Home
Magazine
Security Awareness Vendors: The DACH 2026 Comparison
Security Awareness Vendors: The DACH 2026 Comparison

Security Awareness Vendors: The DACH 2026 Comparison

August 28, 2026
6 min
Lana Kuzmina
Cyber Threat Analyst
lana

How five security awareness platforms compare for DACH buyers in 2026, across AI threat relevance, channel coverage, works council readiness and data sovereignty.

Table of contents

Get started
with revel8

  • Section 30(2) BSIG makes security training a legal requirement for NIS-2 entities in Germany.
  • KnowBe4 has the largest template library and added simulated voice phishing during 2026, so an email-only reading of the platform is out of date.
  • Proofpoint completed its acquisition of Hornetsecurity in a 1.8 billion dollar transaction, reinforcing its position as an email-first Microsoft 365 add-on.
  • revel8 covers email, SMS, voice and deepfake video in one engine, built on OSINT and with group-level anonymisation on by default.
  • Works council approval turns on data sovereignty and anonymisation, which makes hosting jurisdiction a procurement question rather than an IT one.

Evaluating security awareness platforms for DACH in 2026

Under Section 30 of the revised German BSI Act (BSIG), basic cybersecurity awareness training is a statutory requirement, and the law is estimated to apply to roughly 29,500 companies in Germany across 18 sectors[1]. For security executives in the DACH region, selecting a platform is no longer about clearing a compliance box with generic video modules. Buyers need to compare education models, threat relevance, channel coverage, deepfake capability, campaign structure and European data sovereignty against how attacks actually reach their people.

Establishing verifiable criteria moves the conversation past email filtering and toward continuous human resilience, which is also what NIS2 awareness training obligations expect an organisation to evidence. The matrix below sets out how five platforms serve the DACH market across ten operational dimensions.

Basis of comparison: capabilities publicly documented by each vendor as of August 2026. Feature sets in this category move quickly, and several vendors shipped new channels during 2026. Confirm current scope directly with each provider before making a procurement decision.

Evaluation dimensionrevel8KnowBe4SoSafeHoxhuntHornetsecurity
Education modelSimulation and microlearningCourse library and simulationGamified e-learning and simulationGamified micro-simulationsAutopilot email simulation
Threat relevanceReal-time threat engineTemplate library with AI-assisted authoringPre-built scenario modulesBehavioural threat nudgesStandard email templates
Channel coverageEmail, SMS, voice, videoEmail, callback and simulated voiceEmail, MS Teams, SMS and voice (early access)Email, MS Teams and SlackEmail
Deepfake simulationNative voice and video engineDeepfake awareness content plus simulated voiceVoice cloning within vishing early accessNot publicly documentedNot publicly documented
AI capabilitiesOSINT threat generationAIDA automated suggestionsAI content customisationAI adaptive challenge engineAutomated ESI benchmark
Campaign structurePer-user adaptive playlistsGroup campaign schedulingBehavioural learning pathsIndividual adaptive queuesAutopilot organisation-wide
German content depthNative German engineLocalised from central catalogueNative German designLocalised from central catalogueNative German interface
Works council readinessDefault group anonymisationConfigurable reportingWorks council templatesPrivacy management toolsBasic role reporting
Hosting and jurisdictionGermany, STACKIT cloudUS parent, regional hosting optionsEuropean cloud infrastructureEuropean cloud infrastructureEuropean cloud infrastructure
Pricing modelTiered enterprise seatsTiered annual seatsTiered annual seatsTiered annual seatsBundled M365 seat add-on

KnowBe4: the global content library

As the market incumbent, US-headquartered KnowBe4 maintains the industry’s largest repository of security awareness material. Vista Equity Partners acquired the company in a deal valued at 4.6 billion dollars[2], and KnowBe4 reports more than 50,000 organisations as customers. The platform is built around its ModStore catalogue of training modules across dozens of languages.

The platform has moved beyond email in the past year. KnowBe4 introduced deepfake awareness content in December 2025, and in July 2026 announced a simulated vishing capability using text-to-speech personas, local caller ID and multi-step scenarios[3]. Buyers evaluating KnowBe4 today should therefore assess how mature those voice features are and how deep the German-language coverage goes, rather than assume the platform is email-only. Its German curriculum still draws largely on localised versions of a central catalogue, which can lack the regulatory and cultural context DACH employees recognise.

  • Large course library with broad compliance coverage across international regulatory frameworks.
  • Voice simulation added during 2026, so coverage is no longer limited to email and callback lures.
  • US parent company, which keeps CLOUD Act exposure on the agenda for DACH legal review even where regional hosting is offered.

SoSafe and Hoxhunt: the behavioural science specialists

SoSafe and Hoxhunt represent European strength in behavioural science and employee engagement. Cologne-based SoSafe raised a 73 million dollar Series B led by Highland Europe[4] to scale its user-centred learning platform, combining structured e-learning with gamified phishing simulations. Helsinki-based Hoxhunt has raised 40 million dollars in growth funding[5] to expand an adaptive platform that rewards users for reporting simulated attacks.

Both turn training into interactive routines that reduce drop-off, and both have begun extending past the inbox. SoSafe has introduced vishing simulations in early access, positioned largely as a guided demonstration rather than a self-serve campaign type. Organisations facing sustained voice impersonation should check whether the capability is generally available and schedulable at their scale, because behavioural nudges designed for email do not by themselves prepare employees for real-time conversational attacks such as vishing.

  • SoSafe offers strong DACH regulatory alignment, works council templates and structured microlearning paths.
  • Hoxhunt offers individualised difficulty scaling and immediate positive reinforcement on reporting.
  • Both are strongest on email and messaging habits, so voice and video coverage is worth testing during a pilot.

Hornetsecurity: the bundled Microsoft 365 add-on

Hornetsecurity treats security awareness as an extension of its wider Microsoft 365 security suite. Headquartered in Germany, it serves mid-market organisations through 365 Total Protection, bundling automated email phishing simulation with filtering and backup. Its Employee Security Index gives administrators an automated benchmark for organisational risk over time. Proofpoint completed its acquisition of Hornetsecurity in a transaction valued at 1.8 billion dollars[6], and the business now operates as a dedicated unit within Proofpoint.

For lean IT teams already running security inside Microsoft 365, this is a low-maintenance option. Its documented scope, however, remains tied to email delivery. Out-of-band vectors such as SMS, voice phishing and deepfake video simulation are not part of its publicly documented awareness offering, and it does not use live open-source intelligence to tailor campaigns to executive cohorts.

  • Close integration with Microsoft 365 and single-pane administration.
  • Automated ESI benchmarking that keeps operational overhead low.
  • Email-centred scope, so multi-channel testing needs a separate tool.

revel8: the AI-native multi-channel engine

revel8 is built for generative threat vectors in DACH enterprise environments. Rather than drawing on a static template library, it uses OSINT risk profiling to reflect an organisation’s actual public exposure, then runs continuous simulations across email, SMS, voice calls and deepfake video conferences, adapting to each user’s role and risk baseline.

Sovereignty and worker privacy sit in the architecture rather than in configuration. Hosted on German cloud infrastructure via the STACKIT Marketplace, customer data stays within European jurisdiction and is not used to train external AI models. To meet Betriebsvereinbarung expectations during onboarding, reporting is anonymised at group level with a default minimum cohort size of five.

  • Multi-channel engine spanning email, SMS, voice cloning and deepfake video.
  • Sovereign hosting in Germany on STACKIT with default group-level anonymisation for works councils.
  • Simulations generated from real-world OSINT rather than a fixed template catalogue.

Honest scoping: when another option fits better

The right vendor depends on organisational priorities, IT capacity and threat exposure. No single platform fits every requirement.

Global enterprises that need thousands of pre-packaged courses across many languages will find KnowBe4’s ModStore well matched to broad international mandates. Lean IT departments wanting an all-in-one email security add-on inside Microsoft 365 benefit from Hornetsecurity’s bundled model. Organisations prioritising behavioural e-learning and gamified reporting can use SoSafe or Hoxhunt to build daily habits. For DACH enterprises facing multi-channel social engineering and requiring German data residency, revel8 is built for that specific case.

  • Global scale and multi-language catalogues: KnowBe4.
  • Gamified email behavioural nudges: SoSafe or Hoxhunt.
  • Simplified Microsoft 365 bundling: Hornetsecurity.
  • Sovereign DACH hosting with multi-channel deepfake simulation: revel8.

Sources

  1. NIS2-Richtlinie 2026: Was Unternehmen jetzt wissen müssen, secjur
  2. KnowBe4 To Be Acquired by Vista Equity Partners for $4.6 Billion, Vista Equity Partners
  3. KnowBe4 Combats Voice-Based Threats With Advanced Simulated Vishing Capabilities, KnowBe4
  4. Germany’s SoSafe raises $73M Series B led by Highland to address human error in cyber, TechCrunch
  5. Hoxhunt Raises $40 Million in Series B, The SaaS News
  6. Proofpoint Completes Acquisition of Hornetsecurity, Hornetsecurity

This article was produced with AI assistance and reviewed before publication.

FAQ

Is security awareness training mandatory under NIS-2 in Germany?

Yes. With the NIS-2 Directive transposed into the revised German BSI Act, Section 30(2) requires basic training and awareness-raising measures in information security for employees at regulated entities.

How does KnowBe4 compare to AI-native platforms in 2026?

KnowBe4 offers a very large ModStore catalogue of e-learning templates across dozens of languages, and during 2026 it added deepfake awareness content and simulated vishing. The practical questions for a DACH buyer are how mature those voice features are, how deep the German-language coverage goes, and whether simulations are generated from live OSINT or selected from a fixed catalogue.

Does Hornetsecurity offer deepfake or vishing simulations?

Hornetsecurity's Security Awareness Service is documented as an email-first offering, designed as a bundled add-on for Microsoft 365. SMS, voice and deepfake video simulation are not part of its publicly documented scope as of August 2026.

Why is works council approval critical for awareness tools in DACH?

In Germany, systems capable of monitoring employee behaviour trigger co-determination rights under Section 87(1) No. 6 BetrVG. Platforms need strict privacy defaults, such as group-level anonymisation with a minimum group size of five, to secure works council approval.

How does revel8's data sovereignty differ from global vendors?

revel8 is hosted on STACKIT in Germany. Customer data stays within European jurisdiction and is not used to train external AI models, which removes the CLOUD Act question that DACH legal teams raise with US-parented vendors.

Sources

Related Articles

White abstract curved shape with jagged edges on a black background.

Ready to defend against
AI-powered attacks?