Security Awareness Training 2026
Assessment framework
Every capability we assess, the maturity tier it sits in, and how the framework is built. Edition 2026.1, assessment window closed 1 October 2026.
- Capabilities
- 37
- Normalised, each one defined below
- Maturity tiers
- 3
- Tablestakes 12, Common 10, Advanced 15
- Platforms assessed
- 20
- 380+ vendor-stated features
- Edition
- 2026.1
- Window closed 1 October 2026
The capability set
Each capability is listed with its definition, alphabetically within its tier. For how many platforms cover each one, download the breakdown.
Tablestakes
AI-Generated Simulation Content
AI-assisted creation of phishing templates and training scenarios.
Behavioural Risk Scoring
Quantitative risk score per employee based on simulation results, training completion, and security behaviour patterns.
Content Library
Pre-built library of training modules, videos, and awareness content covering common security topics.
Continuous Assessment
Ongoing evaluation of employee security knowledge through quizzes, micro-assessments, and simulation results over time.
Gamification
Leaderboards, badges, points, and competitive elements to drive engagement with training content.
In-Email Report Button
Browser or email client plugin allowing employees to report suspected phishing directly from their inbox.
Interactive Training Modules
Engaging, scenario-based training that requires active participation rather than passive content consumption.
Performance Reporting
Dashboards and reports tracking employee completion rates, simulation results, and overall programme progress.
Phishing Simulation
Simulated phishing emails sent to employees to test awareness and response behaviour.
Platform Customisation
Ability to customise platform branding, training paths, simulation templates, and admin workflows.
Security Baselining
Initial assessment to establish an organisation's security awareness baseline before training begins.
White-Label Branding
Full rebrand capability for MSPs and resellers to deliver training under their own brand.
Common
Adaptive Learning Engine
Phishing simulation content difficulty and pacing adjustment based on accumulated learner performance over time.
Advanced Analytics & Dashboards
Executive-level risk reporting with behavioural trend analysis, department benchmarking, and predictive risk indicators beyond basic performance dashboards.
LMS & Third-Party Integration
Integration with learning management systems and third-party platforms for content delivery and reporting.
Multi-Tenant Management
Centralised management of multiple client or business unit environments from a single admin console.
Multilingual Content
Simulations and training content are automatically delivered in the user's preferred language and regional context, enabling global workforces to receive location-relevant content without requiring manual language configuration per user.
Policy & Compliance Management
Tools for distributing, tracking acknowledgement of, and reporting on security policies and compliance requirements.
REST API Access
Programmatic API access (REST/OpenAPI) for integrating with third-party platforms, automating user provisioning, and pulling training data into custom workflows.
SIEM Integration
Native integration with SIEM platforms for security event correlation, log forwarding, and automated workflow triggers.
Single Sign-On
SSO integration for seamless user authentication via identity providers (SAML, OAuth, SCIM).
Smishing Simulation
Simulated SMS phishing (smishing) attacks testing employee susceptibility to mobile-channel social engineering.
Advanced
AI-Powered Spear Phishing Personalisation
AI generates individually targeted phishing simulations using organisational context - org charts, colleague names, supply chain relationships, role-specific lures - to create hyper-realistic spear phishing and CEO fraud scenarios.
Automated Risk-Based Simulations
Behavioural risk score events automatically trigger targeted phishing simulations at the individual user level without admin intervention.
Autonomous Phishing Simulation Orchestration
AI engine independently plans, schedules, and adapts phishing simulations at the individual user level based on live risk profiles, without requiring admin-configured campaign workflows.
Content Authoring Tools
Built-in tools for creating custom training content, modules, and assessments without external authoring software.
Custom Scenario Builder
Tools for creating custom phishing scenarios and attack simulations beyond the pre-built template library.
Dark Web & Breach Monitoring
Monitoring dark web sources and breach databases for exposed employee credentials and organisational data.
Data Sovereignty
Platform data is stored and processed within a specified geographic region meeting Australian data residency requirements.
Deepfake Simulations
Simulated deepfake audio or video attacks to train employees to identify AI-generated social engineering content.
Geo-Contextual Simulation Targeting
Simulation content and delivery adapt based on user location, regional context, or work environment, enabling country-specific lures and office-vs-remote adaptive targeting.
Hands-On Labs & Skills Assessment
Interactive technical labs, CTF-style exercises, and practical skills assessments for hands-on security learning.
QR Code Phishing (Quishing)
Simulated QR code phishing attacks embedding malicious QR codes in emails or physical materials to test employee recognition and reporting of quishing attempts.
Role & Industry-Specific Content
Training and simulation content tailored to specific job roles or industry verticals.
Structured Learning Paths
Pre-defined curriculum sequences with progressive difficulty, prerequisites, and completion milestones.
Threat Intelligence Reporting
Reports incorporating real-world threat intelligence data to contextualise simulation results against current attack trends.
Vishing Simulation
Simulated voice phishing (vishing) attacks using telephone-based social engineering to test employee recognition of phone-based threat techniques.
How Tekspace Research assesses a category
This is the process behind every Tekspace Research category assessment.
What it measures
How much of a defined capability set a product covers, with more credit given for the capabilities where products genuinely differ.
It does not measure price, support quality, how a product behaves in a specific estate, or the effort of migrating to it. A strong result means broad capability coverage. It does not mean a product is the right choice for every buyer, and a product built deliberately narrow can be exactly right for a narrow requirement.
How the capability set is built
We collect what each vendor states about its product from its own documentation, knowledge base, release notes and API documentation, and test that against review platforms and practitioner communities, so the assessment is not a comparison of marketing pages.
Those raw features are then normalised: names reconciled, duplicates merged, and overlapping claims consolidated into one canonical capability. Vendors describe the same function in different words, and normalisation is what makes a like-for-like comparison possible at all. The normalised set is what gets assessed.
The three maturity tiers
- Tablestakes. What everyone has. The floor of the category.
- Common. What most platforms have. Some differentiation lives here.
- Advanced. What differentiates the category.
A capability's tier reflects both how widely it is held and how deeply it is implemented, and advanced capabilities count for more than tablestakes.
Editions and corrections
Each assessment has a stated window. Capability a vendor ships after it closes is picked up in the next edition. Where a review finds something was miscounted, the published result is corrected rather than annotated.

Security Awareness Training 2026
Capability coverage across 20 platforms
Free to download and share. No email needed.
PDF, A4, 10 pages, 1.8 MB
Next step
Turn the shortlist into a decision.
We match your context to the right platform, then help your team get it running. If nothing fits, we step out of your journey.
See how we help