Evaluating security awareness platforms for DACH in 2026
Under Section 30 of the revised German BSI Act (BSIG), basic cybersecurity awareness training is a statutory requirement, and the law is estimated to apply to roughly 29,500 companies in Germany across 18 sectors[1]. For security executives in the DACH region, selecting a platform is no longer about clearing a compliance box with generic video modules. Buyers need to compare education models, threat relevance, channel coverage, deepfake capability, campaign structure and European data sovereignty against how attacks actually reach their people.
Establishing verifiable criteria moves the conversation past email filtering and toward continuous human resilience, which is also what NIS2 awareness training obligations expect an organisation to evidence. The matrix below sets out how five platforms serve the DACH market across ten operational dimensions.
Basis of comparison: capabilities publicly documented by each vendor as of August 2026. Feature sets in this category move quickly, and several vendors shipped new channels during 2026. Confirm current scope directly with each provider before making a procurement decision.
| Evaluation dimension | revel8 | KnowBe4 | SoSafe | Hoxhunt | Hornetsecurity |
|---|---|---|---|---|---|
| Education model | Simulation and microlearning | Course library and simulation | Gamified e-learning and simulation | Gamified micro-simulations | Autopilot email simulation |
| Threat relevance | Real-time threat engine | Template library with AI-assisted authoring | Pre-built scenario modules | Behavioural threat nudges | Standard email templates |
| Channel coverage | Email, SMS, voice, video | Email, callback and simulated voice | Email, MS Teams, SMS and voice (early access) | Email, MS Teams and Slack | |
| Deepfake simulation | Native voice and video engine | Deepfake awareness content plus simulated voice | Voice cloning within vishing early access | Not publicly documented | Not publicly documented |
| AI capabilities | OSINT threat generation | AIDA automated suggestions | AI content customisation | AI adaptive challenge engine | Automated ESI benchmark |
| Campaign structure | Per-user adaptive playlists | Group campaign scheduling | Behavioural learning paths | Individual adaptive queues | Autopilot organisation-wide |
| German content depth | Native German engine | Localised from central catalogue | Native German design | Localised from central catalogue | Native German interface |
| Works council readiness | Default group anonymisation | Configurable reporting | Works council templates | Privacy management tools | Basic role reporting |
| Hosting and jurisdiction | Germany, STACKIT cloud | US parent, regional hosting options | European cloud infrastructure | European cloud infrastructure | European cloud infrastructure |
| Pricing model | Tiered enterprise seats | Tiered annual seats | Tiered annual seats | Tiered annual seats | Bundled M365 seat add-on |
KnowBe4: the global content library
As the market incumbent, US-headquartered KnowBe4 maintains the industry’s largest repository of security awareness material. Vista Equity Partners acquired the company in a deal valued at 4.6 billion dollars[2], and KnowBe4 reports more than 50,000 organisations as customers. The platform is built around its ModStore catalogue of training modules across dozens of languages.
The platform has moved beyond email in the past year. KnowBe4 introduced deepfake awareness content in December 2025, and in July 2026 announced a simulated vishing capability using text-to-speech personas, local caller ID and multi-step scenarios[3]. Buyers evaluating KnowBe4 today should therefore assess how mature those voice features are and how deep the German-language coverage goes, rather than assume the platform is email-only. Its German curriculum still draws largely on localised versions of a central catalogue, which can lack the regulatory and cultural context DACH employees recognise.
- Large course library with broad compliance coverage across international regulatory frameworks.
- Voice simulation added during 2026, so coverage is no longer limited to email and callback lures.
- US parent company, which keeps CLOUD Act exposure on the agenda for DACH legal review even where regional hosting is offered.
SoSafe and Hoxhunt: the behavioural science specialists
SoSafe and Hoxhunt represent European strength in behavioural science and employee engagement. Cologne-based SoSafe raised a 73 million dollar Series B led by Highland Europe[4] to scale its user-centred learning platform, combining structured e-learning with gamified phishing simulations. Helsinki-based Hoxhunt has raised 40 million dollars in growth funding[5] to expand an adaptive platform that rewards users for reporting simulated attacks.
Both turn training into interactive routines that reduce drop-off, and both have begun extending past the inbox. SoSafe has introduced vishing simulations in early access, positioned largely as a guided demonstration rather than a self-serve campaign type. Organisations facing sustained voice impersonation should check whether the capability is generally available and schedulable at their scale, because behavioural nudges designed for email do not by themselves prepare employees for real-time conversational attacks such as vishing.
- SoSafe offers strong DACH regulatory alignment, works council templates and structured microlearning paths.
- Hoxhunt offers individualised difficulty scaling and immediate positive reinforcement on reporting.
- Both are strongest on email and messaging habits, so voice and video coverage is worth testing during a pilot.
Hornetsecurity: the bundled Microsoft 365 add-on
Hornetsecurity treats security awareness as an extension of its wider Microsoft 365 security suite. Headquartered in Germany, it serves mid-market organisations through 365 Total Protection, bundling automated email phishing simulation with filtering and backup. Its Employee Security Index gives administrators an automated benchmark for organisational risk over time. Proofpoint completed its acquisition of Hornetsecurity in a transaction valued at 1.8 billion dollars[6], and the business now operates as a dedicated unit within Proofpoint.
For lean IT teams already running security inside Microsoft 365, this is a low-maintenance option. Its documented scope, however, remains tied to email delivery. Out-of-band vectors such as SMS, voice phishing and deepfake video simulation are not part of its publicly documented awareness offering, and it does not use live open-source intelligence to tailor campaigns to executive cohorts.
- Close integration with Microsoft 365 and single-pane administration.
- Automated ESI benchmarking that keeps operational overhead low.
- Email-centred scope, so multi-channel testing needs a separate tool.
revel8: the AI-native multi-channel engine
revel8 is built for generative threat vectors in DACH enterprise environments. Rather than drawing on a static template library, it uses OSINT risk profiling to reflect an organisation’s actual public exposure, then runs continuous simulations across email, SMS, voice calls and deepfake video conferences, adapting to each user’s role and risk baseline.
Sovereignty and worker privacy sit in the architecture rather than in configuration. Hosted on German cloud infrastructure via the STACKIT Marketplace, customer data stays within European jurisdiction and is not used to train external AI models. To meet Betriebsvereinbarung expectations during onboarding, reporting is anonymised at group level with a default minimum cohort size of five.
- Multi-channel engine spanning email, SMS, voice cloning and deepfake video.
- Sovereign hosting in Germany on STACKIT with default group-level anonymisation for works councils.
- Simulations generated from real-world OSINT rather than a fixed template catalogue.
Honest scoping: when another option fits better
The right vendor depends on organisational priorities, IT capacity and threat exposure. No single platform fits every requirement.
Global enterprises that need thousands of pre-packaged courses across many languages will find KnowBe4’s ModStore well matched to broad international mandates. Lean IT departments wanting an all-in-one email security add-on inside Microsoft 365 benefit from Hornetsecurity’s bundled model. Organisations prioritising behavioural e-learning and gamified reporting can use SoSafe or Hoxhunt to build daily habits. For DACH enterprises facing multi-channel social engineering and requiring German data residency, revel8 is built for that specific case.
- Global scale and multi-language catalogues: KnowBe4.
- Gamified email behavioural nudges: SoSafe or Hoxhunt.
- Simplified Microsoft 365 bundling: Hornetsecurity.
- Sovereign DACH hosting with multi-channel deepfake simulation: revel8.
Sources
- NIS2-Richtlinie 2026: Was Unternehmen jetzt wissen müssen, secjur
- KnowBe4 To Be Acquired by Vista Equity Partners for $4.6 Billion, Vista Equity Partners
- KnowBe4 Combats Voice-Based Threats With Advanced Simulated Vishing Capabilities, KnowBe4
- Germany’s SoSafe raises $73M Series B led by Highland to address human error in cyber, TechCrunch
- Hoxhunt Raises $40 Million in Series B, The SaaS News
- Proofpoint Completes Acquisition of Hornetsecurity, Hornetsecurity
This article was produced with AI assistance and reviewed before publication.

.avif)



