TrustRadius: an HG Insights company

PhishingBox

Score8 out of 10

10 Reviews and Ratings

What is PhishingBox?

PhishingBox headquartered in Lexington provides a Security Awareness Ecosystem through a suite of tools and services to implement and maintain a high-level security awareness training program. Key components include a phishing simulation tool, security awareness training, a learning management system (LMS), KillPhish reporting button, and the 'Phishing Inbox,' which allows InfoSec teams to thoroughly investigate reported emails and related information.

Top Performing Features

  • Phishing Simulations

    Administrators can run simulated phishing attacks to test the effectiveness of the training and assess vulnerabilities.

    Category average: 9.1

  • Security Reporting

    Reports available may include statistics on phishing simulations, training completion, etc.

    Category average: 8.5

  • Training Gamification

    Training content is available in a gamified format.

    Category average: 8.6

Areas for Improvement

  • Integration with Security Tech Stack

    The product integrates with other security tools, such as a SIEM or SOAR platform, and may provide alerts for potential breaches.

    Category average: 8.2

  • Multilingual Training Content

    Training content is available in multiple languages.

    Category average: 9

  • Industry-Specific Security Training

    Security training can be tailored based on industry-specific requirements, such as HIPAA, PCI DSS, GDPR, etc.

    Category average: 7.1

Trust the Phish

Use Cases and Deployment Scope

I used to use PhishingBox when I worked for Lowe's Companies. We had a large number of issues corporate wide of fake vendors reaching out and sending links to products that would affect the network if clicked on. There wasn't enough education around what was fishy and what was legitimate depending on what area you worked in. Clicking these would obviously caused problems so they incorporated PhishingBox and some extra education around what should be clicked on vs not.

Pros

  • They provided short trainings so we were able to understand what should be flagged
  • Made it really easy to flag unwanted emails
  • Tested employees to see if they were following guidelines

Cons

  • I really don't have much constructive feedback - for us, the program worked exactly how we needed it to

Most Important Features

  • Ease of flagging emails
  • Training and education
  • Practice fraud emails

Return on Investment

  • I was able to reduce clicks on fake vendors selling real (sometimes fake) products by 20% in the first year we used the program

Alternatives Considered

KnowBe4 PhishER

Other Software Used

Lattice, HubSpot Marketing Hub, Coda

Good value for money.

Use Cases and Deployment Scope

We use it in the company to train new workers as part of their onboarding process. For us is super important to let them know that email is one of the biggest threads when speaking about malware. The important thing to remember is that at the end the human is the last step of the chain and always the weakest

Pros

  • Training new employees.
  • Keep our workforce trained with new challenges regularly.
  • We get the latest templates of new phishing attacks what help us to stay ahead.

Cons

  • While most of the examples are good there are a few that are quite obvious.
  • The pricing could be a little bit lower for the type of software.
  • The template creator sometimes has glitches.

Most Important Features

  • To be able to train people on what to see when checking phishing emails.
  • The editor is good for learners.
  • The library of templates is huge with real attack examples.

Return on Investment

  • Well basically to have people trained is the most positive impact of the software.
  • The template library makes our employees know about different types of phishing attacks.
  • The ROI is clear, avoiding a phishing attack is enough to pay the software.

Other Software Used

GoTo Meeting, Skype for Business, now part of Microsoft Teams, OneDrive