# Herd Security > Herd Security is an AI platform security teams use to generate their own security awareness training and phishing simulations from their company's policies and real threats, delivered in Slack and Microsoft Teams. This document contains the full text of every post on the Herd Security blog, plus summaries of our customer stories, provided for AI assistants and answer engines. The page index is at https://www.herdsecurity.io/llms.txt. Product documentation is at https://herd-security.gitbook.io/herd-security-docs/. # Blog ## Buying a New Human Risk Management Platform? Here Are 5 Things to Look For Source: https://www.herdsecurity.io/blog/human-risk-management-platform-checklist Author: Liz Melton Published: August 18, 2026 Updated: August 19, 2026 Topics: Best Practices Despite what old security trainings might’ve led you to believe, the biggest security risk to your company is not some hacker wearing a black hoodie typing as fast as a 50s secretary on Matrix-looking screens. It’s someone on your team. Every year, Verizon runs a large-scale data breach investigations report (we’re talking a review of over 22k breaches). And every year, humans are responsible for at least part of those. In 2026, a “human element” was present in 62% of breaches. Not surprising when you consider how many new threats continue to emerge with the help of AI. Mobile-centric social engineering (think fake texts and voice calls) now succeeds 40% more often than traditional email phishing. At the same time, employee use of unapproved “shadow AI” tools has gone from 15% up to 45%. Every one of those new tools is a new place for company data to leak, giving hackers a new surface to exploit. That is the gap an AI coach is meant to close: scoring how people actually use Claude, ChatGPT, and Copilot rather than banning them. With so much changing, your employees have to be vigilant and in the know. But just as importantly, they have to want to be. No one absorbs a lesson they’re only sitting through to make reminder emails stop. Below we outline five characteristics of a modern security awareness training platform that teaches people what today’s (and tomorrow’s) threats look like, builds lasting habits, and meaningfully decreases your human risk. ## What should you look for in a human risk management platform? A modern platform should do five things well: build simulations from real, current attacks; cover every vector your employees actually get hit on, including voice; adapt training to each person’s role, access, and past results; deliver it inside Slack or Teams in short modules; and produce audit-ready reporting without manual exports. If you’re about to evaluate a new vendor (or reevaluate your existing one), here’s what each one looks like in practice: ### 1. Simulations built from realistic attacks By now, everyone on your team is probably a little skeptical of texts from a Nigerian prince. But they might let their guard down for: - “Everyone opens the email, and many engage further.” (Reddit) - “Using open-source resources to conduct reconnaissance, Star Blizzard identifies hooks to engage their target. They create email accounts impersonating known contacts of their targets. They create fake social media or networking profiles that impersonate respected experts. They use webmail addresses from Outlook, Gmail, Yahoo, and Proton Mail in their initial approach. To appear authentic, the actor also creates malicious domains resembling legitimate organizations.” (CISA Cybersecurity Advisory) - “I’m usually pretty good at recognizing phishing attempts, but although this was really suspicious, I was baffled at how this was trying to phish me…The malicious link was buried in the guest info in the meeting which redirected to an external site somewhere in eastern Europe.” (Reddit) Hackers are getting sneakier and sneakier, and the only way to help employees get at least wary enough not to open or click or join a meeting or send anything is to make these attempts visible. > “To show how emotional manipulation is used against real people, to get them to do things that they shouldn’t be doing, you need real examples from the real world,” Grant Joy, co-founder and CTO at Herd, explains. And because these attacks are changing so dynamically, you need a platform that will: - Constantly comb X, Reddit, and other security feeds for new scams as they surface - Reuse real phishing attempts that employees have previously reported - Learn your tool stack (login flows, notification formats, and email addresses your org uses) to make phishing sims hyperrealistic ### What should you ask a vendor about simulation realism? - Can it auto-generate simulations that match the tools our org uses? (and list them out) - Can it ingest real phishing emails our employees report and turn those into simulations? - Does it pull from AI security feeds so a threat in the news this week becomes a simulation today? ### 2. Simulations on every attack vector, including vishing Email and text phishing simulations are a given now, and should definitely be a box to check on your vendor list. The simulation most human risk platforms are missing, though, is vishing (voice phishing). And “in the ever-changing world of AI,” that is a must-have. A 2025 study out of UC Berkeley tested whether humans could consistently distinguish real voices from AI-generated ones. Turns out, they could only identify a voice as AI-generated about 60% of the time. > “Participants perceived the identity of an AI-generated voice to be the same as its real counterpart approximately 80% of the time.” 80% of the time! That means an attacker who clones your CEO’s voice and asks an employee to send over a spreadsheet because “they’re at a conference and not at their computer right now” has a four-in-five chance of an employee believing it. To show people how difficult it is to tell AI voices from real ones, one of Herd’s trainings prompts employees to record a ten-second voice sample in Slack. That gets sent to an AI duplicator and presented back to the employee right next to the original. They have to pick which one is fake. > “Our goal is to show people how hard it is to identify the AI version and give them a feel for what it might be like to get phished,” says Grant. ### What should you ask a vendor about vishing and multi-step attacks? - Can you play a vishing sim for me? (Then ask yourself if it feels real) - How do you handle multi-step attacks, a text that leads to a call, for instance? - Can you target specific high-risk people (finance, execs, IT) with voice scenarios built around them rather than a generic script? ### 3. Content that adapts to your org and people Blasting out the same content to every employee is not a great way to decrease human risk. Everyone has a different security awareness level, different work habits, uses different tools, and is a target for different kinds of attacks (a finance manager and a backend engineer probably won’t get phished the same way). A top-notch training platform should be able to adapt its training and simulations to every individual’s: - Role and level of access - How their leaders and peers talk, even what emojis their team tends to use (to make training more engaging and simulations more real) - How well (or not so well) they did on their last simulation or training quiz, and what might make them absorb the information better That last point matters more than it sounds. “Failing” a simulation could mean clicking a suspicious link or it could mean typing your password into the fake page it leads to, and those outcomes require different kinds of follow-up. A good platform can tell those apart and respond to each. And for a lesson to stick, employees have to be able to ask questions and confirm their understanding, not just click Next, Next, Next, and answer the most obviously correct multiple-choice question as soon as the final video finishes. The best human risk platforms build in conversational AI so training becomes a back-and-forth. Employees drive the conversation, ask whatever they want, and stay in the sidebar as long as it takes for a concept to click. ### What should you ask a vendor about personalization? - Do you have built-in chat or an AI coach? - What does the platform know about an individual employee, and how does that change what they see? - Does it send dynamic follow-up trainings based on employee behavior? ### 4. Training that’s short, sweet, delivered in tools people use Employees are juggling hundreds of tabs. Asking them to open one more, reset their password, and sit through boring trainings is like pulling teeth: > “Our company, like many companies, has mandatory cyber-security training (only 1 hour to do). The only problem is that even though it’s mandatory, a vast majority of people still don’t do it. (Over 70%). The COO has sent out multiple emails before the training and explained the seriousness of it. He even threatened that your bonus would be in jeopardy if you don’t. However, even with that, people don’t do it.” (Reddit) The easiest way to get people to comply is to make it easy for them: - Deliver trainings entirely within apps they already use every single day, like Slack or Teams. - Keep training short. Bite-sized modules between 5 and 15 minutes can hold their attention. - Nudge gently. A reminder (in Slack or Teams) to pick a training back up, sent at a few different times of day, gives people a chance to knock it out the minute they get a break. (Even better if the platform automatically sends reminders with escalating frequency). ### What should you ask a vendor about delivery and completion? - Do employees have to log into a separate portal to complete training? - Can you deploy natively in our messaging tool? - Can people take training on day one? - What’s your average completion rate across customers? ### 5. Easy backend management with robust reporting Scrambling to pull SOC 2 proof together before an audit is a nightmare for everyone who owns it. Yet, reconciling spreadsheets last minute is what most of them are doing, because their numbers are tracked across a whole bunch of different systems. You want a platform that handles the busywork for you, assigning the right trainings and simulations to the right people, sending them reminders, and logging progress automatically. That way you can spend your time helping the riskiest teams improve their scores instead of babysitting completion rates. > “Your human risk platform should be able to show per person and aggregate scores and see how performance is changing over time,” Grant advises. “That way you know exactly where the risk points are and how you might remediate them quickly.” ### What should you ask a vendor about backend management and reporting? - Does it integrate with your identity provider to assign training automatically by group? - Can you delay enrollment for new hires so it doesn’t conflict with onboarding? - Can I see risk trending over time for an individual, a team, and the whole company? - Does it give me what I need for a SOC 2 audit without manual exports? ## Reducing human risk isn’t about “gotchas” It’s about learning. You want people to fall for your sims, to maybe get an answer or two wrong in a course, but not to embarrass them, to have them know what a modern-day attack looks like before they fall for one. If you’re in the market for a tool that checks all these boxes, give Herd a try — and if you are buying for a few thousand people rather than a few hundred, start with the enterprise program. It: - Learns your security policies - Adapts to new threats and to your employees’ responses - Delivers training right where people already work: Slack and Teams - Produces the evidence your auditors need That list is the whole of what the Herd platform does, and it takes just five minutes to set up. Won’t believe it til you see it? Book a demo → --- ## How startups can make training the easiest part of SOC 2 (and sell to the enterprise faster) Source: https://www.herdsecurity.io/blog/soc-2-training-requirements Author: Liz Melton Published: July 28, 2026 Updated: August 17, 2026 Topics: Compliance Founders have a lot on their minds. Usually, SOC 2 doesn’t top the list. Until they receive the dreaded email or text from their first enterprise prospect: > "Hey, was chatting with my boss. She reminded me we can only partner with vendors that have SOC 2. Just making sure - you all have that, right?" At this point, they’re frantically prompting: “How do I get SOC 2 compliance fast?” and “How to get SOC 2 with no consultant?” They decide that, with Claude or ChatGPT’s help and a free SOC 2 compliance checklist, they can get pretty far. Yet even with LLMs on their side, there will inevitably be parts of SOC 2 prep they can’t tackle themselves. One big one most founders don’t see coming is training. While there isn’t a SOC 2 training requirement, per se, it’s one of the major things auditors look for (we’ll share specifics later). And creating employee security training, deploying it, and continuously verifying that people have completed it takes work and expertise. Below, we explain where training fits into SOC 2, the challenges that founders usually face trying to do it themselves, and how you can knock it out quickly to close whale customers faster. But before we get too far down that road, you need to know what SOC 2 is and whether you truly need it. Here's a primer. ## What’s SOC 2? SOC 2 is a standard set forth by the AICPA (American Institute of Certified Public Accountants) that verifies whether a vendor stores, processes, and transmits its customers’ data – and their customers’ data – safely. The reason preparing for SOC 2 is so arduous, and why audits take so long, is that every company has different processes and, therefore, different controls to meet the five SOC 2 Trust Services Criteria: 1. Security. Are your systems protected against unauthorized access? That covers outside attackers and internal employees. Think: firewalls, MFA, access controls, and the ability to detect and respond when something goes wrong. 2. Availability. Is your system up and reachable when your customers need it? As you can imagine, this matters a lot if your tool is something a customer’s operations depend on. 3. Processing Integrity. Does your system do what it says it does, completely, accurately, and on time? Companies that perform calculations or transactions on a customer’s behalf, like payments, payroll, or analytics, need to pay special attention to this one. 4. Confidentiality. Is information that’s been designated confidential (say, contracts, source code, business plans, IP) restricted to the people who should see it? Access controls and encryption are the major components here. 5. Privacy. Do you collect, use, retain, and dispose of personal information the way your privacy notice describes? Because this one is specifically about PII, it’s where SOC 2 starts to overlap with GDPR and CCPA. Security is listed first here because it’s the only one that’s mandatory. The other four are technically optional. For startups strapped for cash and resources, it makes sense to pursue Security Criteria first, then add the other four as your business model, contractual obligations, or customer expectations change. Ahead of an audit, your CPA will ask you which systems and Trust Services Criteria you want them to review. They’ll ask to see documentation of your various controls, tests you’ve run, and proof that you’re continuously educating your employees on your security policies. It’ll take a few months for the auditor to run their audit and then prepare their findings. ## Do startups need SOC 2? You need a SOC 2 report when your customers start asking for it, and that timing depends entirely on who you’re selling to. If you’re selling into healthcare, fintech, or government, your buyers handle super sensitive data and are heavily regulated themselves. They’ll definitely ask for SOC 2 (and often HIPAA or other frameworks too) from day one. Doesn’t matter if you’re pre-seed or Series C. You have to clear their vendor security review, and SOC 2 is usually a non-negotiable. Most enterprise tech companies will expect SOC 2, too. Procurement, IT, and eng teams want to see it before signing. Plus, discerning mid-market companies (even other startups) see a SOC 2 report as a sign that you’re taking security seriously. So, if you want to sell to any of these businesses, you’ll need it. Once you’ve decided you need SOC 2, there’s one more choice to make: which of the two report types to pursue. ## SOC 2 Type I or Type II: which should you get? There are two kinds of SOC 2 reports you can get: Type I and Type II. A SOC 2 Type I report states that you have the right internal controls in place (i.e., they satisfy the Trust Services Criteria) at the time of an audit. For startups hoping to sell to enterprise customers and pursuing SOC 2 compliance for the first time, SOC 2 Type I is a good way to prepare. Per one CISO’s LinkedIn comment: > “A SOC 2 Type I is a very reasonable ‘first certification’ for startups. It requires them to start thinking about security and compliance, in a more rigorous way than most have done before. Building a policy set that addresses all of the necessary SOC 2 domains is not the difficult part...figuring out how to secure the organization is, which requires addressing all of the areas required for SOC 2.” Showing a prospect you’ve earned a Type I report can also be enough to keep an enterprise deal moving (they can see you’re on your way to Type II). One Redditor points out, “Type I is cheaper and faster than Type II. Most buyers will accept it while you work toward Type II, which requires a 3-12 month monitoring period.” A SOC 2 Type II report states that you have the right internal controls in place (i.e., they satisfy the Trust Services Criteria) and you’re actively using those controls for a period of time. You choose how long that time period is. Typically, it’s in increments of three months (3 months, 6 months, 9 months, a year). ## What are SOC 2 training requirements? Technically, SOC 2 has no training requirement. Search the Trust Services Criteria, and you won’t find one. But training is effectively mandatory, because it’s how you satisfy several of the Common Criteria (CC) in the Security category: ### CC1.4 CC1.4 requires that you attract, develop, and retain people competent to carry out their security responsibilities. By now, employees know full well they shouldn’t reuse passwords, but spammy emails and texts are getting harder to identify with AI and deepfakes in the picture. Gartner predicts 40% of social engineering attacks will target executives and the broader workforce by 2028. Keeping your team competent against threats like these is a moving target, which is why one-and-done training doesn’t cut it. ### CC1.5 CC1.5 requires that you hold those people accountable for those responsibilities. In other words, it’s not enough to offer training. You have to show that specific employees completed it, and that there are real consequences when they don’t. ### CC2.2 CC2.2 requires that entities “internally communicate information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control.” A control only works if the person following it understands it. Access reviews fail when admins don’t grasp least privilege, incident response plans are useless if the on-call engineer can’t find them, etc. A comprehensive security awareness training program – that is uniquely tailored to your organization’s policies – with completion records is one of the primary things auditors expect you to have and produce. And remember: For a Type II report, auditors need proof that training continued throughout the entire monitoring period. Every new hire was trained when they joined, and everyone assigned new training during the 3- to 12-month period of your audit completed it on schedule. ## Why is SOC 2 compliance training so hard? We’ve already given some hints, but here are four areas where founders struggle with SOC 2 training requirements on the DIY path: ### 1. You’re not an expert Startups often don't know what their training even needs to cover. Figuring out the right topics, mapping them to your actual policies, and keeping it all current is a lot of work, and it’s usually not a core expertise for a startup team member. Unless, maybe, you’re operating in a more regulated space and have a GRC person on your team. Even then, it’s going to be a boatload of work for them to create, edit, publish, and track the content (more on that last piece in #4). ### 2. You have to buy another tool A new LMS isn’t cheap, and it takes a while to implement. Worst of all, it’s not user-friendly. Everyone at a startup is busy, and now you’re asking them to: - Create a new login (that they won’t use again until next year) - Learn how to use the LMS (not rocket science, but still) - Sit through hours of training (that can be pretty boring) One Redditor at a 150-person B2B startup complained about how they’re only at 20% compliance with three weeks left in their SOC 2 audit: > “Our soc 2 auditor keeps asking for documentation proving everyone completed security awareness training. leadership asking why HR cant get this done. standard lms setup. hour long video courses. sent slack reminders. mentioned in all hands. > the format just doesn’t work for how remote teams actually operate. nobody has an uninterrupted hour. they live in slack and zoom. opening an lms tab and watching compliance videos feels like assigning homework.” To get people to comply, you need to make training short, engaging, and accessible (i.e., deliver it in a tool that they already use). ### 3. Off-the-shelf training isn’t tailored to your security policies Yes, Vanta and Drata offer security and awareness training. But those are generic courses that don’t necessarily map to your specific security controls. Which means you’re still going to come up with your own customized training. That costs money if you work with a consultant — for comparison, Herd’s plans start at $100 a month. And if you decide to go the route of Mr. Claude, you open yourself up to risk. An auditor may not find your courses acceptable, and you will have gone through the whole auditing process only to have to fix what’s wrong and go through it again (more time and money). ### 4. Tracking is tough To pass an audit, you can’t just say you trained your team, you have to prove it. And auditors are picky. As one auditor shares: The evidence I would look for would be: 1. Active employee listing (always include where this was generated from, it should be the HR system). 2. Sample of employees showing when they completed it and what they completed. This should also be from the LMS system. 3. Timing configuration: if your training system is set up on a frequency timer, employees have xx days to complete, then managers are notified, then closed after xy days. I have seen certain processes and LMS statements set up this way. I don’t typically request this evidence, but for a first-time review of the process and setting it up from the internal side, this helps drive a higher completion %. Unless you’re able to easily cross-reference HR and LMS data and your LMS has built-in tracking, you’re looking at some serious spreadsheet wrangling. ## AI-powered training platforms can help you get SOC 2 compliant faster If you’re starting to sweat at the thought of drafting security and compliance training from scratch or paying tens of thousands of dollars for a firm to do it for you, consider using an AI-powered tool. It already has the security background you don’t, and you can feed it your organization’s policies so the training it produces is fully customized to your needs. Some platforms, like Herd, help you overcome all the other challenges that DIY SOC 2 training presents, too: - Delivering training in bite-sized chunks over Slack, so it doesn’t feel overwhelming. - Automatically recording completions with a timestamp, so you don’t have to juggle spreadsheets. - Reminding employees to complete their assigned training so you don’t have to bug them yourself. - Re-running training periodically, so you don’t have to remember to set up annual training or deploy new training when a policy changes. ### SOC 2-ready in a week with Herd Outfox Health, a healthcare company, used Herd to spin up customized SOC 2 training. Within five minutes, Herd was ingesting information about Outfox’s business, policies, and users, correlating it to the most up-to-date SOC 2 standards, and sending curated training programs to every employee on Slack. They got to a 100% training completion rate within a week. Per Outfox’s CEO, Beth Ann Lopez: > “We were flooded with options in the training space. Herd was the only one that provided time-to-value and a clear win within minutes. Seeing how fast the engine could create tailored trainings to our organization, plus save me personally over 20-30 hours of management and administration time, we were blown away by the results.” All her team had to do was hand the records to their auditors. (Herd gets asked for the same paperwork; ours lives in the trust center.) Outfox successfully completed its first SOC 2 audit, and they’re still using Herd to stay compliant. Every year, the tool automatically sends out new training, and whenever anyone joins the company, they have a SOC 2 training ready and waiting for them to complete in Slack. ## SOC 2 training doesn’t have to be a drag Yes, you’ll have to create your policies first, and yes, Herd only handles the training piece of the SOC 2 puzzle. But for startups on the DIY path, Herd is a way to dramatically cut your time to SOC 2 audit readiness and to stay compliant over time. Plus, you can use Herd to design training for HIPAA, ISO 27001, and other frameworks you might need to comply with in the future. If you’re a startup without a dedicated security hire, that is exactly how Herd works for startups. Don’t let training be the thing standing between you and your next enterprise deal. Get started with Herd → --- ## Herd Security Raises $3M Seed to Make Security Teams the Creators of Their Training Source: https://www.herdsecurity.io/blog/herd-security-seed-fundraise-announcement Author: Brandon Min Published: May 6, 2026 Updated: August 17, 2026 Topics: Announcements Today, we're announcing that Herd Security has raised $3 million in seed funding with participation from Aspiron Ventures, ForwardSlash VC, Team Ignite, Forum Ventures, RightSide Capital, YPO, and several angel investors. We're using this investment to accelerate our agentic AI creative platform — replacing the stagnant, one-size-fits-all content of legacy security awareness training (SAT) with dynamic, practitioner-built curricula designed for the speed of modern threats. ### Why doesn't annual security awareness training change behavior? The training problem isn't expertise. It's execution. Over 95% of organizations run annual SAT for compliance. But outside the checkbox, most programs don't move the needle on actual security behavior. Threats now evolve daily, Gartner predicts that by 2028, 40% of social engineering attacks will target executives and the broader workforce, while the SANS Institute finds it takes 3–5 years to influence employee behavior and up to a decade to shape security culture. Security and GRC teams see the gap. They just don't have the time, headcount, or tooling to close it. New SAT platforms are marginally better at triple the cost. Herd is built specifically to solve this with an agentic AI platform: - AI-Powered Content Creation: generate tailored micro-trainings in seconds from prompts aligned with your organization - Behavioral Learning Signals: understand what's actually changing employee behavior, not just completion rates - Contextual Simulations: active-threat scenarios that bring in your real organizational context This approach has resonated with security teams that want to be creators, not box-checkers, including those at OneBrief, Clearly AI, Outfox Health, and many more. It's also caught the attention of the broader security community: Herd was named a finalist in last year's Okta Startup Challenge, an early signal of the momentum we're now accelerating with this round. Security Team’s “Canva” Moment When we set out to build Herd, we wanted to get away from content libraries. Those pre-set training catalogs became the catalyst for one-size-fits-all programs in the first place. We wanted practitioners to stop looking up training and start creating it. Think of it like the design tools that made every marketer a designer, applied to security: the expertise has always lived inside security teams; what's been missing is a creative surface that lets them ship it. Historically, building training meant weeks or months of work. Drop that on a security practitioner's plate, and it becomes the lowest priority on a list that's already too long. Our team saw AI as the unlock, the difference between security teams shipping a new micro lesson the same day a threat surfaces and filing a vendor request that lands six weeks later. With Herd, practitioners can: - Import policies, compliance frameworks, and security data — Herd parses, understands, and updates them as they change - Generate tailored micro-trainings in seconds with prompts aligned to organizational needs - Deliver training in the tools employees already use — Slack, Teams, LMS — in formats from text and video to conversational AI ### What's next for Herd? This funding accelerates three things: expanding into new training categories like HR and AI risk, optimizing our AI-powered video generation, and growing our partnership ecosystem so Herd shows up wherever security teams already work. Our mission stays the same: put practitioners back at the center of security awareness, turn their expertise into content that actually engages employees, and use every interaction to strengthen the human layer of defense. Want to see Herd in action? Get a trial today. --- ## It's Impossible To Fail A Phishing Simulation Source: https://www.herdsecurity.io/blog/it-s-impossible-to-fail-a-phishing-simulation Author: Brandon Min Published: April 21, 2026 Updated: August 17, 2026 Topics: Phishing, Simulations Ready. Set. Send. Boom! 500 employees received an email promising a $650 holiday bonus. You see it and click it, but instead of a bonus you get cybersecurity training. What a letdown. This was the strategy GoDaddy used with its employees during the Holiday season. Fake Holiday bonuses. Replacing those bonuses with additional security training that needed to be completed before the end of the year. If you’ve seen me write on phishing before, you know that I absolutely despise how they’re run today. How click-rate is an absolute vanity metric that has no correlation to the security of the company. Nor is it a key performance indicator (KPI) that relays how well an employee is retaining security information. Let alone one that should be used in performance reviews. I’m not sure when, but there was a moment when phishing simulations stopped being about awareness. This wasn’t always the case; it wasn’t the original design. However, organizations now use it as a standard to measure the level of human risk defense. I’m here to tell you, there is a better way! It should be impossible to fail a phishing simulation. Ironically using failure rate as a metric may be one the main causes of higher click rates. In this blog, we’ll dive into how organizations use phishing simulations to build a false sense of security and how applying behavioral science and AI can lead to more robust behavior change. Without having to fail a single user. ### How phishing simulations lost their original purpose Before diving into how to improve today’s phishing simulations, we first have to look at how we got here. The word simulation derives from the Latin word Simulātiōnem, which means to imitate, copy, or represent. The original intent of a simulation was to provide the training or reinforcement the individual needed to happen. Therefore, the simulation was run; failures would be tracked; instructors would collect the data; and then use that data to inform better training and future sessions. When phishing attacks arose in the mid 2000’s, primarily with the rise of email adoption, organizations began using the same training principles, with simulations, to combat the rising tide of attacks. The original intent was “build a safe space for employees to see phishing emails so they’d recognize them in the real world.” As simulations grew in popularity, they gradually became the measure of the success rate of a general security awareness program. In essence, it helped answer the question, “How effective is your security training?” This became a more consistent question as auditors for SOC2, ISO, HIPAA, and other common compliance frameworks use security training as a measure of robustness. This formed the dreaded “click rate” KPI. Once “click-rate” became a KPI, phishing simulations became the target of employee shaming. Ironically, this development was actually the beginning of the end in terms of the effectiveness of security awareness programs. Sadly, this number has become a weaponized metric to ridicule employees and “scare them straight”. 42% of organizations use “click rate” to take disciplinary action against employees. With 15% saying they are openly sharing the names of people for failing. A Fortune 50 CISO even admitted to using “click-rate” as a metric to fire people. They followed a “three-strikes, and you’re out” policy. In the case of our earlier example with GoDaddy, it meant losing a “bonus” and being forced to do 40 minutes of training over the Holiday break. Thus, “click-rate” inadvertently created a negative connection between how employees and cybersecurity. ### Why does punishing phishing failures make security worse? The negative association between phishing simulations and employees is pervasive across organizations. Roughly 90% of users say their primary interaction with a security team is either when they click a phishing simulation link or when they are put into remedial training for a failure. Think about what that means. The only time most employees hear from the people responsible for protecting the company is when they've done something "wrong." Security shows up as the department that catches you, not the department that has your back. Decades of behavioral research show that negative reinforcement is one of the hardest ways to get the best results. Negative feedback or shaming in isolation leads to constant pressure. I personally used to feel this when I was in SAT prep class in High School. We took a practice SAT every week, and our scores would be posted on a wall. If your grade was on the bottom, everyone knew. Theoretically, it would motivate you to work harder. However, this was something that was the opposite. The more I personally tried, the less I improved. The less I improved, the more I would just be nervous and fail. Ultimately, my perception of SAT prep is all negative. The test itself and the process. Phishing simulations are no different. The data supports that failing phishing simulations that directly lead to negative feedback leads to heightened anxiety, lower productivity, more resentment, and less willingness to report. CybSafe's lab experiments found this impact was "highly detrimental", and their survey work found that 42% of organizations take disciplinary action against employees for cybersecurity errors anyway, from public shaming (15%) to revoked access (33%) to looping in their manager (63%). That's almost half the industry actively building a system that punishes the behavior they're trying to improve. Here's what almost nobody in the space talks about: forcing people into mandatory training after they click doesn't even fix the clicking. A peer-reviewed study at a major US healthcare system tracked what happened when repeat clickers were funneled into a required training program. Click rates for "offenders" stayed between 10% and 25% after the mandatory training. The program didn't change the behavior because the behavior wasn't a knowledge problem in the first place. It's a workload problem. An attention problem. A context problem. No amount of remedial training solves any of those. It just tells the employee, "You failed, now sit here for 20 minutes and think about what you did." It's the corporate version of writing lines on a chalkboard. It gets worse. ETH Zurich ran one of the largest real-world studies ever done on phishing simulations and found that employees who received contextual training after clicking actually got worse… click rates went up 16%, and dangerous-action rates went up 27%. A separate study out of UC San Diego tracking 19,500 employees found that each additional training session was associated with an 18.5% increase in failure likelihood. The industry's answer to clicking has always been "more training," and the best evidence we have says more training makes things worse. Ultimately, if your phishing program punishes people, it's not a security program. It's a liability program, you're creating evidence for termination while quietly destroying the reporting culture that can be an extension of your security team. ### What does behavioral science say about phishing simulations? Now, with a problem comes the opportunity to evolve phishing simulations from vanity metrics to actual behavior change. News flash, it’s not sticking people with remedial training, and it’s not gamifying everything. It uses actual behavioral psychology to maximize behavioral change. In behavioral science, there’s a theory called Gagné's Hierarchies of Learning, which presents that there are different stages of learning that work in a hierarchical sequence. Think of this as crawl, walk, run. One of the key components of Gagne’s theory was the application of learning in two phases: instruction (designed to produce learning) and assessment (designed to measure whether learning occurred). This is ironically how the industry has been developing phishing simulations for the last 30 years. You have instructions, “don’t click it” relayed to the assessment, “click rate”. However, Gagné explicitly distinguished instruction from assessment. The current phishing simulation model collapses these into a single event, which is exactly the category error Gagné spent his career warning against. In Gagné's framework, instruction and assessment have distinct conditions, purposes, feedback loops, and success criteria. An instructional event that fails (e.g., the learner clicks a link) is data for the instructor; it tells you to adjust rather than how to punish. An assessment event that fails is data about readiness (how prepared is the organization for a real phishing attempt). Confusing them means you punish people for the act of learning, which is pedagogically incoherent. Here's where Gagné's hierarchical task analysis gets genuinely useful. "Don't click phishing emails" is not an atomic skill. It's a higher-order rule that sits atop a stack of prerequisites. If you wanted to build the actual learning hierarchy, it might look something like: - At the bottom: discriminations: telling a legitimate sender domain from a spoofed one, recognizing when a URL preview doesn't match its anchor text, noticing when an email's visual branding is slightly off. - Above that: concrete concepts: "this is a spoofed domain," "this is a display-name mismatch," "this is a suspicious attachment type." - Above that: defined concepts: "this is a pretext," "this is social engineering," "this is credential harvesting," "this is business email compromise." - Above that: rules: "if a request creates urgency AND bypasses normal process, verify through a second channel"; "if an email asks for credentials, never enter them via the link." - At the top: higher-order rules / problem-solving: novel situations where the specific pattern hasn't been seen before but the learner synthesizes from prior rules to recognize something is off. The current phishing simulation model is flat. It tests only the top of this hierarchy, “did you apply the higher-order rule correctly under time pressure?” without having taught or assessed any of the prerequisites. That's like giving someone a calculus exam to find out whether they know algebra. A click isn't one data point; it's a failure somewhere in a stack, and the current model can't tell you where. A further example is, let’s say a finance employee who clicks an invoice-fraud lure might have failed at the discrimination level (didn't notice the domain), the concept level (doesn't know what invoice fraud is), or the rule level (knows the pattern but didn't follow procedure under pressure). These are three completely different training needs, and the flat model treats them identically. In order to change the effectiveness of phishing simulations in your organization, you must start by fundamentally changing how they’re executed. ### A two-tier model for phishing simulations To start, we recommend building phishing campaigns in two tiers: Learning simulations. Low-stakes. Possibly pre-announced. Designed to teach specific patterns: invoice fraud for finance, CEO impersonation for execs, credential harvesting for everyone. The goal isn't to catch anyone. It's to build pattern recognition. A click here is a data point saying "this pattern needs more exposure," not a mark on a record. Testing simulations. Higher stakes in the sense that they measure readiness, but still not punitive. These assess whether the learning is stuck at the department or organizational level, not the individual level (this echoes the "test teams, not individuals" principle). Results inform training investment, not HR files. To build any of these simulations, you need a lot of information. The goal being that executing one phase of simulations can lead to an additional phase of simulations. Data from one interpreting data from the next. With this in mind, security teams need to produce: - More simulation templates and landing pages - Customized phishing scenarios for each type of persona - Understanding of the latest phishing attempts across the industry - Easy ways to track all of the data that comes from clicking, reporting, and even opening ### Building an entire phishing program in 10 minutes with Herd I know what you might be thinking. "Great. So now, in order to get phishing simulations to be valuable, I have to put a ton of extra work into building hierarchies, varying severity, tracking report-rate, designing learning paths vs. testing paths, and rethinking the whole program from scratch." Fair concern. Because honestly, that is what the research points to. A humane, tiered, non-punitive program isn't just an attitude shift. It's a design shift, and design shifts cost time most security teams don't have. This is where the honest truth about tooling comes in. Existing phishing simulation platforms were built for the flat mode. One-size-fits-all campaigns. Generic templates. A single click-rate dashboard. A handful of role-based variations, if you're lucky. They make it easy to run the program we've been arguing against and hard to run anything else. This is the exact gap we built Herd to close. Not by slapping AI on top of the old model, but by making the tiered, learning-first, report-rate-focused model approach with no extra overhead. You bring in your organizational and industry context, and Herd helps you generate phishing simulations and landing pages across varying severity levels, different interaction types, and different learning objectives. What that looks like in practice: teams are building 10 phishing templates in 20 minutes. They're running tiered campaigns without expanding headcount. They're tracking report-rate and interaction depth alongside click-rate, so the program actually reflects security behavior instead of punishing the one behavior that's easiest to measure. Everything we just talked about, the reporting culture, the learning-vs-testing hierarchy, the move away from "click it or ticket", none of it has to be a massive lift. That's the whole point. You shouldn't need to choose between a humane program and a realistic workload. You can see it for yourself with a free trial. ### Stop the click! A click isn't a failure. It's a signal. A learning moment. A data point showing where training hasn't stuck or where an attack pattern is genuinely convincing. Failure only enters the picture when an organization chooses to treat it as failure, and that choice isn't just cruel, it's counterproductive. The only way to truly fail a phishing simulation is to build a culture that punishes people for taking one. --- ## Designing Training Videos For Maximum Retention Source: https://www.herdsecurity.io/blog/designing-training-videos-for-maximum-retention Author: Samantha DeGoey Published: April 14, 2026 Updated: August 17, 2026 Topics: Best Practices Most training videos don't fail because the content is bad. They fail because of how they're delivered. Too long, dropped in the middle of a module with no context, and no interaction to make the learner do anything with what they just watched. This guide covers a better approach: how to use video inside Herd in a way that's fast to build, easy to complete, and actually worth watching. ## Should your video be a step or its own training? Before you build anything, you need to make one decision. If your video is 15 seconds or less, it can live as a single step inside a larger training module. If it runs longer than 15 seconds, it should stand alone as its own training, with its own title, description, and follow-up question. This isn't an arbitrary cutoff. Short videos embedded in a step are like quick demonstrations: they make a single point and hand the learner back to the module. Longer videos carry enough weight that they deserve their own space. Trying to cram a longer video into a step creates a pacing problem the learner feels like they just watched a short film in the middle of a conversation. And if you find yourself thinking "I'll just squeeze two concepts into one video," that's a sign to split them. Two separate 10-second clips that each make one clear point will outperform a 25-second clip that makes two blurry ones. ## Sketch the sequence before you build Once you know you're building a video step, sketch the surrounding structure before you open the editor. The pattern is simple: A context step that tells the learner what this is about and why it matters A video step (ideally step 2 or 3 in the module) A reinforcement step with a quick interaction a button choice, quiz, or scenario Place the video within the first three steps. This is intentional. Early in a module, learners are attentive and curious. Deeper in, they've accumulated cognitive load from earlier steps. Put the video where it can land cleanly, before attention starts to drift. The pre-video step should be simple: one sentence of context and a clear call to action, like a button that says "Start the video." That's it. No paragraphs summarizing what the video will cover that's what the video is for. ## What goes in a video step? When you build the video step, keep it minimal. A strong video step has four elements: - A short title that names what the video shows ("Watch: Spotting a fake login page") - One line of instruction that tells the learner what to do ("Watch this short video, then choose what you'd do next") - The video asset - Buttons for the next action Everything else is noise. Don't write a paragraph explaining what the video is about. Don't give multi-step instructions that mix watching with reading and scrolling. The learner has one job: watch the video and then do something with it. Make that obvious. ## Always add buttons This is where a lot of trainings quietly break down. If you leave the video step without buttons, the platform will auto-progress to the next step when the video ends. That sounds fine until you think about what it actually means: the learner can't pause, can't rewatch, and doesn't make any choice. They're just carried forward. You lose the interaction point entirely. Buttons solve this, and they do more than just move the learner forward. You can use them to: - Confirm completion: "Got it, next." — simple, but keeps the learner active - Capture a decision: "This looks safe" / "This looks suspicious" — turns passive watching into a judgment call - Branch the experience: different buttons can lead to different follow-up steps, letting you tailor feedback to what the learner chose Even a single "Continue" button is better than no button. It gives the learner control, which keeps them more engaged and gives you a measurable interaction point. ## After the video, reinforce immediately The step after the video should do one thing: help the learner apply what they just saw. One question. One scenario. Not a full quiz, not a new concept just something that prompts them to process the video rather than move past it. This is where the real learning happens. Watching something activates recognition. Doing something with it builds retention. The reinforcement step doesn't need to be complex — "What would you do if you saw this in your inbox?" with two or three button choices is enough. ## How long should a training module be? Throughout all of this, aim to keep your total module to 8–10 steps. That's the range where most learners can complete a training in a focused sitting without feeling like they're being paced through a novel. If you find yourself going over that limit, look first at whether any of your steps are doing double duty. A step that tries to explain something and ask a question about it and introduce the next topic is really three steps. Break them apart, or cut the least essential one. The goal is a module that feels purposeful — where every step earns its place, including the video. ## The pattern in practice Here's what it looks like assembled: Step 1 — "Phishing attacks often look legitimate. Here's a short video showing what to watch for." (button: "Start the video") Step 2 — "Watch: Spotting a fake login page" / "Watch this short video, then choose what you'd do next." (video + buttons: "I'd report this" / "I'd ignore it" / "I'd enter my password") Step 3 — "You're about to log into your bank account and the page looks slightly off. What do you do?" (buttons: scenario choices) Three steps. A video that makes one clear point. A decision that puts the learner in the situation. That's the whole structure. ## Join the Herd Video steps work when they're short, placed early, and paired with something that requires a response. Without those elements, a video is just something to sit through. With them, it becomes a focused moment that moves the learner from watching to thinking to doing, which is the whole point. Herd builds those steps from your own policies rather than from a stock library — that is how security awareness training works here. Want to see for yourself? Start a trial with Herd today. --- ## Building Effective Cross-Channel Simulations Source: https://www.herdsecurity.io/blog/building-effective-cross-channel-simulations Author: Samantha DeGoey Published: April 10, 2026 Updated: August 17, 2026 Topics: Best Practices Simulations are most effective when they mirror real‑world threats without blindsiding employees. Too easy, and your team learns very little; too tricky, and you erode trust, spike anxiety, and teach people to fear your security program instead of embracing it. Simulations in Herd should help employees feel prepared, not punished. This guide shares simple practices for designing cross-channel (phishing, smishing, and vishing) simulations that genuinely build resilience while keeping your program credible and fair. ## Foundations for fair but effective simulations These principles apply across every simulation type in Herd and help you keep the right balance. ### 1. Start at the right difficulty level Match difficulty to your organization’s current security maturity. - Beginner: generic sender names, clear urgency cues, mismatched URLs - Intermediate: branded templates, plausible scenarios, subtle red flags - Advanced: highly targeted content, internal impersonation, multi‑step attacks In Herd, you can gradually move from simpler to more sophisticated simulations as your users improve. ### 2. Never use emotionally manipulative content Simulations should test alertness, not exploit personal fears. Avoid scenarios that reference layoffs, health emergencies, family issues, or anything likely to cause genuine distress. Avoid examples such as: - “Your paycheck has been delayed” - creates real financial anxiety - “HR has flagged your conduct” - triggers fear of job loss - “A family member has tried to reach you” - crosses personal boundaries ### 3. Always follow up with education, not blame When an employee falls for a simulation, the next step should be learning, not a public call‑out. In Herd, you can automatically trigger a short training module after a failure so the teachable moment is captured. How to in Herd Link a training module to your simulation so that when an employee fails, they are automatically enrolled in a follow‑up course. Every miss becomes a structured learning opportunity. ### 4. Maintain a consistent, rolling cadence Sporadic, one‑off simulations can feel like “gotcha” moments and increase anxiety. Instead, run simulations on a regular cadence (for example, monthly per employee) so people see them as an ongoing part of your security program rather than rare surprises. At the same time, keep individual messages unpredictable. Stagger send times and vary templates so employees might encounter a simulation while they are busy or distracted -just like a real attack. Clearly communicate that simulations are a standing, learning‑focused control, not a punishment tool. This framing helps reduce stress while still teaching employees that suspicious messages can appear at any time and should always be treated with care. ## Phishing simulations Phishing remains the most common attack vector, and effective simulations train employees to pause and review emails before acting, even when they appear legitimate. The problem hasn’t been the quantity of options, but being able to keep up to date on what real attackers are sending. ### What makes a phishing simulation effective? Choose realistic but recognizable scenarios Use scenarios employees are likely to encounter, such as shared document notifications, IT password resets, or benefits enrollment reminders. Red flags should be present but not obvious. - Use sender names that look almost correct (for example, support@company‑helpdesk.com vs. support@company.com) - Include a plausible call‑to‑action (review a document, sign in to verify, confirm details) - Avoid relying on obvious typos or broken formatting at beginner levels—real attacks increasingly look polished Build in detectable red flags Each simulation should include at least one clear signal that something is off. The goal is to train employees to look for signals, not to trick them indefinitely. - Mismatched reply‑to and sender addresses - URLs that do not match the claimed domain - Unusual urgency or pressure to act within minutes - Requests for credentials or sensitive information via email Vary your templates over time Reusing the same template only trains people to spot that simulation. Rotate scenarios across IT alerts, HR communications, or vendor invoices to keep coverage broad and realistic. Track these stats within the dashboard or within the campaign that you sent out. You can also ask Herd AI for the statistics on specific campaigns. How to in Herd Browse Herd’s simulation template library and rotate between categories each quarter. You can automate this by creating a phishing campaign containing multiple templates. What to track - Click rate: percentage of recipients who clicked the simulated link - Report rate: percentage who reported the message as suspicious - Dwell time: time between delivery and click (longer often indicates more caution) - Repeat offenders: employees who fail multiple simulations and may need targeted support ## SMS phishing (smishing) simulations Smishing (SMS phishing) is growing quickly, and employees are often less guarded on their phones than on email, which makes smishing simulations a valuable but often underused control. ### What makes a smishing simulation effective? - Mirror common SMS scams: Effective simulations mirror real attack patterns such as package delivery failures, bank alerts, two‑factor prompts, or IT helpdesk texts. - Keep messages concise - real smishing are short and direct. - Make sure to include a link the employee is asked to tap or visit, and use a plausible sender name or short cod - Account for the mobile context - On mobile, employees cannot hover over links to preview URLs. Design smishing simulations that teach mobile‑specific detection skills, such as recognizing shortened links, unfamiliar numbers, and unexpected requests. Fairness considerations Because smishing is newer to many employees than email phishing, start with clear red flags (ie. unfamiliar sender numbers, misspelled brand names) before progressing to more subtle, sophisticated scenarios. How to in Herd Create a smishing simulation by choosing SMS as the delivery channel, then customize the message and link destination. What to track - Link click rate: the SMS equivalent of click rate - Report rate: percentage of employees who reported the suspicious text - Completion rate for follow‑up training after a failure ## Voice phishing (vishing) simulations Vishing (voice phishing) simulates phone‑based social engineering, where attackers pose as IT support, executives, vendors, or auditors to obtain sensitive information or access. ### What makes a vishing simulation effective? User clear, realistic pretexts and scripts - Because vishing is interactive, you need a realistic script that reflects common attack patterns (ie. IT asking for credentials to “fix an issue,” an executive assistant requesting urgent wire transfer approval, or a vendor seeking account access.) - Keep the script natural and conversational - Use realistic pressure tactics: urgency, authority, a “helpful” tone - Define clear boundaries for what the simulated caller will and will not ask for Make it convincing but not impossible - The most effective vishing simulations are believable yet still offer cues for a vigilant employee to catch. - Caller asks for full credentials instead of simple identity confirmation - Scenario attempts to bypass normal processes (“we need to do this before the ticket system comes back online”) - Caller discourages verification through another channel Always debrief participants - Because vishing involves real‑time interaction, it carries more emotional weight than a link click. Whether an employee passes or fails, follow up with a clear explanation of what happened and what to watch for next time. - Brief managers before running vishing simulations so they can support their teams - After the campaign, send a company‑wide reminder that it is always acceptable to hang up and verify via a known number - Avoid blame or shame - vishing exploits trust and helpfulness, not incompetence Fairness considerations Vishing is typically harder than email or SMS simulations because it uses live conversation and social pressure. - Expect higher failure rates and frame success around improved awareness and reporting, not perfection. - Start with simpler, clearly suspicious scenarios before moving to more subtle pretexts. - Avoid scenarios that create fear about job loss, discipline, or personal crises. - Make your rules of engagement explicit (what callers will never ask for, whether calls are recorded, how results are used) so employees understand the boundaries What to track - Compliance rate: percentage of employees who provided the requested information - Hang‑up and verify rate: employees who ended the call and confirmed via a trusted channel - Escalation/report rate: employees who reported the call to IT or security ### Putting it all together The strongest programs treat simulations as structured practice, not pop quizzes. When you pick realistic scenarios, avoid cheap emotional hooks, and clearly explain what you were testing, people understand that the goal is to help them handle real threats, not to call them out. In Herd, you can run coordinated phishing, smishing, and eventually vishing into your program, automatically trigger follow-up training, and use your results over time such as clicks, reports, escalations, to tune difficulty rather than to shame individuals. That steady calibration is what builds long‑term trust in your security team and real confidence in spotting attacks. Try it for yourself with a free trial today. --- ## How To Build Better Training Engagement with Herd Source: https://www.herdsecurity.io/blog/how-to-build-better-training-engagement-with-herd Author: Samantha DeGoey Published: April 9, 2026 Updated: August 17, 2026 Topics: Best Practices, Training > This guide runs through practical steps to raise engagement in on-going security trainings. The Problem: Many users aren’t used to ongoing security training. Their first thoughts of doing a training daily, weekly, or monthly are probably negative. How to: This is how you can change that narrative while maintaining a high level of risk awareness and full security training compliance. ## Why does microlearning improve training engagement? Microlearning improves knowledge retention by 20% and drives roughly 50% more engagement right off the bat. In other words, by simply shifting to any microtraining format, you have already given yourself a 70% chance at a better security training program. How To Do this: - Break topics down into 30 second to 1 minute trainings - Use multiple training types: video, audio, conversational ai, etc. - Make it accessible in multiple tools Touching on that last bullet, traditional learning management systems (LMS) can only be accessed in one place. Limiting the capacity to be used on a normal basis. By extending reach into Slack/Teams, web logins, mobile, etc. You give employees the opportunity to learn the way they want, when they want. The Best Way To Start In Herd: - Go to Herd AI and prompt a topic into a training. > “Build me a training about safely using a chatbot LLM” - A micro-lesson will populate in seconds. - Send it to your users. ## How do you tailor security training to each role? > People lean in when training clearly connects to the decisions they make every day. Start by segmenting your users into a few high-impact groups based on risk and behavior (who clicks, who reports, who has sensitive access), not just job title. In Herd, this can be done by creating Herd groups based on existing user attributes (department, role, etc) or by importing groups from your identity provider (Okta, Azure AD, Google Workspace). Then decide what each group actually sees and does. For each group, answer: “What kinds of attacks are most likely to hit them, and what mistakes would hurt us the most?” For example: - Finance users might see more invoice fraud, vendor impersonation, and payment redirect scenarios - Engineers/IT might see more access abuse, OAuth consent, and technical phishing - Executives might see spear-phishing, urgent requests, and data handling From there, build targeted tracks instead of assigning one universal program: - For Finance: create modules and simulations that use invoice, vendor, and payment language. - For Engineering/IT: use examples that reference their tools (GitHub, cloud consoles, admin panels) and technical access. - For Executives: write shorter, story‑driven examples that mimic real “from the CEO” or “from Legal/Finance” requests. Lastly, assign and iterate - Assign each role the track built for them. - After a month or a quarter, look at which simulations they failed or reported, then swap in new content that targets the gaps you see. Here’s a Herd Example: You see in your phishing report that the Finance group is mostly clicking on invoice-themed phishing emails from “vendors”. Here’s how to respond: Create a training module on invoice fraud or vendor payment scams with Herd AI by specifically asking it to pull from a sample or a simulation that you’ve run. > Build a training for the finance team that corresponds to the information that we’ve seen about them clicking on fake invoice links. Start the training with a message about it’s relevance. For example: “We’ve recently seen several fake invoice emails targeting Finance. This quick training will walk you through how to spot scams and fake payment requests”. This creates a tight feedback loop: Phishing simulation → Results → Finance-specific training that uses the same kind of fake invoice language and screenshot → improved behavior on the next round. ## Why does immediate feedback improve training completion? Motivation is based off of the dopamine response, triggering a reward or learning experience in the brain. We recommend setting up immediate feedback, whether positive or constructive. Some examples: - A user completes a training, it gets announced in a team channel. - They add points to a leaderboard in Slack. - They successfully reported a phishing simulation, they get a message in Teams. Completion and behavior change both improve when users can see how they’re doing and feel good about progress. Easy steps in Herd: - Use multiple choice questions within trainings. These dynamically share whether questions are correct or incorrect. - Use leaderboards within Slack, they can be displayed via Slack Canvas for teams. ## Conclusion These frameworks are the start of building secure behavior across an organization, while maintaining the compliance needed to pass security audits. Learn more by signing up for a free trial account. --- ## How To Automatically Get 100% Training Completion Rate For Compliance Source: https://www.herdsecurity.io/blog/how-to-automatically-get-100-completion-rate Author: Samantha DeGoey Published: April 6, 2026 Updated: August 17, 2026 Topics: Best Practices, Compliance When you're staring down an audit deadline or new regulatory requirement, you need high completion rates fast. This guide shows you how to hit 100% completion quickly without burning out your team or chasing stragglers manually. In order to get the full effect, let’s set this up as an example. You recently join a company and realize your audit is in less than 30 days. You have a laundry list of items to get to, but mainly you need to get every employee through training as quickly as possible. Note that in this situation, you’d be thinking less about training efficacy (retention) and more about completion. Assuming this, let’s dig in. ## How should you announce a training deadline? Set the deadline 30 days out and get the message out for visibility as quickly as possible. You don’t want people to see a training for the very first time and not understand the importance. Announce the deadline clearly in the kickoff message so there’s no ambiguity. If possible, have leadership reinforce it to show it’s required, not optional. > Required training is due in 30 days, you’ll be receiving trainings through Slack/Teams that last 2 minutes each. The keys to this opening message are: - Get to the point and stress urgency - Let everyone know they can complete trainings in Slack/Teams (including mobile) - Get leaderships backing With this, you’re off to the races. Now, it’s about setting up a program with minimal fuss. ## How long should each training lesson be? When it comes to completion rates, the shorter the training, the better. Aim for about two minutes per lesson, short enough that nobody needs to set aside time for it. The goal is to be straight to the point and get people to have as little friction as possible. The first key decision you’ll make is whether you want to create these trainings manually, generate lessons with AI, or use trainings from Herd’s preexisting catalog. Some of which are already mapped to existing compliance frameworks. If you’re looking for the shortest time, we suggest using Herd’s preexisting trainings. However, Herd provides the ability to create a set of trainings, across multiple subjects in less than 30 minutes. (Yes, I’m serious). Once you have the trainings you want to use, you can place them into a “Track” which is a series of trainings in a row. - Create the track - Set a cadence (how often people get the trainings) - Setup reminders - we’ll talk about this in the next section ## What reminder cadence drives training completion? The single biggest driver of fast completion is a well-timed reminder cadence that escalates as the deadline approaches. In Herd, you can setup reminders to go through Slack/Teams that automatically run on a cadence. Use consistent, automated reminders to help drive completion. Start with a heads-up before launching so employees know what’s coming, how long it will take, and when it’s due. Then send a kickoff message when the training goes live with a clear deadline. From there, follow up regularly: as the deadline approaches. Increase urgency closer to the due date, and make sure employees know how long it takes (~2 minutes) so they don’t delay Here’s how it could look: - Week 0: (pre-launch): - Hey team a quick heads up: our Annual Security Compliance training will go live next week in Herd. It takes about 2 minutes total and will be due on [DATE]. You’ll get a link directly in email/Slack/Teams when it’s ready. - Week 1 (launch): Friendly kickoff message with clear deadline and time estimate. - Week 2 (midpoint): Automated nudges depending on what was scheduled. - A few days before deadline: Increase urgency with automated message to anyone still incomplete: "3 days left - takes 2 minutes, due Friday." - Deadline day: Automated message Training Due Today [Training Name]. - Post-deadline: - After the deadline: Notify overdue users and loop in managers for follow-up “Overdue Training: [Track/Training] was due on [DATE]. This training is now overdue.” In Herd: Set up automated reminder schedules in your campaign settings and enable manager escalation for anyone still incomplete 1-2 days past the deadline. ## How do managers help drive training completion? Managers are your secret weapon for fast completion. - Send manager targeted lists: Share which of their direct reports haven’t completed training so they know exactly who to follow up with. - Make it easy to act: Include direct links or instructions so managers can tap someone on the shoulder in Slack or a 1:1. - Set the expectation: Make it clear to managers that 100% completion on their team is expected, and compliance leadership is tracking by department. Example manager slack/teams (2 days before deadline): "Hi [Manager], your team is at 85% completion for the Q1 Security Compliance training (due Friday). The following 3 people still need to complete it: [Names]. Can you check in with them today? Training takes ~20 minutes. Thanks for helping us hit 100%." ## Do incentives improve training completion rates? Compliance can feel like a chore. A little friendly competition or recognition makes people move faster. - Celebrate users who completed their trainings early: Post a Slack message or send an email highlighting teams or departments that hit 100% completion first. - Gamify if possible: Use Herd's leaderboards to create friendly competition between departments or offices. - Avoid public shaming: Never call out individuals who haven’t completed their training publicly. Instead, have managers follow up privately and frame it as support, not punishment. Example Slack post (mid-campaign): "Shoutout to the Finance and Engineering teams. They both are at 100% completion for Q1 Security Compliance with 5 days to remaining! 🎉 Who's next?” ## Final thoughts You don’t need a massive campaign to hit your compliance goals quickly. When deadlines, reminders, manager follow‑up, and positive incentives all work together, 100% completion becomes predictable instead of painful. By focusing on short trainings, smart automation, and clear ownership, you can turn Herd into a low‑effort engine for fast, reliable completion without chasing the last 10% all day. Get started today with a free trial. --- ## Herd Security Partners With Okta To Transform How Security Teams Protect Their Employees Source: https://www.herdsecurity.io/blog/herd-security-partners-with-okta-to-transform-how-security-teams-protect-their-employees Author: Brandon Min Published: October 21, 2025 Updated: August 17, 2026 Topics: Integrations # Herd Security Partners With Okta To Transform How Security Teams Protect Their Employees ## TL;DR Herd has built direct integrations with Okta to expand identity access management into a complete human risk protection solution. Okta locks the doors, Herd trains the people inside. Together, they turn everyday security IAM data into instant learning moments, building a workforce that defends itself. With 90% of Herd customers already using Okta, it was natural to align our platform to enhance existing identity data and leverage it for educational engagement. Okta customers can instantly onboard Herd to expand identity protection into contextualized content for remediation, training, and risk reduction. This blog will show how Herd & Okta make security simple and engaging for employees by combining pre-existing IAM policies and extending that reach to human security controls. ## Okta is more than identity access management At its core, Okta is the leading identity access management (IAM) platform in the world. With over 6,000 employees across 5 continents, Okta has become the fortified leader in the space since it’s IPO in 2017. From IAM, they’ve expanded to cover almost the entire user access stake, including Single Sign On (SSO), Multi-Factor Authentication (MFA), lifecycle management, and newer AI-based controls. By anchoring security in identity, Okta has naturally become a core piece of any organization’s cyber defense. With its coverage across the organization, Okta naturally begins to analyze human interactions with applications across the entire enterprise. With wide visibility, it was natural for Herd to build our initial inference models around telemetry provided by Okta. ## What is Herd Security? The philosophy of Herd Security is simple: help organizations protect their herd — their people — by making cybersecurity more accessible to everyone. To do this, Herd wanted to leverage the people who know security best: the internal security team. After all, who knows an organization better than its own security professionals? The problem we identified is that enterprises don't prioritize how employees interact with cybersecurity tools. This creates a cascade of issues — adoption of technical tools becomes difficult, the security team gets cast as the bad guys, and security culture becomes an afterthought. Herd is transforming this narrative by building the first AI creative platform designed specifically for security teams. It's now easier than ever to build communications, training, AI agents, and other tooling that optimizes how employees engage with security tools and knowledge. However, this only works if organizations stop treating security as a compliance checkbox and start treating it as a culture. ## Going beyond the compliance checkbox 85% of employees report that the only time they hear about cybersecurity internally is during their annual security training, better known as security awareness training. Although this is training in the name of cybersecurity, it really should be viewed closer to compliance training. Long human resources style videos that people barely pay attention to. Even when forcing attendance, trying to gamify it, nothing seems to work. This is how security training has been done for the last two decades. But the unforeseen consequence is organizations have unintentionally labeled cybersecurity as something that’s of the same importance as HR. Essentially the police of the organization, that suck the fun out of everything. Think Toby Flenderson from Dunder Mifflin. Ultimately, this perception is what prevents many security teams from securing their organization. Human error accounts for 80% of vulnerabilities, however, we believe that much of that is due to a lack of proper cybersecurity hygiene. Which in practice, care, and visibility, can be a lot more effective with a different approach. ## The Herd approach Herd was built to make cybersecurity more accessible for every employee. In order to do this, we knew two things needed to happen: - Content needed to be easier to create. - Security needed to be seen more often than annual security training. To address content, we centered our focus on how content could be generated quickly, but with context of the organization. How do we understand policies, language, branding, industry, and other information without a huge lift by the current team? This is where integrations, like Okta, became key to our success. In order to make content that’s right for each organization, we need to understand it first. Okta helps us take the first steps to that by understanding how users interact with their SaaS applications. With this information, we take our first steps into building workforce engagement, which is driven through modernizing older forms of security training, simulations, and tabletop exercises with generative AI. ## How does Herd use Okta data? Okta already provides a tremendous amount of security information. Why hasn’t anyone leveraged built-in Okta detections, data, and logs to create contextual training? That’s where Herd comes in. By connecting directly with Okta, we bring real-time training and awareness into the human layer of security. Here are some powerful examples: - Live response to Okta alerts - If Okta detects a brute-force login attempt, Herd immediately prompts the targeted user with a short training on strong passwords and account safety — right in the moment they need it. - Behavior-driven remediation - If an employee disables MFA, Herd automatically delivers a curated module via Slack. The user learns why MFA matters and how to fix their mistake instantly. - From incident to education in minutes - If one employee reports a phishing email, Herd amplifies that exact attack into a training simulation for the entire organization. Everyone learns from a real-world event, not a hypothetical scenario. By pairing Okta’s identity protection with Herd’s behavioral reinforcement, organizations finally get end-to-end defense for the human layer. ## Real-world impact: from threat to training in minutes The power of Herd isn’t theoretical. Our customers are already seeing transformational results. One Unicorn defense startup discovered an engineering vulnerability in a GitHub pull request. Remediating the issue and then creating a training module may take weeks. With Herd, the security team was able to: - Identify and block the vulnerability, - Convert it into a tailored training for engineers, and - Distribute it across the team within 5 minutes. The results spoke for themselves: 90% of engineers completed the training within 24 hours, reinforcing secure coding habits at the exact moment it mattered most. That’s the difference between compliance and culture. ## Try Herd with Okta today Cybersecurity is no longer just the job of the security team; it’s the responsibility of the entire organization. Herd exists to make that shift possible, turning static compliance training into dynamic, engaging, and adaptive learning. Okta secures your identity layer. Herd secures your human layer. Together, they deliver the strongest defense organizations can have. Okta is one of many: Herd also reads from Slack, Teams, Entra ID, your SIEM and your HRIS. See every integration. 👉 If you’re already an Okta customer, you can try Herd today and see the benefits instantly. --- ## Why I Joined The Herd (Security) Source: https://www.herdsecurity.io/blog/why-i-joined-the-herd-security Author: Grant Joy Published: February 3, 2025 Updated: August 17, 2026 Topics: Herd Story I have spent a lot of time thinking about the moment I understood what I had built. Not during the build. During the build, it was just a problem to solve, a model to train, a metric to optimize. The reckoning came later, quietly, the way these things usually do. I have worked at the intersection of technology and human behavior for most of my career, and the through-line I keep returning to is this: the most powerful systems are not the ones that process the most data or run the fastest inference. They are the ones who understand people. That cut both ways then. It cuts both ways now. What follows is an honest account of what that has looked like, and what we are building because of it. ## Where it all started In 2012, I helped build a neural network used by payday lending companies. The goal was straightforward and deeply predatory: figure out the exact amount of money to loan someone so they could almost pay it back, but not quite. Just enough to trap them in a cycle of endless debt, paying back thousands of percent on a few hundred dollars. That was over a decade ago. The world of AI has changed dramatically since then, but the lesson has never left me: machine learning can be used to hurt people. ## The double-edged sword of AI AI understands aspects of human behavior better than people do. The same capability that lets a neural network trap someone in debt can also be used to protect people. It can recognize manipulation, intervene before a bad decision is finalized, or build habits that make people harder to exploit. That is the fundamental thesis behind Herd. We believe that just as AI can learn to exploit human psychology, it can also learn to strengthen it. The pathway is natural language: the mediums people use to communicate are the same ones bad actors use for manipulation, and the same ones through which people learn most effectively. We believe the best way to help people is to meet them where they are. That is where they are actually vulnerable. Real language, real context, real engagement. ## Why is phishing harder to spot in 2026? Modern language models have made the situation orders of magnitude more dangerous than anything we saw in 2012, even though the parallel to my experience building payday loan machine learning models still holds. It is worth remembering that just a few years ago, standard security awareness training encouraged employees to spot phishing emails by looking for typos. In 2026, that advice is essentially useless. Bad actors now have access to the same AI tools as everyone else, but without the compliance departments, ethics reviews, or procurement cycles that slow legitimate organizations down. Someone with a language model and bad intentions can generate thousands of unique, psychologically targeted messages in an afternoon. This is the reality of 2026. Bad actors have the same technology and none of the friction. The gap between what is possible with AI and what most people are prepared for is growing every day. ## Why did AI chatbots change how people learn? There is a reason ChatGPT became the fastest-adopted technology in history. It was not just the capability. It was the experience. It feels human. It feels like magic. It feels limitless. People do not need to learn a new interface or translate their thoughts into search keywords. They simply communicate, and the machine responds. This is not a gimmick. It is a fundamental shift in how humans interact with technology, and it is just the beginning. Instead of passive content consumption, users get active engagement. Instead of one-size-fits-all information, they get something that adapts to the individual in front of it. ## Why does chat-based security training work? Text-based communication should not be underestimated. There is a reason Slack achieved such rapid, widespread adoption. Text is the ideal mechanism for collaboration: ambiguity is reduced because everything is recorded, and threaded conversations allow people to stay on topic in ways that spoken communication often cannot. Building tools that properly leverage modern communication platforms and natural language AI is still in its early stages, and the potential is far greater than most people recognize. One way to think about it: this is an opportunity for AI to actively accelerate human development. We have a chance to let AI understand what it takes to teach people effectively, to observe and refine the patterns that lead to real learning, both individually and collectively. If the first era of AI was defined by machines learning from humans, the next phase may be defined by machines learning how humans learn. For us at Herd, this idea is foundational. As Marshall McLuhan observed, the medium is the message. Information is only as powerful as the medium carrying it allows. ## Where Herd comes in Herd exists because we have seen both sides. We know what happens when you point AI at human psychology with bad intentions. We have also seen how powerful AI tools can be when used to help people master skills and reinforce positive behaviors. Our mission is to make good decisions easier, in the language people already speak, at the moment it actually matters. The machine knows you better than you know yourself. The question is who is holding the controls. ## Join the Herd Herd is built to empower security teams to become creators. It is the fastest, easiest way to deliver security awareness content in multiple formats that genuinely engage employees. See it for yourself. More on why we started Herd and the people behind it — and if this is the problem you want to work on, we are hiring. # Customer stories ## Onebrief turns threats into training in minutes with Herd Source: https://www.herdsecurity.io/case-studies/onebrief-turns-emerging-threats-into-company-wide-training-in-minutes-with-herd Customer: Onebrief See how Onebrief's lean GRC team used Herd to turn a live security threat into company-wide training in about 10 minutes, no manual training builds required. --- ## Outfox Health gets SOC 2-ready in a week with Herd Source: https://www.herdsecurity.io/case-studies/outfox-health-gets-soc2-ready-in-a-week-with-herd Customer: Outfox Health See how Outfox Health hit 100% SOC 2 training completion in 1 week with Herd Security, saving 20+ hours of admin time.