
Infosec: Cybersecurity Training and Phishing Simulation Software
Infosec provides comprehensive cybersecurity education and awareness training for IT professionals and general workforces to reduce risk and close skill gaps.
Overview
Infosec (formerly Infosec Institute) is a leading provider of cybersecurity education and workforce development solutions. Founded in 1998, the company has spent over two decades specializing in fortifying organizations against cyber threats by focusing on the human element of security. In 2022, Infosec was acquired by Cengage Group, further strengthening its position as a global leader in professional online learning.
The company serves two primary audiences through its core platforms. For the general workforce, Infosec IQ provides security awareness training and phishing simulations designed to change risky behaviors and build a culture of security. For IT and security professionals, Infosec Skills offers an expansive library of technical training, boot camps, and hands-on labs aimed at closing skills gaps and preparing teams for over 100 industry-standard certifications (such as CISSP, CEH, and Security+).
Infosec’s market presence is substantial, serving more than 70% of the Fortune 500 and training millions of learners worldwide. Their target audience ranges from small-to-medium businesses looking for easy-to-manage compliance training to large enterprises and government agencies requiring sophisticated, hands-on technical upskilling. By bridging the gap between basic awareness and advanced technical proficiency, Infosec provides a holistic solution for organizational cyber-resilience. Their business focus remains steadfast on staying ahead of the evolving threat landscape by constantly updating their curriculum to reflect modern attack vectors and regulatory requirements.
Positioning
Infosec positions itself as the "Gold Standard" in cybersecurity education, sitting at the intersection of corporate compliance and professional skill development. While competitors like KnowBe4 focus heavily on the security awareness and phishing market, and platforms like Coursera or Pluralsight offer broad IT training, Infosec occupies a unique niche by offering deep, specialized expertise in both areas exclusively for cybersecurity.
Their brand messaging centers on the "Role-Guided" approach. They do not just provide content; they provide career and risk-mitigation pathways. They position their solutions as a way to "outsmart cybercrime" by making every employee a security asset. This positioning appeals to CISOs and HR leaders who are concerned not just with meeting regulatory requirements, but with the tangible reduction of human-driven security breaches.
In a crowded market, Infosec differentiates its messaging by highlighting its pedagogical heritage. They emphasize that they are educators first and software developers second. This allows them to pivot away from the "feature wars" of SaaS platforms and instead focus on learning outcomes, certification pass rates, and measurable behavioral changes. Their competitive strategy is to be the single-source provider for an organization’s entire cybersecurity learning lifecycle—from the new hire’s first phishing test to the lead architect’s advanced certification.
Differentiation
The Infosec product suite is defined by its depth of content and its dual-platform strategy: Infosec IQ and Infosec Skills.
Infosec IQ focuses on security awareness and phishing simulations. Its primary differentiator is the sheer volume and variety of its content library, which includes over 2,000 resources. It utilizes "Choose Your Own Adventure" style training and localized content in over 30 languages, making it highly effective for global enterprises. The platform’s advanced personalization features allow administrators to automate training based on individual employee risk scores, ensuring that high-risk users receive more frequent or specialized interventions.
Infosec Skills caters to technical professionals and is distinguished by its hands-on learning environment. Unlike platforms that rely solely on video lectures, Infosec Skills includes 190+ pre-configured cloud labs that allow learners to practice hacking, defense, and forensics in a safe, sandboxed environment. The platform is mapped directly to the NICE Cybersecurity Workforce Framework, helping organizations align their team’s development with industry standards.
Furthermore, Infosec’s integration capabilities are a significant technical advantage. The platforms sync seamlessly with leading HRIS, LMS, and endpoint security tools, allowing for automated user provisioning and the ability to trigger training based on real-world security events (e.g., an employee clicking a real malicious link). This creates a "just-in-time" learning model that is far more effective than annual compliance training.
Ideal Customer Profile
The ideal Infosec customer typically falls into one of these categories:
- Mid-Market to Enterprise (500 - 50,000+ employees): Organizations large enough to face significant phishing risks and those needing automated, scalable training solutions.
- Regulated Industries: Finance, Healthcare, Government, and Energy sectors that require meticulous record-keeping for compliance audits.
- Technically Mature IT Teams: Organizations that value deep-dive technical training (Infosec Skills) alongside general awareness to foster a 'security-first' culture across both technical and non-technical staff.
- Global Footprint: Companies with a diverse, multi-lingual workforce that require high-quality, localized content that resonates across different cultures.
Best Fit
Infosec excels in the following scenarios:
- Compliance-Driven Organizations: When a company must meet specific regulatory hurdles (like SOC2, HIPAA, or PCI-DSS) that require documented proof of security awareness training for all employees.
- Upskilling Technical Teams: Unlike basic awareness platforms, Infosec is a premier choice for organizations that need to train SOC analysts, penetration testers, and developers through hands-on labs (Infosec Skills).
- Phishing Defense Readiness: It is ideal for firms looking to move beyond simple 'click-rate' metrics to a behavioral change model using sophisticated, automated phishing simulations and localized content.
- Consolidated Training Needs: Best for companies that want a single vendor to handle both general employee awareness and deep-dive technical certifications (CISSP, CISM, etc.) for their IT staff.
Offerings
Infosec divides its offerings into three primary pillars:
- Infosec IQ: The flagship Security Awareness and Training (SA&T) platform. It includes the PhishSim simulation tool, Content Library (2,000+ assets), and the AwareEd learning management system.
- Infosec Skills: A workforce development platform featuring 1,200+ courses, custom learning paths, and cloud-hosted labs for technical roles like Cloud Architect, Pentester, and Incident Responder.
- Infosec Boot Camps: Live, instructor-led training (online or in-person) focused on high-stakes certification prep. These include 'Exam Pass Guarantees' and are designed for rapid knowledge transfer.
- Infosec Managed Services: A 'done-for-you' service where Infosec experts manage the strategy, execution, and reporting of your awareness program.
Get our evaluation of Infosec
Our advisory team has deep experience with Infosec. We'll give you an honest, independent assessment — including how they compare to alternatives and what to watch out for.
Request EvaluationBuying Guide: Infosec
Everything you need to evaluate Infosec— from features and pricing to implementation and security.
Introduction
Welcome to the Comprehensive Buying Guide for Infosec (an ITPRO company). In an era where human error accounts for the vast majority of security breaches, choosing the right education partner is critical. This guide evaluates Infosec’s dual-pronged approach: Infosec IQ, which focuses on enterprise-wide security awareness and phishing simulations, and Infosec Skills, a technical training platform designed to upskill cybersecurity professionals.
As you navigate this guide, you will learn how Infosec differentiates itself through role-based content, hands-on cyber ranges, and automated behavioral analytics. Whether you are a CISO looking to satisfy compliance requirements or a Talent Development Manager aiming to bridge the cybersecurity skills gap, this guide provides the technical and strategic insights necessary to determine if Infosec is the right fit for your organization’s security posture.
Key Features
Infosec provides a comprehensive suite of features designed to change user behavior and build technical expertise:
Infosec IQ (Security Awareness & Phishing)
- Automated Phishing Simulations: Over 1,000 templates based on real-world threats, allowing for automated, randomized campaigns that test employee vigilance.
- Personalized Learning Paths: AI-driven recommendations that deliver training based on an individual's past performance and role-specific risks.
- PhishSim & TeachPriv: Interactive modules that provide 'just-in-time' education the moment a user clicks a simulated phishing link.
- Extensive Content Library: High-quality, localized videos, posters, and newsletters in 30+ languages to support global deployments.
Infosec Skills (Technical Training)
- Hands-on Cyber Ranges: Cloud-hosted environments where IT pros can practice offensive and defensive tactics in a risk-free setting.
- Certification Prep: Structured paths for industry-standard certs like CISSP, CEH, Security+, and CCSP, including practice exams.
- Skill Assessments: Pre-and-post training evaluations to measure knowledge gains and identify team-wide skill gaps.
- Boot Camps: Intensive, instructor-led training options for rapid certification attainment with a 'Pass Guarantee.'
Use Cases
- Global Manufacturing Compliance: A multi-national manufacturer uses Infosec IQ to deliver localized security awareness training in 15 languages, ensuring all factory and office staff meet GDPR and ISO 27001 requirements while tracking compliance from a centralized dashboard.
- Financial Services Phishing Defense: A mid-sized bank uses automated phishing simulations to target 'high-risk' departments like Wire Transfer and HR. By using the 'Report Phish' button, employees have decreased the company's average click rate from 15% to under 2% in one year.
- Government Agency Upskilling: A state agency uses Infosec Skills to provide their IT department with access to hands-on labs. This allows their generalist IT staff to transition into dedicated cybersecurity roles, filling internal vacancies without external hiring.
- Retail Rapid Onboarding: A large retailer integrates Infosec IQ with their HRIS (Workday). New hires are automatically enrolled in 'Security Essentials' training on day one, ensuring immediate compliance and risk reduction.
Pricing Models
Infosec generally operates on a subscription-based SaaS model:
- Infosec IQ: Priced per-user, per-year. Tiers are usually based on the volume of learners and the level of content access (Standard vs. Enterprise). Volume discounts apply for large organizations.
- Infosec Skills: Available as individual or team licenses. Team accounts include administrative dashboards to track progress and assign paths.
- Boot Camps: Priced per-seat, per-course. These are higher-cost, fixed-fee engagements that include live instruction and exam vouchers.
- Additional Costs: Consider costs for professional services (managed services where Infosec runs your campaigns) and any custom content development needs.
Technical Requirements
Infosec is a cloud-native platform with minimal local infrastructure requirements:
- Browser: Compatibility with latest versions of Chrome, Firefox, Safari, and Microsoft Edge.
- Email Environment: Ability to whitelist specific IP addresses and domains in your email gateway (Mimecast, Proofpoint, etc.) and mail server (O365, Google) to ensure phishing simulations bypass spam filters.
- Network: Sufficient bandwidth for streaming high-definition video content and accessing cloud-based cyber ranges (for Skills).
- End-User Devices: Training is responsive and accessible via desktop, tablet, and mobile devices.
- Whitelisting: Requires the ability to modify 'Safe Senders' lists and potentially bypass 'Link Rewriting' (like Mimecast TTP or Outlook Safelinks) for simulation accuracy.
Business Requirements
To maximize the ROI of Infosec, organizations should meet these business prerequisites:
- Executive Sponsorship: Security awareness is a cultural shift; leadership must endorse the time spent by employees on training and simulations.
- Dedicated Program Manager: While the platform offers automation, a designated individual (usually in IT or HR) should oversee campaign schedules and follow-up on non-compliance.
- Process for Remediation: A defined policy for how to handle employees who consistently fail phishing simulations (e.g., mandatory additional training vs. HR intervention).
- Internal Communication Plan: A strategy to announce the program to employees to ensure high engagement and transparency regarding the purpose of phishing simulations.
Implementation Timeline
A typical Infosec IQ implementation follows this schedule:
- Phase 1: Discovery & Planning (1-2 weeks): Define goals, identify target learner groups, and establish baseline phishing metrics.
- Phase 2: Technical Setup (1 week): Domain verification, whitelisting Infosec mail servers, and setting up SSO/Active Directory synchronization.
- Phase 3: Content Customization (2 weeks): Selecting training modules, branding the learner dashboard, and customizing phishing templates.
- Phase 4: Pilot Launch (1-2 weeks): Rolling out to a small subset of users to test delivery and gather initial feedback.
- Phase 5: Full Go-Live (Week 6+): Launching the first company-wide awareness campaign and automated phishing cadence.
- Note: Professional technical training (Infosec Skills) can be deployed almost instantly once licenses are assigned.
Support Options
Infosec provides tiered support to ensure client success:
- Customer Success Managers (CSM): Enterprise clients are typically assigned a dedicated CSM to help align training with business goals and review quarterly progress.
- Technical Support: Available via email and phone during standard business hours, with 24/7 options for critical platform issues.
- Managed Services: For overstretched IT teams, Infosec offer 'Managed Awareness Services' where their experts design and execute your phishing and training roadmap.
- Knowledge Base: A robust self-service portal with documentation, 'how-to' videos, and best-practice templates.
- Community: Access to a network of security professionals and peer-led forums.
Integration Requirements
Infosec offers robust integration capabilities to streamline administration:
- User Provisioning: Native integrations with Microsoft Azure AD (Entra ID), Google Workspace, and on-premise Active Directory via SCIM to automate user onboarding and offboarding.
- Authentication: Support for SAML 2.0 and OpenID Connect for Single Sign-On (SSO) across all platforms.
- Security Stack Integration: API-based connections with SEIM/SOAR tools to feed phishing report data into your broader security operations.
- LMS Integration: Content can often be exported via SCIM/AICC for organizations that prefer to host training within their existing Learning Management System.
- Phish Notification: A 'Report Phish' Outlook/Gmail add-in that integrates directly with the Infosec IQ dashboard for real-time threat analysis.
Security & Compliance
Infosec maintains enterprise-grade security standards:
- Certifications: SOC 2 Type II compliant, ensuring rigorous controls over data security, availability, and privacy.
- Data Residency: Options for data storage in various regions to comply with local laws like GDPR (EU) and CCPA (California).
- Privacy: Strict data minimization practices; Infosec only requires minimal PII (Name/Email) to function.
- Accessibility: Content is designed to meet WCAG 2.1 AA standards, ensuring training is accessible to employees with disabilities.
- Audit Logs: Comprehensive logging of all admin actions and learner progress for compliance auditing.
More Cloud & Application Security Vendors
View allConsidering Infosec?
Independent. Vendor-funded. Expert-backed.
We'll help you evaluate Infosecagainst alternatives, negotiate better terms, and ensure a successful implementation. Our advisory services are funded through the vendor ecosystem — at no cost to you.





