Security Awareness Training

Checkbox training doesn't change behavior. Point-of-failure training does.

Outdated annual training won't stop phishing. We run a continuous program: threat-aligned simulations, instant training upon failure, and metrics tracking real behavior, not completion rates.

Quarterly
Minimum cadence, set
in your SOW
Custom
Built for your threats
and industry
3 to 30 days
Setup time, based on
user data speed
4 hrs
Turnaround on changes, business hours

We track behavior, not completion rates.

The Difference

We tune every simulation to threats active in your industry. Your consistent team tracks performance by department and adjusts difficulty as your people improve.

Track your team's behavior

Every simulation tuned to your industry, every training triggered at the point of failure. Every department tracked over time, not just once a year.

Proof point

How it works

Training is the easy part. Follow-through is what makes it work.

One-time setup. Tenant configured, users synced, first campaign validated before launch.

1. Tenant & Branding Setup

KnowBe4 tenant configured with your branding, domains, and admin access controls.

2. Identity Provider Integration

Automated sync via Active Directory, SCIM, or Google Workspace (or manual list via TAM with 4-hr SLA for changes).

3. Threat-Aligned Template Build

Senior SOC Analysts build custom phishing templates tailored to your specific industry and vertical risks.

How we stay accountable

Every campaign logged. Every month reported, without exception.

Security awareness without accountability is a completion report nobody reads twice. A consistent TAM owns your program, tracks behavior trends over time, and prepares the monthly report.

Your Team

  • CX Manager — relationship owner, service escalations, on-demand leadership reviews
  • TAM — owns the SAT program, prepares the monthly report, tracks completion and click trends
  • Senior SOC Analyst(s) — build and configure phishing templates, manage platform setup

Communication Cadence

  • Monthly report — sent automatically, no live call required
  • Standalone quarterly review — for SAT-only customers
  • Folded into existing reviews — for bundled customers, part of your SIEM/EDR/VM cadence
  • Platform support — OneAxiom is your one point of contact with KnowBe4

Monthly Report Includes

  • Campaign completion by department
  • Click-rate trend over time
  • Repeat-miss flagging for follow-up
  • Template performance by threat type
  • Training records for compliance documentation

5

compliance frameworks require training

3

training formats: quizzes, puzzles, videotrending down

4x

Formal simulations per
year, minimum

4 hrs

Turnaround on user
changes

Why this matters

Running simulations isn't a training program. Here's the difference.

Behavior changes, not just completion rates

Completion rates tell you who finished the module. Click rate trends tell you whether behavior is actually changing.

Training fires at the point of failure

When someone clicks a simulated phishing link, training launches in their browser immediately, not in the next scheduled campaign.

Risk is tracked, not assumed

Monthly reports show completion rates, click trends, and department risk scores. The program never resets.

Your SOC gets smarter too

Repeat-click patterns become part of your ongoing risk profile, reviewed alongside the rest of your security program.

How often are phishing simulations run?

Continuously, with at minimum one formal exercise per quarter. Simulation frequency and difficulty are tuned based on your team's performance over time.

If you want simulations more often than the standard monthly cadence, we'll train your team to self-manage those additional off-cadence campaigns directly in the platform.

Can you integrate with our HR system or Active Directory for user management?

Yes. We support Active Directory, SCIM, and Google Workspace for automated user sync, along with manual list management through your TAM for customers without automated provisioning.

What tools do we need to buy first?

None. OneAxiom is built to work with your existing stack wherever possible.

What happens when someone clicks on a phishing simulation?

A training module fires immediately in the browser, not in the next scheduled campaign.

The module explains what made the simulation convincing and what to watch for. The moment of failure is the most effective time to teach.

How do you handle users who repeatedly fail phishing simulations?

Repeat offenders are tracked and surfaced in the monthly report. We flag them to your designated contact.

What happens next, whether that's additional training, manager notification, or HR involvement, is your organization's call.

Do you produce reports for compliance or cyber insurance purposes?

We don't produce a single standard report, since different frameworks and different auditors tend to ask for different things.

What we do is help gather or generate the specific artifacts your auditor or insurer requires, built to their request rather than off a template.

What if our team has low participation rates?

Participation depends partly on internal leadership sponsorship: we flag the issue, you have the lever to pull.

On the platform side, we adjust reminder cadence, escalate delinquencies to your contact, and can recommend training content that tends to drive higher engagement.

Any users not completing mandatory training get raised with your team during your regular review meetings or by email, depending on how often those meetings happen.

Got questions

Frequently asked

Security Awareness Training

Book a 30 min call

No commitment yet. We'll walk through your environment and see if there's a fit.

Book your call