Top Free Security Awareness Training Software - Page 5

How Many Security Awareness Training Software Products Does G2 Track?

Total Products under this Category: 225

Category Stats (Sep 2026)

  • Average Rating: 4.66/5 (↓0.01 vs Aug 2026) The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: iluminr (+6.65%) - Among all products in this category, iluminr recorded the largest rating increase compared to last month

Last updated: September 15, 2026

How Does G2 Rank Security Awareness Training Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 15,200+ Authentic Reviews
  • 225+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Security Awareness Training Software

G2 Grid® for Security Awareness Training Software plotting products by satisfaction and market presence

Highlighted products: KnowBe4 Security Awareness Training, Hoxhunt, Hornetsecurity Security Awareness Service, Adaptive Security, SoSafe, Arctic Wolf, Proofpoint ZenGuide, and Mimecast Security Awareness Training.

Underlying data: [Grid® JSON](https://www.g2.com/categories/security-awareness-training/grids.json?focus%5B%5D=knowbe4-security-awareness-training&focus%5B%5D=hoxhunt&focus%5B%5D=hornetsecurity-security-awareness-service&focus%5B%5D=adaptive-security&focus%5B%5D=sosafe&focus%5B%5D=arctic-wolf&focus%5B%5D=proofpoint-zenguide&focus%5B%5D=mimecast-security-awareness-training)

Doubleflow Security Awareness

Doubleflow is a gamified cybersecurity awareness platform that turns passive compliance training into interactive, gamified experiences employees actually act on. It is the engagement layer that complements security awareness training (SAT) platforms like KnowBe4, turning passive compliance content into active, memorable experiences that change behavior. Trusted by more than 1,000 organizations and +500,000 employees worldwide, Doubleflow boasts a 97% user recommendation rate. The Ultimate Toolkit for Cybersecurity Awareness Month (October) While built for year-round security culture, Doubleflow is the premier turnkey solution for Cybersecurity Awareness Month in October. Instead of forcing employees to watch generic videos, security and L&D teams use Doubleflow to launch high-impact October campaigns, factory floor roadshows, and corporate all-hands events. It gives teams the exact tools, games, and narratives needed to drive massive engagement during the industry’s most critical awareness window. Core Product Offerings & Features: Beat the Hacker® Cybersecurity Escape Room: A premier interactive cybersecurity training game available in flexible 5, 15, and 30-minute editions to fit any corporate schedule. Interactive Gamified Training: Hands-on problem-solving and narrative-driven scenarios that ensure long-term learning retention. 1-Click Customizable Campaigns: Pre-built, industry-tailored campaign templates designed for instant deployment. Keep your traditional compliance platform to satisfy the auditors—use Doubleflow to transform your corporate security culture and turn your employees from your biggest vulnerability into your strongest line of defense.

Who Is the Company Behind Doubleflow Security Awareness?

Hut Six

Hut Six's comprehensive solution builds a security awareness culture by focusing on your greatest asset your employees. By training and reinforcing the importance of security awareness, your organisations defences are strengthened against malicious attackers, reputational damage, and potential fines and litigation, whilst satisfying compliance regulations.

Who Is the Company Behind Hut Six?

  • Seller: Hutsix
  • Year Founded: 2016
  • HQ Location: Newport, GB
  • Twitter: @HutSixSecurity
    487 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    6 employees on LinkedIn®

Jericho Security

Jericho Security uses AI to fight AI in the new frontier of cybersecurity. By simulating hyper-personalized attacks, Jericho trains employees to recognize and respond to new AI threats, resulting in increased testing efficiency, reduced costs, and fewer security incidents. Jericho trains employees to recognize and respond to new AI threats by simulating hyper-personalized attacks, resulting in increased testing efficiency, reduced costs, and fewer security incidents. Our approach to training involves: >Test: Replicate real-life phishing simulations with our AI-powered email generator > Monitor: Report on how your organization is performing in granular detail > Train: Leverage AI-powered training that drives behavioral change Jericho learns from its attack simulation and adapts to test your organization and continuously detect generative attacks. At Jericho Security, we believe that effective cybersecurity training must go beyond simply imparting knowledge—it must foster a culture of security awareness and preparedness. To achieve this, we've developed a unique approach that sets us apart from traditional training vendors: >Generative AI-Powered Content: Our advanced AI technology enables us to create customized, up-to-date training modules and phishing simulations that address the latest threats and industry trends. This ensures employees are always prepared for the most current cyber risks. >Customized Training Solutions: We recognize that every organization has unique needs and vulnerabilities. That's why we tailor our training content to address your organization's specific risks and requirements, ensuring maximum relevance and effectiveness. >Engaging Microlearning Format: Our training modules are designed in a short, digestible format that minimizes workflow disruptions and enhances retention of key concepts. >Dual reporting features: Generate reports in our Web-based app or your Learning Management System (LMS) to provide valuable data on employee participation, quiz scores, and more, enabling you to monitor the effectiveness of your training program. >Seamless Import Integration: Jericho's solutions integrate with your existing tools, including SCIM-enabled directories (Microsoft and Okta) and OAUTH-enabled API integration (Google Workspace). Integrations can also be customized to work with any directory. >Expert-created training: Certified Cybersecurity and Instructional Design experts develop engaging, up-to-date content that addresses emerging threats and best practices. >One-Click Phishing Reporting: Empower employees to report phishing attempts with just one click, allowing for rapid response and mitigation of potential threats. >Regulatory Compliance: Our training programs meet and exceed industry standards and guidelines, helping your organization maintain compliance and demonstrate due diligence in safeguarding sensitive data.

Who Is the Company Behind Jericho Security?

Lephish

LePhish is a French cybersecurity company specializing in automated phishing simulations and employee training to enhance organizational security. Their services include realistic phishing campaigns and personalized training modules designed to transform employees into the first line of defense against cyber threats. Key Features and Functionality: - Realistic Phishing Simulations: LePhish offers over 30 ready-to-use phishing scenarios with dedicated domains, replicating techniques used by cybercriminals. - Automated Training Modules: The platform provides micro-learning modules that educate employees on identifying and responding to phishing attempts, ensuring continuous and effective learning. - Comprehensive Dashboard and Reporting: LePhish's intuitive dashboard allows real-time tracking and analysis of phishing campaign results, measuring click rates, compromise rates, and identifying the most exposed departments. Primary Value and Problem Solved: LePhish addresses the critical need for organizations to bolster their cybersecurity defenses by transforming employees into vigilant defenders against phishing attacks. By simulating realistic phishing scenarios and providing targeted training, LePhish reduces the risk of data breaches and enhances overall organizational security. Their approach ensures that employees are not only aware of potential threats but are also equipped with the knowledge to prevent them, thereby safeguarding sensitive information and maintaining business continuity.

Who Is the Company Behind Lephish?

Lucy Awareness

Lucy is the expert's choice in Awareness solution, developed by ethical hackers to provide a realistic and effective test of your vulnerability to attacks which exploit your human factor vulnerabilities. Lucy is the only product int he market which can be installed on premise and totally isolated making it a firm favorite with the most cautious of customers Banks, Government and the more security conscious. Of course it can also be provided in SaaS mode or set up on a customers private cloud. Crucially a customer can move between these modes if they wish meaning Lucy provides a policy/hosting strategy safe, solution. An unrivaled Phishing simulation capability is also highly valued by customers who want to go beyond mundane and vanilla tick box simulations. Sure, a template library exists, with hundreds of templates covering all types of attacks. You can use them as is or personalize these if you wish, you can take any existing email or real world attack, defang it and use it as a simulation. Other vendors mainly focus on email attacks but the threat landscape has changed and gone mobile and our capability here cannot be matched with the ability to deliver attacks via SMS, WhatsApp, Teams, AI Agent voice and QR codes. We can also provide you with Automated Adaptive Phishing capability which adjusts to the risk ratings of your users, or you can set up custom campaigns, perhaps for your high risk employees or other groups of interest. Serious testing of your employees is essential to understand your resilience levels and weaknesses, and of course demonstrating the full range of available threat types to your employees immediately improves their threat perception levels. However, Lucy also provides a comprehensive Awareness training capability to further develop your employees. Lucy can work with your own LMS or with our in built LMS and we also provide a great End user Portal to give your users a home for their training and much more. Our awareness content is comprehensive and available in many formats to meet differing needs, from one pagers, through short and advanced modules. Content includes video, interactivity and gamification elements, sort card activities, tests as well as text and audio. And you could probably guess already, but with Lucy you can edit these modules, add your own content, policies, messages, branding etc. This really helps your training hit own, gain traction and improve your employees understanding of threats and response to them. Lucy is a multinational business, our customers operate all around the world and many of them have employees with many different first languages, so why wouldn't our tool match this? Lucy has attack templates and awareness modules in hundreds of languages. Our AI translation tool can translate your attack simulations into any language for a small fee and our team can translate awareness modules (or you can do this yourself) if we don't already have the exact translation you require. These are the things that make Lucy stand out from the grey competition, we don't always follow the norm, because the norm is often not enough. If you want to know more reach out to us and we can help you with a consultation call to understand your particular circumstances and challenges and tell you how we can help.

Who Is the Company Behind Lucy Awareness?

  • Seller: Lucy Awareness
  • HQ Location: Cham, CH
  • Twitter: @lucysecurity
    4,387 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    32 employees on LinkedIn®

NexGuards

NexGuards is an AI-powered human-layer security platform built to help organizations defend against modern social engineering attacks. Founded by cybersecurity engineers with experience in offensive and defensive security, NexGuards focuses on securing the most targeted attack surface today - employees. The platform simulates highly realistic phishing, smishing, and vishing attacks using OSINT and generative AI. Unlike traditional solutions that rely on generic templates, NexGuards creates personalized attack scenarios in seconds, closely mirroring how real attackers operate. This allows organizations to uncover true vulnerabilities in employee behavior across departments and roles. When users interact with a simulated attack, NexGuards delivers instant, tailored microlearning to help them understand what they missed and how to respond in the future. Combined with detailed analytics and behavioral insights, NexGuards enables security teams to measure, understand, and reduce human risk in a practical and scalable way.

Who Is the Company Behind NexGuards?

OpenText Core Security Awareness Training​

OpenText Core Security Awareness Training is a cloud-based solution designed to reduce human risk by educating employees to recognize and respond to cyber threats such as phishing, social engineering, and malware. The platform combines engaging, easy-to-understand training content with real-world phishing simulations that mimic current attack techniques. This allows organizations to continuously test user awareness, reinforce best practices, and improve security behavior over time. Administrators gain visibility into user performance through detailed reporting and can identify high-risk individuals or departments that need additional training. Key benefits: Reduce human-related breaches – train users to identify and avoid phishing and social engineering attacks Real-world phishing simulations – safely test employee behavior with realistic attack scenarios Continuous improvement – track progress and strengthen awareness over time Actionable insights – identify vulnerable users with detailed reporting and analytics Easy deployment and management – cloud-based platform with minimal setup Improve compliance posture – support security awareness requirements across regulations In short, it transforms employees from a security risk into a proactive line of defense, helping organizations prevent attacks before they start.

Who Is the Company Behind OpenText Core Security Awareness Training​?

  • Seller: OpenText
  • Year Founded: 1991
  • HQ Location: Waterloo, ON
  • Twitter: @OpenText
    21,565 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    22,835 employees on LinkedIn®
  • Ownership: NASDAQ:OTEX

Paraphish

Paraphish by Parafox Technologies is a comprehensive Security Awareness Training and Phishing Simulation platform that helps organizations combat one of the biggest cybersecurity risks: human error. As phishing attacks become more frequent and sophisticated, Paraphish empowers organizations to proactively educate employees and reduce risk through simulated attacks, targeted training, and actionable insights. Designed for ease of use and scalability, Paraphish enables IT and security teams to launch realistic phishing simulations that mimic real-world threats. The platform offers a library of customizable phishing templates, automated campaign scheduling, and detailed performance tracking, helping organizations measure susceptibility and tailor interventions. Employees who fall for a simulated phishing attempt are immediately enrolled in short, engaging microlearning modules that address the specific risks they encountered. Beyond simulations, Paraphish includes a robust training and compliance suite. It delivers adaptive learning paths, interactive modules, and regular knowledge checks to ensure that employees stay informed and alert. With multilingual support and customizable content, Paraphish can meet the needs of global teams and industry-specific compliance requirements. Security and compliance leaders benefit from a powerful analytics dashboard that tracks user progress, training completion, and overall risk posture. Paraphish provides insights that support compliance with regulatory frameworks such as ISO 27001, GDPR, HIPAA, and NIST, making it a valuable asset in audit preparation and risk management. Whether you're a small business or a global enterprise, Paraphish integrates seamlessly into your environment, supporting identity providers, learning management systems, and custom workflows. Developed by Parafox Technologies—a cybersecurity company known for innovation and reliability—Paraphish reflects a deep commitment to user-centric design and measurable results. Key Features: Realistic phishing simulations with automated campaigns Adaptive, role-based security awareness training Risk-based scoring and employee segmentation Compliance tracking and audit-ready reporting Customizable templates and learning content Integration with existing IT infrastructure Paraphish helps you turn your employees into your first line of defense—strengthening your cybersecurity culture from the inside out.

Who Is the Company Behind Paraphish?

PhishByte

PhishByte is an Australian-focused phishing simulation and cyber awareness training platform designed to help organisations reduce human risk through real-world scenarios and measurable behavioural change. While firewalls and software protect systems, attackers increasingly target people. PhishByte helps organisations strengthen their human layer of defence — equipping employees to recognise, question and stop phishing and social engineering attacks before damage is done. Our platform delivers realistic phishing simulations, adaptive micro-training, and behaviour-driven reporting that fits seamlessly into everyday workflows. Rather than one-off compliance exercises, PhishByte builds safer, instinctive behaviours through continuous reinforcement. Organisations use PhishByte to: • Reduce successful phishing incidents • Improve reporting behaviour and awareness • Identify training gaps and human risk trends • Strengthen security culture without adding complexity Not sure where your organisation stands? Take our free 2-minute Human Phishing Risk Assessment and get an instant personalised risk score — no sign-up required. phishbyte.com.au/phishing-risk-assessment Built in Australia for Australian organisations, PhishByte is trusted across local government, education, healthcare, construction, retail, hospitality and corporate environments. We focus on simple, practical training that drives measurable behavioural change — without jargon, enterprise bloat, or unnecessary complexity. Cyber security isn’t just a technical challenge. It’s a human one. PhishByte helps turn employees from potential risk into resilient human firewalls — protecting organisations year-round..

Who Is the Company Behind PhishByte?

PhishGun

PhishGun is a phishing simulation and employee training platform engineered by the offensive security experts at Haxoris Labs. Built to replace generic content libraries and heavy enterprise suites, PhishGun delivers realistic, attacker-grounded simulations tailored for security teams that need to drive measurable behavior change without operational overhead. Core Capabilities - Campaign Studio & Templates: Deploy role-based and localized campaigns using a growing library of real-world scenarios, including credential harvesting, MFA-fatigue, and invoice lures. - In-the-Moment Training: Deliver concise, contextual training that reinforces secure habits and explains missed indicators without relying on punitive workflows or public shaming. - Phishing Report Button: Turn suspicious email reporting into a measurable habit for employees directly within their standard workflows. - Compliance & Risk Dashboards: Track crucial metrics like click rates, reporting rates, and repeat risks, while exporting clean, audit-ready evidence for NIS2, ISO 27001, and DORA reviews.

Who Is the Company Behind PhishGun?

Phishtime

Phishtime is a phishing simulation and security awareness training platform for organizations that want to test and improve how their employees respond to real-world social-engineering attacks. Admins launch simulated phishing campaigns against their own workforce using realistic lure types, such as deceptive emails, QR-code lures, fake login/MFA-approval pages, malicious attachments, and SMS/Viber messages - then track who opened, clicked, or submitted data in real time. Employees who fall for a simulation are automatically routed to a short awareness training page explaining what they missed, while a scorecard and leaderboard reinforce good behavior over time. Reporting ranges from campaign-level funnels to board-ready executive PDF reports, with configurable retention and per-department breakdowns. Phishtime supports Microsoft Entra ID directory sync and SSO, a REST API, and self-serve signup with a free plan (Hello World) for small teams to get started before upgrading to paid tiers with higher limits and more advanced reporting.

Who Is the Company Behind Phishtime?

Redflags

Redflags is your Intelligent Behaviour Change Tool. When and where it matters. Measure human risk, nudge pre-emptively and prove operational impact, all without slowing people down. Redflags pairs on-device behavioural telemetry with intelligent, pre-emptive nudges at the point of decision. Turns moments of risk into learning moments, building secure habits without disrupting work. Redflags is: -Lightweight to deploy and fast to deliver value. -Backed by behavioural science and proven in the field. -Demonstrates clear, measurable results in reducing operational risk. Redflags is the intelligent Human Risk Management tool empowering global organisations to transform human cyber risk, delivering proven and measurable behaviour change that truly protects your business. 3 steps to success: STEP 1 - Engage your people: Empower colleagues with engaging bite-sized, non-intrusive cyber guidance and real-life examples delivered to their desktops without disrupting workflow. STEP 2 - Intervene intelligently: Redflags intercepts risky behaviour just before and at the point of risk, applying behavioural science and context. STEP 3 - Measure and Monitor: Track and compare measurable risk reductions in risky actions and show the board how culture is shifting.

Who Is the Company Behind Redflags?

Security Awareness Training & Phishing Simulations

empowsec helps businesses reduce human cyber risk with security awareness training, realistic phishing simulations, email reporting, and automated remediation in one platform. Teams can launch targeted phishing exercises in minutes, track clicks, replies, credential submissions, and user reports, then automatically assign short, relevant training based on each employee's behavior. With interactive lessons, compliance-ready reporting, Outlook and Gmail reporting add-ins, and clear risk analytics, empowsec turns security awareness from a checkbox activity into a measurable program that improves employee resilience over time.

Who Is the Company Behind Security Awareness Training & Phishing Simulations?

SirAskalot

SirAskalot helpt organisaties om informatiebeveiliging structureel te verbeteren door gedragsverandering centraal te stellen. In plaats van traditionele e-learning maakt SirAskalot gebruik van gamification en korte, wekelijkse vragen die medewerkers actief betrekken en bewust houden van veilig gedrag. Elke week ontvangen medewerkers één praktische vraag over informatiebeveiliging, privacy of digitale weerbaarheid. Door herhaling en spelelementen blijft kennis beter hangen en wordt veilig gedrag onderdeel van het dagelijks werk. Fout beantwoorde vragen keren automatisch terug, zodat leren effectief en meetbaar is. Het platform is wetenschappelijk onderbouwd en biedt duidelijke dashboards met inzicht in risicogebieden, voortgang en bewustzijnsniveaus binnen teams en de hele organisatie. Implementatie is eenvoudig, onder andere via koppelingen met Azure AD / Entra ID. SirAskalot wordt gebruikt door meer dan 250 organisaties, waaronder overheden, onderwijsinstellingen, zorgorganisaties, mkb en corporates.

Who Is the Company Behind SirAskalot?

  • Seller: Recourse
  • Year Founded: 2015
  • HQ Location: Zoetermeer, NL
  • LinkedIn® Page: www.linkedin.com
    9 employees on LinkedIn®

Tartan App

Tartan App is an easy-to-use, AI-driven cybersecurity awareness training and phishing simulation solution designed specifically for K-12 schools. We understand IT Directors face tight budgets and limited time. Tartan App offers quick, hassle-free setup, automates phishing simulations tailored to your school. We provide 10 second training tips personalized for every employee's skill level. Our simple flat pricing covers your entire district, eliminating complicated licensing. With detailed reporting, Tartan App helps create a positive security culture, reduces cyber risks, ensures compliance, and empowers you to protect your school community.

Who Is the Company Behind Tartan App?

Brandon Summers-Miller
BS
Researched and written by Brandon Summers-Miller
Updated October 1, 2025