Tekspace Cyber Lab Presents

Security Awareness Training

A Cyber SaaS Analysis 2026
Get future research sooner. We never share or sell your data.

Foreword

The real problem with security awareness training happens before the product is chosen.

Cyber training programs are typically evaluated and purchased by IT and cybersecurity teams. Criteria is technical, shaped by vendor demos, largely disconnected from the people in the business: what shifts their behaviour and fits into busy days?

If this vital human question is skipped in selection, no feature list alone will deliver lasting change. This report shows why teams need executive sponsorship, and effective socialisation.

Without these foundations, adoption stays low regardless of which platform is selected. Teams go back to market blaming the product for what the program never delivered.

Meanwhile, attackers study supply chains and org charts, pull data from LinkedIn and public records, and use AI to produce requests near-indistinguishable from legitimate ones.

The capacity of any workforce to absorb, retain, and act on security knowledge under pressure has a ceiling. Beyond it, the responsibility shifts to the defence-in-depth layers that wrap around your people: email security, endpoint controls, identity management.

This report is produced in collaboration with Parabellum, Byte and CodeBlue New Zealand. We examined 20 platforms based on real testing across staff bases. Assessing the cyber curriculums that deliver lasting change.

This report finds that people are not the problem. They can be a solution with the right training solution.

Portrait photo of Frank De Pasquale
Frank De Pasquale
CEO at Tekspace

Threat Context

Insights from Parabellum Logo

CREST Pen Test certification badge. OffSec OSCE3 certification badge OffSec OSCE certification badge OffSec OSCP certification badge OffSec OSEP certification badge OffSec OSWE certification badge OffSec OSED certification badge OffSec OSWP certification badge

Security awareness training is growing the skills gap

Most organisations train staff once a year1,2. A 20-minute module, a completion-rate report filed for audit. They satisfy a regulatory checkbox. But they do not change behaviour.3

It's been true since 1885. Forgetting Ebbinghaus' Curve,4 or countless studies telling us infrequent training only produces a minimal change in behaviour. Closer to home, an Adelaide study found that where training improved phishing identification, improvement had disappeared by 6 months.5

The Australian Information Commissioner recorded 1,113 notifiable data breaches in 2024 (the highest annual total since the NDB scheme began).6

Human factors, including phishing, credential theft, and social engineering, were implicated in approximately 45% of all incidents.7 The skills gap between staff and attackers is widening.

Attacker AI vs. SAT AI · 2020–2026

The adoption gap

Attacker AI adoption
SAT AI deployment
Index (%) 0% 25% 50% 75% 100% 2020 2021 2022 2023 2024 2025 2026 ChatGPT launches 31% less effective than human-crafted

Attacker AI · 2025

24% more effective than human-crafted phishing
~80% of attacks AI-generated

SAT programmes · 2025

7.5% personalise training to individual risk

0% 50% 100% 2020 2021 2022 2023 2024 2025 2026 ChatGPT launches Attacker AI · 2025 24% more effective than human-crafted phishing ~80% of attacks AI-generated SAT programmes · 2025 7.5% personalise training to individual risk

Sources: Brightside AI (2025); e-Bits (2025). Attacker adoption indexed to AI-generated phishing prevalence. SAT personalisation rate (7.5%, 2025) confirmed; 2020–2024 training trend estimated. See sat_divergence_dataset_v1.md. 2026 values projected.

Training can't teach beyond the inbox

Tekspace's Email Security research supports email as the dominant vector in AU breach data.8

But the attack surface grew beyond the inbox and programs do not train the gap. Voice phishing surged fourfold in the past year9, yet only one in five orgs train staff for phone-based attacks10. SMS phishing had more than doubled11, with similarly thin training coverage. And virtually no training assesses the established QR code phishing vector.

AI shifts the balance further. By early 2025, AI-generated phishing outperformed human-crafted attacks by approximately 24%12. It was estimated 80% of phishing in that period was AI-generated13 The attacks are more convincing and produced at a scale no human team could sustain.

The deepfake dimension compounds the risk. Mastercard-commissioned research found 20% of Australian businesses received deepfake threats in the prior 12 months14, but many of the trusted training software vendors have no plan to offer deepfake capability in the next 6 months.15

For organisations responsible for customer data, not training staff to identify emerging vectors indicates training does not satisfy the regulatory requirements for cyber awareness outlined by The OAIC's APP 11: Security of personal information.

The regulatory cost of inadequate training

In 2025, the Federal Court handed down the first civil penalty ever issued under the Privacy Act for a data breach: $5.8 million against Australian Clinical Labs16. The court specifically noted that “the IT team leader had no formal cybersecurity training and had never seen the organisation's cyber playbooks”.

In 2024, an enforceable undertaking against Oxfam Australia became the first to explicitly mandate a security awareness training program.17

For the first time ever, cybersecurity training is now a business obligation, not an IT task. When a breach happens, businesses face a greater financial cost from the government than the APTs.

Across the regulated economy, the bar for adequate training has moved from completion to demonstrated behaviour change.

Regulatory penalties · Australia 2025

Privacy Act $50M

Or 30% of domestic turnover. Up from $2.2M before December 2022.

SOCI Act $660K

Per day. 11 sectors. All approved frameworks require SAT.

APRA CPS 234 Board
metric

Phishing test rates named as Board-level reporting.

OAIC determination, October 2025 $5.8M

Australian Clinical Labs — first civil penalty in Privacy Act history.
Court cited no formal cybersecurity training for key IT staff.

Australian and New Zealand staff record the second highest phish-prone rate in the world.18

That position alone warrants attention. But the deeper problem is the awareness-action gap that knowledge-based training alone cannot close. It becomes clear in post-incident reviews, the users who engage in unsafe behaviour are fully aware of the risk and proceed anyway.19

Legacy training modules can only inform. They can't change what people do under pressure, under deadline, or under the authority cues that modern social engineering exploits. The psychology is well understood. The challenge is building programmes that account for it.

When the goal shifts from compliance to sustained behavioural change, the human layer moves from liability to a functioning part of an organisation's cyber strategy.

Security Outcomes

With the threat context as a backdrop, what do information technology professionals prioritise when considering a new security awareness training solution?

1

Efficacy

Delivers training effective to the intent of the organisation; in-line with regulations, effective phishing simulations, the ability to report emails when they see them, resulting in improved metrics across the organisation.

2

Operational Efficiency

The platform can automate campaigns, content, reporting and learning, so admins are not spending hours each week to deliver cyber training programs to one or many tenants.

3

Reporting and Analytics

A single behavioural risk score that aggregates simulation data, training engagement, and incident reporting into one view.

4

User Experience

Engaging, relevant, localised content that earns attention and delivers learning rather than demanding compliance.

Product Landscape

Security awareness training is a well-defined category with a clear set of capabilities.

The Tekspace Cyber Continuum™ ranks 20 of the leading security awareness training vendors in one transparent, measureable spectrum.

We assessed 300+ vendor features across the field, normalising to 39 distinct capabilities. A weighted scoring model produces a single maturity score per vendor, giving a picture of feature depth rather than feature count alone.

Focused

  • Hacker Rangers Icon
    Hacker Rangers
  • ID Agent
    ID Agent
  • CyberHoot Icon
    CyberHoot
  • Boxphish Icon
    Boxphish
  • Riot Icon
    Riot
  • Mimecast Icon
    Mimecast

Features

  • Phishing Simulations
  • Training Content Library
  • Interactive Training Modules
  • Continuous Assessment
  • Performance Reporting
  • Platform Customisation
  • Security Baselining
  • AI-Generated Simulation Content
  • Gamification
  • White-Label Branding
  • Behavioural Risk Scoring
  • In-Email Report Button

Broad

  • Huntress Icon
    Huntress
  • uSecure Icon
    usecure
  • MetaCompliance Icon
    MetaCompliance
  • SANS Institute Icon
    SANS Institute
  • Ninjio Icon
    Ninjio
  • Infosec IQ Icon
    Infosec IQ
  • Barracuda Icon
    Barracuda
  • Immersive Labs Icon
    Immersive Labs
  • SoSafe Icon
    SoSafe
  • Proofpoint Icon
    Proofpoint

Features

  • Advanced Analytics & Dashboards
  • Adaptive Learning Engine
  • Smishing Simulation
  • Single Sign-On
  • LMS & Third-Party Integration
  • Multilingual Content
  • Policy & Compliance Management
  • Multi-Tenant Management
  • REST API
  • SIEM Integration

Comprehensive

See Vendors and Features
Hoxhunt Icon
Adaptive Security Icon
Phished Icon
KnowBe4 Icon

Comprehensive

  • Hoxhunt Icon
    Hoxhunt
  • Adaptive Security Icon
    Adaptive Security
  • Phished Icon
    Phished
  • KnowBe4 Icon
    KnowBe4

Features

  • Vishing Simulation
  • QR Code Phishing (Quishing)
  • Dark Web & Breach Monitoring
  • AI-Powered Spear Phishing Personalisation
  • Automated Risk-Based Simulations
  • Custom Scenario Builder
  • Threat Intelligence Reporting
  • Role & Industry-Specific Content
  • Autonomous Training Orchestration
  • Autonomous Phishing Simulation Orchestration
  • Geo-Contextual Simulation Targeting
  • Content Authoring Tools
  • Hands-On Labs & Skills Assessment
  • Structured Learning Paths
  • Deepfake Simulations
  • Data Sovereignty

Get matched with your best-fit

You could just pick a leader on our Cyber Continuum™ - but a logo on a chart is not a reflection of how it truly fits your environment with your team. We help with that.

Book your session

Completely free. If we can't find a match, we exit your journey.

Conclusion

Start with the learning model, not the feature list.

The quickest way to assess a platform's maturity is how it teaches.

Platforms built like a library hand administrators a content catalogue and hope for the best. Others work like an exam, training only on failure. Neither reliably changes behaviour.

The model that produces measurable change is a curriculum. Sequenced content that builds foundations first, repeats the basics, layers complexity, and adapts to each person's skill level and susceptibility traits. IT teams often find this approach too simple. That is their lens, not their workforce's.

With automated set ups or smart baselining the best platforms deliver value from day one, not after six months is spent setting up the curriculum.

Because a platform is only half the investment. Without executive support, without socialising why it's being done, without normalising failure, adoption will be low regardless of platform.

And it is why teams go back to market blaming the solution.

An opportunity to reimagine your training

Once-off induction sessions and annual modules are not delivering the outcomes Australian organisations need.

Technical controls handle what they can. Between what technology covers and what falls through the cracks, a well-run training program is the highest-return investment most organisations have not yet made properly.

If your current program is not producing measurable behaviour change, we can help. We will map your program against the outcomes in this report, identify the gaps, and match you with the platform best suited to your people, your compliance obligations, and your risk profile.

Addendum

Credits

In launching this report, the Tekspace would like to acknowledge contributions from the following teams and individuals.

Prepared by

  • Frank De Pasquale, CEO at Tekspace
  • George Hagivassilis, CCO at Tekspace
  • Mike Ross, Service Director at Tekspace
  • Finn Astle, Marketing Specialist at Tekspace

Contributions from

  • Martin Dybalski, Director, Parabellum
  • Stuart Shanahan, Director of Technical Services, Parabellum
  • Kris Bowen, Senior Offensive Security Consultant, Parabellum
  • Mathew Jose, Chief Information Security Officer at CodeBlue New Zealand
  • Stacy Gurrie, Cheif Executive Officer at Byte
  • Alison Bourke, Fractional CMO at The Launch Project
  • Romain Pondard, Founder at Klippable

References

  1. Australian Signals Directorate (2025), ASD Annual Report 2024-25
  2. Australian Signals Directorate (2025), ASD Annual Report 2024-25
  3. Australian Federal Police (2025), Criminals target construction sector with Business Email Compromise scams
  4. Australian Signals Directorate (2025), Annual Cyber Threat Report 2024-25: fact sheet for businesses and organisations
  5. Practice Protect AU (2025), The devil is still in the email: what BEC looks like in 2025.
  6. Riposte Cybersecurity Consultancy (2025) Phishing threats in Australia's legal sector
  7. SecurityBrief Australia (2025) Email attacks surge in APAC, phishing up by 30% in 2024
  8. Australian Signals Directorate (2025), ASD Annual Report 2024-25.
  9. Australian Institute of Criminality (2024), Cybercrime in Australia 2023-24
  10. DeepStrike (2025), AI cybersecurity threats 2025: how to survive the AI arms race
  11. Keepnet Labs (2024), Navigating the email security market in 2025
  12. Abnormal Security (2024), H1 2024 Phishing Frenzy: C-suite receives 42x more QR code attacks than average employee
  13. Integris (2025) 2025 Integris report: law firms, cybersecurity and AI - what clients really think
  14. Google Threat Intelligence Group, Mandiant & Google Security Operations, (2025) Cybersecurity Forecast 2026
  15. VIPRE Security Group (2025) Cyber threats in 2025: how AI is changing phishing tactics
  16. StrongestLayer (2025) StrongestLayer secures US$5.2M to combat emerging AI-driven email threats
  17. Australian Institute of Criminality (2024), Cybercrime in Australia 2023-24

Scope

This report evaluates platforms delivering phishing simulations, in-email reporting, and cybersecurity awareness education. It does not cover standalone email security gateways, broader governance/risk/compliance platforms, or physical security awareness programs.

Twenty-three vendors were researched. Three were excluded as out-of-category following technical review, leaving 20 platforms in the final evaluation.

Scoring Methodology

One hundred and forty-four enriched features were normalised into 32 canonical capabilities across 20 evaluated vendors. Each capability was classified into one of three maturity bands based on how many vendors offer it.

Tablestakes capabilities (offered by 13 or more vendors) represent market baseline. Common capabilities (5-12 vendors) represent meaningful differentiation. Advanced capabilities (4 or fewer vendors) represent specialist depth.

A weighted scoring model assigns higher value to capabilities requiring greater technical depth, producing a single maturity score per vendor.

Feature Granuality Model

At the outset, we aimed to produce an analysis that is both strategic and practical. It needs to be useful to all IT leaders, regardless of how familiar they are with a given product domain.

In doing so, we gave consideration to how products are compared against one another.

Comparison at a superficial level is too shallow and doesn't give insight as to differentiation between products. At the same time, diving into technical minutiae can often mean losing focus of how products are meaningfully differnt.

As such, we conduct our evaluation at what we call, Level 2: The Functional Group.

In doing so, we can consistently assess whether a product's capabilities are more or less likely to help IT leaders achieve their desired outcomes.

Domain Level 1
The Module
Level 2
The Functional Group
Level 3
The Micro-Feature
Grocery Fruit Banana Sold in bunches of 5
Automotive Car Wheels 5 spokes, 5 lug nuts
Education Course Mathematics Weekly problem sets
Healthcare Clinic GP Consultations 15 Minute Standard Appointment

Disclaimers

Where commercial relationships exist, we apply the same evaluation criteria we use for all technologies, including tools we do not resell. We recognise the importance of independence in this research, and do not let commercial relationships affect our framework.

Findings reflect our professional judgement at the time of publication, based on the data available to us. Product capabilities and roadmaps change, so organisations should treat this report as a guide to practical decision making, not as a substitute for their own due diligence.

If you have identified errors in this report, or wish to have another product assessed, please contact our team.

Contact our team
Close

Focused

  • Hacker Rangers Icon
    Hacker Rangers
  • ID Agent
    ID Agent
  • CyberHoot Icon
    CyberHoot
  • Boxphish Icon
    Boxphish
  • Riot Icon
    Riot
  • Mimecast Icon
    Mimecast

Features

  • Phishing Simulations
  • Training Content Library
  • Interactive Training Modules
  • Continuous Assessment
  • Performance Reporting
  • Platform Customisation
  • Security Baselining
  • AI-Generated Simulation Content
  • Gamification
  • White-Label Branding
  • Behavioural Risk Scoring
  • In-Email Report Button
Close

Broad

  • Huntress Icon
    Huntress
  • uSecure Icon
    usecure
  • MetaCompliance Icon
    MetaCompliance
  • SANS Institute Icon
    SANS Institute
  • Ninjio Icon
    Ninjio
  • Infosec IQ Icon
    Infosec IQ
  • Barracuda Icon
    Barracuda
  • Immersive Labs Icon
    Immersive Labs
  • SoSafe Icon
    SoSafe
  • Proofpoint Icon
    Proofpoint

Features

  • Advanced Analytics & Dashboards
  • Adaptive Learning Engine
  • Smishing Simulation
  • Single Sign-On
  • LMS & Third-Party Integration
  • Multilingual Content
  • Policy & Compliance Management
  • Multi-Tenant Management
  • REST API
  • SIEM Integration
Close

Comprehensive

  • Hoxhunt Icon
    Hoxhunt
  • Adaptive Security Icon
    Adaptive Security
  • Phished Icon
    Phished
  • KnowBe4 Icon
    KnowBe4

Features

  • Vishing Simulation
  • QR Code Phishing (Quishing)
  • Dark Web & Breach Monitoring
  • AI-Powered Spear Phishing Personalisation
  • Automated Risk-Based Simulations
  • Custom Scenario Builder
  • Threat Intelligence Reporting
  • Role & Industry-Specific Content
  • Autonomous Training Orchestration
  • Autonomous Phishing Simulation Orchestration
  • Geo-Contextual Simulation Targeting
  • Content Authoring Tools
  • Hands-On Labs & Skills Assessment
  • Structured Learning Paths
  • Deepfake Simulations
  • Data Sovereignty
Get future research