Security Awareness Training 2026

Assessment framework

Every capability we assess, the maturity tier it sits in, and how the framework is built. Edition 2026.1, assessment window closed 1 October 2026.

Capabilities
37
Normalised, each one defined below
Maturity tiers
3
Tablestakes 12, Common 10, Advanced 15
Platforms assessed
20
380+ vendor-stated features
Edition
2026.1
Window closed 1 October 2026

The capability set

Each capability is listed with its definition, alphabetically within its tier. For how many platforms cover each one, download the breakdown.

Tablestakes

What everyone has. The floor of the category. 12 capabilities.

  • AI-Generated Simulation Content

    AI-assisted creation of phishing templates and training scenarios.

  • Behavioural Risk Scoring

    Quantitative risk score per employee based on simulation results, training completion, and security behaviour patterns.

  • Content Library

    Pre-built library of training modules, videos, and awareness content covering common security topics.

  • Continuous Assessment

    Ongoing evaluation of employee security knowledge through quizzes, micro-assessments, and simulation results over time.

  • Gamification

    Leaderboards, badges, points, and competitive elements to drive engagement with training content.

  • In-Email Report Button

    Browser or email client plugin allowing employees to report suspected phishing directly from their inbox.

  • Interactive Training Modules

    Engaging, scenario-based training that requires active participation rather than passive content consumption.

  • Performance Reporting

    Dashboards and reports tracking employee completion rates, simulation results, and overall programme progress.

  • Phishing Simulation

    Simulated phishing emails sent to employees to test awareness and response behaviour.

  • Platform Customisation

    Ability to customise platform branding, training paths, simulation templates, and admin workflows.

  • Security Baselining

    Initial assessment to establish an organisation's security awareness baseline before training begins.

  • White-Label Branding

    Full rebrand capability for MSPs and resellers to deliver training under their own brand.

Common

What most platforms have, and where some differentiation lives. 10 capabilities.

  • Adaptive Learning Engine

    Phishing simulation content difficulty and pacing adjustment based on accumulated learner performance over time.

  • Advanced Analytics & Dashboards

    Executive-level risk reporting with behavioural trend analysis, department benchmarking, and predictive risk indicators beyond basic performance dashboards.

  • LMS & Third-Party Integration

    Integration with learning management systems and third-party platforms for content delivery and reporting.

  • Multi-Tenant Management

    Centralised management of multiple client or business unit environments from a single admin console.

  • Multilingual Content

    Simulations and training content are automatically delivered in the user's preferred language and regional context, enabling global workforces to receive location-relevant content without requiring manual language configuration per user.

  • Policy & Compliance Management

    Tools for distributing, tracking acknowledgement of, and reporting on security policies and compliance requirements.

  • REST API Access

    Programmatic API access (REST/OpenAPI) for integrating with third-party platforms, automating user provisioning, and pulling training data into custom workflows.

  • SIEM Integration

    Native integration with SIEM platforms for security event correlation, log forwarding, and automated workflow triggers.

  • Single Sign-On

    SSO integration for seamless user authentication via identity providers (SAML, OAuth, SCIM).

  • Smishing Simulation

    Simulated SMS phishing (smishing) attacks testing employee susceptibility to mobile-channel social engineering.

Advanced

What differentiates the category. 15 capabilities.

  • AI-Powered Spear Phishing Personalisation

    AI generates individually targeted phishing simulations using organisational context - org charts, colleague names, supply chain relationships, role-specific lures - to create hyper-realistic spear phishing and CEO fraud scenarios.

  • Automated Risk-Based Simulations

    Behavioural risk score events automatically trigger targeted phishing simulations at the individual user level without admin intervention.

  • Autonomous Phishing Simulation Orchestration

    AI engine independently plans, schedules, and adapts phishing simulations at the individual user level based on live risk profiles, without requiring admin-configured campaign workflows.

  • Content Authoring Tools

    Built-in tools for creating custom training content, modules, and assessments without external authoring software.

  • Custom Scenario Builder

    Tools for creating custom phishing scenarios and attack simulations beyond the pre-built template library.

  • Dark Web & Breach Monitoring

    Monitoring dark web sources and breach databases for exposed employee credentials and organisational data.

  • Data Sovereignty

    Platform data is stored and processed within a specified geographic region meeting Australian data residency requirements.

  • Deepfake Simulations

    Simulated deepfake audio or video attacks to train employees to identify AI-generated social engineering content.

  • Geo-Contextual Simulation Targeting

    Simulation content and delivery adapt based on user location, regional context, or work environment, enabling country-specific lures and office-vs-remote adaptive targeting.

  • Hands-On Labs & Skills Assessment

    Interactive technical labs, CTF-style exercises, and practical skills assessments for hands-on security learning.

  • QR Code Phishing (Quishing)

    Simulated QR code phishing attacks embedding malicious QR codes in emails or physical materials to test employee recognition and reporting of quishing attempts.

  • Role & Industry-Specific Content

    Training and simulation content tailored to specific job roles or industry verticals.

  • Structured Learning Paths

    Pre-defined curriculum sequences with progressive difficulty, prerequisites, and completion milestones.

  • Threat Intelligence Reporting

    Reports incorporating real-world threat intelligence data to contextualise simulation results against current attack trends.

  • Vishing Simulation

    Simulated voice phishing (vishing) attacks using telephone-based social engineering to test employee recognition of phone-based threat techniques.

How Tekspace Research assesses a category

This is the process behind every Tekspace Research category assessment.

What it measures

How much of a defined capability set a product covers, with more credit given for the capabilities where products genuinely differ.

It does not measure price, support quality, how a product behaves in a specific estate, or the effort of migrating to it. A strong result means broad capability coverage. It does not mean a product is the right choice for every buyer, and a product built deliberately narrow can be exactly right for a narrow requirement.

How the capability set is built

We collect what each vendor states about its product from its own documentation, knowledge base, release notes and API documentation, and test that against review platforms and practitioner communities, so the assessment is not a comparison of marketing pages.

Those raw features are then normalised: names reconciled, duplicates merged, and overlapping claims consolidated into one canonical capability. Vendors describe the same function in different words, and normalisation is what makes a like-for-like comparison possible at all. The normalised set is what gets assessed.

The three maturity tiers

  • Tablestakes. What everyone has. The floor of the category.
  • Common. What most platforms have. Some differentiation lives here.
  • Advanced. What differentiates the category.

A capability's tier reflects both how widely it is held and how deeply it is implemented, and advanced capabilities count for more than tablestakes.

Editions and corrections

Each assessment has a stated window. Capability a vendor ships after it closes is picked up in the next edition. Where a review finds something was miscounted, the published result is corrected rather than annotated.

Security Awareness Training 2026

Capability coverage across 20 platforms

Free to download and share. No email needed.

Download the breakdown

PDF, A4, 10 pages, 1.8 MB

Next step

Turn the shortlist into a decision.

We match your context to the right platform, then help your team get it running. If nothing fits, we step out of your journey.

See how we help