TL;DR
The biggest security risk at most companies is now their own employees. Verizon’s 2026 Data Breach Investigations Report found a human element in 62% of breaches, and AI has made the attacks harder to catch: mobile social engineering (fake texts and voice calls) succeeds 40% more often than email phishing, and employee use of shadow AI tools has climbed from 15% to 45%. A modern security awareness training platform should do five things well:
- Realistic simulations built to help your team assess modern-day threats and prevent full-blown attacks.
- Coverage across every vector. We’re talking phishing (email), smishing (text), and vishing (voice) formats that today’s hackers use.
- Personalized, conversational training. You want content that adapts to every employee’s role, level of access, and past performance on simulations and quizzes, with a built-in AI coach that can help solidify their understanding.
- Delivery inside Slack or Teams with short modules (between 5 and 15 minutes) that hold their attention and built-in reminders with escalating frequency.
- Built-in reporting to track risk scores over time and produce evidence for SOC 2 and other security frameworks.
Despite what old security trainings might’ve led you to believe, the biggest security risk to your company is not some hacker wearing a black hoodie typing as fast as a 50s secretary on Matrix-looking screens. It’s someone on your team.
Every year, Verizon runs a large-scale data breach investigations report (we’re talking a review of over 22k breaches). And every year, humans are responsible for at least part of those. In 2026, a “human element” was present in 62% of breaches. Not surprising when you consider how many new threats continue to emerge with the help of AI.
Mobile-centric social engineering (think fake texts and voice calls) now succeeds 40% more often than traditional email phishing. At the same time, employee use of unapproved “shadow AI” tools has gone from 15% up to 45%. Every one of those new tools is a new place for company data to leak, giving hackers a new surface to exploit.
With so much changing, your employees have to be vigilant and in the know. But just as importantly, they have to want to be. No one absorbs a lesson they’re only sitting through to make reminder emails stop.
Below we outline five characteristics of a modern security awareness training platform that teaches people what today’s (and tomorrow’s) threats look like, builds lasting habits, and meaningfully decreases your human risk.
What to look for in a modern security awareness training platform
If you’re about to evaluate a new vendor (or reevaluate your existing one), here’s what to look for:
1. Simulations built from realistic attacks
By now, everyone on your team is probably a little skeptical of texts from a Nigerian prince. But they might let their guard down for:
- “Everyone opens the email, and many engage further.” (Reddit)
- “Using open-source resources to conduct reconnaissance, Star Blizzard identifies hooks to engage their target. They create email accounts impersonating known contacts of their targets. They create fake social media or networking profiles that impersonate respected experts. They use webmail addresses from Outlook, Gmail, Yahoo, and Proton Mail in their initial approach. To appear authentic, the actor also creates malicious domains resembling legitimate organizations.” (CISA Cybersecurity Advisory)
- “I’m usually pretty good at recognizing phishing attempts, but although this was really suspicious, I was baffled at how this was trying to phish me…The malicious link was buried in the guest info in the meeting which redirected to an external site somewhere in eastern Europe.” (Reddit)
Hackers are getting sneakier and sneakier, and the only way to help employees get at least wary enough not to open or click or join a meeting or send anything is to make these attempts visible.
“To show how emotional manipulation is used against real people, to get them to do things that they shouldn’t be doing, you need real examples from the real world,” Grant Joy, co-founder and CTO at Herd, explains.
And because these attacks are changing so dynamically, you need a platform that will:
- Constantly comb X, Reddit, and other security feeds for new scams as they surface
- Reuse real phishing attempts that employees have previously reported
- Learn your tool stack (login flows, notification formats, and email addresses your org uses) to make phishing sims hyperrealistic
Questions to ask a vendor
- Can it auto-generate simulations that match the tools our org uses? (and list them out)
- Can it ingest real phishing emails our employees report and turn those into simulations?
- Does it pull from AI security feeds so a threat in the news this week becomes a simulation today?
2. Simulations on every attack vector, including vishing
Email and text phishing simulations are a given now, and should definitely be a box to check on your vendor list. The simulation most human risk platforms are missing, though, is vishing (voice phishing). And “in the ever-changing world of AI,” that is a must-have.
A 2025 study out of UC Berkeley tested whether humans could consistently distinguish real voices from AI-generated ones. Turns out, they could only identify a voice as AI-generated about 60% of the time.
“Participants perceived the identity of an AI-generated voice to be the same as its real counterpart approximately 80% of the time.”
80% of the time! That means an attacker who clones your CEO’s voice and asks an employee to send over a spreadsheet because “they’re at a conference and not at their computer right now” has a four-in-five chance of an employee believing it.
To show people how difficult it is to tell AI voices from real ones, one of Herd’s trainings prompts employees to record a ten-second voice sample in Slack. That gets sent to an AI duplicator and presented back to the employee right next to the original. They have to pick which one is fake.
“Our goal is to show people how hard it is to identify the AI version and give them a feel for what it might be like to get phished,” says Grant.
Questions to ask a vendor
- Can you play a vishing sim for me? (Then ask yourself if it feels real)
- How do you handle multi-step attacks, a text that leads to a call, for instance?
- Can you target specific high-risk people (finance, execs, IT) with voice scenarios built around them rather than a generic script?
3. Content that adapts to your org and people
Blasting out the same content to every employee is not a great way to decrease human risk. Everyone has a different security awareness level, different work habits, uses different tools, and is a target for different kinds of attacks (a finance manager and a backend engineer probably won’t get phished the same way).
A top-notch training platform should be able to adapt its training and simulations to every individual’s:
- Role and level of access
- How their leaders and peers talk, even what emojis their team tends to use (to make training more engaging and simulations more real)
- How well (or not so well) they did on their last simulation or training quiz, and what might make them absorb the information better
That last point matters more than it sounds. “Failing” a simulation could mean clicking a suspicious link or it could mean typing your password into the fake page it leads to, and those outcomes require different kinds of follow-up. A good platform can tell those apart and respond to each.
And for a lesson to stick, employees have to be able to ask questions and confirm their understanding, not just click Next, Next, Next, and answer the most obviously correct multiple-choice question as soon as the final video finishes.
The best human risk platforms build in conversational AI so training becomes a back-and-forth. Employees drive the conversation, ask whatever they want, and stay in the sidebar as long as it takes for a concept to click.
Questions to ask a vendor
- Do you have built-in chat or an AI coach?
- What does the platform know about an individual employee, and how does that change what they see?
- Does it send dynamic follow-up trainings based on employee behavior?
4. Training that’s short, sweet, delivered in tools people use
Employees are juggling hundreds of tabs. Asking them to open one more, reset their password, and sit through boring trainings is like pulling teeth:
“Our company, like many companies, has mandatory cyber-security training (only 1 hour to do). The only problem is that even though it’s mandatory, a vast majority of people still don’t do it. (Over 70%). The COO has sent out multiple emails before the training and explained the seriousness of it. He even threatened that your bonus would be in jeopardy if you don’t. However, even with that, people don’t do it.” (Reddit)
The easiest way to get people to comply is to make it easy for them:
- Deliver trainings entirely within apps they already use every single day, like Slack or Teams.
- Keep training short. Bite-sized modules between 5 and 15 minutes can hold their attention.
- Nudge gently. A reminder (in Slack or Teams) to pick a training back up, sent at a few different times of day, gives people a chance to knock it out the minute they get a break. (Even better if the platform automatically sends reminders with escalating frequency).
Questions to ask a vendor
- Do employees have to log into a separate portal to complete training?
- Can you deploy natively in our messaging tool?
- Can people take training on day one?
- What’s your average completion rate across customers?
5. Easy backend management with robust reporting
Scrambling to pull SOC 2 proof together before an audit is a nightmare for everyone who owns it. Yet, reconciling spreadsheets last minute is what most of them are doing, because their numbers are tracked across a whole bunch of different systems.
You want a platform that handles the busywork for you, assigning the right trainings and simulations to the right people, sending them reminders, and logging progress automatically.
That way you can spend your time helping the riskiest teams improve their scores instead of babysitting completion rates.
“Your human risk platform should be able to show per person and aggregate scores and see how performance is changing over time,” Grant advises. “That way you know exactly where the risk points are and how you might remediate them quickly.”
Questions to ask a vendor
- Does it integrate with your identity provider to assign training automatically by group?
- Can you delay enrollment for new hires so it doesn’t conflict with onboarding?
- Can I see risk trending over time for an individual, a team, and the whole company?
- Does it give me what I need for a SOC 2 audit without manual exports?
Reducing human risk isn’t about “gotchas”
It’s about learning. You want people to fall for your sims, to maybe get an answer or two wrong in a course, but not to embarrass them, to have them know what a modern-day attack looks like before they fall for one.
If you’re in the market for a tool that checks all these boxes, give Herd a try. It:
- Learns your security policies
- Adapts to new threats and to your employees’ responses
- Delivers training right where people already work: Slack and Teams
- Produces the evidence your auditors need
And it takes just five minutes to set up. Won’t believe it til you see it? Book a demo →




