Tekspace Research

Security Awareness Training

A Cyber SaaS Analysis 2026
New domain assessments as they publish. Unsubscribe any time, and we never share or sell your data.

Foreword

The real problem with security awareness training happens before the product is chosen.

Cyber training programs are typically evaluated and purchased by IT and cybersecurity teams. Criteria is technical, shaped by vendor demos, largely disconnected from the people in the business: what shifts their behaviour and fits into busy days?

If this vital human question is skipped in selection, no feature list alone will deliver lasting change. This report shows why teams need executive sponsorship, and effective socialisation.

Without these foundations, adoption stays low regardless of which platform is selected. Teams go back to market blaming the product for what the program never delivered.

Meanwhile, attackers study supply chains and org charts, pull data from LinkedIn and public records, and use AI to produce requests near-indistinguishable from legitimate ones.

The capacity of any workforce to absorb, retain, and act on security knowledge under pressure has a ceiling. Beyond it, the responsibility shifts to the defence-in-depth layers that wrap around your people: email security, endpoint controls, identity management.

This report is produced in collaboration with Parabellum, Byte and CodeBlue New Zealand. We examined 20 platforms, assessing the cyber curriculums that deliver lasting change.

This report finds that people are not the problem. They can be a solution with the right training solution.

Portrait photo of Frank De Pasquale
Frank De Pasquale
CEO at Tekspace

Threat Context

Insights from Parabellum Logo

CREST Pen Test certification badge. OffSec OSCE3 certification badge OffSec OSCE certification badge OffSec OSCP certification badge OffSec OSEP certification badge OffSec OSWE certification badge OffSec OSED certification badge OffSec OSWP certification badge OffSec OSAI certification badge

Security awareness training is growing the skills gap

Most organisations train staff once a year1: a 20-minute module, filed for audit. It satisfies the checkbox. It does not change behaviour.2

That tracks with Ebbinghaus' 1885 forgetting curve3 and later studies: infrequent training produces only a minimal, short-lived lift. An Adelaide study found phishing-identification gains from training had disappeared within six months.4

The Australian Information Commissioner recorded 1,113 notifiable data breaches in 2024, the highest annual total since the NDB scheme began.5

Human factors, including phishing, credential theft and social engineering, were implicated in roughly 45% of all incidents.1 The skills gap between staff and attackers keeps widening.

Attacker AI vs. SAT AI · 2020–2026

The adoption gap

Attacker AI adoption
SAT AI deployment
0% 25% 50% 75% 100% 2020 2021 2022 2023 2024 2025 2026 ChatGPT launches 31% less effective than human-crafted

Attacker AI · 2025

24% more effective than human-crafted phishing
~80% of attacks AI-generated

SAT programmes · 2025

7.5% personalise training to individual risk

0% 50% 100% 2020 2021 2022 2023 2024 2025 2026 ChatGPT launches Attacker AI · 2025 24% more effective than human-crafted phishing ~80% of attacks AI-generated SAT programmes · 2025 7.5% personalise training to individual risk

Sources: Brightside AI (2025); e-Bits (2025). Attacker adoption indexed to AI-generated phishing prevalence. SAT personalisation rate (7.5%, 2025) confirmed; 2020–2024 training trend estimated. 2026 values projected.

Training can't teach beyond the inbox

Tekspace's Email Security research confirms email as the dominant breach vector in Australia.1 But the attack surface has moved past the inbox, and training hasn't followed.

Channels training leaves uncovered · 2025
Voice phishing 4x

Surged in the past year.6 Only one in five organisations train staff to spot it.7

SMS phishing 2x+

More than doubled in the same period,8 with training coverage just as thin.

QR code phishing Untested

An established vector, and one we did not see assessed in the training programs we reviewed.

AI widens the gap further. By 2025, AI-generated phishing outperformed human-crafted lures by 24%9 and made up an estimated 80% of all phishing traffic.10

Deepfakes compound the risk: Mastercard-commissioned research found 20% of Australian businesses received deepfake threats in the prior 12 months,11 yet most trusted training vendors have no plan to add deepfake capability within six months.12

For organisations holding customer data, that coverage gap means training no longer satisfies the OAIC's APP 11 requirement to safeguard personal information.

The regulatory cost of inadequate training

In 2025, the Federal Court handed down the first civil penalty ever issued under the Privacy Act for a data breach: $5.8 million against Australian Clinical Labs13. The court specifically noted that “the IT team leader had no formal cybersecurity training and had never seen the organisation's cyber playbooks”.

In 2024, an enforceable undertaking against Oxfam Australia became the first to explicitly mandate a security awareness training program.6 Across the regulated economy, the bar for adequate training has moved from completion to demonstrated behaviour change.

For the first time ever, cybersecurity training is now a business obligation, not an IT task. When a breach happens, businesses face a greater financial cost from the government than the APTs.

Regulatory penalties · Australia 2025

Privacy Act $50M

The maximum civil penalty for a serious or repeated privacy interference, or 30% of adjusted turnover if that's greater.

Privacy Legislation Amendment Act 2022 →
SOCI Act $660K

The maximum daily penalty for non-compliance with a critical infrastructure risk management program, across the Act's 11 regulated sectors.

Security of Critical Infrastructure Act 2018 →
APRA CPS 234

Requires APRA-regulated entities to test their information security controls, phishing resilience included, at least annually, and to report material failures directly to the Board.

CPS 234 Information Security →
OAIC determination, October 2025 $5.8M

Australian Clinical Labs: first civil penalty in Privacy Act history. $4.2M for failing to protect personal information, plus $1.6M for failing to assess and notify the breach. The court cited no formal cybersecurity training for key IT staff.

OAIC media release →
Enforceable undertaking 1st

Oxfam Australia's undertaking mandates an ongoing privacy and information security training program for staff, contractors and volunteers, with regular refresher training required.

OAIC enforceable undertaking →

In 2025, Australian and New Zealand staff record the third highest phish-prone rate in the world.14

That ranking alone warrants attention.

The deeper problem is the awareness-action gap that knowledge-based training alone can't close: post-incident reviews show staff who take the risk know it's risky and proceed anyway.19

Legacy modules can inform, but they can't change behaviour under pressure, deadline, or the authority cues modern social engineering exploits. The psychology is well understood; building programs that account for it is the challenge.

Shift the goal from compliance to sustained behavioural change, and the human layer moves from liability to a functioning part of the organisation's cyber strategy.

Security Awareness Training 2026

Assessing the security awareness training market?

We can help in two ways.

  • 37 capabilities scored
  • 20 of 20 offer a report button in the inbox
  • 4 of 20 simulate deepfakes of your own executives
  • 3 of 20 teach a structured curriculum, in order
  1. Start with the guide

    Our category breakdown sets out the threats driving this category and the capabilities that separate the platforms, with how many of the 20 cover each one.

  2. Then assess it with us

    Bring the capabilities your environment can't do without. We'll show you which platforms meet them and where your security awareness training spend goes furthest. If nothing fits, we step out.

Assess the market with us

Tell us about your environment and we'll be in touch to find a time.

Security Outcomes

With the threat context as a backdrop, what do information technology professionals prioritise when considering a new security awareness training solution?

What matters in your assessment? Whatever the domain, a security product earns its place against the same four outcomes. Expand each to see how we assess the security awareness category.

1

Efficacy

  • Simulation coverage across email, SMS, voice, QR and deepfake lures
  • A reporting button in the mail client so staff can flag what they spot
  • Adaptive difficulty that responds to how each person performs
2

Operational Efficiency

  • Campaigns, enrolment and follow-up training orchestrated without administrator scheduling
  • Risk-based targeting that selects its own audiences each cycle
  • Multi-tenant administration, with LMS or SSO integration where required
3

Reporting and Analytics

  • A behavioural risk score per person, team and organisation, tracked over time
  • Policy attestation and completion records held as compliance evidence
  • Board-level summaries alongside a SIEM feed for the security team
4

User Experience

  • Content localised and matched to role, industry and language
  • Interactive modules and hands-on labs rather than passive completion
  • Branding and tone that earn attention instead of demanding compliance

Product Landscape

This is a crowded category: we screened more than 70 vendors offering some level of training. We’ve ranked the 20 platforms that deliver phishing simulation, in-email reporting and awareness education on the Tekspace Cyber Continuum™ to show what makes the top platforms so effective for buyers.

Focused

  • Hacker Rangers Icon
    Hacker Rangers
  • ID Agent
    ID Agent
  • CyberHoot Icon
    CyberHoot
  • Boxphish Icon
    Boxphish
  • Riot Icon
    Riot
  • Mimecast Icon
    Mimecast

Features

  • Phishing Simulations
  • Training Content Library
  • Interactive Training Modules
  • Continuous Assessment
  • Performance Reporting
  • Platform Customisation
  • Security Baselining
  • AI-Generated Simulation Content
  • Gamification
  • White-Label Branding
  • Behavioural Risk Scoring
  • In-Email Report Button

Broad

  • Huntress Icon
    Huntress
  • uSecure Icon
    usecure
  • MetaCompliance Icon
    MetaCompliance
  • SANS Institute Icon
    SANS Institute
  • Ninjio Icon
    Ninjio
  • Infosec IQ Icon
    Infosec IQ
  • Barracuda Icon
    Barracuda
  • Immersive Labs Icon
    Immersive Labs
  • SoSafe Icon
    SoSafe
  • Proofpoint Icon
    Proofpoint

Features

  • Advanced Analytics & Dashboards
  • Adaptive Learning Engine
  • Smishing Simulation
  • Single Sign-On
  • LMS & Third-Party Integration
  • Multilingual Content
  • Policy & Compliance Management
  • Multi-Tenant Management
  • REST API
  • SIEM Integration

Comprehensive

See Vendors and Features
Hoxhunt Icon
Adaptive Security Icon
Phished Icon
KnowBe4 Icon

Comprehensive

  • Hoxhunt Icon
    Hoxhunt
  • Adaptive Security Icon
    Adaptive Security
  • Phished Icon
    Phished
  • KnowBe4 Icon
    KnowBe4

Features

  • Vishing Simulation
  • QR Code Phishing (Quishing)
  • Dark Web & Breach Monitoring
  • AI-Powered Spear Phishing Personalisation
  • Automated Risk-Based Simulations
  • Custom Scenario Builder
  • Threat Intelligence Reporting
  • Role & Industry-Specific Content
  • Autonomous Training Orchestration
  • Autonomous Phishing Simulation Orchestration
  • Geo-Contextual Simulation Targeting
  • Content Authoring Tools
  • Hands-On Labs & Skills Assessment
  • Structured Learning Paths
  • Deepfake Simulations
  • Data Sovereignty

We collated 380+ unique vendor features across the twenty vendors, normalising them down to 37 scored capabilities in 9 capability groups, each group sitting under one of the four outcomes above. A weighted scoring model then produces a single maturity score per vendor: a picture of feature depth, not just feature count.

Want to know which of these fits your environment? We help with that.

A logo on a chart does not tell you whether the content will land with your people, in their languages and their roles, or just record another completion.

Book your session

Conclusion

Start with the learning model, not the feature list.

The quickest way to assess a platform's maturity is how it teaches.

Platforms built like a library hand administrators a content catalogue and hope for the best. Others work like an exam, training only on failure. Neither reliably changes behaviour.

The model that produces measurable change is a curriculum. Sequenced content that builds foundations first, repeats the basics, layers complexity, and adapts to each person's skill level and susceptibility traits. IT teams often find this approach too simple. That is their lens, not their workforce's.

With automated set ups or smart baselining the best platforms deliver value from day one, not after six months is spent setting up the curriculum.

Because a platform is only half the investment. Without executive support, without socialising why it's being done, without normalising failure, adoption will be low regardless of platform.

And it is why teams go back to market blaming the solution.

An opportunity to reimagine your training

Once-off induction sessions and annual modules are not delivering the outcomes Australian organisations need.

Technical controls handle what they can. Between what technology covers and what falls through the cracks, a well-run training program is the highest-return investment most organisations have not yet made properly.

If your current program is not producing measurable behaviour change, we can help. We will map your program against the outcomes in this report, identify the gaps, and match you with the platform best suited to your people, your compliance obligations, and your risk profile.

We're having this exact conversation right now, as security teams lock in next year's training program. When you're ready to pressure-test your current program against these outcomes, you can book time with Tekspace directly.

Addendum

Credits

In launching this report, the Tekspace would like to acknowledge contributions from the following teams and individuals.

Contributors

  • Lead Analysts — Frank De Pasquale, CEO at Tekspace.
  • Threat Context — Martin Dybalski, Director; Stuart Shanahan, Director of Technical Services; and Kris Bowen, Senior Offensive Security Consultant, all at Parabellum.
  • Security Outcomes — Mathew Jose, Chief Information Security Officer at CodeBlue New Zealand; and Stacy Gurrie, Chief Executive Officer at Byte.
  • Research and analysis by the Tekspace Research team.

References

  1. Australian Signals Directorate (2025), ASD Annual Report 2024-25
  2. Australian Federal Police (2025), Criminals target construction sector with Business Email Compromise scams
  3. Australian Signals Directorate (2025), Annual Cyber Threat Report 2024-25: fact sheet for businesses and organisations
  4. Practice Protect AU (2025), The devil is still in the email: what BEC looks like in 2025.
  5. Riposte Cybersecurity Consultancy (2025) Phishing threats in Australia's legal sector
  6. Australian Institute of Criminology (2024), Cybercrime in Australia 2023-24
  7. DeepStrike (2025), AI cybersecurity threats 2025: how to survive the AI arms race
  8. Keepnet Labs (2024), Navigating the email security market in 2025
  9. Abnormal Security (2024), H1 2024 Phishing Frenzy: C-suite receives 42x more QR code attacks than average employee
  10. Integris (2025) 2025 Integris report: law firms, cybersecurity and AI - what clients really think
  11. Google Threat Intelligence Group, Mandiant & Google Security Operations, (2025) Cybersecurity Forecast 2026
  12. VIPRE Security Group (2025) Cyber threats in 2025: how AI is changing phishing tactics
  13. StrongestLayer (2025) StrongestLayer secures US$5.2M to combat emerging AI-driven email threats
  14. Australian Cyber Security Magazine (2025), KnowBe4 research reveals most phish-prone countries (KnowBe4 Phishing by Industry Benchmarking Report 2025).

Security Awareness Training category

What this report does and doesn’t claim to cover, how we compare products fairly, and what to do if you still have questions.

Scope

This report evaluates platforms delivering phishing simulations, in-email reporting, and cybersecurity awareness education. It does not cover standalone email security gateways, broader governance/risk/compliance platforms, or physical security awareness programs.

Twenty-three vendors were researched. Three were excluded as out-of-category following technical review, leaving 20 platforms in the final evaluation.

Feature Granularity Model

We compare products at what we call Level 2: The Functional Group: specific enough to be meaningful, broad enough to compare very different products fairly, without losing sight of how they’re meaningfully different.

Further questions

Why isn't annual or compliance-driven training enough on its own?

Most organisations still train staff once a year with a single module that satisfies a regulatory checkbox but proves attendance, not behaviour change. As this report's threat context shows, any improvement from one-off training measurably fades within months, while attackers increasingly use AI to produce phishing that is more convincing than anything a once-a-year module prepares people for.

How is this different from a one-off phishing simulation or a training content library?

A single simulated phishing test or a library of modules staff pick through on their own proves attendance, not behaviour change. The platforms in this report run a continuous, sequenced curriculum that adapts to each person's risk profile instead, which is the model most training programs have not yet adopted.

How were the 20 vendors in this report actually compared?

We normalised the market to a shared set of scored features and assessed each vendor at what we call the Functional Group level: specific enough to be meaningful, broad enough to compare very different products fairly. See Feature Granularity Model above for how that scale works.

What happens if I want another vendor assessed?

Get in touch. This report focuses on solutions widely regarded as market leaders or strong emerging players, not every product on the market, and we are glad to look at ones we have not yet covered.

Disclaimers

Findings reflect our professional judgement at the time of publication, based on the data available to us. Product capabilities and roadmaps change, so organisations should treat this report as a guide to practical decision making, not as a substitute for their own due diligence.

If you have identified errors in this report, or wish to have another product assessed, please contact our team.

Contact our team
Close

Focused

  • Hacker Rangers Icon
    Hacker Rangers
  • ID Agent
    ID Agent
  • CyberHoot Icon
    CyberHoot
  • Boxphish Icon
    Boxphish
  • Riot Icon
    Riot
  • Mimecast Icon
    Mimecast

Features

  • Phishing Simulations
  • Training Content Library
  • Interactive Training Modules
  • Continuous Assessment
  • Performance Reporting
  • Platform Customisation
  • Security Baselining
  • AI-Generated Simulation Content
  • Gamification
  • White-Label Branding
  • Behavioural Risk Scoring
  • In-Email Report Button
Close

Broad

  • Huntress Icon
    Huntress
  • uSecure Icon
    usecure
  • MetaCompliance Icon
    MetaCompliance
  • SANS Institute Icon
    SANS Institute
  • Ninjio Icon
    Ninjio
  • Infosec IQ Icon
    Infosec IQ
  • Barracuda Icon
    Barracuda
  • Immersive Labs Icon
    Immersive Labs
  • SoSafe Icon
    SoSafe
  • Proofpoint Icon
    Proofpoint

Features

  • Advanced Analytics & Dashboards
  • Adaptive Learning Engine
  • Smishing Simulation
  • Single Sign-On
  • LMS & Third-Party Integration
  • Multilingual Content
  • Policy & Compliance Management
  • Multi-Tenant Management
  • REST API
  • SIEM Integration
Close

Comprehensive

  • Hoxhunt Icon
    Hoxhunt
  • Adaptive Security Icon
    Adaptive Security
  • Phished Icon
    Phished
  • KnowBe4 Icon
    KnowBe4

Features

  • Vishing Simulation
  • QR Code Phishing (Quishing)
  • Dark Web & Breach Monitoring
  • AI-Powered Spear Phishing Personalisation
  • Automated Risk-Based Simulations
  • Custom Scenario Builder
  • Threat Intelligence Reporting
  • Role & Industry-Specific Content
  • Autonomous Training Orchestration
  • Autonomous Phishing Simulation Orchestration
  • Geo-Contextual Simulation Targeting
  • Content Authoring Tools
  • Hands-On Labs & Skills Assessment
  • Structured Learning Paths
  • Deepfake Simulations
  • Data Sovereignty
Get the next assessment
No vendors selected yet
Make an enquiry