All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
KnowBe4 sells security awareness training, simulated phishing, and Microsoft 365 email security to organisations from 25 seats up. Founded in 2010, it raised over $300 million, including a KKR-led round, and went public in 2021, when it had 1,366 full-time employees. Vista Equity Partners bought it for about $4.6 billion in 2023. In its last public quarter, September 2022, it reported over 54,200 customers and $347.2 million of annual recurring revenue. It now counts 70,000 customers. Its hardest assets for a rival to match are a library of over 1,000 training modules, videos and games, 71 US patents as of 2021, and a blocklist built from what its customers report. Its email products run on Microsoft 365 interfaces, so their position depends on Microsoft's platform.
| Description | KnowBe4 sells a platform that trains employees to recognise social engineering, runs simulated phishing attacks against them, filters inbound and outbound email for Microsoft 365 and Teams, and remediates the messages users report. | [f1] |
|---|---|---|
| Founded | 2010 | [f2] |
| HQ | Clearwater, Florida, United States | [f3] |
| Funding | $300M total | [f2] |
| Latest funding | Take-private by Vista Equity Partners at 24.90 USD per share, about 4.6B USD equity value (closed 1 February 2023) | [f4] |
| Product | What it does |
|---|---|
| Security Awareness Training | Training library, simulated phishing and vishing attacks, and a per-employee risk score that decides which content each user receives. |
| KnowBe4 Defend | Inbound email and Microsoft Teams security that runs either as an SMTP gateway or as a post-delivery layer on the Microsoft Graph API, and warns the user in place when it holds a message. |
| KnowBe4 Prevent | Outbound email security that learns each sender's habits and interrupts misdirected mail, sends to personal accounts, and regulated data leaving the mailbox. |
| PhishER Plus | Handles the mail users report as suspicious, categorising it automatically, blocking matching patterns, and pulling similar messages out of other inboxes. |
| AIDA | A set of agents that write phishing templates, pick training and landing pages per user, and run simulation campaigns without an administrator scheduling them. |
| Agent Risk Manager | Inventories the AI agents running in a customer's tenant and watches what they access, offered as a technical preview rather than a generally available product. |
Cyber Defense Matrix
| Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|
| Devices Workstations, servers, phones, tablets, storage, network devices, IoT infrastructure, and similar hardware. | |||||
| Applications Software, interactions, and application flows on the devices. | |||||
| Networks Connections and traffic flowing among devices and apps, plus communication paths. | |||||
| Data Content at rest, in transit, or in use across devices, apps, and networks. | |||||
| Users The people using the devices, apps, networks, and data. |
Security Awareness Training scores each employee and changes behaviour, Defend holds phishing in email and Microsoft Teams, PhishER Plus removes reported messages from mailboxes, and Prevent stops regulated data leaving in outbound mail. These lines are mapped to the Cyber Defense Matrix. [f5]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score | Rationale |
|---|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 | KnowBe4 names its buyer and its problem cleanly. Its 10-K argues that social engineering targets the people in an organisation rather than its infrastructure, and that spending on infrastructure-centric tools has not closed that gap, which puts the security team that owns the residual risk in the buying seat. Every figure sizing that pain in the reviewed sources comes from KnowBe4's own pages and its own filings, and no independent quantification of the problem appears in them. [s13, s5, s4] |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs and third-party validation. | 3/5 | The capability detail is concrete rather than sloganeering. The buyer chooses where inbound inspection sits, ahead of delivery in the mail path or behind it inside the tenant, and can watch detections in a report-only mode before switching blocking on. Outbound inspection begins with an automatic ingestion of twelve months of the customer's email history. All of it sits on KnowBe4's own pages, and the reviewed sources carry no third-party technical evaluation and no independent benchmark of the detection claims. [s6, s7, s8, s5] |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 | Security awareness training is an established budget line rather than an emerging one, and the demand under it is real enough that the company reported more than 54,200 customers in its last public quarter in 2022. What the reviewed sources do not carry is a buyer-side demand signal dated within the last twelve months from a source outside the company. The analyst placement KnowBe4 leads with on its homepage reaches this record only through KnowBe4's own page, which is one kind of signal and a vendor-displayed one. [s14, s1, s13] |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 | Stu Sjouwerman co-founded Sunbelt Software before starting KnowBe4 in 2010, took KnowBe4 public in 2021 and sold it to Vista Equity Partners in 2023, so the founder carries two in-domain exits, the earlier of them recorded by KnowBe4's own history page. Bryan Palma, chief executive since May 2025, previously ran Trellix, the company formed from FireEye and McAfee Enterprise, per CRN Australia. Independent detail in the reviewed sources reaches those two people and the chief information security officer, whom a CyberScoop article quotes. [s2, s22, s21, s15, s3] |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 5/5 | The traction sits in regulatory filings rather than in vendor claims. The 10-K for 2021 recorded 47,174 customers on $285.4 million of annual recurring revenue, up from 36,753 customers a year earlier, and the last public quarter recorded more than 54,200 customers and $347.2 million of annual recurring revenue growing 32.4 percent. An arm's-length buyer then paid about $4.6 billion for the company, a price two independent articles carry alongside the filings. The corroboration stops at February 2023, and the 70,000 organisations KnowBe4 claims today is its own count. [s13, s14, s15, s18, s19, s1] |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 4/5 | Output per dollar is confirmed rather than asserted for the period the filings cover. Against more than $300 million of venture funding raised before the 2021 listing, the 10-K for 2021 recorded free cash flow of $71.2 million, $36.7 million and $18.9 million across 2021, 2020 and 2019, on revenue that grew 40.8 percent in 2021. The last public quarter carried an 86.7 percent gross margin and a positive GAAP operating margin. Nothing in the reviewed sources confirms the position since the company went private in 2023. The acquiring entity entered a $1 billion term loan facility that day. [s13, s14, s19, s16] |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 4/5 | Independent outlets place the company consistently. SecurityWeek articles from 2022 and 2024 describe it as a security awareness training company and a security awareness training firm, a CyberScoop article from 2024 uses the same label, and a CRN Australia article describes it as a cybersecurity education platform. Its own positioning has moved past that label towards securing a workforce of people and AI agents, and its own 10-K placed it against Proofpoint, Mimecast and Cofense, so the label the press uses and the one the company now uses have separated. [s18, s20, s21, s22, s1, s13] |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 3/5 | The email half of the platform runs on interfaces Microsoft controls. Defend deploys as a gateway in front of Microsoft 365 or as a layer on the Microsoft Graph API and feeds Defender XDR and Sentinel, and Prevent authorises through a single Microsoft 365 grant. Against that KnowBe4 holds friction an incumbent would work through: a phishing-report corpus its own page attributes to more than 13 million users, 71 issued US patents as of 2021, and a training library its site puts past a thousand modules, videos and games. Each of those assets is exposed to bundling. [s6, s7, s8, s13, s5] |
KnowBe4 sells against the employee who clicks. Its 10-K for 2021 frames social engineering as a risk aimed at the people in an organisation rather than at its infrastructure, and argues that years of spending on infrastructure-centric tools have not stopped breaches from being reported with increasing frequency. The buyer is the security team that owns what is left over.
The scale of that pain is stated by KnowBe4 rather than measured independently in the reviewed sources. Its training page carries figures for how much training is forgotten, what share of breaches involve employees, and what share of phishing is now written with AI. Each is credited either to KnowBe4's own research or to a third-party report the reviewed sources do not include.
The company's own 2024 hiring incident is the most concrete instance of the problem in this record, and the account of it is KnowBe4's own. CyberScoop reported that the company disclosed in a blog post that a remote software engineer it had hired for its internal IT team was a persona run by a North Korean threat actor, who cleared background checks, verified references and four video interviews on a stolen US identity and a photograph altered with AI. KnowBe4 said no data was lost or exfiltrated, and the reviewed sources carry no independent account of what the operative reached. [s13, s5, s21]
The platform is four buying decisions. Security Awareness Training pairs a content library with simulated phishing and a per-employee risk score that KnowBe4 says is computed from 316 indicators. Defend inspects inbound mail and Microsoft Teams. Prevent inspects outbound mail. PhishER Plus handles what users report.
The deployment detail is specific. Defend runs either as an inline SMTP gateway or as a post-delivery layer on the Microsoft Graph API, starts in a report-only mode before an administrator turns on blocking, and sends its detections into Microsoft Defender XDR and Sentinel. Prevent authorises through a single Microsoft 365 grant and ingests twelve months of historical email so it can learn who each sender normally writes to.
PhishER Plus closes the reporting loop. It categorises reported mail, blocks matching patterns across the tenant, pulls similar messages out of other inboxes, and turns a real attack into a template for the next simulation. KnowBe4 says it draws on more than 13 million users worldwide and a blocklist built from what they report.
Every efficacy figure attached to all of this is published by KnowBe4. The company says its training takes an organisation from an average phish-prone percentage of 33.1 to 4.1 within a year, that PhishER Plus categorises 90 percent of reported mail without a human, and that its return in year one is 650 percent. The sources reviewed for the 2026-09-04 profile carry no independent check of any of them. [s4, s5, s6, s7, s8]
KnowBe4's own filing named its competition. The 10-K for 2021 says that Proofpoint, Mimecast and Cofense are larger enterprise providers that address human risk inside an offering tied to other products rather than as a singular focus. It was filed in 2022, when KnowBe4 sold training and simulation, and before it acquired an email security business.
The company then bought the other half. A SecurityWeek article from April 2024 states that KnowBe4 agreed to acquire Egress, a London cloud email security business that had raised $48 million, on terms neither side disclosed. The same article records that the plan was to combine Egress email security technology with KnowBe4's training and simulated phishing products. That added an email security business to the training and simulation products the filing had described.
Its category label and its positioning have separated. Articles SecurityWeek and CyberScoop published in 2024 still describe it as a security awareness training company, and its homepage now leads with securing a workforce of people and AI agents. The two halves meet on Microsoft's rails, where the product pages describe Defend as a partner in the Microsoft Defender ecosystem for integrated cloud email security. [s13, s20, s18, s21, s1, s6]
The traction record rests on regulatory filings to a point and on the company's own statements after it. The 10-K for 2021 recorded 47,174 customers, up from 36,753 a year earlier, carrying $285.4 million of annual recurring revenue. The last quarter KnowBe4 reported as a public company, ending September 2022, recorded more than 54,200 customers and $347.2 million of annual recurring revenue growing 32.4 percent.
Everything after February 2023 rests on the company's own count. KnowBe4 says today that it serves 70,000 organisations and that one in three full-time United States workers has been trained by it. No source in the reviewed record outside the company checks either figure.
Expansion inside the existing base was modest in the years the filings cover. The 10-K put the dollar- based net retention rate at 108.4 percent for 2021 and at 102.8 percent for 2020, and recorded that 22.1 percent of customers subscribed to more than one product. Revenue over 2021 grew 40.8 percent. Whether the email security lines acquired since have moved either number is not established in the reviewed sources. [s13, s14, s1]
Stu Sjouwerman started KnowBe4 in August 2010, after co-founding Sunbelt Software, which GFI Software acquired earlier that year. He took the company public in 2021 and agreed its sale to Vista Equity Partners in 2022. CRN Australia records that he led it through multiple venture rounds, several acquisitions and a public offering.
Bryan Palma has run the company since May 2025, with Sjouwerman moving to executive chairman. CRN Australia records that Palma was previously chief executive of Trellix, the company formed from the merger of FireEye and McAfee Enterprise, and before that held roles at Cisco, Boeing, EDS, PepsiCo and the US Secret Service.
Below those two the bench is published but thinly corroborated. KnowBe4's leadership page names a full executive team including a chief product officer, a chief technology officer, a chief scientist and a chief information security officer. Independent detail in the reviewed sources reaches Palma, Sjouwerman and the chief information security officer, whom a CyberScoop article quotes.
Kevin Mitnick appears in the company's history. KnowBe4's own timeline records that he joined in 2011 as chief hacking officer and part owner, and the 10-K's platform description still carried his name on the training product a decade later. [s2, s22, s3, s13, s15]
KnowBe4 publishes a long list of security credentials. Its security statement records a FedRAMP Moderate authorisation to operate for the training and PhishER platform held since 14 November 2023, SOC 2 Type 2 across all products covering all five trust services criteria, and ISO 27001, 27701, 27017, 27018 and 42001 certifications.
Two of those reach past the usual enterprise set. The 42001 certification covers AI management systems rather than information security, and the same page records UK Cyber Essentials certification and an accreditation from ACN, the Italian national cybersecurity agency, for the training and PhishER products.
Its own client software has been on the receiving end. The National Vulnerability Database records CVE-2024-29209, a flaw scored 6.0 in the update mechanism of KnowBe4's Phish Alert Button for Outlook that allowed remote code execution on a host, found by Ceri Coburn at Pen Test Partners. The remediation note on that record says automated updates would be pushed and that users of affected versions should verify the latest version is applied. [s11, s23]
| Company | Relationship | Note | Compare |
|---|---|---|---|
| Proofpoint | competes with | KnowBe4's own 10-K names it as a larger enterprise provider addressing human risk inside an offering tied to other products. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Mimecast | competes with | KnowBe4's own 10-K names it as a larger enterprise provider addressing human risk, and the profile treats it as a rival for the same email security and human risk budget. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Cofense | competes with | KnowBe4's own 10-K names it as a larger enterprise provider addressing human risk inside an offering tied to other products. | |
| Abnormal AI | competes with | Competes, in the profile's judgment, for the inbound email security budget at organisations running Microsoft 365, which is where Defend sells. | N/AWe captured the evidence for these companies under different evidence-model versions (v1 vs v2), so the totals were scored under different conditions and are not directly comparable. |
| Keep Aware | adjacent | Adjacent, in the profile's judgment, on the same employee risk budget KnowBe4's training and email products serve. | N/AThese companies operate in different domains, so the scores reflect readiness in different markets. |
| Microsoft | adjacent | Adjacent as the platform vendor whose mailbox, collaboration product and API layer the email half of KnowBe4's platform runs on. | N/AMicrosoft is scored by product line, not as a whole company, so there is no company-wide column to compare. Open its profile to compare a specific product. |
Add analyzed competitors to compare them side by side with KnowBe4.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
press the advantage
KnowBe4's defensible assets are its training library, its patents and what its customers report. Its site puts the library past 1,000 modules, videos and games, and the 10-K for 2021 recorded 71 issued US patents. KnowBe4 says PhishER Plus draws on more than 13 million users, and that its global blocklist blocks threats from their crowdsourced reports. Defend and Prevent work through Microsoft 365, so the mailbox and the interfaces they authorise against belong to Microsoft. KnowBe4 does not publish what leaving it costs a customer. Its durable holds are the library, the patents and the cross-customer reporting, and its email products depend on Microsoft.
| Dimension | Score | Rationale |
|---|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 | KnowBe4 sells seats. Its training list price is per employee per month on a three-year term, and what the customer administers is subscription software. The training library is content KnowBe4 holds under its own name, which its site puts past a thousand modules, videos and games, and its incident response product runs on what customers report. The sources reviewed for the 2026-09-04 profile describe no human-expertise delivery layer the customer buys alongside them. The customer pays for software and content. |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 | The profile infers real friction from the integrations, and none of it is sized. A customer that routes outbound mail through the KnowBe4 gateway, wires detections into Microsoft Defender XDR and Sentinel, and accumulates per-employee risk history has work to undo on exit. The reviewed sources describe none of that work, giving no migration duration, no parties, and no answer on whether the risk history and tuned campaign content can be exported. The one figure the pages do carry measures arrival rather than departure, at about six minutes to deploy. |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 2/3 | The credential set is broad, and a funded rival could obtain the same certifications. A FedRAMP Moderate authorisation to operate held since November 2023 covers the training product and PhishER, and an accreditation from ACN, the Italian national cybersecurity agency, covers the same two. A rival chasing those government buyers would need equivalent authorisations. SOC 2 Type 2, UK Cyber Essentials and the ISO certifications are ordinary enterprise-market preparation. Nothing in the record blocks replacement outright. |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 | This is not weekend software. Prevent ingests twelve months of a customer's historical mail to learn who each sender normally writes to, Defend inspects live mail either in the delivery path or through the tenant interface, and the risk engine produces a score for every employee from 316 indicators. The 10-K for 2021 recorded 71 issued United States patents with 62 more pending. Substantial implementation work sits behind these features. |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 2/3 | The evidenced buyer class spans the range rather than sitting at the regulated-enterprise end. The published price list starts at 25 seats, and the 10-K for 2021 said the platform is designed to scale from small businesses to large enterprises. That filing recorded 47,174 customers on $285.4 million of annual recurring revenue, which works out at a little over $6,000 each. A FedRAMP Moderate authorisation covers the training product and PhishER, which is what a federal buyer would require, and the reviewed sources name no federal customer. |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 2/3 | KnowBe4 operates as a platform its customers use. The 10-K for 2021 describes products deployed on a common data platform with embedded analytical tools and reporting APIs, and the mail products sit in or beside the delivery path and push their output into Microsoft Defender XDR and Sentinel. Nothing in the reviewed record shows another application depending on KnowBe4 in order to run. |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 3/3 | Three assets are evidenced rather than inferred. The 10-K for 2021 records 71 issued United States patents with 62 more pending, a granted right nobody can recreate from scratch. KnowBe4's site puts its own training library past a thousand modules, videos and games. And PhishER Plus accumulates reported mail across what the company says are more than 13 million users, feeding a blocklist that acts on other customers' reports, which is vendor-held cross-customer data rather than data kept per tenant. |
The published price list reaches down to small buyers. KnowBe4 publishes seat prices in bands beginning at 25 seats and stopping at 1,000, above which the page asks for a quote. Its 10-K for 2021 said the platform is designed to scale from small businesses to large enterprises.
The figures reported for 2021 give an average per customer. At the end of 2021 KnowBe4 had 47,174 customers carrying $285.4 million of annual recurring revenue, which the profile calculates as a little over $6,000 of subscription a year for each of them. Nothing in the filing breaks that base down by customer size, so the shape behind the average is not established.
Cross-selling into that base was still early when the record closed. The same filing recorded that 22.1 percent of customers held more than one product at the end of 2021, and that customer growth had slowed as the company put more weight on enterprise accounts and managed service providers, which it said carry longer sales cycles.
The regulated credentials cover part of the platform. The FedRAMP Moderate authorisation and the Italian ACN accreditation each cover the training product and PhishER, and neither reaches the two email security lines.
KnowBe4 dates its AI work further back than the current wave. Its own AIDA timeline puts a first use of AI in security awareness training at 2016 and a first AIDA patent at 2018, when it also launched a risk-scoring function it called the Virtual Risk Officer.
What the agents do is administrative before it is defensive. KnowBe4 describes AIDA as a suite of agents that continuously automates administration and content personalisation so security teams can focus on strategic risk decisions rather than operational tasks. Its own timeline dates an eighth agent, which runs phishing simulations end to end, to 2026.
The scoring engine is what the rest hangs on. KnowBe4 says a risk score is produced for every employee from 316 indicators drawn across the organisation's security tooling, and that the score decides which content each person receives. AIDA ships inside the higher training tier, KnowBe4 SAT Advanced.
Agent Risk Manager is the line that defends AI rather than uses it, and it is not generally available. Its page promises discovery of every agent in a customer's tenant with no configuration, and says the product is in technical preview.
Free diagnostic tools sit at the top of the funnel. KnowBe4's free tools section lists an attack simulation test, a Phish Alert Button, a program maturity assessment, a weak password test, a domain spoof test, an email exposure check, a ransomware simulator and a breach simulator, all of them reachable without a purchase.
Named references are published rather than merely counted. The homepage carries case studies on Crawford, Anglo-Eastern Ship Management, Publix Employees Federal Credit Union and Well Pharmacy, two of which name the email security products in their titles rather than the training.
The partner motion is built out and its size is not disclosed. The site runs a channel partner programme, a technology alliances track, a risk and insurance track, a partner portal and a public partner directory. The 10-K for 2021 recorded that customer growth had slowed partly because the company was leaning harder on enterprise accounts and managed service providers.
KnowBe4 publishes its training price rather than quoting it. The pricing page shows two content tiers, Foundation and Advanced, priced per seat per month on a three-year term, in eight currencies, and dated May 2026.
The bands fall as the seat count rises. In US dollars, Foundation runs from $2.40 a seat a month in the 25 to 50 band down to $1.63 in the 501 to 1,000 band, and Advanced from $3.75 down to $2.79 across the same bands. Above 1,000 seats the page stops publishing a number and asks for a quote.
Of the other three lines, only PhishER Plus carries a published price, as an add-on on the same page: $1.50 per seat per month for 101 to 500 seats and $1.15 for 501 to 1,000 seats on a three-year term, with a quote above 1,000. Defend and Prevent are not priced in the reviewed sources.
Time to value is what KnowBe4 measures on its own pages. Prevent claims an average deployment of six minutes with no configuration or rules to write, through a four-step setup that syncs Microsoft 365 domains, defines which groups get nudged, ingests twelve months of mail history and routes outbound mail through a KnowBe4 gateway.
Defend lets a team turn the volume up gradually. It can run in a report-only mode while administrators check what it would have caught, and only then move to automated blocking. It also groups related phishing and graymail waves into one investigative view rather than leaving an analyst to triage message by message.
Defend's output lands where the security team already looks. Quarantine, detection timelines and threat-hunting data flow into Microsoft Defender XDR and Sentinel, and one allow-and- deny list covers email and Microsoft Teams together. PhishER Plus closes its own loop by turning a real reported attack into a template for the next simulation.
The authorisation boundary is narrower than the platform. The security statement puts the FedRAMP Moderate authorisation on what it calls the KnowBe4 Platform, defined there as the training product plus PhishER, and puts the ACN accreditation on the same two products. The reviewed sources place neither email security line inside a federal authorisation.
Some evidence is published and some is gated. The ISO certificates and a SOC 3 report are linked from the page, while a reader wanting the full SOC 2 Type 2 report is directed to a sales representative or a customer success manager, and the trust centre is where access to security documentation is requested.
One certification covers a different domain. KnowBe4 lists ISO 42001, which covers AI management systems rather than information security, alongside the 27001, 27701, 27017 and 27018 certifications an enterprise buyer expects.
Microsoft is the ecosystem that matters most. Defend describes itself as a partner in the Microsoft Defender ecosystem for integrated cloud email security, it works against Microsoft 365 and Microsoft Teams, and its quarantine, detection timelines and threat-hunting data flow into Microsoft Defender XDR and Sentinel. Prevent takes a single Microsoft 365 authorisation to route outbound mail.
The reporting side is a network rather than an integration. PhishER Plus draws on what KnowBe4 says are more than 13 million users worldwide, and both its global blocklist and its mailbox-clearing function work from what those users report, so a message one customer flags can produce a block for others.
Everything else is a programme rather than a catalogue. The site runs technology alliances alongside its channel and managed service partners, and the reviewed sources do not enumerate the integrations available through it.
The reviewed sources carry one headcount figure, in a filing. The 10-K for 2021 recorded 1,366 full-time employees at the end of 2021, of whom 264 worked outside the United States, alongside 71 issued United States patents and 62 more pending. No later headcount appears in the reviewed sources.
The company's own security function is unusually visible. Its chief information security officer is named on the leadership page, and CyberScoop quoted him saying that little had changed in the company's controls after the 2024 hiring incident, because those controls were what detected it.
That incident says something about the hiring process as well as about the attacker. CyberScoop reported that the person cleared background checks, verified references and four video interviews before a laptop was shipped, and that detection came only once the machine reached the operative's hands.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | KnowBe4: About Us page | official | 2026-09-04 |
| f2 | TechCrunch: Vista Equity Partners to acquire cybersecurity company KnowBe4 for $4.6B | press | 2026-09-04 |
| f3 | SEC EDGAR: KnowBe4, Inc. Form 8-K reporting completion of the Vista merger | regulatory | 2026-09-04 |
| f4 | SEC EDGAR: KnowBe4, Inc. Form 8-K Exhibit 99.1 announcing the Vista Equity Partners merger agreement | regulatory | 2026-09-04 |
| f5 | KnowBe4: platform overview page | official | 2026-09-04 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Use, quotation, automated retrieval, and redistribution of the content are governed by the Terms of Use at cybercompanyprofiles.com/terms, which permit personal and internal business use with attribution and prohibit republication and resale.