Phishing simulation platforms send fake phishing emails to your employees, track who clicks, and trigger follow-up training. The market has matured significantly — KnowBe4 dominates the enterprise segment, Phished and Barracuda Phish Threat have built strong mid-market positions, and SANS Security Awareness (now SANS Security Awareness Foundations SAF) covers organisations with a compliance-first orientation. For NZ businesses, the question is not which platform has the most templates — it is which one meets NZ-specific requirements and fits your actual team size and budget.
---
KnowBe4 — Market Leader, Enterprise Focus
KnowBe4 is the largest security awareness training and phishing simulation platform globally, with over 65,000 customers. Its phishing simulation library runs to thousands of templates, its AI-driven smart groups auto-enrol high-risk users in additional training, and its integration ecosystem covers Active Directory, SIEM, and major identity providers.
What it does well:
- Largest phishing template library available
- Per-user risk scoring across email behaviour and training completion
- Advanced reporting for compliance teams
- Strong enterprise SSO and directory integrations
Limitations for NZ:
- USD pricing — expensive at SME scale
- Templates are primarily US and UK-centric; IRD, myIR, NZ Post lures require custom configuration
- Compliance reporting is not pre-built for NZISM, NZ PSR, or NZ cyber insurer requirements
- Sales-led process with no self-serve trial for small teams
Best for: NZ enterprises with 200+ staff, a dedicated security team, and US or global compliance requirements.
---
Phished — Behavioural Science Approach
Phished is a Belgian platform that has grown rapidly in the UK and European market. Its differentiator is a behavioural science engine that adapts simulation difficulty and training content based on individual performance, rather than running everyone through the same material.
What it does well:
- Adaptive difficulty based on individual click behaviour
- Clean UX and straightforward deployment
- Good reporting for non-security managers
- Reasonable mid-market pricing
Limitations for NZ:
- No NZ-specific phishing templates out of the box
- Not aligned with NCSC NZ requirements or NZ frameworks
- Compliance documentation is not mapped to NZ frameworks
- Limited presence in the NZ market; no local support
Best for: Mid-market NZ businesses that want adaptive simulation without enterprise complexity, and where NZ-specific compliance documentation is not a hard requirement.
---
Barracuda Phish Threat — MSP-Friendly Option
Barracuda Phish Threat is a phishing simulation and awareness training platform positioned primarily for the managed service provider channel. NZ MSPs that already run Barracuda email security often bundle it for clients.
What it does well:
- MSP multi-tenancy model makes it easy to manage across clients
- Good integration with Barracuda email gateway
- Solid phishing simulation templates
- Reasonable per-seat pricing through the MSP channel
Limitations for NZ:
- Awareness training content is limited compared to KnowBe4 or SecureAZ
- No NZ-specific content
- Compliance documentation not mapped to NZ frameworks
- Primarily a phishing simulation tool, not a full awareness programme
Best for: NZ SMEs managed by an MSP already running Barracuda infrastructure, where basic phishing simulation is the primary requirement.
---
SANS Security Awareness — Compliance-Grade Content
SANS Security Awareness (now branded Security Awareness Foundations SAF in some markets) is the training arm of the SANS Institute, the most respected name in information security education. The platform is content-heavy, compliance-oriented, and designed for organisations where the training programme needs to stand up to a formal audit.
What it does well:
- Very high quality training content built by security practitioners
- Strong compliance documentation across major frameworks (ISO 27001, SOC 2, NIST)
- Credible brand that satisfies auditors
- Includes phishing simulation capability
Limitations for NZ:
- Pricing is at the enterprise end
- Content is not NZ-localised
- Compliance documentation does not cover NZISM, NZ PSR, or NZ cyber insurer requirements specifically
- Primarily designed for US/EU compliance environments
Best for: NZ organisations pursuing ISO 27001 certification or SOC 2 compliance, where the SANS brand carries weight with auditors.
---
SecureAZ — Built for NZ and AU Compliance
SecureAZ is the only platform on this list built specifically for NZ and Australian businesses. Where KnowBe4 and Phished start from global templates and ask you to configure for NZ, SecureAZ starts from NZ.
What sets it apart:
- NZ-localised phishing simulations — IRD scams, NZ Post lures, myIR credential harvesting, ANZ and ASB bank phishing, government impersonation
- Aligned with NCSC NZ requirements and usable by government agencies
- Compliance documentation pre-built for NZISM 3.2.18, NZ PSR, Privacy Act 2020, NZ cyber insurer requirements
- NZD pricing from $3/user/month
- 45-day free trial, self-serve, setup in under 30 minutes
Best for: Any NZ or AU business that needs compliance documentation for a regulator, insurer, or government procurement, or that wants phishing simulations that look like the actual threats NZ staff receive.
---
Side-by-Side
| Feature | KnowBe4 | Phished | Phish Threat | SANS SAF | SecureAZ |
|---|---|---|---|---|---|
| NZ-localised templates | ❌ | ❌ | ❌ | ❌ | ✅ |
| NCSC NZ aligned | ❌ | ❌ | ❌ | ❌ | ✅ |
| NZ compliance docs | ❌ | ❌ | ❌ | ❌ | ✅ |
| NZD pricing | ❌ | ❌ | ❌ | ❌ | ✅ |
| Free trial (self-serve) | ❌ | ✅ | ❌ | ❌ | ✅ |
| SME-friendly setup | ❌ | ✅ | ✅ | ❌ | ✅ |
| Adaptive simulation | ❌ | ✅ | ❌ | ❌ | ✅ |
For the full picture on what to look for in a phishing simulation programme, read employee phishing tests: how to run one that changes behaviour.
Start your free 45-day SecureAZ trial — NZ-localised phishing simulations, NCSC aligned, NZD pricing.
External references: