Barracuda Email Protection is an email security solution that uses machine learning to provide protection against threats. It combines email gateway defenses and API-based inbox defense to prevent attacks, respond to threats in real time, and secure Microsoft 365 data.
N/A
Cofense PhishMe
Score 9.7 out of 10
Enterprise companies (1,001+ employees)
Cofense PhishMe is a cyber threat and phishing simulator meant to be of use in training employees to be wary against threats and also to gain information about general employee threat knowledge and preparedness. A free trial is available for small business.
N/A
Pricing
Barracuda Email Protection
Cofense PhishMe
Editions & Modules
No answers on this topic
No answers on this topic
Offerings
Pricing Offerings
Barracuda Email Protection
Cofense PhishMe
Free Trial
Yes
Yes
Free/Freemium Version
No
No
Premium Consulting/Integration Services
No
Yes
Entry-level Setup Fee
No setup fee
No setup fee
Additional Details
—
—
More Pricing Information
Community Pulse
Barracuda Email Protection
Cofense PhishMe
Features
Barracuda Email Protection
Cofense PhishMe
Secure Email Gateway
Comparison of Secure Email Gateway features of Product A and Product B
Barracuda Email Protection
6.6
16 Ratings
24% below category average
Cofense PhishMe
-
Ratings
Anti-malware
10.016 Ratings
00 Ratings
Customizability
5.015 Ratings
00 Ratings
Data Loss Protection
2.013 Ratings
00 Ratings
Threat Detection
9.016 Ratings
00 Ratings
Sandboxing
3.012 Ratings
00 Ratings
End-to-End Encryption
8.013 Ratings
00 Ratings
Management Tools
9.016 Ratings
00 Ratings
Security
Comparison of Security features of Product A and Product B
Barracuda Email Protection
-
Ratings
Cofense PhishMe
7.8
4 Ratings
9% below category average
Single sign-on capability
00 Ratings
7.44 Ratings
Role-based user permissions
00 Ratings
8.24 Ratings
Security Awareness Training
Comparison of Security Awareness Training features of Product A and Product B
I would definitely recommend it due to the decent pricing. I wish the MS built-in M365 tools were better, but Barracuda does a good job of taking their place. For industries that need DLP on their email, like healthcare, banking, and education, Barracuda provides a reliable product for a good cost. The additional services you get, malware/AV filtering, URL filtering, spam protection, business continuity, those are all icing on the cake. The only issues we've ever really had with them is that it will sometimes take a back/forth string of emails and decide randomly to encrypt it, so what was a flowing benign conversation is now locked behind a wall for recipients. As the sender, you have no idea when it's going to decide to do this and have to remember to tag emails with a decrypt tag long before it happens or face the consequences
Cofense PhishMe is an excellent solution for scenarios where it will be sold as a managed service. I believe that PhishMe is too expensive for many clients and instead would benefit from the economies of scale where an MSSP sells it as part of a whole service, which offers the analysts and reporting included. PhishMe is excellent for training and awareness of Phishing, but shouldn't replace mandatory training for new joiners or yearly refreshers, it should only be used as an additional training option.
It gives clear-cut segregation of different parts of an email, header, text and HTML body, URL, attachments, HTML preview and some analytical insight like "similar reports." This distinctive approach actually helps reduce data overload during an analysis.
The URLs captured here pass through an automatic reputation check [in our case VirusTotal] and add a tag of the reputation. If it is a well-known bad URL the tag helps us take the decision fast.
For creating automation rules on the reported emails the "Recipes" section is really helpful. We can create easy recipes [or rules ] to handle a huge flow of reports and also we can create more sophisticated rules depending on the Cyber intelligence feed to catch the really bad currently less known attack attempts by malicious emails.
The "Threat Indicators" section is also useful to use as a threat intelligence source to check the URLs for their maliciousness.
The product is pretty solid so I am not sure how it can be improved. One thing I noticed recently, I am not getting the emails back from Sentinel when I send in a "miss". Used to be I got an email back saying "sorry we missed this, we are improving." That does happen anymore, so I am assuming that when I send a miss, the AI is getting better.
I would expand this to cover all kinds of email fraud like ransomware and spam rather than creating another product.
Although cost competitive, we still feel like we are not digging deep enough to train our staff. We have little to no way other than digging through reports that have not proven to be adequately documented (hey you, Barracuda campaign reports) to identify and require users to take more training who have not passed their requirements.
Regarding usability, we like it to be an easy solution to implement and configure on the server. Routine backups are made frequently and reports are issued for control and analysis by information security teams. It has great integration with the cloud and encryption.
Its built with UX in mind and is aimed at non-tech people, to ensure that almost everyone can run the campaign. But if we go deeper - sometimes you will need an HTML editor or support in order to figure out some advanced edits you might want to add in your scenarios.
I have not had to use customer support yet which goes to show the effectiveness of the program. It also shows how easy the program is to use for the average person with no experience using this type of program. Our IT department also does a great job at teaching us to detect emails with malware that in combination with this software issues rarely arise even though we have over 500 employees.
I have not had to use their support for pretty much anything. The software works well, and is very intuitive. I would imagine their support would be rather basic as there is not too much that can go wrong with a report phishing button, and if it were I would probably consider a different software.
Barracuda Essentials has a far easier admin pannel than is provided by mimecast along with far more filtering options such as dkim. Much easier to do the initial setup along with much better support provided. Barracuda Essentials has Advanced threat protection that uses AI to spot patterns and gives you the option to remove a suspect email from all inboxs
Cofense PhishMe was the first choice for us as the user interface as well as their bundle package with Cofense Triage and Vision has helped the organisation to alleviate the overall security awareness posture. The other vendors did not provide a vast range of phishing scenarios as compared to Cofense PhishMe platform.
Recipes in the system are capable of handling almost 2x what an analyst does, which cuts down the efforts [of] an analyst and provides more time for accurate strategies.
With roughly 90% false positives coming through, the remaining 10% of true positives need as much attention as they can get for the full investigation and analysis.
1,500 or more phishing messages can come through in a given week and the amount of time/employees required to review this without a tool like Cofense is surely beyond [the] expected/anticipated budget.