shouldiuse.io

VERDICT

Should I use KnowBe4?

Secure Your Digital Workforce: Human + AI - knowbe4.com

Depends. Solid pick for mid-size and larger organizations with compliance mandates and IT admin bandwidth. Small teams and buyers who want transparent, self-serve pricing should look elsewhere.

Confidence

Medium. Based on 20+ public sources; pricing details thin — sales-gated quotes only. Review snippets truncated, so no verbatim quotes extracted.

Ratings

  • Value for money
  • Ease of useNo direct usability evidence in sources
  • Feature depth
  • Support quality
  • Security posture

Pricing

Quote only

Per-user subscription (Diamond is top tier)

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed

Best for

  • Compliance-heavy industries (finance, healthcare)
  • Mid-size to enterprise IT teams
  • Orgs running ongoing phishing simulations

Not for

  • Small teams — per-user pricing and admin overhead dwarf the value
  • Buyers who need transparent, self-serve list pricing
  • Orgs with no staff to run and manage campaigns ongoing
  • Anyone wanting simple one-off training, not a platform

Gotchas - check before you buy

high

1.9/5 Trustpilot across 39 reviews — read recent ones before multi-year commitments

medium

Per-user, per-year quote pricing — negotiate hard; list prices hidden behind sales

medium

Phishing simulations require mail-server whitelisting — budget IT setup time

medium

Costs scale with headcount; Reddit MSPs report leaving for other options

Pros and cons

Pros

  • Tops G2 Grid for security awareness training
  • Scales to 22 billion events on AWS infrastructure
  • 70,000+ organizations, per vendor site
  • Free assessment tools: Email Exposure Check and BreachSim
  • Compliance-ready positioning, including FFIEC banking guidance

Cons

  • 1.9/5 Trustpilot rating per 2026 third-party analysis
  • Quote-only per-user pricing; no public list prices
  • Reddit sysadmins and MSPs document churn to alternatives
  • Recent CVEs plus a 2025 data-exposure event disclosed

Sources & method

Analyzed 9/26/2026 - 12 sources - No confirmed customer-platform breach found; several product CVEs and two disclosed incidents (2024 insider hire, 2025 data release).

official x3review x5security x2news x2
  • CVE-2024-29210, Vendor-published advisory with remediation guidance on the KnowBe4 support portal.
  • CVE-2024-29209, Vendor-published advisory affecting users of a KnowBe4 component, per vendor notice.
  • CVE-2020-36844, Vulnerability in the KnowBe4 Security Awareness Training application, catalogued in NIST NVD.
  • January 2025 darknet data release, Security event released previously collected darknet data on Telegram; company publicly disclosed it.
  • July 2024 North Korean insider hire, KnowBe4 accidentally hired a North Korean fake IT worker; company reports no illegitimate access.

Key stats

  • Value for money: 2/5

    Rating

  • Quote only

    Starting price

  • 12

    Sources

  • Analyzed

  • Value for money: 2/5. Quote-only pricing; recurring user complaints
  • Ease of use. No direct usability evidence in sources
  • Feature depth: 5/5. G2 Grid #1; scales to 22B events
  • Support quality: 2/5. 1.9/5 Trustpilot per third-party analysis
  • Security posture: 2/5. Multiple CVEs; 2025 data exposure disclosed
  • 1.9/5 Trustpilot rating Per 2026 third-party analysis; 39 reviews
  • 3,127 G2 reviews G2 Grid leader in security awareness training
  • 70,000+ Customers Organizations, per knowbe4.com
  • $4.6B Acquisition Vista Equity Partners, 2022

Pricing

Per-user subscription (Diamond is top tier)

Quote only

  • Per-user, per-year billing
  • 'Diamond' bundle referenced by Reddit users
  • Sales-gated quote process

Security

No confirmed customer-platform breach found; several product CVEs and two disclosed incidents (2024 insider hire, 2025 data release).

  • CVE-2024-29210Vendor-published advisory with remediation guidance on the KnowBe4 support portal.
  • CVE-2024-29209Vendor-published advisory affecting users of a KnowBe4 component, per vendor notice.
  • CVE-2020-36844Vulnerability in the KnowBe4 Security Awareness Training application, catalogued in NIST NVD.11
  • January 2025 darknet data releaseSecurity event released previously collected darknet data on Telegram; company publicly disclosed it.12
  • July 2024 North Korean insider hireKnowBe4 accidentally hired a North Korean fake IT worker; company reports no illegitimate access.

What users say

G2 reviewers are broadly positive, but r/sysadmin and r/msp threads show growing gripes about pricing, support, and switching to alternatives.

Companies that use it

  • athenahealth
  • Elica
  • Location World
  • Desktop (telecommunications)
  • Washington University in St. Louis
Full analysis

Based on 20+ public sources; pricing details thin — sales-gated quotes only. Review snippets truncated, so no verbatim quotes extracted.

Category-leading security awareness training; strong feature depth, but quote-only pricing, admin overhead, and weak Trustpilot reviews.

Methodology

Based on 20+ public sources; pricing details thin — sales-gated quotes only. Review snippets truncated, so no verbatim quotes extracted.

Sources

  1. review
  2. review
  3. review
  4. news
  5. official
  6. KnowBe4 Homepageknowbe4.com
    official
  7. news
  8. review
  9. review
  10. official
  11. security
  12. security

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.