TrustRadius: an HG Insights company

SANS Security Awareness Training

Score7.9 out of 10

9 Reviews and Ratings

What is SANS Security Awareness Training?

The SANS Security Awareness Training, provided by the SANS Institute, aims to equip organizations of all sizes with the necessary knowledge and skills to mitigate human risk and enhance their cybersecurity posture, according to the vendor. This training is suitable for small, medium, and large businesses across various industries, including IT professionals, security professionals, developers, industrial control systems engineers, and organizations in the healthcare sector.

Key Features

EndUser Training: This training offers culturally relevant and effective computer-based modules that are designed to be easily implemented. With a diverse library of training modules covering a wide range of security topics, organizations can customize the content to meet their specific needs. The training is also available in over 34 languages.

PCI DSS Compliance Training: This training is specifically designed to address the compliance requirements of the Payment Card Industry Data Security Standard (PCI DSS). It aims to ensure that organizations' employees understand and comply with the regulations. The training covers areas such as secure payment processing, protection of cardholder data, and proper handling of sensitive information.

Phishing Platform: The vendor provides a platform that offers a simulated environment to test and enhance employees' ability to recognize and respond to phishing attacks. It includes pre-configured templates for phishing simulations, with varying levels of difficulty and support for multiple languages. In the event of simulation failure, the platform provides automated remedial training. It also offers actionable insights and reporting capabilities to track and measure the effectiveness of the phishing awareness program.

Specialized Training: The vendor offers specialized training tailored to address the unique cybersecurity challenges faced by different professions and industries. The Developer Training focuses on secure coding techniques and best practices for web application development. The ICS Engineer Training covers security behaviors for individuals involved in Industrial Control Systems. The NERC CIP Training is designed for individuals responsible for Critical Infrastructure Protection (CIP) compliance in the electric industry. The IT Administrator Training aims to provide technical teams with a comprehensive understanding of evolving security concepts and best practices.

Categories & Use Cases

Top Performing Features

  • Training Content Library

    A pre-built library of security awareness training content that can be used immediately.

    Category average: 8.7

  • Single sign-on capability

    The software system supports a centralized authentication mechanism allowing the user to access multiple systems with a single, centrally managed password.

    Category average: 9.3

  • Role-based user permissions

    Permissions to perform actions or access or modify data are assigned to roles, which are then assigned to users, reducing complexity of administration.

    Category average: 8.4

Areas for Improvement

  • Multilingual Training Content

    Training content is available in multiple languages.

    Category average: 9

  • Training Gamification

    Training content is available in a gamified format.

    Category average: 8.6

  • Integration with Security Tech Stack

    The product integrates with other security tools, such as a SIEM or SOAR platform, and may provide alerts for potential breaches.

    Category average: 8.2

SANS Security Awareness Training prepares your employees for cyber attacks

Use Cases and Deployment Scope

The SANS Security Awareness Training was used across our company to educate staff on cyber threats and bad actors. It was used throughout the year and emphasized in October for a yearly training program that included a certificate of completion. It helped our staff stay up to date with new cyber threats by providing them with web-based training material and exercises.

Pros

  • Variety of cyber threat videos and presentations
  • Web based and mobile access to the platform
  • Easy to manage administrator access to configure the training sessions

Cons

  • Mass import of users was a bit confusing
  • User interface was sometimes not intuitive
  • Ability to upload custom content was difficult to use

Most Important Features

  • Large variety of videos and training options
  • Ease of use for end users on mobile devices
  • Videos and exercises are short and contain relevant material

Return on Investment

  • Positive impact knowing we are educating our staff from phishing and potential cyber criminals
  • Considering the potential for bad actors infiltrating our network, this is a small expense
  • Pricing based on actual end users, worth the investment

Alternatives Considered

Proofpoint Security Awareness Training and KnowBe4 Security Awareness Training

Other Software Used

Proofpoint Advanced Threat Protection, Lansweeper, Freshservice