TL;DR:
- KnowBe4 is the market leader for small businesses: large content library, straightforward phishing simulation, usable self-service interface; ~£20–35/user/year
- Proofpoint PSAT is data-driven and integrates well with Proofpoint email security, but is better suited to larger teams with a dedicated IT person managing the platform
- Hoxhunt uses adaptive gamification and consistently gets the highest completion rates — good for UK SMBs where staff have limited time for training
- NCSC Cyber Aware resources are free and legitimately useful for budget-constrained businesses, but have no phishing simulation capability
- Minimum effective cadence: one simulated phish per month, one short training module per quarter; annual “read a PDF” security training alone does not work
Your existing phishing training guide may cover the principles. What it doesn’t tell you is which platform to actually buy — and whether the one your IT reseller recommended is the right choice for a 15-person business that doesn’t have a dedicated security team.
What These Platforms Do
Security awareness training platforms combine two things: simulated phishing campaigns that send realistic fake phishing emails to your staff (to test who clicks) and training content that teaches staff to recognise and report real threats. The combination of testing and teaching, run consistently over months, reduces click rates on malicious emails by 60–70% according to vendor data — figures broadly supported by independent security research.
The key is “run consistently.” A one-time training exercise doesn’t rewire the reflexes that make people click. Monthly exposure to simulated phishes does.
KnowBe4
KnowBe4 is the most widely used security awareness platform globally, with over 65,000 organisations. For small businesses, its main advantages are a large content library (thousands of training modules covering phishing, ransomware, social engineering, compliance topics) and a self-service admin interface that a non-specialist can navigate.
Phishing simulations include UK-specific lures — HMRC refund notices, Royal Mail parcel delivery failed, Companies House filing reminders — which matter because generic American phishing templates don’t replicate the actual threats UK staff encounter. The platform also tracks who clicked, who reported, and who completed remedial training.
Pricing: Approximately £20–35/user/year depending on tier (Silver, Gold, Platinum, Diamond). Minimum five seats. Annual contract.
Best for: UK SMBs with 5–100 users who want a proven platform and can commit to a minimum 12-month contract. The self-service interface means a small business owner or office manager can run it without specialist help.
Watch out for: The Diamond tier is priced for enterprise budgets and includes features small businesses won’t use. Silver or Gold is typically sufficient.
Proofpoint Security Awareness Training (PSAT)
Proofpoint PSAT takes a more analytical approach. Its strength is the Threat Intelligence integration — Proofpoint’s email security products share real-time data about active phishing campaigns, and PSAT can automatically simulate the same lure types currently targeting organisations in your industry. This is genuinely more sophisticated than static template libraries.
The admin interface and reporting are more detailed than KnowBe4, which is an advantage for a business with an IT manager who wants granular per-user data, and a disadvantage for one where the person running the platform also handles the accounts payable.
Pricing: Approximately £15–30/user/year. PSAT is often purchased bundled with Proofpoint email filtering.
Best for: Small businesses already using Proofpoint email filtering (Proofpoint Essentials is popular with 20–500 user organisations) who want a training platform from the same vendor with data sharing between products.
Watch out for: Overkill without the email security integration. The data-driven features that differentiate it require the email product to be present.
Hoxhunt
Hoxhunt takes the most distinctive approach: adaptive phishing simulations that adjust difficulty based on each individual user’s performance, combined with gamification that makes reporting suspicious emails feel rewarding rather than anxiety-inducing.
The platform rewards staff with points for correctly reporting phishing simulations, builds individual risk profiles, and increases simulation difficulty as users improve. This produces consistently high completion rates — staff engage because it doesn’t feel like mandatory compliance training. The leaderboards and team challenges work particularly well in office environments where a bit of competitive culture already exists.
Pricing: Approximately £25–40/user/year. Minimum team sizes apply.
Best for: UK SMBs that struggle with low completion rates on traditional training. Businesses where culture matters — where you want staff to feel empowered about security, not burdened by it.
Watch out for: The gamification doesn’t appeal to everyone, and some organisations find it too lightweight on formal compliance documentation. Check whether Cyber Essentials reporting requirements can be met with Hoxhunt’s reporting exports before committing.
Mimecast Awareness Training
Mimecast’s training platform uses three-minute microlearning modules — short enough that completion rates are high without the platform requiring dedicated training time. Like Proofpoint, it integrates with Mimecast’s email security products.
The content quality is good and the UK focus is solid. For businesses already using Mimecast email filtering, it’s a natural addition. Standalone, it sits in roughly the same position as KnowBe4 but with less content depth.
Pricing: Approximately £15–25/user/year.
NCSC Cyber Aware and Free Resources
The NCSC’s Cyber Aware programme offers genuinely useful free resources: staff training materials, templates, and guidance calibrated to UK threats and regulation. The NCSC’s “Top Tips for Staff” and “Exercise in a Box” scenarios are worth using for businesses where paying £20/user/year is not feasible.
The gap is phishing simulation — the NCSC doesn’t run fake phishing campaigns for you, which is the most effective behaviour-change mechanism the paid platforms provide. Free resources are a reasonable starting point; they don’t replace a simulation platform for businesses serious about reducing click rates.
What to Check Before Buying
UK-specific phishing templates: Ask vendors to show you their UK template library. HMRC, Royal Mail, NHS, Gov.uk, Barclays, and Lloyds lures should be present. American-centric templates waste simulation value.
Cyber Essentials evidence support: If you hold or plan to pursue Cyber Essentials Plus certification, check whether the platform produces compliance reports acceptable as evidence of user security training.
Minimum seat counts and contract length: Most platforms require at least 5 users and annual contracts. Factor this into budget planning.
Trial or pilot: KnowBe4 and Hoxhunt both offer free trial periods. Run a baseline phishing test with your team before the training starts — it establishes click rates before intervention and makes the improvement measurable.
For a 20-person UK business spending roughly £500/year on a training platform, the return on investment is straightforward: average cost of a successful phishing breach for a UK SMB is over £8,000 in incident response, downtime, and recovery, before any regulatory or reputational consequences. Monthly phishing simulation is among the highest-return security expenditures available at that budget level.