For a medium to large enterprise, we are reviewing options for phishing simulation tools to enhance our security awareness program. Could you share any recommendations or experiences with specific tools that have worked well in your organisations?
Sort by:
We do not use tools per say for Phishing, rather CSIRC sends emails that look legit to measure those who report versus those who click the link.
Our experience is with the KnowBe4 solution. It is an excellent tool. It provides hundreds of phishing templates, which prevents users from knowing about the campaign from each other. Creating smart groups based on the number of clicks in recurring campaigns is also a key feature. The tool's cost-benefit is very worthwhile. I recommend it.
We have been using Cofence for a few years now and we are satisfied with the platform.
I have experience with a couple of different phishing simulation solutions, from the earlier Wombat phishing simulation platform (now Proofpoint ThreatSim) to KnowBe4.  Wombat was always a good solution, but I haven't used them in some time, so I don't know what improvements Proofpoint may have added.
The KB4 platform has a lot of great features, such as the ability to dynamically adjust to users.  For example, if they pass easier phishing tests, they can automatically be challenged with harder future tests automatically.  The system also has the ability to vary the phishing type, from QR or attachment phish, to simple form phishing.  I also like how they keep up with recent "real-world" phishing intel, and use those in thier samples.  The reporting and metrics are also nice, with the ability to measure your organization's phish prone percentage against other organizations in your sector or industry.  So we're pretty happy with the KnowBe4 platform.  I hope that helps.
Many Thanks for the response. KB4 is definitely one of the options we will be looking at. Currently using Phishing Tackle, but it has not matured over the last couple of years as we'd hoped.

We are using Hoxhunt and are quite successful with it. Awareness and click rates have improved.