behaviour change and reporting habits are more important than a traditional annual course library. Confirm channel availability, Microsoft or Google integration, language coverage, role personalisation, simulation controls, reporting button, managed support, risk analytics, data handling, implementation, minimum population and pricing model.
Review official Hoxhunt trainingProvider Profile
MetaCompliance
MetaCompliance provides automated security awareness, phishing simulation, policy communication and human-risk analytics, with broad language coverage and configurable campaigns. Include it where an organisation wants training, phishing and policy evidence within one platform and values structured implementation support. Confirm the selected modules, user and administrator licences, content languages, custom content, simulation delivery, policy-management boundaries, manager access, risk scoring, SSO and directory integration, support, data region, retention and implementation services.
Review official MetaCompliance awarenessProvider Profile
SoSafe
SoSafe provides behaviourally informed, gamified microlearning, personalised security-awareness content, phishing and multi-channel simulations and human-risk analytics. Include it where employee experience, European delivery and adaptive learning are priorities. Confirm the exact platform modules, simulation channels, languages, accessible content, role targeting, risk scoring, integrations, managed-service options, privacy settings, employee communications, data location, onboarding, renewal and whether advanced functions require separate commercial tiers.
Review official SoSafe trainingProvider Profile
Proofpoint ZenGuide
Proofpoint ZenGuide combines targeted security education, phishing simulations, user-risk insights and behavioural or role-based intervention within Proofpoint’s human-risk proposition. Include it where a business already uses Proofpoint email security or wants awareness informed by wider threat exposure. Confirm whether the quote is ZenGuide or legacy Security Awareness Training packaging, content and simulation rights, languages, user-risk signals, reporting integrations, Proofpoint Essentials suitability, support, data processing, administrator effort and required wider Proofpoint products.
Review official Proofpoint human-risk trainingProvider Profile
Mimecast Engage
Mimecast Engage provides continuous awareness learning, phishing simulation, personalised intervention and human-risk reporting through Engage Core and Engage Pro within Mimecast’s broader Human Risk Management Platform. Include it where email risk signals, Mimecast integration or short recurring content are important. Confirm the current Core or Pro edition, standalone availability, simulation and reporting features, integrations, risk signals, content, languages, support, data retention, user minimums, email-platform dependencies and whether existing Mimecast licences create overlap or commercial advantage.
Review official Mimecast EngageProvider Profile
Arctic Wolf Managed Security Awareness
Arctic Wolf Managed Security Awareness provides a managed awareness programme using recurring microlearning, quizzes, phishing simulations and concierge-style programme support. Include it where a lean internal team wants the provider to operate campaign administration while the employer retains policy, culture and employee governance. Confirm whether the awareness service can be bought independently, included content and simulation cadence, administrator access, integrations, reporting, employee data, managed responsibilities, service contacts, support region, minimum term and separation from Arctic Wolf’s MDR services.
Review official Arctic Wolf awarenessProvider Profile
usecure
UK-founded usecure provides adaptive awareness training through uLearn, phishing simulations through uPhish and a wider human-risk platform designed for internal teams and managed-service partners. Include it where an SME wants automation, short personalised learning and partner-led deployment. Confirm the exact modules, minimum users, phishing domains and templates, reporting button, languages, custom content, policy functions, dark-web or breach modules, partner administration, support, data processing, contract term and the difference between direct and MSP-managed service.
Review official usecure trainingWhat Changes Security Awareness Training Cost
The per-user licence is only one component. Simulations, languages, managed delivery, integrations and internal programme ownership can materially change the budget.
| Cost Driver | Why It Changes Spend | What A Comparable Proposal Should Show |
|---|---|---|
| Active learners and minimum licence band | Providers may price per user, employee band or minimum annual population | Employees, contractors, seasonal workers, growth, inactive users, minimums, true-up and reduction rights |
| Training and simulation modules | Awareness content, phishing simulations, reporting buttons, policy modules and advanced human-risk features may use separate tiers | Exact products, included campaigns, channels, content, limits, add-ons and duplicated tools |
| Languages and custom content | Additional languages, localisation, branding, policy-specific modules and custom video or scenario production can increase cost | Required languages, editing rights, custom modules, review, accessibility, ownership and update charges |
| Managed programme service | Campaign planning, scheduling, user management, reports and reviews may be delivered by the vendor or a partner | Included hours, decisions, communications, changes, reporting, service levels and out-of-scope work |
| Phishing and multi-channel simulation | Advanced templates, custom domains, SMS, voice, QR or collaboration-platform simulations may require higher tiers or usage fees | Channels, messages, domains, mobile costs, frequency, technical setup, approvals and overage |
| Integrations and implementation | Directory synchronisation, SSO, reporting buttons, SIEM, LMS, HR and ticketing integration require setup and support | Systems, connectors, professional services, customer tasks, testing, failure handling and ongoing ownership |
| Risk analytics and data retention | Longer history, advanced user scoring, cross-product signals, benchmarking and exports may be premium functions | Metrics, data inputs, retention, exports, API, manager access, privacy controls and deletion |
| Support and customer success | Named success managers, programme reviews, technical support and content guidance vary by package | Hours, channels, response, named contact, quarterly review, training, escalation and additional rates |
| Contract term and user changes | Multi-year discounts, licence floors, annual uplifts and acquisition growth affect lifetime cost | Term, renewal, uplift, cancellation, user increase, reduction, transfer and unused licences |
| Exit and data transfer | Campaign history, user results, risk trends, content, custom templates and reporting-button removal create transition work | Export formats, data retention, custom-content rights, integration removal, assistance and deletion |
How The Workforce Changes The Shortlist
The right platform depends on workforce scale, languages, risk concentration, internal ownership, privacy expectations and existing communication technology.
Small Business With Limited Administration
Prioritise automatic user synchronisation, short relevant learning, sensible default simulations, clear employee reporting, proportionate managed support and straightforward pricing without enterprise-only complexity.
Regulated Or Data-Intensive Organisation
Prioritise induction and refresher evidence, role-specific learning, accessibility, policy alignment, data-protection content, manager reporting, retention controls and defensible programme governance.
Microsoft 365 Or Email-Security-Centred Environment
Prioritise reliable message injection, reporting-button integration, directory groups, real-threat feedback, SIEM or ticketing workflows and clarity on whether existing security licences duplicate platform functions.
Enterprise Or International Workforce
Prioritise languages, cultural localisation, complex roles, multiple directories, distributed administration, behavioural analytics, employee-relations controls, data locations and scalable campaign governance.
How To Compare Training Proposals
Give every provider the same workforce profile, directories, locations, roles, languages, induction requirement, threat scenarios, simulation channels, reporting process, privacy constraints, integrations and programme-owner capacity. Require each response to show the exact platform and service responsibilities.
- Content and scenarios map to real employee actions and policies
- Simulations are technically safe, proportionate and supportive
- Completion, reporting and behaviour metrics use consistent definitions
- Accessibility, non-desk users and temporary workers are demonstrated
- Employee data, profiling and manager visibility are controlled
- Campaign history, custom content and integrations are covered at exit
Make Every Provider Demonstrate The Same Workforce Journey
Use one new starter, finance approver, executive, remote worker, contractor and repeat simulation responder across the same 90-day programme.
Compare assignment, learning relevance, simulation, reporting, manager action and evidence before comparing content-library size.
Six Questions To Put To Every Awareness Provider
The answers expose irrelevant content, weak measurement, excessive employee profiling and hidden managed-service effort before the agreement starts.
How Will The Programme Change Employee Behaviour?
Ask for the learning model, reinforcement, simulation feedback, reporting practice, repeat-user support and the evidence used to improve the programme.
Which Users, Roles And Languages Are Covered?
Confirm employees, contractors, temporary staff, non-desk workers, executives, finance, administrators, locations, languages and accessibility.
How Are Phishing Simulations Controlled?
Request delivery method, allow-listing, templates, custom domains, landing pages, data captured, ethical rules, exclusions, multi-channel use and technical support.
Which Metrics Will Managers And The Board Receive?
Define coverage, completion, knowledge, susceptibility, reporting, repeat behaviour, real-event contribution, trends, actions and user-level access.
How Is Employee Data Used And Protected?
Confirm purpose, data sources, profiling, lawful and fair use, locations, subprocessors, retention, manager visibility, export and deletion.
What Work Is Included In Implementation And Ongoing Service?
Separate directory setup, SSO, reporting button, campaign planning, custom content, managed administration, reviews, support, changes and exit.
A Seven-Stage Security Awareness Training Evaluation
Move from workforce risks to measured behaviour change rather than buying a library before defining the decisions employees must make safely.
- Identify workforce groups, business risks, recent incidents, employee-reporting routes, existing training, policies, languages, accessibility needs and accountable programme owners.
- Define behaviour outcomes such as recognising payment fraud, protecting credentials, handling data safely and reporting suspicious messages or mistakes quickly.
- Choose an in-house, platform-led or managed delivery model while keeping technical penetration testing and MSSP procurement outside the programme scope.
- Issue one written brief and obtain comparable platform, content, simulation, privacy, implementation, managed-service and three-year commercial responses.
- Run a representative pilot with new starters, high-risk roles, non-desk or remote users, accessibility needs, reporting workflows and a controlled simulation.
- Roll out in stages with workforce communications, manager guidance, directory reconciliation, induction, recurring learning, support and approved metrics.
- Operate through regular programme review, real-incident lessons, content updates, simulation governance, employee feedback, privacy review and annual commercial optimisation.
Security Awareness Training Comparison Checklist
Use this table before approving a training platform, phishing-simulation programme or managed-awareness service.
| No. | Requirement | Evidence To Obtain Before Award | Confirmed |
|---|---|---|---|
| 01 | Workforce scope and accountable owner agreed | Employees, contractors, temporary staff, volunteers, locations, languages, non-desk users and programme owner | |
| 02 | Behaviour and business-risk outcomes defined | Phishing, payment fraud, credentials, data handling, remote work, reporting, AI use and role-specific risks | |
| 03 | Induction and refresher requirements approved | Assignment timing, completion period, recurring cadence, managers, reminders, exceptions and escalation | |
| 04 | Content and role coverage demonstrated | Modules, roles, languages, policies, sectors, custom content, accessibility and update frequency | |
| 05 | Simulation scope and ethics accepted | Email, QR, SMS, voice or collaboration channels, scenarios, exclusions, feedback, data and employee communication | |
| 06 | Reporting route and operational handoff tested | Reporting button, mailbox, ticket, triage, confirmation, response, evidence and real-incident workflow | |
| 07 | Directory and user lifecycle validated | HR or identity source, groups, new starters, movers, leavers, duplicates, failed sync and owner | |
| 08 | Accessibility and inclusion tested | Captions, transcripts, screen reader, mobile, reading level, language, non-email users and reasonable adjustments | |
| 09 | Metrics and denominators approved | Coverage, completion, knowledge, susceptibility, reporting, repeat behaviour, exclusions and trend definitions | |
| 10 | Employee-data governance accepted | Purpose, notice, profiling, lawful and fair use, manager access, locations, subprocessors, retention and deletion | |
| 11 | Managed and internal responsibilities agreed | Campaigns, content, user management, communications, simulations, reports, manager action and support | |
| 12 | Pilot and rollout plan accepted | Representative groups, technical setup, baseline, feedback, corrections, communications, support and success criteria | |
| 13 | Evidence and improvement process defined | Real incidents, user reports, trends, repeat behaviour, actions, owner, due date and programme changes | |
| 14 | Three-year total cost compared | Users, minimums, modules, simulations, managed service, integrations, internal effort, employee time and growth | |
| 15 | Exit and data-transfer terms agreed | Users, completion, simulation history, reports, custom content, integrations, removal, assistance and deletion |
Common Security Awareness Training Buying Mistakes
Most avoidable failures begin with compliance-only objectives, punitive simulations or metrics that reward activity rather than safer behaviour.
| Mistake | Why It Creates Risk | Better Control |
|---|---|---|
| Buying an annual course only | Knowledge fades and the programme does not respond to changing threats or roles | Use recurring relevant reinforcement |
| Measuring completion as the main outcome | A completed module does not prove safe behaviour or timely reporting | Track behaviour and operational contribution |
| Using humiliating phishing simulations | Employees hide mistakes, distrust the programme and stop reporting genuine concerns | Use supportive, proportionate coaching |
| Covering staff awareness with an MSSP contract | Managed security monitoring does not automatically provide a complete workforce-learning programme | Procure and govern awareness separately |
| Mixing penetration testing into the training scope | Technical system assessment uses different objectives, skills and evidence | Keep the service boundary workforce-specific |
| Training every employee identically | Generic content wastes time and misses role-specific payment, data or privilege risks | Use targeted role and behaviour pathways |
| Ignoring contractors and non-desk workers | Significant users remain outside the reporting and training process | Map the complete workforce |
| Running simulations without a reporting workflow | Staff learn to spot suspicious messages but cannot escalate them effectively | Integrate a trusted reporting route |
| Publishing individual league tables | Shaming can create employee-relations risk without improving security decisions | Use controlled coaching and cohort trends |
| Keeping programme data indefinitely | Detailed employee behaviour records create unnecessary privacy and access risk | Set proportionate retention and deletion |
Frequently Asked Questions
Answers to common questions from UK businesses comparing staff cyber-security training platforms and managed programmes.
What Is Security Awareness Training?
Security awareness training helps employees understand cyber and data risks and make safer decisions at work. Effective programmes combine induction, recurring learning, role-specific content, practical simulations, reporting practice and feedback rather than relying on one annual compliance course.
Which Employees Need Cyber Security Training?
Training should cover all employees and relevant contractors, temporary staff and volunteers who use business systems or handle information. Executives, finance, administrators, developers and data-intensive roles may need additional content based on their access and exposure.
How Often Should Security Awareness Training Be Delivered?
Use induction before or soon after system access, followed by short recurring learning and reminders throughout the year. The right cadence depends on workforce risk, incidents and role. Frequent irrelevant assignments can create fatigue, so programmes should remain proportionate.
Are Phishing Simulations Necessary?
Simulations can help employees practise recognising and reporting suspicious messages, but they should be safe, proportionate and supportive. They are most useful when connected to immediate coaching, a working reporting process and trends that improve controls rather than shame individuals.
What Topics Should Security Awareness Training Cover?
Common topics include phishing, business email compromise, payment verification, passwords, MFA, social engineering, data handling, ransomware, remote work, mobile devices, cloud sharing, removable media, personal-data incidents and safe use of generative AI tools.
How Should A Business Measure Training Effectiveness?
Measure workforce coverage, induction timeliness, knowledge retention, simulation susceptibility, suspicious-message reporting, time to report, repeat behaviour, real-incident contribution and completed improvement actions. Completion alone shows activity, not reduced risk.
Does Security Awareness Training Satisfy UK GDPR Requirements?
Training can support organisational security and accountability obligations, but buying a platform does not by itself prove compliance. Programmes should reflect employee roles, personal-data risks, induction and refresher needs, incident reporting, documented oversight and effectiveness review.
How Much Does Security Awareness Training Cost?
Cost depends on active learners, minimum licence bands, content, simulations, languages, managed service, integrations, support and contract term. Compare a three-year total including internal administration and employee time rather than only the advertised per-user licence.
Should Security Awareness Training Be Outsourced?
Outsourcing may suit organisations without enough time or expertise to plan campaigns and analyse results. Internal ownership is still required for policies, employee communication, risk decisions and manager action. Compare a managed service with a platform-led in-house model using the same outcomes.
How Should A UK Business Compare Awareness Providers?
Give every provider the same workforce, roles, languages, risks, simulation channels, reporting process, privacy constraints and integrations. Compare the configured learning journey, pilot evidence, administration, support, three-year cost and exit—not only content volume or phishing-click rates.
Official Guidance And Security Awareness Provider Resources
Reviewed by Bhav Giva, Founder & Lead Analyst at CompareServices.co.uk, on 17 July 2026.
Use NCSC, ICO, UK Government and official provider documentation to confirm current platform modules, simulation channels, privacy terms, integrations, support and pricing. Product names and human-risk features can change during procurement.
- NCSC — Defending Organisations Against Phishing
- NCSC — Exercise In A Box
- ICO — Training And Awareness
- UK Government — Cyber Security Breaches Survey 2025/2026
- KnowBe4 — Security Awareness Training
- Hoxhunt — Security Awareness Training
- MetaCompliance — Automated Security Awareness
- SoSafe — Security Awareness Training
- Proofpoint — ZenGuide Human Risk Management
- Mimecast — Engage Awareness Training
- Arctic Wolf — Managed Security Awareness
- usecure — Security Awareness Training
