By Kaci, founder of NovaShield, Master's in Cybersecurity & Cloud from IPSSI. NovaShield is a registered provider on the Cybermalveillance.gouv.fr platform.
Estimated reading time: 12 min · Published September 5, 2026 · Updated September 5, 2026
Transparency note: NovaShield (ranked #2 in this list) is the publisher of this article. All data cited comes from publicly verifiable sources. We explicitly indicate cases where other solutions are better suited than NovaShield.
Key Takeaways
- The 10 solutions cover four profiles: American giants (KnowBe4, Proofpoint, Cofense, Barracuda), French specialists (NovaShield, Mailinblack, Mantra), European players (Hoxhunt, SoSafe), and open source (GoPhish)
- No solution is universally superior: the right choice depends on your size, budget, and security maturity level
- For a French SMB without a CISO: NovaShield or Mailinblack — fast deployment, predictable pricing, France-hosted data
- For a large enterprise with a SOC: Cofense or Proofpoint — integrated threat intelligence, advanced reporting
- For a zero budget with technical skills: GoPhish — free, open source, but no post-click training
- KnowBe4's Trustpilot user rating (1.8/5) is a reminder that a solution can be recognized by analysts and still be rejected by the employees it's supposed to train
- Top criterion: will this tool actually be used and accepted long-term?
In April 2026, more than 40 platforms compete in the French phishing simulation market. On the demand side, pressure is mounting: the EU NIS2 directive requires proof of employee awareness training, cyber insurers are conditioning coverage on the existence of a training program, and phishing remains the leading attack vector, involved in approximately 60% of incidents in France (CESIN, Enterprise Cybersecurity Barometer, 2025).
On the supply side, the choice has itself become a problem. American giants charging enterprise-tier licensing, French startups promising 15-minute deployment, a free open-source tool, email security suites adding a simulation module — each category has its own logic, strengths, and blind spots.
This ranking reviews the 10 most relevant solutions for a French SMB in 2026. The goal is not to crown a universal winner, but to provide the data to make a choice suited to your size, budget, and regulatory constraints. All figures come from public sources: official pricing pages, G2 and Gartner Peer Insights reviews, analyst reports, and publisher documentation.
Selection Methodology
Before examining each solution in detail, here are the criteria that guided the selection and analysis.
- Coverage of the French market. Every selected solution has documented presence in France: identifiable French clients, French-language content, or an active French-speaking community. Tools available only in English with no French localization were excluded.
- Relevance for SMBs (25 to 250 employees). The French market is 99% SMBs. This ranking evaluates each solution through the lens of SMB constraints: limited budget, small IT team, need for autonomy, GDPR requirements.
- Factual and verifiable data. Every claim is based on public data: official pricing pages, user reviews on G2, Gartner Peer Insights and Trustpilot, analyst reports, technical documentation, and publisher press releases.
- Diversity of approaches. The ranking deliberately includes varied profiles: French specialist solutions, American market leaders, European players, open source tools, and email suite add-ons.
Evaluation criteria for each solution:
- Quality and depth of simulations (templates, customization, attack vectors)
- Post-failure training (micro-learning, adaptive pathways, French-language content)
- Reporting and compliance (dashboards, exportable reports, audit evidence)
- Pricing and transparency (public prices, per-user model, hidden costs)
- Hosting and GDPR compliance (data location, DPA, sovereignty)
- Ease of deployment and administration (setup time, autonomy)
1. KnowBe4 — The Global Leader Built for Enterprise
Publisher: KnowBe4 Inc. (Clearwater, Florida, USA). Founded in 2010 by Stu Sjouwerman. Acquired by Vista Equity Partners in 2023 for $4.6 billion. New CEO Bryan Palma (ex-Trellix) since May 2025. Around 2,400 employees. Over 70,000 client organizations worldwide.
Key features. The largest template library on the market: over 25,000 phishing scenarios and 1,300 training modules, covering 35 languages. PhishER for triaging reported emails. SmartRisk Agent for individual risk scoring (316 indicators). AIDA, an AI campaign orchestration agent (Diamond tier only).
Pricing. Public pricing grid, structured in four tiers: Silver (~$1.90/seat/month), Gold ($2.23), Platinum ($2.60), and Diamond ($3.25). 25-seat minimum. The difference between tiers is significant: at Silver, no micro-learning, no SmartRisk, no AIDA. Add-ons (PhishER, SecurityCoach, Compliance Plus) add $0.17 to $1.50/seat/month. Multiple sources document 20–40% price increases at renewal.
Strengths. Unmatched catalog depth. Unanimous analyst recognition (Gartner Magic Quadrant Leader 2025). G2 rating of 4.6/5 across nearly 3,000 admin reviews.
Limits for French SMBs. Trustpilot rating of 1.8/5 (85% one-star reviews): end users — those the training is supposed to convince — overwhelmingly reject it. French content represents only ~2% of the total catalog. Setup described as "overwhelming" in 26 negative G2 mentions. Pricing is opaque in practice despite a published grid, with add-ons that can double the entry invoice.
Best suited for: large enterprises and international mid-market companies with significant budgets and a full security team. → NovaShield vs KnowBe4 comparison
2. NovaShield — Phishing Simulation Built for French SMBs
Publisher: NovaShield (France). French SaaS solution specializing in phishing simulation and awareness training for SMBs with 50 to 500 employees, and for MSPs managing cybersecurity for multiple SMB clients.
Key features. Scenarios calibrated to attacks actually observed in France: fake Chronopost, fake Ameli, bank transfer fraud, fake URSSAF reminders, fake DGFiP letters. Post-failure micro-learning (3 to 5 minutes), automatically triggered after each click. AI email verification: employees forward a suspicious email and receive a verdict — legitimate or suspicious — with header analysis and SPF/DKIM/DMARC authentication check. Dashboard with risk score by department. Exportable NIS2 compliance reports. Multi-tenant dashboard for MSPs managing multiple SMB clients.
Pricing. Freemium free up to 50 users, no time limit. Pro plan from €79/month for 1 to 50 users, up to €599/month for 501 to 1,000 users. Monthly billing with no commitment, annual option with 13% discount. Create a free Freemium account
Strengths. 15-minute deployment, no vendor intervention required. Content designed for the French context rather than translated. France hosting (target). AI email verification addresses a gap most competitors don't cover: helping employees at the moment of doubt, not only after failure. Multi-tenant MSP dashboard differentiates from Mailinblack and Mantra.
Limits. Smaller scenario catalog than KnowBe4 or Proofpoint. Less suited for organizations over 500 employees or multinational multi-language deployments. No email filtering module — a positioning choice rather than an oversight. Younger platform than most others in this ranking.
Best suited for: French SMBs with 50 to 500 employees wanting a phishing simulation program running quickly, with French-context scenarios, predictable pricing, and documented NIS2 compliance. Also MSPs adding phishing awareness to their service catalog. → NovaShield features · NovaShield pricing
3. Mailinblack Cyber Coach — The French All-in-One Email and Simulation Solution
Publisher: Mailinblack (Marseille, France). Founded in 2003. Historic French email filtering vendor with its Protect solution. Over 20,000 clients, primarily SMBs, local authorities, and healthcare organizations.
Key features. Mailinblack's offering is structured around two components: Protect (inbound email filtering with allowlist/blocklist, anti-spam, anti-malware) and Cyber Coach (phishing simulation with predefined scenarios and awareness modules). Cyber Academy completes the offering with e-learning training pathways. The positioning is an integrated suite: filter technical threats and train employees, in a single contract.
Pricing. Not public. Mailinblack operates on a quote basis through a partner/reseller network. Price depends on the number of email accounts, chosen modules, and commitment period.
Strengths. Established French vendor with a strong installed base. Data hosted in France on OVHcloud. All-in-one approach simplifies vendor relationships. Strong coverage of public sector and healthcare.
Limits. Cyber Coach is a complementary module to Protect, not a standalone product. Simulation scenarios are less customizable than dedicated platforms. Reporting is filtering-oriented rather than human-risk focused. For an SMB that already has an email filter, buying Protect to access Cyber Coach creates a redundancy.
Best suited for: French SMBs and public sector organizations that don't yet have an email filter and want an all-in-one filtering and simulation solution. → NovaShield vs Mailinblack comparison
4. Cofense — The Phishing Reporting Specialist for SOC Teams
Publisher: Cofense (Leesburg, Virginia, USA). Formerly PhishMe, rebranded in 2018. Specialized in phishing detection and reporting. Acquired in 2018 by a consortium led by Pamplona Capital Management and BlackRock.
Key features. Cofense stands out for its reporting-centered approach rather than simulation alone. Cofense Reporter is a button integrated into Outlook and Gmail allowing employees to report a suspicious email in one click. Cofense Triage automatically analyzes reported emails and classifies them by threat level. Cofense Intelligence provides threat intelligence from the reporting community (over 35 million emails analyzed).
Pricing. Not public. Enterprise quote model. The entry ticket is high: annual budgets start in the tens of thousands of euros, placing Cofense beyond most SMB reach.
Strengths. The simulation, reporting, threat intelligence loop is the most complete on the market. For organizations with a SOC, native integration with SIEM/SOAR tools is a significant asset.
Limits for SMBs. Requires a structured security team to exploit triage and threat intelligence. Without a SOC, half of Cofense's value is inaccessible. Content is predominantly English. US data hosting. Long sales cycle with mandatory commercial qualification.
Best suited for: mid-market and enterprise organizations with a SOC wanting to integrate phishing reporting into their incident management workflow. → NovaShield vs Cofense comparison
5. Proofpoint Security Awareness Training — The Enterprise Suite That Includes Simulation
Publisher: Proofpoint (Sunnyvale, California, USA). Founded in 2002. Acquired by Thoma Bravo in 2021 for $12.3 billion. The Security Awareness Training branch comes from the 2018 acquisition of Wombat Security Technologies. Over 4,000 employees.
Key features. Proofpoint SAT offers a massive multi-language phishing template library, professionally produced video training modules, and a user risk scoring system fed by threat intelligence data from the Proofpoint email gateway. Simulations cover email, SMS, and USB.
Pricing. Not public. Enterprise quote model after commercial qualification. According to market feedback (Gartner Peer Insights, G2), annual budgets for an SMB start in the high five figures.
Strengths. The correlation between threat intelligence data and awareness simulations is a genuine advantage for large organizations. Video training content is among the most professionally produced in the market.
Limits for SMBs. Enterprise pricing places the solution beyond most French SMBs' budgets. Deployment takes weeks, not minutes. The value of the threat intel/simulation correlation only exists if you also use Proofpoint's email gateway. Interface and support primarily in English.
Best suited for: large enterprises already using the Proofpoint email suite and wanting to unify email security and awareness in one dashboard. → NovaShield vs Proofpoint comparison
6. Hoxhunt — AI-Driven Gamification
Publisher: Hoxhunt (Helsinki, Finland). Founded in 2016 by Mika Aalto. The startup has raised over $40 million (Series B in 2022). Around 200 employees. Over 2 million trained users claimed, primarily in large Nordic and European enterprises.
Key features. Hoxhunt bets on adaptive AI and gamification. Each employee receives simulations whose difficulty adjusts automatically based on past performance. Employees who correctly report a simulation email earn stars and advance in a leaderboard. Hoxhunt Respond enables reporting suspicious emails via an Outlook/Gmail button.
Pricing. Not public. Enterprise quote model. Hoxhunt targets organizations of 1,000+ employees, placing the entry ticket above SMB budgets.
Strengths. The adaptive approach adjusts difficulty per individual rather than sending the same email to everyone. Gamification generates measurable engagement. G2 rating of 4.6/5.
Limits for SMBs. The pricing model and commercial cycle are designed for large enterprises. Deployment requires SCIM/SSO integration and several weeks of guided onboarding. Scenarios are not natively designed for the French context. Data hosted in the EU (Finland), not in France.
Best suited for: European mid-market and enterprise organizations seeking a gamified, adaptive approach with an awareness budget exceeding €10,000/year. → NovaShield vs Hoxhunt comparison
7. SoSafe — The German Behavioral Science Approach
Publisher: SoSafe (Cologne, Germany). Founded in 2018 by Niklas Hellemann, Lukas Schaefer, and Felix Schürholz. The startup has raised over €100 million in total (€73 million Series B in 2023, led by Highland Europe). Around 500 employees. Over 4,000 client organizations in Europe.
Key features. SoSafe positions itself on behavioral sciences applied to cybersecurity. The platform combines AI-personalized phishing simulations, gamified e-learning pathways with badges and leaderboards, a reporting button (Phish Assist), and a compliance module covering ISO 27001, NIS2, and DORA. Content is available in over 30 languages.
Pricing. Not public. Quote model after a demonstration. SoSafe targets mid-market and enterprise organizations (500+ employees).
Strengths. The behavioral science approach (nudges, cognitive biases, positive reinforcement) is methodologically sound and well documented. Wide European coverage. The multi-regulation compliance module is an asset for organizations subject to multiple regulatory frameworks.
Limits for SMBs. The commercial model targets mid-market and enterprise. The sales process is calibrated for 500+ person organizations. For an 80-employee SMB without a CISO, the sales cycle and budget are concrete barriers. Data hosted in Europe (Germany), GDPR-compliant, but not in France.
Best suited for: European mid-market and enterprise organizations operating across multiple countries seeking a scientific approach to awareness training with multi-regulation coverage. → NovaShield vs SoSafe comparison
8. Mantra (Cyber Guru Group) — Real-Time Coaching, French Style
Publisher: Mantra (France), founded in Paris in 2020 by Gaspard Droz and Guillaume Charhon. In March 2025, Mantra was acquired by Cyber Guru (Rome, Italy). The French team joined the group, and Gaspard Droz became Country Managing Director France. Mantra is no longer an independent French startup but a brand integrated into an Italian group.
Key features. The product relies on a browser extension that analyzes emails in real time within the inbox (Gmail, Outlook). When an email shows phishing signals, an alert banner appears directly in the email interface, before the employee clicks. Phishing simulations are integrated into the detection engine.
Pricing. Not public. Mantra shares pricing after a demonstration.
Strengths. Real-time intervention, before the click, is a differentiating approach that complements traditional simulation. Team based in France. The UX is modern and designed not to disrupt the employee's workflow.
Limits. The approach requires deploying a browser extension on every workstation, which may be a challenge for SMBs without endpoint management tools. Installed base is still limited compared to established players. Data hosting status should be verified following integration into the Cyber Guru group (Italy).
Best suited for: French SMBs and mid-market organizations seeking a complementary approach to traditional simulation, with real-time protection at the moment of email reading. → NovaShield vs Mantra comparison
9. GoPhish — Open Source for Pentesters and Zero Budgets
Publisher: Open source project (MIT license) created by Jordan Wright. Maintained by the community on GitHub. No commercial entity behind the project.
Key features. GoPhish enables creating and sending simulated phishing campaigns from a self-hosted server. The web interface allows creating email templates, landing pages, managing recipient lists, and tracking results. The project is written in Go, making it lightweight and easy to deploy on a Linux VPS.
Pricing. Free. Source code available under MIT license. The real cost is IT time: plan 2 to 5 days for a functional deployment including SMTP server configuration, domain setup, SSL certificate, and first templates.
Strengths. Free and transparent (auditable source code). Full control over infrastructure and data. No vendor dependency. Widely used by pentesters and red teams.
Limits. No built-in post-failure training: when an employee clicks, they see a static page, not a micro-learning module. No compliance reports. No human risk scoring. Templates must be hand-crafted in HTML. Server maintenance, security updates, and email deliverability are your responsibility.
Best suited for: pentesters, red teams, and technically skilled organizations wanting full control and zero budget for simulation, but not a complete awareness program. → NovaShield vs GoPhish comparison
10. Barracuda Security Awareness Training — The Email Suite Add-On
Publisher: Barracuda Networks (Campbell, California, USA). Founded in 2003. Acquired by KKR in 2022 for $4 billion. Historically specialized in email security, Barracuda added a Security Awareness Training module (formerly PhishLine, acquired in 2018) to its offering.
Key features. The module includes phishing simulations (email, SMS, voicemail, found USB drive), short video training modules, a reporting portal, and an email reporting button. The offering is designed to integrate into the Barracuda suite.
Pricing. Not public as a standalone product. The module is typically sold as a bundle with Barracuda Email Protection or Total Email Protection. Barracuda distributes primarily through MSPs and resellers.
Strengths. For organizations already using Barracuda for email security, adding the simulation module is a natural extension. The MSP partner network provides local support in many regions.
Limits. Phishing templates are primarily designed for the North American market. The module is an add-on to the email suite, not a standalone product. English-language interface. Hosting outside France. Reporting is email-security oriented, not human-risk focused.
Best suited for: organizations already using Barracuda for email security that want to add a simulation layer without changing vendors. → NovaShield vs Barracuda comparison
Summary Comparison Table
| Solution | Country | Specialty | Entry pricing (public) | Hosting | Native FR content | Primary target |
|---|---|---|---|---|---|---|
| KnowBe4 | USA | Simulation + training | ~$1,140/yr (50 users, Silver) | AWS Ireland/Frankfurt | No (translated) | Enterprise |
| NovaShield | France | Simulation + micro-learning | Freemium free + Pro from €79/month | France (target) | Yes | SMBs 50–500 + MSP |
| Mailinblack | France | Email filtering + simulation | On quote | France (OVHcloud) | Yes | SMBs, public sector |
| Cofense | USA | Reporting + threat intel | On quote (enterprise) | USA | No | SOC / enterprise |
| Proofpoint SAT | USA | Email suite + simulation | On quote (enterprise) | USA / international | No (translated) | Enterprise |
| Hoxhunt | Finland | Gamification + adaptive AI | On quote (enterprise) | EU (Finland) | No (translated) | Mid-market / enterprise |
| SoSafe | Germany | Behavioral science | On quote (enterprise) | EU (Germany) | Partial | European mid-market |
| Mantra (Cyber Guru) | France / Italy | Real-time coaching | On quote | France (to verify) | Yes | SMBs / mid-market |
| GoPhish | Open source | Bare simulation | Free | Self-hosted | No | Pentesters / red team |
| Barracuda SAT | USA | Email suite + simulation | On quote (bundled) | USA / international | No | Barracuda customers |
How to Choose Based on Your Profile
The right choice depends on your context. Here are five typical profiles and the best-suited solution for each.
- French SMB with 30 to 200 employees, limited budget, no CISO. You need a tool that works autonomously, with French-language scenarios, quick deployment, and predictable pricing. NovaShield or Mailinblack (if you also need an email filter) are the most aligned options.
- Mid-market organization with 500 to 2,000 employees, security team in place, European presence. SoSafe's behavioral approach or Hoxhunt's gamification provide added value that SMB solutions don't cover. KnowBe4 remains viable for this segment, provided you accept the French content limitations.
- Large enterprise with a SOC and a six-figure cybersecurity budget. Cofense (if reporting and threat intelligence are the priority) or Proofpoint SAT (if you're already in the Proofpoint suite) are the most relevant options. KnowBe4 at Diamond level also provides complete coverage.
- Tech startup or pentesting firm wanting to test its own teams. GoPhish provides full control and zero cost, provided you have the technical skills to deploy and maintain it.
- SMB wanting real-time protection in addition to simulation. Mantra offers a pre-click coaching approach that complements a traditional simulation program.
Questions to Ask Before Signing
Whatever tool you're evaluating, ask these seven questions before committing:
- Where is my data hosted? France, EU, or USA? What is the hosting subprocessor? Do you offer a GDPR-compliant DPA?
- What is the total cost in year one, then at renewal? Including add-ons, premium support, setup fees. Document renewal terms in writing.
- How long to deploy and launch the first campaign? 15 minutes or 4 weeks? Do I need your team for every campaign?
- Are your phishing scenarios adapted to the French context? Not translated — adapted. Fake Chronopost, fake Ameli, bank transfer fraud, fake DGFiP notices.
- What happens when an employee clicks a simulation link? Static page? 3-minute micro-learning? Nothing? The post-click response determines the program's educational effectiveness.
- What compliance reports can you generate automatically? NIS2, ISO 27001, SOC 2? In what format? Exportable for an auditor?
- Can I test the platform for free before committing? A full trial (not a guided commercial demo) is the best way to validate whether the tool actually fits your context.
The Best Tool Is the One Your Teams Actually Use
One observation recurs across every analysis in this ranking: the value of a phishing simulation solution is not measured by the number of templates in the catalog or analyst recognition from Gartner. It is measured by actual employee behavior change.
KnowBe4 has 25,000 templates, but a Trustpilot rating of 1.8/5 from end users. GoPhish is free, but without post-click training, it doesn't change habits. Proofpoint has the best threat intelligence, but an 80-person SMB will never exploit it.
The number one selection criterion should be: will this tool be used, maintained, and accepted by employees over time? If the program falls into disuse after three months because it's too complex to administer or too widely rejected by teams, it protects no one.
Test before committing. Launch a first simulation campaign. Measure the initial click rate. Observe how employees react. That is the only way to validate that the tool fits your reality.
Sources
- G2 and Gartner Peer Insights for independent reviews of each solution (KnowBe4, Hoxhunt, SoSafe, Cofense — search by product name on these platforms).
- CESIN, Enterprise Cybersecurity Barometer, 2025 edition, for the 60% phishing-related incident figure.
- Official KnowBe4 pricing pages for Silver/Gold/Platinum/Diamond tier grids.
- Official press releases for funding rounds (SoSafe Series B 2023, Hoxhunt Series B 2022) and acquisitions (Mantra by Cyber Guru March 2025, KnowBe4 by Vista Equity 2023, Barracuda by KKR 2022).
- KnowBe4 Trustpilot data (1.8/5 rating) verifiable directly on KnowBe4's Trustpilot page.
- Data collected and verified in April 2026.
This ranking does not constitute a contractual commitment. Features and pricing mentioned may have changed since the writing date.
About the Author
Kaci is founder of NovaShield, with a Master's in Cybersecurity & Cloud from IPSSI. NovaShield is a registered provider on the Cybermalveillance.gouv.fr platform.
