Skip to content
Article

Your peers are re-shopping KnowBe4

By DoGood Team · July 22, 2026

Member Signal

The Member Signal is DoGood’s weekly peer-intelligence briefing for the member network. This issue went to members on July 22, 2026, and appears here lightly edited for the web.

The Signal

The network is re-shopping the security-awareness layer, and this time members are naming the tool they want out. KnowBe4 is the most-named vendor in this month’s human-risk submissions, and in nearly every case it comes up as the platform members are trying to replace, not adopt.

A manufacturing Global CISO says the current training and human-risk platform is outdated and no longer fits the business. A real-estate VP of IT and a higher-education technology chief are both actively shopping KnowBe4 alternatives. On the other side of the same decision, two finance security leaders are evaluating Fable Security by name for its behavioral analytics and real-time interventions. Different industries, one motion: out of legacy awareness training, into human-risk management.

The shared driver is measurement. Members are not asking for more phishing simulations. They are asking for a per-employee risk number they can trend and defend, plus coverage for the AI and deepfake vectors their old program never contemplated. That is a category decision, not a renewal.

From the Network

“Our current training and human risk platform is outdated, and I do not believe it fits the needs of the business.”

Global CISO, Manufacturing

“Currently using KnowBe4 for security training, looking at alternatives in the space.”

VP of Information Technology, Real Estate

“Considering alternatives to our current approach, including the way we use KnowBe4 training paired with standard risk management.”

Associate VP for IT & CTO, Higher Education

Three industries, one motion: the awareness tool that was settled infrastructure a year ago is back on the shopping list.

Top Open Priorities This Week

“Evaluating alternatives to KnowBe4 to improve employee security behavior, reduce Shadow AI risk, and deliver measurable human-risk reduction through more effective, real-time interventions for our workforce.”

Senior Director, IT Operations, Software

“I want to explore Fable Security to better understand how AI-driven human risk management and security awareness can reduce phishing, insider threats, and employee-driven cyber risk.”

Information Security Leader, Finance

One team is leaving KnowBe4 for measurable, real-time risk reduction; the other is evaluating a named human-risk platform to get there. Both asks are two weeks old, and both trade training-completion for behavior change.

Member Spotlight

This week’s Signal is about the human layer of security, and Howard has already seen where it points: phishing written by AI without the tells, and teams that cannot hire fast enough to keep up. He leads information security at FirstBank, and put his answer plainly in his DoGood member spotlight, “Build the peer group before you need it.”

Read his full story →

Deep Dive: Human Risk & Security Awareness

Twelve member priorities in the last 90 days touched security awareness, phishing, or human risk, and the dominant pattern is incumbent replacement: members leaving legacy awareness training for platforms that measure and change behavior rather than track course completion.

Where activity is concentrated

The volume splits three ways. The largest cluster is members explicitly shopping KnowBe4 alternatives: a software senior director wants measurable human-risk reduction and real-time intervention, a real-estate VP is simply looking at alternatives in the space, and a higher-education technology chief is reconsidering a KnowBe4-plus-risk-management approach. A second cluster is members evaluating dedicated human-risk platforms by name, with two finance security leaders assessing Fable Security’s behavioral analytics, automated interventions, and reporting. A third, newer cluster is the AI and deepfake vector: a software CISO wants to detect deepfakes and social-engineering attempts aimed at large call-center teams, a threat the old awareness curriculum never covered.

What your peers are buying

One vendor is booking these meetings across the network right now. Fable Security has taken meetings in the last three weeks with a hospital-system CIO, a manufacturing Global CISO, and a higher-education IT leader, spanning exactly the industries raising the asks above. Abnormal Security is the other name drawing meetings on the human-behavior side, mostly at CIO and CISO level, on the email and social-engineering front.

What’s still open

Two capability areas have clear demand and no settled answer. First, the board-ready number: members want a per-employee or per-team risk score they can trend over time, and none of them name a tool they trust to produce it. Completion rates and click rates are not it. Second, real-time coverage of the deepfake and voice-phishing vector. The training content exists; in-the-moment detection for the people actually being targeted does not.

What it means for your stack

Pull your awareness tool’s headline report before its next renewal. If it leads with training-completion or phishing-click rate and cannot give you a per-employee risk score you can trend, you are holding the exact metric your peers are switching away from. Ask your incumbent for a behavior-to-risk mapping now. If they cannot produce one, you already have your reason to build a shortlist.

The Context

The headlines are catching up to what the network already knew. Over the past year the industry quietly renamed the category members are now leaving. What everyone called security awareness training is becoming human risk management, and the change is more than branding. Analysts now tell buyers to grade these programs on measured behavior and risk reduction rather than course completion, the exact standard members are applying when they call their current tool outdated. Even KnowBe4 has repositioned itself as a human-risk platform, adding AI agents and deepfake training at this year’s RSAC. The incumbent and its challengers now agree on where this is going; your peers are just deciding who takes them there.

Bottom Line: The category did not only get a new name, it got a new number. If your program still reports how many people finished the training, you are tracking the one metric the market just agreed no longer counts, while the number your peers are moving toward is the one you can put in front of a board.

What to Do About It

Before your next security-awareness renewal, ask your current vendor one question: can you give me a per-employee risk score I can trend and defend to my board? If the honest answer is a completion rate or a phishing-click percentage, you already have your reason to look. Put your incumbent’s newest release next to the human-risk platforms your peers are testing, Fable among them, and judge all of them on that single number.

Build pipeline you can actually follow up on.