Executive Summary

By the Numbers
Embedded phishing training reduced the likelihood of clicking a phishing link by only about 2% in an eight-month randomized controlled study of more than 19,500 employees.
In the same study, more than half of employees had clicked at least one simulated phishing link by month eight, despite ongoing training.
A meta-analysis of 69 studies found training strongly improves knowledge, but its effect on actual behavior was less than half as large and not statistically reliable.
Around 60% of breaches still involve a human element, which is why the gap between knowing and doing is the most expensive gap in security.
KnowBe4 and SavvyShield both exist to reduce human risk, but they attack the problem from opposite directions. KnowBe4 is the market's most established security awareness training platform: a vast content library, email phishing simulations, and enterprise reporting, built around the idea that educated users make safer choices. SavvyShield is a protection-first human risk platform: it defends users in the browser at the moment they encounter a threat, runs adaptive simulations across browser and email workflows, and delivers short, contextual training tied to what just happened.
The distinction matters because a growing body of independent research shows that scheduled training, on its own, does little to change what users actually do when a real attack arrives. This comparison walks through that research, both platforms' capabilities and pricing, and the situations where each is the right choice.
Two Different Philosophies
Every human risk product makes a bet about where risk is actually reduced.
KnowBe4's bet is knowledge. Its model, refined since 2010, is to teach users to recognize threats before they encounter them: scheduled training modules assigned from a library of over 1,300 items, unlimited simulated phishing emails to test retention, and reporting to track completion and click rates over time. Protection during a live attack is not part of the core product; a real-time coaching add-on (SecurityCoach) exists, but it delivers coaching messages based on what other security tools in your stack detect; it does not detect or block threats itself.
SavvyShield's bet is the moment of decision. Training and simulations matter, but the platform's foundation is a browser-native layer that evaluates the pages and links users actually interact with, and steps in when something is dangerous, whether the lure arrived by email, search result, ad, or chat message. Simulations are adaptive and span browser and email workflows, and training is delivered as short, contextual lessons at the moment a user encounters a threat, triggers a risky action, or fails a simulation, when the lesson still maps to something concrete.
Neither philosophy is wrong. But they produce very different outcomes when a convincing attack reaches a busy employee on a Tuesday afternoon, and the research below explains why.
What Independent Research Shows

The most rigorous evidence available on security awareness training comes from large-scale randomized controlled studies, and it is not kind to the scheduled-training model.
The UC San Diego Health Study (2025)
Researchers ran an eight-month randomized controlled experiment covering ten simulated phishing campaigns sent to more than 19,500 employees at a large healthcare organization, published at the IEEE Symposium on Security and Privacy. The findings:
- There was no significant relationship between whether a user had recently completed annual cybersecurity awareness training and their likelihood of failing a phishing simulation.
- Embedded training (the “you clicked, here's a lesson” model used by mainstream awareness platforms) reduced the likelihood of clicking by roughly 2 percentage points.
- Most users spent minimal time engaging with the training material, and for some content types, users who completed more training were more likely to fail later simulations.
- By the eighth month, more than 50% of employees had clicked at least one simulated phishing link.
The authors' conclusion: anti-phishing training programs, in their current and commonly deployed forms, are unlikely to offer significant practical value in reducing phishing risks.
The 2026 Reproduction Study
A 2026 study reproduced these findings using the NIST Phish Scale across more than 12,000 participants. Neither interactive nor lecture-based training produced statistically significant changes in click rates or reporting behavior. What did predict user behavior was the difficulty of the lure itself: click rates roughly doubled, from 7% to 15%, as lures became more convincing. As AI makes convincing lures cheap to produce at scale, that finding should worry every security leader.
The Knowledge-Behavior Gap
A 2024 meta-analysis of 69 studies in Computers & Security adds the nuance: training genuinely works at building knowledge. Effects on knowledge and attitudes were strong. But when studies measured actual behavior change, the effect dropped by nearly two-thirds and was no longer statistically reliable. People learn what phishing is; they still click when a well-timed, well-crafted attack meets them inside a normal-feeling workflow.
The takeaway is not that training is worthless. It is that training alone leaves the moment of decision undefended. Knowledge fades, attention lapses, and attackers only need one busy moment. A modern program needs a layer that is present at the point of click, which is precisely the layer where these two platforms differ most.
KnowBe4 at a Glance
KnowBe4 is the largest and most established vendor in security awareness training, with a mature platform and strong market validation (around 4.6/5 across roughly a thousand G2 reviews). Its core strengths are real:
- Content breadth. The Diamond tier unlocks a library of 1,300+ training items (modules, videos, games, posters, and newsletters), plus compliance-specific content across many languages.
- Mature simulation tooling. Unlimited email phishing tests with an enormous template library, plus vishing tests at higher tiers.
- Enterprise plumbing. Active Directory integration, SCORM support, user event APIs, webhooks, and detailed reporting for audit and compliance needs.
- AI features at the top tiers. AIDA (AI Defense Agents) selects phishing templates and recommends training per user, available on Platinum and Diamond.
The documented trade-offs, drawn from public reviews on G2, Gartner Peer Insights, PeerSpot, and independent analyses:
- Administrative complexity. Reviewers consistently describe a dense interface and a significant learning curve, particularly for Smart Groups and AIDA configuration. Running a fresh, effective program requires meaningful ongoing admin investment.
- Content fatigue. Long-term users report modules feeling repetitive after 12 to 18 months, and tech-literate employees frequently describe the training as basic or tedious.
- Feature paywalls. Capabilities are spread across four tiers (Silver, Gold, Platinum, Diamond), and the features most relevant to modern programs (AI personalization, advanced reporting APIs) sit at the top.
- Email-centric simulations. The simulation engine is built around the inbox, while real attacks increasingly begin in search results, ads, collaboration tools, and the browser.
- Real-time coaching, not real-time protection. SecurityCoach, the closest thing to an in-the-moment capability, is an extra per-seat cost on top of Platinum or Diamond and requires at least 101 seats. More importantly, it does not detect or block anything itself: it consumes events from your existing security tools and sends the user a coaching message about what those tools did. The protection still has to come from somewhere else in your stack.
SavvyShield at a Glance
SavvyShield approaches human risk as a protection problem first and a training problem second. The platform combines four capabilities in one connected loop:
- Real-time browser protection. A browser-native layer evaluates the links and pages users actually engage with and intervenes at the point of decision, before credentials are entered or a malicious action completes. Protection is core to the product, not an add-on, and it does not depend on detections from other tools.
- Adaptive simulations across browser and email. AI generates and adapts realistic practice scenarios based on modern attack patterns and the risks employees actually face, so testing continues without hand-building every campaign.
- Contextual training at the moment of risk. When a user encounters a threat, triggers a risky action, or fails a simulation, they receive a short lesson tied to what just happened: the delivery model the research says is missing from scheduled programs.
- Risk visibility. SavvyScore assessments, organizational benchmarks, simulation performance, and training completion in one dashboard, so teams can measure behavior change over time rather than course completions.
The honest trade-offs run the other direction from KnowBe4's: SavvyShield does not try to match a 1,300-item content library, and organizations whose primary requirement is a deep catalog of off-the-shelf, compliance-specific coursework in dozens of languages will find more of that at KnowBe4. SavvyShield's design center is behavior change and live protection, with automation doing the campaign management an admin would otherwise do by hand.
Side-by-Side Comparison
| Dimension | KnowBe4 | SavvyShield |
|---|---|---|
| Core philosophy | Scheduled awareness training and email phishing tests build knowledge over time | Protection-first: defend the moment of decision, then train in context |
| Real-time protection | None built in; the SecurityCoach add-on (extra per-seat cost, 101+ seats, Platinum/Diamond) coaches users about detections made by your other security tools; it does not block threats itself | Built-in, browser-native, included in the core platform |
| Phishing simulations | Email-centric with a very large template library; unlimited sends | Browser and email workflows; AI-generated and adaptive to each user's risk |
| Training model | Scheduled modules from a 1,300+ item library (full library at Diamond tier) | Short contextual lessons delivered at the moment of risk or failure |
| AI personalization | AIDA template selection and training recommendations, on Platinum and Diamond tiers | Adaptive by default across simulations, training, and risk scoring |
| Coverage beyond the inbox | Limited; simulations and training center on email | Browser-native, covering threats that arrive via search, ads, chat, and fake login pages |
| Admin overhead | Powerful but documented as complex; Smart Groups and AIDA require significant learning investment | Automation-first; simulations and training adapt without hand-built campaigns |
| Packaging | Four tiers (Silver to Diamond) with key features gated to upper tiers; add-ons priced separately | One platform; protection, simulations, training, and visibility included |
| Best fit | Large enterprises needing maximum content breadth and compliance coursework | Teams that want measurable behavior change and live protection with low admin effort |
Coverage: Where Threats Actually Reach Users

The inbox is no longer where most phishing journeys end, and increasingly it is not where they begin. Modern lures arrive through search results and malicious ads, collaboration platforms, text messages that point to a link, and convincing fake login pages that can sit behind any of those channels. Whatever the entry point, nearly every phishing attack converges on the same place: the browser, where the user decides whether to click, sign in, download, or approve.
This is the structural difference between the two platforms. An email-centric simulation and training program can only rehearse a shrinking slice of the attack surface. A browser-native layer sits at the convergence point, which means it is present for the email-borne attack and for the search ad, the chat link, and the spoofed login page, including the ones no simulation ever rehearsed.
KnowBe4 acknowledges this gap in its own product line: SecurityCoach exists precisely because scheduled training cannot act in the moment. But SecurityCoach is a messenger, not a shield: it inherits the coverage of whatever detection tools you already own and coaches the user about what those tools did, after they act. SavvyShield's protection is the detection layer, standing between the user and the threat, so coverage does not depend on the rest of the stack.
Administrative Overhead
The cost of a human risk program is not just the subscription; it is the hours your team spends running it. This is one of the most consistent themes in KnowBe4's public reviews: the platform is deep, but that depth demands expertise. Administrators describe cumbersome campaign and group management, reporting that requires manual work, and a learning curve that grows with each feature tier. KnowBe4's own implementation guidance acknowledges that keeping content feeling fresh requires actively rotating categories and configuring Smart Groups: work that falls on your team, indefinitely.
SavvyShield's automation-first design exists to eliminate that recurring tax. AI generates and adapts simulations, training triggers itself based on user behavior, and risk scoring updates continuously, so the program improves without someone rebuilding campaigns every quarter. For lean security teams, the difference between “a platform you operate” and “a program that runs” is often the deciding factor.
Which Platform Fits Your Organization
KnowBe4 is likely the better fit if:
- Reaching compliance metrics matters more than actual risk reduction.
- You have dedicated program administrators with time to manage campaigns, Smart Groups, and content rotation.
- Your security team runs existing security tools that can feed detections into SecurityCoach.
SavvyShield is likely the better fit if:
- Your goal is measurable behavior change and risk reduction alongside completion rates.
- You want active protection in the browser: an additional layer of security at the user's moment of decision.
- Your security team is lean, or making a push toward automation.
- You want training that is short, relevant, and tied to what just happened.
The Bottom Line
KnowBe4 built the category and remains the strongest choice for organizations whose requirement is awareness content at maximum breadth. But the best available research is unambiguous about the limits of that model: scheduled training and email simulations, on their own, barely move real-world click behavior: a 2% reduction in the largest controlled study, with over half of employees clicking within eight months anyway.
Human risk is decided in the browser, at the moment of decision. SavvyShield was built for that moment: real-time protection that does not depend on the rest of your stack, simulations that rehearse the attacks users actually face, and training delivered when it can still change the outcome. If the goal of your program is behavior, not just completion rates, that is the comparison that matters.
Assess your organization’s risk to see SavvyShield against your current program, or explore the Human Risk Defense Playbook for a deeper look at building an adaptive program.
Sources / References
- Ho, G., et al. Understanding the Efficacy of Phishing Training in Practice, IEEE Symposium on Security and Privacy, 2025. Randomized controlled experiment: 19,500+ employees, ten campaigns, eight months. Referenced for the ~2% embedded-training effect, the null result for annual training, and cumulative click rates.
- UC San Diego Today / TechXplore. Cybersecurity training programs don't prevent employees from falling for phishing scams, September 2025. Referenced for plain-language summary of the study above.
- Anti-Phishing Training (Still) Does Not Work: A Reproduction of Phishing Training Inefficacy Grounded in the NIST Phish Scale, 2026. Referenced for the reproduction results (no significant training effect; click rates driven by lure difficulty, 7% to 15%).
- Assessing the effect of cybersecurity training on end-users: A meta-analysis, Computers & Security, 2024. Referenced for the knowledge-versus-behavior effect gap across 69 studies.
- KnowBe4. Security Awareness Training Pricing and Subscription Levels. Referenced for tier features and SecurityCoach add-on requirements, as published as of May 2026; offerings may change and vary by region.
- Aggregated public reviews and analyses of KnowBe4 (G2, Gartner Peer Insights, PeerSpot, Trustpilot; Valydex and other independent 2026 reviews). Referenced for documented strengths (content breadth, platform maturity) and criticisms (admin complexity, content fatigue, reporting friction).
- Verizon. Data Breach Investigations Report. Referenced for the share of breaches involving a human element.
KnowBe4 is a trademark of KnowBe4, Inc. All third-party product information is drawn from public sources linked above and reflects those sources as of July 2026; capabilities and pricing may change. This comparison is published by SavvyShield.
