Skip to content

Security Awareness Training Platform Evaluation

Purpose

Cirius Group is a 20-person HIPAA-regulated organization that needs a security awareness training platform to satisfy HIPAA 164.308(a)(5) workforce security training requirements and SOC2 CC1.4 competence requirements. This document evaluates three candidate platforms and recommends one.

Related story: COMP-008.


Requirements

Must-have

  • HIPAA training content — role-appropriate modules for general workforce and for privileged users, with assigned due dates and completion tracking
  • Phishing simulation — integrated or natively supported, with click/report metrics per user
  • Audit evidence export — CSV / PDF of completion rates per user per training cycle, suitable for SOC2 auditors and HIPAA risk assessments
  • SSO with Entra ID — users authenticate via Entra, no second set of credentials
  • Low admin overhead — Rory is sole IT; platform must be runnable in under 2 hours per month of total admin time

Nice-to-have

  • Pre-built SOC2 and NIST CSF content libraries
  • Behavioral risk scoring per user
  • Short-form (under 5 minute) micro-trainings for new-hire onboarding

Scale

  • 20 users today; assume growth to 40 within two years
  • No in-person delivery needed — all remote/async

Candidates

1. KnowBe4 Security Awareness Training

  • Positioning: Industry standard for SMBs. Largest content library of the three. Strong phishing simulation baked in since day one.
  • HIPAA content: Dedicated HIPAA module library, role-targeted for healthcare workforce and privileged users. Updated on an ongoing basis as regulations shift.
  • Phishing simulation: Native, mature, with PhishER for click triage. Tight integration between training content and simulation results — click assigns a targeted remediation module automatically.
  • Reporting: Strong. CSV / PDF exports for any cycle. AuditReady module targets SOC2 / HIPAA evidence directly.
  • SSO: Entra ID SSO supported via SAML or OIDC. SCIM provisioning available.
  • Admin burden: Low once templates are configured. Campaign scheduling takes about 30 minutes per quarter. Automated assignment via AD groups.
  • Cost (20 users, Diamond tier — typical for SMB with HIPAA): Approximately $18–25 per user per year, list price. Often discounted through the CDW / Pax8 channel. Expect ~$400–600/year for 20 users at the Silver tier (sufficient for a 20-person HIPAA SMB) or higher if the customer wants PhishER and AIDA.
  • Gotchas: Support quality has been uneven in the last 12 months per customer reports. The Gold+ tiers add features that a 20-person org rarely needs.

2. Proofpoint Security Awareness (formerly Wombat)

  • Positioning: Enterprise-focused. Strongest behavioral risk scoring of the three. Tightly coupled with Proofpoint's email security platform.
  • HIPAA content: Yes, but library is smaller than KnowBe4. Stronger on healthcare-specific privacy content than on general HIPAA security rule.
  • Phishing simulation: Excellent, tied to Proofpoint threat intel so simulated lures reflect real campaigns seen in the wild.
  • Reporting: Good. CISO dashboard is the best of the three. SOC2 / HIPAA evidence export is available but less first-class than KnowBe4 AuditReady.
  • SSO: Entra ID SSO supported.
  • Admin burden: Moderate. Configuration is more flexible and therefore more complex than KnowBe4. Best value if Cirius already runs Proofpoint email protection (we run Defender for Office 365 — so this synergy does not apply).
  • Cost (20 users): Approximately $30–50 per user per year for a standalone license. Expect ~$700–1000/year for 20 users. List-price gap narrows at 500+ seats.
  • Gotchas: Not a fit for a 20-person org unless Cirius is also buying Proofpoint email security. The richer-than-needed feature set is paid for regardless of use.

3. Microsoft Viva Learning + Attack Simulator

  • Positioning: Bundled with existing Microsoft 365 licensing (we run M365 E5). Uses Attack Simulator (Defender for Office 365) for phishing simulation and Viva Learning for training content delivery.
  • HIPAA content: None native. Must be supplied by bringing in content from LinkedIn Learning, a third-party publisher, or an internal course. This is the weakest point for a HIPAA org.
  • Phishing simulation: Attack Simulator is solid and free with Defender for Office 365 P2 (which we have via M365 E5). Payloads and reporting are adequate.
  • Reporting: Fragmented. Training completion lives in Viva; simulation results in Defender portal. Stitching them for a single audit export is manual.
  • SSO: Native — all users are already signed in.
  • Admin burden: Moderate to high. Content sourcing and the stitched reporting model consume the admin time savings from the free SKU.
  • Cost (20 users): Effectively $0 incremental (Viva Learning basic and Attack Simulator are included in our existing M365 E5). Any published content library would be separate (~$20 per user per year for LinkedIn Learning).
  • Gotchas: No turnkey HIPAA course library. Audit evidence stitching is manual. Good baseline, but does not satisfy HIPAA workforce training on its own.

Comparison

CriterionKnowBe4ProofpointViva + Attack Sim
HIPAA content qualityStrongModerateNone native
Phishing simulationStrongStrongAdequate
SOC2 / HIPAA evidence exportStrong (AuditReady)GoodManual
Entra SSOYesYesNative
Admin burden (20 users)LowModerateModerate–High
Cost per year, 20 users~$400–600~$700–1000~$0–400
Fit for 20-person HIPAA SMBBestOver-scopedUnder-scoped for HIPAA

Recommendation

Adopt KnowBe4 (Silver or Diamond tier) as the primary security awareness platform.

Reasoning:

  1. HIPAA content library is the strongest and most maintained of the three
  2. AuditReady evidence exports land directly into our SOC2 binder with minimal manual reformatting
  3. Cost at 20 users is in the $400–600 range — the lowest real-world cost of a platform that actually covers HIPAA requirements end-to-end
  4. Phishing simulation integrates with training assignment — click = instant remediation module, which is the cadence we want for EMAILSEC-011
  5. It is the industry-standard choice for a HIPAA SMB; auditors are familiar with it and do not ask follow-up questions
  6. Proofpoint is only justified if we also buy Proofpoint email security, which we do not
  7. Viva Learning + Attack Simulator alone cannot satisfy HIPAA workforce training without a separate HIPAA content source, and the stitched reporting model increases admin burden

Next steps:

  • Request a KnowBe4 quote via Pax8 (our Microsoft distribution partner — they resell KnowBe4 too)
  • Request references from two similarly sized HIPAA orgs to sanity-check the current support experience
  • Scope Silver tier initially; upgrade to Diamond only if PhishER and AIDA prove necessary after one year of baseline usage
  • Budget line: ~$600/year for the first year. Tie to the phishing simulation cadence in compliance/phishing-simulation-schedule.md

SOC2 / HIPAA Mapping

  • HIPAA 164.308(a)(5) — workforce security awareness and training
  • SOC2 CC1.4 — competence (training and evidence thereof)
  • SOC2 CC2.2 — internal communication of security responsibilities

Internal use only — Cirius Group