Skip to main content

Every exercise is indexed by name, CWE, OWASP, MITRE ATT&CK, CIS, NIST CSF, GDPR and EU AI Act reference.

Try

Security Training Buyer's Guide

A framework for evaluating security awareness training platforms. What to look for, what questions to ask, and where most vendors fall short.

CISO evaluation framework: a vendor-evaluation clipboard listing 12 weighted criteria with the first five named and checked, plus a scoring panel showing an overall score and per-criterion bars

12 Criteria for Evaluating Security Awareness Training

A structured checklist for comparing vendors and making an informed decision.

1

Interactive Engagement Over Passive Content

What to look for

  • Scenario-based simulations where employees make real decisions
  • Consequences for wrong choices that create lasting memory
  • Practice environments that mirror actual attack patterns
  • Completion rates above 85% without mandating participation

How RansomLeak delivers

Every RansomLeak exercise is an interactive 3D simulation. Employees make decisions under pressure inside a scenario instead of watching a video about one, and a wrong choice plays out to its consequence.

That is what builds recall weeks later. Organizations report completion rates above 90% because people finish something they are actually playing.

The microlearning drills run the same mechanic in five to ten minutes for staff who cannot stop for a full course. Every exercise in the catalogue is free to play with no sign-up, so you can test the format before you talk to sales.

See how interactive training works
2

Content Breadth Across Threat Categories

What to look for

  • Coverage beyond just phishing: social engineering, device security, AI threats
  • Role-specific content for technical and non-technical staff
  • Real-world incident case studies, not just theoretical scenarios
  • Emerging threat coverage updated for current attack trends

How RansomLeak delivers

The catalogue spans 200+ exercises, from security awareness and privacy and compliance to real-world incident case studies.

AI and LLM Security carries three dedicated courses: the OWASP Top 10 for LLM Applications, the OWASP Top 10 for Agentic Applications, and the OWASP MCP Top 10. Between them they cover prompt injection, agent goal hijacking, tool exploitation, memory poisoning, and cascading failures across multi-agent systems.

Technical staff get the same hands-on format in the developer track, which is live now: Application Security on the OWASP Top 10 for web, API Security, Git and Repository Security, and Cloud Security.

Browse the training catalogue
3

Compliance Framework Coverage

What to look for

  • Mapping to specific framework controls (SOC 2, ISO 27001, ISO 27701, NIST CSF, GDPR, HIPAA)
  • Audit-ready completion reports with timestamps and scores
  • Evidence packages that satisfy auditor requirements
  • Coverage for industry-specific regulations (HITRUST, PCI DSS, NIS2, DORA, CMMC, CCPA)

How RansomLeak delivers

RansomLeak maps exercises to thirteen frameworks with specific control references: SOC 2, ISO 27001, ISO 27701, NIST CSF 2.0, GDPR, the EU AI Act, CCPA / CPRA, HIPAA, HITRUST CSF, PCI DSS, NIS2, DORA, and CMMC Level 1.

The mapping is visible per exercise, not just in a sales deck. Every catalogue card shows the MITRE ATT&CK techniques, CWE weaknesses, CIS Controls, and NIST CSF functions that exercise covers.

The analytics dashboard generates completion reports with timestamps, scores, and department breakdowns that auditors accept as training evidence. Framework deep dives sit in the compliance guides, including SOC 2, ISO 27001, HIPAA, and the EU AI Act.

View the compliance mapping guide
4

Deployment Flexibility

What to look for

  • SCORM 1.2 and 2004 support for existing LMS integration
  • LTI 1.3 launch with deep linking, grade passback, and roster sync
  • Standalone platform option for organizations without an LMS
  • Hosting choice: US or EU region, dedicated private cloud, or on-premises for air-gapped networks
  • No vendor lock-in or proprietary format requirements

How RansomLeak delivers

Every exercise exports as a SCORM 1.2 or 2004 package, compatible with Cornerstone, SAP SuccessFactors, Workday, Moodle, and Canvas.

LTI 1.3 is the newer path, with deep linking, grade passback, and roster sync, so content stays current in your LMS without re-uploading a package each release. Step-by-step guides cover Moodle and Canvas.

Organizations without an LMS run the built-in cloud LMS, with SSO, learning paths, and certificates included.

Hosting is a choice, not a constraint. The Cloud LMS runs in a US or EU region you pick at sign-up, and a dedicated single-tenant private cloud is available in the region you choose. An on-premises edition runs as containers on your own Kubernetes or Docker hosts, including air-gapped networks.

Compare SCORM and LTI deployment
5

Phishing Simulation and Behavioral Measurement

What to look for

  • Campaigns that reach the inbox instead of the spam quarantine
  • Coverage beyond email: SMS, QR codes, and voice pretexts
  • A reporter button that captures who reports, not only who clicks
  • Full-funnel metrics from delivery through click, submission, and time to report

How RansomLeak delivers

Phishing simulations deliver through direct mailbox injection using the Microsoft 365 Graph API or the Google Workspace API, so a campaign is never eaten by your own perimeter filter.

Reporter buttons capture what employees actually do, and the funnel is measured end to end: delivered, opened, clicked, credentials submitted, reported, and how long the report took. Anyone who fails lands on a teaching page that names the red flags, not a scolding.

Smishing simulations run the same campaign model over SMS. Vishing ships today as an in-browser drill, with outbound voice campaigns still in development, and we say so rather than selling a roadmap.

See phishing simulations
6

Human Risk Scoring and Automated Remediation

What to look for

  • A per-person risk score you can explain to the person it describes
  • Scoring built on observed behavior, not quiz results
  • Automatic enrollment for the people whose score says they need it
  • Evidence that measured risk falls, not just that training was assigned

How RansomLeak delivers

Every employee carries a human risk score from 0 to 100, calculated from what they did in real simulations rather than from a quiz they passed once.

The score is explainable, so you can show a person which events moved it and by how much. Risk-based automation then enrolls the people the score flags, without an analyst rebuilding a spreadsheet every quarter.

The next campaign re-tests the same people. That loop is what turns a training budget into a number your board can watch fall.

See human risk management
7

Analytics and Reporting Depth

What to look for

  • Real-time dashboards showing completion, scores, and trends
  • Department and team-level breakdowns for targeted follow-up
  • Knowledge gap identification across specific threat categories
  • Export capabilities for board reporting and audit preparation

How RansomLeak delivers

The dashboard tracks completion rates, average scores, time spent, and knowledge gaps in real time. Filter by department, team, or individual.

Export reports as PDF or CSV for board presentations and audit submissions. Certificates and learning-path progress export with them.

The same events also stream out over signed webhooks, so training and human-risk data can sit next to the signals your SOC already watches in Grafana, Datadog, New Relic, or your SIEM.

Explore analytics features
8

Content Freshness and Update Cadence

What to look for

  • Monthly content updates reflecting current attack trends
  • New exercises covering emerging attack techniques
  • Version control so you know what changed and when
  • Proactive additions after major industry incidents

How RansomLeak delivers

RansomLeak ships new training content every month, and whole categories land as the attack surface shifts. The OWASP MCP Top 10 course and the four developer-track categories are both recent additions.

When a major incident makes headlines, like the MGM Resorts breach, a case-study exercise follows within weeks.

What we track is documented in public rather than promised in a roadmap deck. The threat guides cover phishing, smishing, vishing, business email compromise, ransomware, deepfakes, social engineering, and prompt injection.

9

Customization and Branding

What to look for

  • White-label options for branded training portals
  • Custom content development for industry-specific scenarios
  • Role-based learning paths tailored to different departments
  • Ability to add internal policies and procedures to training

How RansomLeak delivers

RansomLeak supports branded training portals and custom learning paths assigned by team, department, or role.

The content team builds industry-specific exercises on request, folding your actual policies and compliance requirements into the scenarios.

Sector-specific starting points already exist for ten industries and ten programme use cases, from employee onboarding to M&A due diligence and LMS migration.

10

Enterprise Integration and SSO

What to look for

  • SAML 2.0 and OIDC single sign-on support
  • SCIM provisioning for automated user management
  • SIEM integration for security event correlation
  • REST API for workflow automation

How RansomLeak delivers

SAML 2.0 and OIDC single sign-on with SCIM provisioning, so joiners and leavers sync without a manual CSV. Setup guides cover Okta, Microsoft Entra ID, and Duo.

New hires can also be provisioned straight from your HR system. Merge connects 80+ HRIS platforms through one integration.

Everything else runs on a token-authenticated REST API and HMAC-signed webhooks: assign training from Jira Service Management or PagerDuty, and post live completion evidence to Vanta and Drata.

Browse all integrations
11

Gamification That Drives Participation

What to look for

  • Points, badges, and leaderboards that motivate without trivializing
  • Team-based challenges that build security culture
  • Progress tracking visible to individual employees
  • Voluntary participation rates as a genuine engagement metric

How RansomLeak delivers

Points and badges for exercise completion, with team leaderboards that turn a compliance chore into friendly competition.

A TalentLMS survey found 83% of employees feel more motivated by gamified training, and gamified programmes see 3x higher completion than standard compliance modules.

Progress, badges, and certificates stay visible to each employee, so people can see where they stand without a manager chasing them.

See the platform features
12

Vendor Track Record and Support Quality

What to look for

  • Founded by security practitioners, not just marketers
  • Responsive support with dedicated account management
  • Transparent roadmap and feature development pace
  • Free trial or pilot program to evaluate before committing

How RansomLeak delivers

RansomLeak was founded by the creator of Kontra Application Security Training, which is why the developer track reads like it was written by people who have shipped secure-coding content before.

Support responds within one business day, with priority SLA options for enterprise customers. Onboarding runs in days, not quarters.

Every exercise in the catalogue is free to play with no sign-up, so an evaluation starts with your team using the product rather than watching a sandbox demo.

Learn about our story

Questions to Ask Every Security Training Vendor

Use these questions during vendor evaluations to compare platforms on substance, not marketing.

Content Quality

  • How often is new content released?
  • Can I try exercises before purchasing?
  • Are scenarios based on real attack patterns?
  • How do you handle emerging threats?
  • Do you run phishing simulations, or only training?

Technical Requirements

  • Which SCORM versions are supported?
  • Do you support LTI 1.3 with grade passback?
  • What SSO providers can you integrate with, and is SCIM included?
  • Is there an API for automation?
  • What LMS platforms have you tested with?

Support and Implementation

  • What does onboarding look like?
  • Is there a dedicated account manager?
  • How quickly can we go live?
  • Who runs the first simulation campaign, us or you?
  • Do you build custom content?

Pricing and Terms

  • Is pricing per-seat or unlimited?
  • Are there volume discounts?
  • Are phishing simulations included or an add-on?
  • What's included vs. add-on?
  • Can we start with a pilot?

Frequently asked questions

What is the most important factor when choosing security awareness training?

Engagement is the single most important factor. Training that employees skip or forget delivers zero security value, regardless of how comprehensive the content library is. Look for platforms with voluntary completion rates above 80%.

Beyond engagement, evaluate whether the vendor can demonstrate measurable behavioral change. Completion certificates prove attendance, not learning. The best platforms track knowledge retention over time and show reduction in security incidents.

How much does enterprise security awareness training cost?

Enterprise security awareness training typically costs between $15 and $50 per employee per year. Pricing varies based on the number of users, contract length, and feature tier. Some vendors charge per seat while others offer unlimited licensing.

When comparing costs, factor in hidden expenses like implementation fees, custom content charges, and LMS integration support. RansomLeak offers transparent pricing with no setup fees. Contact the sales team at ransomleak.com/contact-us for a custom quote.

Should we use SCORM, LTI, or a standalone training platform?

If your organization already runs an LMS like Cornerstone, Workday, or SAP SuccessFactors, keeping training in that system reduces login friction and simplifies reporting. SCORM packages suit a fixed annual curriculum; LTI 1.3 suits a library that changes every month, because deep linking and roster sync mean nobody re-uploads a package each release.

Organizations without an LMS, or those wanting advanced analytics and gamification features, benefit from a standalone platform. RansomLeak supports all three, so you can start with SCORM and move later without losing data. Compare them on the LMS integration page.

How do we measure the ROI of security awareness training?

Track three categories of metrics: engagement (completion rates, voluntary participation, time spent), knowledge (assessment scores, improvement over time, knowledge gap closure), and behavior (phishing report rates, incident frequency, time to report).

The Ponemon Institute estimates that the average cost of a data breach reached $4.88 million in 2024. Even a modest reduction in successful social engineering attacks can justify training budgets many times over. A human risk score per employee turns the third category into one trend line you can put in front of a board.

What is the difference between phishing simulations and security awareness training?

Phishing simulations measure behavior. They tell you who clicks, who submits credentials, and who reports, but a click on its own teaches nobody anything. Security awareness training is what changes the behavior the simulation measured.

The two only pay off as a loop. RansomLeak runs both: simulations produce the behavioral signal, a human risk score ranks it per person, and automation enrolls the people who failed into the exercises that cover what they missed.

How quickly can we deploy RansomLeak training?

SCORM deployment takes hours, not weeks. Export the exercise packages, upload them to your LMS, and assign them to users. Most organizations run their first exercises the same day.

A full platform rollout with SSO, SCIM provisioning, and custom branding usually takes three to five business days. A dedicated onboarding specialist handles the technical configuration so your security team can focus on picking content and building learning paths.

See RansomLeak in Action

Try the free exercises or book a demo to see analytics, SCORM export, SSO, and custom content in your environment.