Appearance
Security Awareness Training Platform Evaluation
Purpose
Cirius Group is a 20-person HIPAA-regulated organization that needs a security awareness training platform to satisfy HIPAA 164.308(a)(5) workforce security training requirements and SOC2 CC1.4 competence requirements. This document evaluates three candidate platforms and recommends one.
Related story: COMP-008.
Requirements
Must-have
- HIPAA training content — role-appropriate modules for general workforce and for privileged users, with assigned due dates and completion tracking
- Phishing simulation — integrated or natively supported, with click/report metrics per user
- Audit evidence export — CSV / PDF of completion rates per user per training cycle, suitable for SOC2 auditors and HIPAA risk assessments
- SSO with Entra ID — users authenticate via Entra, no second set of credentials
- Low admin overhead — Rory is sole IT; platform must be runnable in under 2 hours per month of total admin time
Nice-to-have
- Pre-built SOC2 and NIST CSF content libraries
- Behavioral risk scoring per user
- Short-form (under 5 minute) micro-trainings for new-hire onboarding
Scale
- 20 users today; assume growth to 40 within two years
- No in-person delivery needed — all remote/async
Candidates
1. KnowBe4 Security Awareness Training
- Positioning: Industry standard for SMBs. Largest content library of the three. Strong phishing simulation baked in since day one.
- HIPAA content: Dedicated HIPAA module library, role-targeted for healthcare workforce and privileged users. Updated on an ongoing basis as regulations shift.
- Phishing simulation: Native, mature, with PhishER for click triage. Tight integration between training content and simulation results — click assigns a targeted remediation module automatically.
- Reporting: Strong. CSV / PDF exports for any cycle. AuditReady module targets SOC2 / HIPAA evidence directly.
- SSO: Entra ID SSO supported via SAML or OIDC. SCIM provisioning available.
- Admin burden: Low once templates are configured. Campaign scheduling takes about 30 minutes per quarter. Automated assignment via AD groups.
- Cost (20 users, Diamond tier — typical for SMB with HIPAA): Approximately $18–25 per user per year, list price. Often discounted through the CDW / Pax8 channel. Expect ~$400–600/year for 20 users at the Silver tier (sufficient for a 20-person HIPAA SMB) or higher if the customer wants PhishER and AIDA.
- Gotchas: Support quality has been uneven in the last 12 months per customer reports. The Gold+ tiers add features that a 20-person org rarely needs.
2. Proofpoint Security Awareness (formerly Wombat)
- Positioning: Enterprise-focused. Strongest behavioral risk scoring of the three. Tightly coupled with Proofpoint's email security platform.
- HIPAA content: Yes, but library is smaller than KnowBe4. Stronger on healthcare-specific privacy content than on general HIPAA security rule.
- Phishing simulation: Excellent, tied to Proofpoint threat intel so simulated lures reflect real campaigns seen in the wild.
- Reporting: Good. CISO dashboard is the best of the three. SOC2 / HIPAA evidence export is available but less first-class than KnowBe4 AuditReady.
- SSO: Entra ID SSO supported.
- Admin burden: Moderate. Configuration is more flexible and therefore more complex than KnowBe4. Best value if Cirius already runs Proofpoint email protection (we run Defender for Office 365 — so this synergy does not apply).
- Cost (20 users): Approximately $30–50 per user per year for a standalone license. Expect ~$700–1000/year for 20 users. List-price gap narrows at 500+ seats.
- Gotchas: Not a fit for a 20-person org unless Cirius is also buying Proofpoint email security. The richer-than-needed feature set is paid for regardless of use.
3. Microsoft Viva Learning + Attack Simulator
- Positioning: Bundled with existing Microsoft 365 licensing (we run M365 E5). Uses Attack Simulator (Defender for Office 365) for phishing simulation and Viva Learning for training content delivery.
- HIPAA content: None native. Must be supplied by bringing in content from LinkedIn Learning, a third-party publisher, or an internal course. This is the weakest point for a HIPAA org.
- Phishing simulation: Attack Simulator is solid and free with Defender for Office 365 P2 (which we have via M365 E5). Payloads and reporting are adequate.
- Reporting: Fragmented. Training completion lives in Viva; simulation results in Defender portal. Stitching them for a single audit export is manual.
- SSO: Native — all users are already signed in.
- Admin burden: Moderate to high. Content sourcing and the stitched reporting model consume the admin time savings from the free SKU.
- Cost (20 users): Effectively $0 incremental (Viva Learning basic and Attack Simulator are included in our existing M365 E5). Any published content library would be separate (~$20 per user per year for LinkedIn Learning).
- Gotchas: No turnkey HIPAA course library. Audit evidence stitching is manual. Good baseline, but does not satisfy HIPAA workforce training on its own.
Comparison
| Criterion | KnowBe4 | Proofpoint | Viva + Attack Sim |
|---|---|---|---|
| HIPAA content quality | Strong | Moderate | None native |
| Phishing simulation | Strong | Strong | Adequate |
| SOC2 / HIPAA evidence export | Strong (AuditReady) | Good | Manual |
| Entra SSO | Yes | Yes | Native |
| Admin burden (20 users) | Low | Moderate | Moderate–High |
| Cost per year, 20 users | ~$400–600 | ~$700–1000 | ~$0–400 |
| Fit for 20-person HIPAA SMB | Best | Over-scoped | Under-scoped for HIPAA |
Recommendation
Adopt KnowBe4 (Silver or Diamond tier) as the primary security awareness platform.
Reasoning:
- HIPAA content library is the strongest and most maintained of the three
- AuditReady evidence exports land directly into our SOC2 binder with minimal manual reformatting
- Cost at 20 users is in the $400–600 range — the lowest real-world cost of a platform that actually covers HIPAA requirements end-to-end
- Phishing simulation integrates with training assignment — click = instant remediation module, which is the cadence we want for EMAILSEC-011
- It is the industry-standard choice for a HIPAA SMB; auditors are familiar with it and do not ask follow-up questions
- Proofpoint is only justified if we also buy Proofpoint email security, which we do not
- Viva Learning + Attack Simulator alone cannot satisfy HIPAA workforce training without a separate HIPAA content source, and the stitched reporting model increases admin burden
Next steps:
- Request a KnowBe4 quote via Pax8 (our Microsoft distribution partner — they resell KnowBe4 too)
- Request references from two similarly sized HIPAA orgs to sanity-check the current support experience
- Scope Silver tier initially; upgrade to Diamond only if PhishER and AIDA prove necessary after one year of baseline usage
- Budget line: ~$600/year for the first year. Tie to the phishing simulation cadence in
compliance/phishing-simulation-schedule.md
SOC2 / HIPAA Mapping
- HIPAA 164.308(a)(5) — workforce security awareness and training
- SOC2 CC1.4 — competence (training and evidence thereof)
- SOC2 CC2.2 — internal communication of security responsibilities