TrustRadius: an HG Insights company

KnowBe4 PhishER/PhishER Plus

Score9.2 out of 10

215 Reviews and Ratings

What is KnowBe4 PhishER/PhishER Plus?

PhishER is presented as a lightweight Security Orchestration, Automation and Response (SOAR) platform to orchestrate threat response and manage the high volume of potentially malicious email messages reported by users. And, with automatic prioritization of emails, PhishER helps InfoSec and Security Operations team cut through the inbox noise and respond to the most dangerous threats more quickly.

Media

Screenshot of how PhishER Plus enables a critical workstream to help IR teams work together to mitigate the phishing threat and is suited for any organization that wants to automatically prioritize and manage potentially malicious messages.

Screenshot of how PhishER Plus enables a critical workstream to help IR teams work together to mitigate the phishing threat and is suited for any organization that wants to automatically prioritize and manage potentially malicious messages.

Top Performing Features

  • Machine Learning to Prevent Incidents

    Incident prevention powered by machine learning with no human intervention

    Category average: 8.8

  • Company-wide Incident Reporting

    Built-in enterprise-level ticketing system to leverage the knowledge of the entire workforce, not just the security team

    Category average: 8.8

  • Centralized Dashboard

    A central dashboard provides analysts with a clear look at the most important data

    Category average: 8.5

Areas for Improvement

  • Live Response for Rapid Remediation

    Live remediation response allows incident responders to initiate remediation from anywhere over secure connection

    Category average: 8.3

  • Integration with Other Security Systems

    Pre-built integration with other security systems like SIEM and threat intelligence

    Category average: 7.5

KnowBe4 PhishER/PhishER Plus - Saving Organizations Hundreds of Thousands 1 Click at a time

Use Cases and Deployment Scope

We’ve been Phishing our employees utilizing KnowBe4 over 6 years now and recently implemented KnowBe4 PhishER/PhishER Plus's AIDA AI Phishing Tool- All advanced Phishing Simulations! Absolutely fantastic results! I highly recommend organizations move to KnowBe4 PhishER/PhishER Plus's AI Phishing Tool. Over the years I’ve been given another title from employees - “The Phisherman” :) All employees use the Phish Alert Button to report suspicious emails and they actually appreciate being Phished regularly! KnowBe4 PhishER/PhishER Plus provides an excellent service! We have successfully removed threat emails from 50 mailboxes at once in a matter of seconds using PhishER - Threat is detected query automatically created threats found and we instantly remove all emails - We teach our employees if you see something say something!!!! The "Say Something" is clicking on the PAB - Phish Alert Button ""KnowBe4 PhishER/PhishER Plus's plug in- in Outlook - and then we are instantly alerted of the Phishing threat! We also utilize all of the incredible online trainings and employees love the courses! Even if they fail a Phishing Simulation from AIDA AI and have to retrain the love the makeup courses! Thank you KnowBe4 PhishER/PhishER Plus for an incredible service! I would highly recommend KnowBe4 PhishER/PhishER Plus to everyone!!!!!!!!!!!! Sincerely, Glenn Romano Director of IT Services Sutro Biopharma Inc

Pros

  • Report threats instantly
  • Query instantly
  • Remove emails from inboxes instantly

Return on Investment

  • hundreds of thousands most likely

Usability

Solid Product with Great Support

Use Cases and Deployment Scope

KnowBe4 PhishER/PhishER Plus has several components of use. 1) We use the Phish testing. We run regular tests against our users to find individuals that may need additional education or training. This allows us to close weak links. 2) Training: We are a small team and do not have the time to do one on one training with users. Because of this we can lean on KnowBe4 PhishER/PhishER Plus training programs to help us educate our users. 3) PhishER+PAB: This function has now proven to be one of the most useful tools. With the automation and PhishRIP(+) we are able to more quickly remove emails that would prove to be risky. We have mitigated several large Phishing attacks because a user reported an email that was ripped company wide.

Pros

  • Quick phishing mitigation
  • Insight and data tracking
  • Education
  • Testing customizability

Cons

  • Issues with Global Blocklist
  • Email Template Modification - Simplification
  • Target Specific Users vs. Groups
  • PhishRIP info tabs (i.e. if improperly check ripped emails are turned into tests. This has caused issues.) Info tabs or markers allow user to hover and get more information about what action a check box or slider provides.

Return on Investment

  • Freed security managers from spending hours investigating and manually ripping emails
  • Provided easily accessible training materials
  • Helped identified areas of weakness

Usability

Alternatives Considered

Proofpoint Insider Threat Management

Other Software Used

Bitdefender GravityZone, Microsoft 365, LogMeIn Central by GoTo

Spend your time fishing not falling for Phishing with KnowBe4 PhishER/PhishER Plus

Use Cases and Deployment Scope

We needed a way to pull all confirmed phishing emails out of our team's inboxes, sandbox the emails and prevent others from falling for the same email. KnowBe4 PhishER/PhishER Plus does all this and more. Protecting the weakest link in our security, us. We are notified of any suspicious emails and we are then able to take action. Sometime a user will report a legitimate email and we are able to confirm to the user that it's not a suspicious email or on the flip side, we can notify everyone if there is something going on in real time. Security is vital to us as an organisation.

Pros

  • Ripping out emails from users inbox if a suspicious email was sent to the entire organisation or multiple people.
  • Uses real emails to make templates to run phishing tests on users
  • Reporting on any vulnerabilities and simulated phishing tests

Cons

  • From a non-technical person viewpoint, easier to understand reports on the phishing attempts received by our team

Return on Investment

  • Freed up resources to focus on work and not on reports
  • Reduced our cybersecurity insurance cost
  • Kept us safe from major breaches and therefore increased our trustworthiness with our clients

Usability

Other Software Used

Xero, Stripe Payments, HubSpot CRM

KnowBe4 PhishER is well worth it

Use Cases and Deployment Scope

We are using KnowBe4 for educational purposes, as well as logging phishing attempts to the orgainzation. As a small IT department, it has been a fantastic tool to get a overall vision of stengths and areas that need to be enhanced. We can then take information and provide better feedback to KnowBe4 to allow better protection against future spam attacks.

Pros

  • Great overall vision on how to build training and resources for better secuirty
  • Allows for presonalized focus on individuals and how to give them better, more focused training.
  • Allows to show leadership trends and patterns in graphical form

Cons

  • The spam control is most reliant on human interaction to make it effective. It would be nice to see some more proactive controls
  • The intergration with 365 has been a little more complex than it should

Return on Investment

  • Every time a staff member doesn't click on a link or open a bad email, saves me hours. Every time!
  • As a single IT person in the company, having a single point of view on starting a new teaching campaign, look at stats finding out who is struggling the most is worth ever cent.
  • I love the fact that everything has little to no impact on the network. The integration with our email is fantastic.

Usability

Other Software Used

Microsoft 365 Business Premium, Pulseway, Cisco Duo

KnowBe4 PhishER/PhishER Plus saves our organization lots of time while increasing our security posture.

Use Cases and Deployment Scope

KnowBe4 PhishER/PhishER Plus is our chosen solution for automated phish submission review and remediation. It allows for an AI review of submissions and automated search and removal for similar emails in our organization. This helps to remove the manual review for identifying threats and manual remediation for removing them throughout our organization.

Pros

  • Identifying Real Phishing Emails
  • Creating block lists for emails
  • Removing real threats from our environment

Cons

  • Better PhishRIP capability - some emails are missed
  • Better identification - less false positives

Return on Investment

  • The automated review allows for a real-time response rather than awaiting a human's review

Usability

Alternatives Considered

Proofpoint Threat Response Auto-Pull