Try our new research platform with insights from 80,000+ expert users

KnowBe4 vs Sophos Phish Threat comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 2, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

KnowBe4
Ranking in Security Awareness Training
1st
Average Rating
8.6
Reviews Sentiment
6.6
Number of Reviews
15
Ranking in other categories
No ranking in other categories
Sophos Phish Threat
Ranking in Security Awareness Training
3rd
Average Rating
8.8
Reviews Sentiment
7.4
Number of Reviews
12
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of July 2025, in the Security Awareness Training category, the mindshare of KnowBe4 is 27.3%, down from 34.0% compared to the previous year. The mindshare of Sophos Phish Threat is 4.2%, down from 5.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Security Awareness Training
 

Featured Reviews

Amran Hossain - PeerSpot reviewer
Training program enables comprehensive security awareness and cautious email practices
One feature that would be highly beneficial in a future release is the ability to automatically send training articles or security tips to users on a regular, scheduled basis—for example, weekly or monthly. While the current training modules and phishing simulations are highly effective, ongoing awareness is equally important to keep security top of mind in day-to-day operations. These short, digestible articles or micro-learning content could cover recent phishing trends, real-world examples of security breaches, or quick tips on secure online behavior. Periodic delivery would serve as a continuous learning touchpoint, reinforcing key concepts from the main training and adapting to evolving threats. Ideally, this feature would also include personalization, allowing content to be tailored based on a user’s role, previous training performance, or common mistakes observed in phishing simulations. This kind of proactive, lightweight training approach could significantly enhance employee engagement with security practices and help maintain a strong security posture over time.
Shaun Gordon - PeerSpot reviewer
Identifies vulnerable employees through customized simulations
Sophos Phish Threat effectively identifies susceptible employees. It depends on knowing my staff. For example, if I receive an email claiming my Facebook account is compromised, I immediately recognize it as suspicious, as I don't have Facebook. If I know my staff use LinkedIn, I utilize the LinkedIn simulation. Similarly, if they bank with Absa, I use the Absa simulation. There isn't a single 'one size fits all' approach. Sophos Phish Threat ensures users do not click on dodgy emails or dodgy links within an environment.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The main thing is the overall report card. We get to tell the percentages of users who click on links and who don't click on links. We also get an overall score or risk score from them, which also helps us."
"Their support is very quick and informative, deserving a rating of 10."
"KnowBe4's formulas for risk reduction simply work. Being a technical company, our initial phish-prone percentage wasn't super high, but it was still around 18%. Since we have been requiring ongoing training and simulated phish testing, our average phish-prone percentage hovers in the 0 to 3% range now."
"The benefits I have seen from using KnowBe4 include that many people are now cautious."
"The ability to have business leadership be aware of their users' security posture as well as any kind of security awareness training being pushed by cybersecurity insurance and underwriters is valuable."
"KnowBe4 has a training program that lasts approximately 15 or 30 minutes, and we provide this security training for our employees so they learn which emails they should open, which links they should click, which links they should not click, and which software they should install."
"KnowBe4 has been quite useful for us as a mid-size company, providing a lot of information."
"It has helped us tremendously in cybersecurity awareness."
"Sophos Phish Threat is valuable as it is easy to use and effectively educates end users on the threats they may face and how to identify them."
"I have found the implementation process to be simple and straightforward."
"The scalability is very good."
"The installation is straightforward. You only need to upload the user's email address to the cloud and you can start using it."
"The solution is easy to integrate because it is on the cloud. We have been able to limit users to only accessing the Sophos platform by modifying the firewall and Sophos platform settings. The dashboard gives us detailed reports allowing us to be able to manage better."
"It is simple to push tests out to a group of users."
"Sophos Phish Threat effectively identifies susceptible employees."
"I find the solution's reports very valuable."
 

Cons

"The training program is very interactive, but sometimes it is hard to follow the process, particularly the steps."
"It can be more interactive with users. We want to put the users in different scenarios and let them make decisions. For example, instead of making users go through a video and then asking questions, it can have a video where they click on the scenarios and have to make decisions. It can maybe have something like a live simulation. It would be nice for users."
"Much of the content they have might not be required, and that might cause frustration, especially when you're trying to implement a cybersecurity program where you're training your entire workforce, as it may frustrate someone if they're forced to do training on how to set a password."
"A lot of their training is designed for people who are almost entirely computer illiterate, which is fine because you want to be comprehensive in your cybersecurity training, but much of the content they have might not be required, and that might cause frustration, especially when you're trying to implement a cybersecurity program where you're training your entire workforce."
"KnowBe4 should focus more on these issues and provide guidance on dealing with links received from individuals who attempt to manipulate our emotions, particularly on social media platforms such as Facebook and LinkedIn."
"Enhancing the product's emotional intelligence, particularly by providing training content tailored to specific audiences, is an area for improvement."
"This product has a questions and answers section which is in text form. It could be updated to include a video game format where an employee uses the game to answer these scenarios."
"As an exceptional product, they are relatively expensive, but it is worth it because compared to offline education with hired dedicated people, it would be much more expensive and not obviously more efficient."
"The product's price is an area of concern, and it can be improved if Sophos reduces the prices by seven to nine percent, considering the current market price at which the product is offered."
"Sophos Phish Threat can improve load balancing."
"The pricing of Sophos Phish threat can be improved."
"Integration with other products could be improved."
"Sophos should offer tests where we can emulate new attacks happening now."
"The security of the solution could improve."
"The security could be simplified within the product."
"Sophos Phish Threat can improve by adding other languages, such as Mandarin or Cantonese to their online trainer video center, it would be helpful."
 

Pricing and Cost Advice

"It's about five dollars a seat per month."
"I don't know the cost, but I believe we are paying yearly. We did like a three-year or five-year contract. I am not aware of any extra costs in addition to a standard licensing fee."
"Licensing is paid on a yearly basis. You can go to the official site to check their approximate pricing. It's based on the number of users or staff. It can vary from country to country, but for Ukraine, it works as it's stated on the site."
"I rate the product pricing as four out of ten."
"Licensing fees are paid annually."
"The license for the product comes with the firewall offered by Sophos, so a user need not buy it separately."
"There are monthly and annual subscriptions available to use Sophos Phish Threat. The price is reasonable."
"There is a license required for this solution and the cost depends on the number of users."
"The pricing is very good, and some of my customers who have used other vendors say that Sophos is priced well within the market."
report
Use our free recommendation engine to learn which Security Awareness Training solutions are best for your needs.
860,592 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Financial Services Firm
7%
Healthcare Company
6%
Construction Company
6%
Financial Services Firm
15%
Real Estate/Law Firm
13%
Insurance Company
11%
Performing Arts
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about KnowBe4?
Their customizable nature allows us to create scenarios that closely resemble real-world phishing attempts, making them highly relatable to our end users.
What needs improvement with KnowBe4?
I think KnowBe4 focuses primarily on emails, phishing emails, and business. We need more experience about dealing with hackers and scams on social media, especially when we receive links from unkno...
What do you like most about Sophos Phish Threat?
I find the solution's reports very valuable.
What needs improvement with Sophos Phish Threat?
There is a need for improvement regarding false negatives dealing with Office 365. The issue stems from policies in Office 365 that prevent scanning certain elements, which might trigger errors. I ...
What is your primary use case for Sophos Phish Threat?
I use Sophos Phish Threat to test employee security awareness. Essentially, my clients utilize Phish Threat to ensure that users are not clicking on suspicious emails or links. It is a simulated ca...
 

Also Known As

No data available
Phish Threat
 

Overview

 

Sample Customers

West Aurora Public School District 129
Information Not Available
Find out what your peers are saying about KnowBe4 vs. Sophos Phish Threat and other solutions. Updated: June 2025.
860,592 professionals have used our research since 2012.