Should you bundle awareness into M365 or manage multi-channel risk?
Chief Information Security Officers evaluating security awareness architectures face a fundamental strategic question: should human risk management be treated as an integrated feature of an email security suite or as a specialized, multi-channel operational discipline? Email suite providers like Hornetsecurity, an established Hanover-based vendor whose flagship product is its Microsoft 365 security suite, approach awareness primarily as an extension of Microsoft 365 inbox protection. By bundling email phishing simulations and automated e-learning modules into unified licensing tiers like 365 Total Protection, suite vendors minimize administrative friction for IT teams managing M365 tenants.
However, modern social engineering threat vectors have extended far beyond the traditional email boundary. Contemporary threat actors rarely restrict their reconnaissance or initial contact to corporate inboxes. Instead, adversarial campaigns execute orchestrated, multi-stage operations that move fluidly between corporate communication tools, mobile messaging, voice calls, and direct phone contact. When security awareness remains tethered exclusively to email gateways, security leaders risk leaving critical human entry points unmonitored and untrained.
- Inbox-Centric Perimeter: Focusing training solely on email lures leaves employees unprepared for attacks delivered through SMS, voice, and instant messaging.
- Bundled Convenience vs. Specialized Depth: Suite add-ons prioritize ease of administrative deployment over continuous, contextual risk mitigation.
- Evolving Adversary TTPs: Threat actors exploit out-of-band channels precisely because traditional email filters cannot inspect voice or SMS traffic.
What does Hornetsecurity's awareness add-on actually cover?
To evaluate how an M365 email security add-on compares against a dedicated human risk platform, security leaders must analyze operational coverage, content adaptation, and compliance architecture. Hornetsecurity's awareness service runs automated spear phishing simulations and e-training steered by its Employee Security Index (ESI) benchmark, and the company's own benchmark report found it takes employees an average of three months of training to reach what it calls an acceptable level of security. Dedicated engines instead evaluate the entire human attack surface across multiple communication media using live threat intelligence.
| Architecture & Capability | M365 Email Suite Add-on (Hornetsecurity) | Dedicated Multi-Channel Engine |
|---|---|---|
| Primary Delivery Vectors | Email spear phishing simulations and e-training | Email, SMS, WhatsApp, voice (vishing), and deepfake video |
| Personalization Mechanism | Simulated attacks categorized into seven levels of varying difficulty, steered automatically by user level | Dynamic OSINT enrichment tailored to role and public footprint |
| Voice & Deepfake Coverage | Published service scope covers spear phishing simulation and e-training, with no documented vishing or deepfake video simulation | Native voice cloning and synthetic video attack scenarios |
| Compliance & Benchmark Metrics | Employee Security Index (ESI) reporting with ESI history and forecast | ISO 27001 and NIS-2 audit-ready group logs |
| Data Residency & Hosting | 12 regional data centers, independent of Microsoft's infrastructure, to match local data protection requirements | Sovereign German cloud hosting on STACKIT |
While the consolidated M365 suite model streamlines software procurement, treating awareness as a secondary feature of mail filtering limits an organization's ability to measure or mitigate complex social engineering techniques.
Why is an email-first awareness strategy no longer enough?
The fundamental limitation of an email-first awareness tool lies in its architectural scope. Hornetsecurity's own service description defines the offering around spam and malware filtering, archiving, and automated email attack simulations delivered to the inbox. Generative AI tools, meanwhile, have sharply reduced the cost for threat actors to produce voice clones and conversational social engineering attacks on channels no mail filter can inspect.
Adversaries routinely execute multi-channel attacks that bypass email gateways entirely. A typical enterprise vector begins with an OSINT reconnaissance phase, followed by an urgent WhatsApp message or a cloned voice call impersonating an executive or IT helpdesk engineer. Organizations relying solely on email phishing tests leave employees unequipped to handle vishing defense or synthetic media attacks.
Countering these vectors requires dynamic frameworks like the Awareness Playlist, which continuously deploys role-specific simulations across email, SMS, messaging apps, and synthetic voice. Training delivered in real time on the same channels attackers use builds durable reporting habits that hold up under a live attack.
How do static phishing templates compare to OSINT data?
The effectiveness of any attack simulation depends on its contextual credibility. Hornetsecurity's Spear Phishing Engine generates the phishing emails itself and categorizes the simulated attacks into seven levels of varying difficulty, automatically controlling which employee receives which level and when. That set-it-and-forget-it design keeps administrative effort low, but it also means scenario variation is bounded by the engine's email content and difficulty scaling.
Generic or poorly targeted phishing templates quickly lose operational value. When employees receive generic lures about fake package deliveries or standard password resets, they recognize the synthetic nature of the exercise. This leads to artificially inflated reporting rates that fail to reflect how staff would perform against targeted spear-phishing or executive impersonation.
Modern human risk architectures take a different route, using organizational OSINT risk profiling to build attack scenarios that match each recipient's actual exposure. By analyzing publicly available company data, organizational structures, and job roles, continuous simulation engines generate personalized scenarios that mirror the reconnaissance techniques real-world threat actors use.
- Static Template Libraries: Require ongoing administrative oversight to maintain relevance and avoid employee fatigue.
- OSINT-Driven Targeting: Uses public footprint data to mirror actual adversary reconnaissance without manual campaign building.
- Role-Specific Context: Ensures high-value targets like finance leads or executive assistants face realistic, tailored scenario mechanics.
Why does sovereign data residency matter for NIS-2 in the DACH region?
For enterprises operating across the DACH region, regulatory mandates under the EU NIS-2 Directive and the German BSIG transposition act (NIS2UmsG) have elevated cybersecurity awareness from an administrative initiative to a strict legal obligation. Section 30 of the updated BSIG requires regulated entities to implement mandatory basic cybersecurity training and risk management measures across their workforce.
Non-compliance carries substantial financial and legal exposure. Under the BSIG framework, administrative fines for essential entities (besonders wichtige Einrichtungen) reach up to EUR 10 million or 2% of total global annual turnover, while important entities face penalties up to EUR 7 million or 1.4% of global turnover. Furthermore, Section 38 of the BSIG establishes direct personal liability for corporate managing directors who fail to oversee mandatory risk management and awareness requirements.
Beyond regulatory compliance, European enterprises increasingly prioritize strict data sovereignty. While suite providers operate across broader European cloud footprints, organizations seeking sovereign infrastructure leverage dedicated platforms hosted on the German STACKIT marketplace. Hosting telemetry exclusively within German data centers ensures complete alignment with GDPR guidelines and works council (Betriebsrat) privacy requirements.
When is an M365 bundle the better choice?
Selecting between an M365 email security add-on and a dedicated human risk platform depends on an organization's existing security stack, administrative capacity, and primary threat exposure. Since December 2025, Hornetsecurity has been part of Proofpoint, which completed its acquisition of the Hanover-based vendor for a total consideration of $1.8 billion. Hornetsecurity now operates as a dedicated business unit within Proofpoint focused on MSPs and SMBs, and it remains a strong choice for small-to-midsize organizations that prioritize vendor consolidation. Businesses already utilizing 365 Total Protection benefit from unified billing, integrated cloud backup, and automated email phishing simulations that require minimal daily management.
The acquisition also changes the vendor landscape this article sits in. Because Proofpoint now owns Hornetsecurity, the two buyer considerations this series treats separately are converging: our comparison of revel8 and Proofpoint covers the same corporate parent, including the CLOUD Act data-sovereignty questions that now apply to Hornetsecurity customers as well. DACH buyers evaluating Hornetsecurity should weigh both the product's M365 strengths and its new US-parent ownership structure.
Conversely, mid-market enterprises and DAX organizations facing AI-driven social engineering require specialized defensive depth. The revel8 Platform is engineered specifically for security teams that need multi-channel simulation coverage across voice, SMS, and deepfakes, paired with OSINT-driven personalization and sovereign STACKIT cloud hosting in Germany. Organizations like Alexander Bürkle demonstrate how automated, contextualized simulations systematically reduce employee risk across complex operational structures.
- Choose Hornetsecurity if: Your organization seeks a single vendor for M365 email filtering, backup, and basic email phishing awareness under a consolidated subscription.
- Choose a Dedicated Platform if: Your organization requires comprehensive defense against voice cloning and deepfakes, automated OSINT personalization, and audit-ready NIS-2 compliance on sovereign German cloud infrastructure.
To determine the optimal architecture for your workforce, conduct an internal audit of your human attack surface across non-email channels and benchmark your current incident reporting metrics against modern AI-driven threat scenarios.

.avif)




