KC Phishing — Security Awareness Training · KnowledgeCity Skip to content
KnowledgeCity

SolutionsComplyKC Phishing

Test your team with realistic phishing simulations.

KC Phishing runs scheduled simulations across email and chat, then turns every risky click into a lesson — no manual follow-up.

An IT security lead reviewing threat activity on a laptop in a calm modern office
Why KC Phishing

Every click becomes a lesson.

The click that trains itself.

IT security analyst leaning toward a monitor reviewing simulation results in a modern security operations room, a teammate softly blurred at a second workstation behind
  • Every simulated click auto-assigns a short, relevant lesson in seconds
  • Repeat clickers roll straight into refresher paths — no manual chasing
  • Completion lands in the same record as the simulation, ready for audit

Know your human risk by name.

A CISO and a security manager comparing risk trends on a laptop in a glass-walled meeting room, city skyline through the window, focused expressions
  • Click and report rates broken down by team, department, and role
  • Per-employee risk scores from every simulation and lesson taken
  • Spot the departments trending the wrong way before an attacker does

Turn every employee into a sensor.

Office employee at a standing desk pausing to flag a suspicious email on their laptop, bright open-plan workspace softly blurred behind
  • A one-click Report Phishing button in Outlook, Gmail, Slack, and Teams
  • Real reports route straight to the security queue for triage
  • Reporters get instant positive feedback, so the habit sticks
Features

Everything in KC Phishing.

Simulated Phishing Campaigns

Realistic, scheduled simulations across email and messaging.

Security-Awareness Microlearning

Short lessons triggered the moment someone clicks a simulation.

Reporting & Risk Visibility

Click and report rates by team, department, and role.

Template Library

Pre-built lures spanning common attack themes.

One-Click Reporting

A Report Phishing button routed straight to the security queue.

Risk Scoring

Per-employee risk scores from simulation and training history.

Automated Enrollment

Repeat clickers auto-assigned refresher training.

Security & Integrations

SSO, SCIM, plus Slack, Teams, and your LMS.

Everything your workforce needs, on one platform.

A quick walkthrough tailored to your team — learning, compliance, skills, and performance on one login.

What to expect in your demo:

Your goals & challenges

A focused conversation about your team’s goals and where training falls short today.

See it in action

A live demo of the course library, LMS, compliance, skills, and performance tools.

Pricing for your team

Straightforward pricing based on your team size and the solutions you choose.

Answers & next steps

Integrations, rollout, support — ask anything and leave with a clear plan.

Request your demo

Tell us about your goals and we’ll tailor the walkthrough to your team.

By requesting a demo, you agree to our Privacy Policy.

FAQ

Frequently asked questions

What's the best phishing simulation software that automatically trains employees who click?
KC Phishing runs realistic, scheduled simulations across email and messaging, then does what most tools stop short of: the moment an employee clicks, it auto-assigns a short security-awareness lesson tailored to what they fell for. Repeat clickers roll into refresher paths automatically. That training and its completion land in the same record as the simulation, with no separate LMS to wire up and no manual follow-up. You get the full loop from click to remediation to audit evidence in one platform.
How do I run security-awareness training that actually reduces click rates?
Reducing click rates takes more than an annual video. KC Phishing pairs ongoing simulated campaigns with microlearning that fires the instant someone clicks, when the lesson lands hardest. It tracks click and report rates by team, department, and role so you see what's working and where to focus. Repeat clickers are automatically enrolled in refreshers, and because results flow through one data model, at-risk employees can be routed to targeted learning paths in KC Skills. Over time you train the specific people attackers target — not everyone, equally, once a year.
Can employees report suspicious emails with one click and route them straight to security?
Yes. KC Phishing adds a one-click Report Phishing button to Outlook, Gmail, Slack, and Teams. Real reports route straight to your security queue for triage, and reporters get instant positive feedback so the habit sticks. Every report and simulation result feeds the same risk model, so the employees who consistently spot threats show up alongside those who keep clicking. That reporting activity also becomes evidence in Comply's audit trail automatically — one platform, so the signal you collect in KC Phishing is usable everywhere without exporting or reconciling data.
How does KC Phishing measure and score human risk across departments?
KC Phishing builds a per-employee risk score from simulation history and training completion — who clicks, who reports, and who's finished their refreshers. Roll it up and you see click and report rates by team, department, and role, so a high-risk group like Finance is obvious before an attacker finds it. Because scores live in one shared data model, they don't stay trapped in a security tool: they surface as security-skill gaps in KC Skills, turning your riskiest teams into targeted learning paths. You measure human risk and act on it in the same platform.
Do phishing simulations integrate with Slack and Microsoft Teams, not just email?
KC Phishing simulates threats across both email and messaging, including Slack and Microsoft Teams, because modern attacks don't stop at the inbox. It supports SSO and SCIM for provisioning and connects to your existing LMS. But the real advantage is that there's nothing to integrate internally: a simulated click can auto-assign training in KC LMS and feed Comply's audit trail on its own. You cover email, chat, and remediation from one platform instead of buying a stack of point tools.
Does security-awareness training completion feed our compliance audit trail automatically?
Yes. Every simulation, lesson, and completion in KC Phishing is recorded against the employee and flows into Comply's audit trail automatically. When an auditor asks who received security-awareness training and when, the evidence is already there, because remediation you trigger from a phishing click doubles as compliance evidence in the same system as KC Docs. KnowledgeCity is SOC 2 compliant, and the platform is built so the training you run and the proof you need never live in separate systems.
How does KC Phishing handle repeat clickers without manual follow-up?
Repeat clickers are the whole reason KC Phishing has automated enrollment. When someone clicks a simulation, they're auto-assigned a relevant lesson; when they click again, they're rolled into a refresher path, with no admin chasing anyone down. Their risk score updates automatically, and the enrollment happens right in KC LMS with completion feeding back into the same record. Your security and L&D teams set the rules once and let the loop run, so attention goes to the handful of people who need it rather than to manual assignment work.
Is KC Phishing SOC 2 compliant, and does it support SSO and SCIM for large organizations?
KnowledgeCity is SOC 2 compliant, and KC Phishing supports SSO and SCIM so large organizations can provision and deprovision employees automatically as the directory changes. It integrates with Slack, Teams, and your LMS, and covers simulations across email and messaging. Beyond those connectors, simulation results, risk scores, and training completions already move to KC LMS and Comply's audit trail on their own, with nothing extra to build. It's enterprise-ready security awareness that fits how your identity stack and compliance program already work.