Skip to main content
Precursor Security
2026 Comparison Guide

Best Phishing Simulation Providers UK

The best UK phishing simulation providers in 2026 split into two categories: CREST-accredited human-led testing services and self-service awareness-training platforms. This guide compares 7 providers: Precursor Security, KnowBe4, Proofpoint Security Awareness, Hoxhunt, Cofense, MetaCompliance, and usecure, labelling each honestly as a testing service or a training platform so buyers know exactly what they are comparing.

Seven providers compared on the distinction that matters most: CREST-accredited human-led testing versus self-service awareness-training platforms. Pricing you can see, ownership you can check, and where each provider genuinely fits.

Updated August 2026
Every claim verifiable
Platform vs service labelled honestly
Scroll
3,000+ Assessments DeliveredTriple-CREST Accredited24/7 UK SOC in NewcastleReports Accepted by Insurers & RegulatorsEst. 2018
Read This First

We are Precursor Security, and we have ranked ourselves first on this list.

Rather than pretend otherwise, we publish the selection criteria in full and describe every other provider fairly, including labelling honestly whether each is a human-led testing service or a self-service software platform. Precursor is a CREST-accredited testing service: our analysts design bespoke pretexts, run the campaign, and follow every click through to impact. We are not a self-service awareness-training platform, and we do not claim to be. The six platforms below serve a real and different need: continuous, always-on training your own team administers. You can verify our accreditation directly in the CREST member directory.

At a Glance

Seven providers, side by side

ProviderHQ / ownershipPricing publishedFrom
1. Precursor SecurityHuman-led testing serviceUK. Independent.YesFrom £3,000
2. KnowBe4Self-service SaaS platformClearwater, Florida, US. Privately held (Vista Equity Partners).NoOn application
3. Proofpoint (Security Awareness)Self-service SaaS platformSunnyvale, California, US. Owned by Thoma Bravo (private equity, since 2021).NoOn application
4. HoxhuntSelf-service SaaS platformHelsinki, Finland. Privately held (VC-backed, Series B).NoOn application
5. CofenseSelf-service SaaS platformLeesburg, Virginia, US. Privately held (private-equity backed).NoOn application
6. MetaComplianceSelf-service SaaS platformDerry~Londonderry, Northern Ireland, UK. Owned by Keensight Capital (private equity, since Dec 2024).NoOn application
7. usecureSelf-service SaaS platformManchester, England, UK. Privately held, independent.NoOn application

Verified against each provider's public website and third-party filings, August 2026. "Not published" means we could not find a fixed public rate card; it does not mean the provider lacks a price.

The 7 best UK phishing simulation
providers in 2026

1. Precursor Security

Human-led testing serviceBest for: Organisations that want a tested outcome tied to real attack paths, not just an ongoing training tool

Precursor is CREST-accredited and runs human-led, objective-based phishing and social engineering testing: bespoke pretexts built from OSINT reconnaissance (LinkedIn profiles, Companies House filings, company news), spear phishing, credential harvesting against cloned Microsoft 365 and Google Workspace login pages, attachment payload testing, and CEO fraud (BEC) simulation. Every click that fails is followed through to a teachable moment, and every campaign produces a structured report (open, click, and compromise rates, plus phish-prone percentage trend) built for board and auditor submission. Phishing simulation starts from £3,000 for a baseline campaign; combined social engineering testing (adding vishing, physical intrusion, and pretexting) starts from £5,000. Pricing is published, and a fixed-fee proposal follows a 30-minute scoping call.

Trade-off: A managed testing service, not a self-service awareness-training platform. Organisations wanting a continuous, always-on training dashboard for the whole year should pair this with one of the platforms below rather than expect Precursor to replace it.

2. KnowBe4

Self-service SaaS platformBest for: Large organisations that want a self-managed, continuous training dashboard with a huge template library

KnowBe4 is the biggest name in security awareness training: a self-service platform with an extensive library of simulated phishing templates, e-learning modules, and a phish-prone percentage dashboard your own team configures and runs. It is headquartered in Clearwater, Florida, and was taken private by Vista Equity Partners in 2023. For an IT or security team that wants to own the training programme in-house and run campaigns themselves, the platform gives broad reach and a mature feature set.

Trade-off: It is a platform you administer, not an analyst-led engagement. Campaigns are built from template libraries rather than bespoke OSINT-driven pretexts, and there is no CREST-accredited tester behind an individual campaign. Pricing is not published on KnowBe4's own site; third-party review sites cite roughly $2.79 to $3.75 per seat per month as a general guide, but a firm quote requires a sales conversation.

3. Proofpoint (Security Awareness)

Self-service SaaS platformBest for: Enterprises already running Proofpoint email security who want awareness training in the same ecosystem

Proofpoint Security Awareness is the training and simulation module inside Proofpoint's wider email security suite, useful for enterprises that want phishing simulation data correlated against real inbound threat telemetry from the same vendor. Proofpoint is headquartered in Sunnyvale, California, and has been owned by private equity firm Thoma Bravo since 2021.

Trade-off: Pricing is quote-only; Proofpoint does not publish a rate card, and third-party benchmarks suggest enterprise per-user pricing varies significantly by deployment size. It is a platform integrated into a broader security stack, not an independent testing engagement, and campaigns are self-administered rather than run by a dedicated analyst.

4. Hoxhunt

Self-service SaaS platformBest for: Organisations wanting a gamified, adaptive training experience to drive employee engagement

Hoxhunt is a Helsinki-founded human risk management platform built around gamification and adaptive, personalised training paths rather than static campaigns. It is privately held, backed by venture funding through a Series B round, and has built a strong reputation for engagement-driven behaviour change scores in independent review sites.

Trade-off: A self-configured platform rather than a tested engagement; there is no CREST accreditation or analyst-led pretexting behind a campaign. Pricing is not published; third-party sources indicate per-employee subscription pricing scaled by simulation volume, with a firm number only available through a sales quote.

5. Cofense

Self-service SaaS platformBest for: Organisations wanting phishing simulation paired with a managed reported-email detection and response product

Cofense (formerly PhishMe) pairs simulated phishing campaigns with a phishing detection and response platform built around user-reported emails, threat intelligence, and analyst triage of what staff flag as suspicious. It is headquartered in Leesburg, Virginia, and operates as a privately held, private-equity-backed company.

Trade-off: The simulation side is a self-service platform, and full detection-and-response capability is a separate, quote-only product bundle. Pricing is not published; third-party benchmarks suggest per-user monthly costs after volume discounts, but a complete bundle price requires a sales conversation.

6. MetaCompliance

Self-service SaaS platformBest for: UK organisations wanting simulated phishing bundled with e-learning, policy management, and incident management in one platform

MetaCompliance is a UK-founded (2003) platform combining simulated phishing with e-learning, policy management, and incident management in a single compliance-focused suite, listed on the UK government's G-Cloud Digital Marketplace. It was acquired by growth-equity firm Keensight Capital in December 2024.

Trade-off: A configurable platform rather than an analyst-led test; campaigns are template-based and self-administered. No public rate card is published outside G-Cloud listings, so pricing requires a direct quote.

7. usecure

Self-service SaaS platformBest for: MSPs and SMEs wanting an affordable, self-managed human risk platform bundling phishing simulation with dark web credential monitoring

usecure is a Manchester-founded human risk management platform aimed primarily at MSPs and small-to-mid-sized businesses, bundling adaptive security awareness training, phishing simulation, exposed-credential monitoring, and policy acknowledgement into one dashboard. It remains an independent, privately held UK company.

Trade-off: A self-service platform built for breadth and MSP resale rather than a bespoke testing engagement; there is no CREST accreditation or analyst behind an individual campaign. Pricing is tiered by user count and features but is not published as a fixed public rate card.

Methodology

How we ranked them

Six criteria, each something a buyer should care about and can verify without taking anyone's word for it. The most important distinction is the first one: whether you are buying a tested outcome or a training tool. Read more on why we structure our own services this way in our closed-loop security model.

Human-led bespoke pretexts vs template SaaS campaigns

Whether a campaign is built by an analyst researching your specific organisation (OSINT, staff roles, current threat patterns) or selected from a shared template library that many other organisations use, and that staff may already recognise.

Ties to real attack paths, follows the click to impact

A test worth paying for demonstrates what happens after the click: credential capture, MFA bypass exposure, or a chained path toward a real objective. A platform that stops at a click-rate percentage never shows you the impact.

CREST accreditation

Whether the organisation and the individual testers carry CREST accreditation, independently audited and verifiable in the official directory. Awareness-training platforms are software products, not accredited testing bodies, so this criterion does not apply to them in the same way.

Reporting for the board vs vanity click-rate metrics

Whether the output is a report built for board presentation and audit submission with business impact and remediation, or a dashboard of click percentages with no narrative behind the number.

Awareness training integration

Whether the provider connects the test findings to a teachable moment and, where relevant, to an ongoing training programme, or leaves the result as an isolated data point.

Frequency: point-in-time test vs continuous programme

Whether the offering is a periodic tested assessment (typically annual, for audit and compliance evidence) or a continuous, always-on training programme run monthly by your own team. Both have a place, and the right answer depends on what you are trying to prove.

Buyer Beware

Red flags when choosing
a phishing simulation provider

Whichever provider you choose, including us, walk away if you see these.

Template-only campaigns staff already recognise

If the same handful of email templates are shared across thousands of customers, your employees have likely seen them before, at this organisation or a previous one. A campaign built from OSINT on your actual organisation is a fundamentally harder test.

Click-rate vanity metrics with no impact analysis

A percentage on a dashboard tells you nothing about business risk on its own. Ask what happens after the click: was a credential actually captured, was MFA bypassed, could the path have reached a real objective?

No follow-through past the click

A simulation without an immediate teachable moment wastes the one chance you have to turn a mistake into a lesson. If a provider cannot describe what an employee sees the moment they click, the exercise is measurement without education.

A tool with no expert behind it

Self-service platforms are honest about being software your own team configures. A provider that markets itself as expert-led testing but is, underneath, the same template-driven platform anyone can buy, is not being honest about what you are getting.

Punitive framing that erodes reporting culture

Naming and shaming individual employees who click discourages people from reporting real suspicious emails later, which is the opposite of what a simulation programme should build. Ask how results are presented, at an organisation and department level, or by name.

No board-ready outcome

If the only output is a raw dashboard export, your stakeholders and auditors get nothing usable. Ask for a redacted sample report before you buy: it should read as a narrative with business impact and prioritised next steps, not a spreadsheet.

What It Costs

UK phishing simulation prices in 2026

Precursor's managed phishing simulation starts from £3,000 for a baseline campaign, with most mid-market 12-month programmes falling between £3,000 and £8,000 per year. Full social engineering testing, adding vishing and physical intrusion, starts from £5,000. Self-service platforms typically price per seat per year on a quote-only basis and do not publish a fixed rate card.

Full phishing simulation service details
Baseline campaignFrom £3,000
Annual programme£3,000 to £8,000/yr
Combined (phishing + vishing)From £5,000
Full scope (+ physical)From £10,000

Comparing offensive security providers more broadly? See our guide to the best penetration testing companies in the UK, or explore our penetration testing services.

Make It a Fair Fight

Compare us against anyone on this list.

CREST-accredited, human-led phishing simulation from £3,000. A fixed-fee proposal within days of a scoping call.

CREST Triple Accredited|Fixed Price Quotes|Free Scoping Call|UK Based Team
FAQs

Choosing a phishing simulation provider

The questions buyers ask most when comparing UK providers.

Precursor Security's managed phishing simulation starts from £3,000 for a baseline campaign, with ongoing 12-month programmes typically running £3,000 to £8,000 per year depending on organisation size and campaign complexity. Combined social engineering testing (phishing plus vishing and physical intrusion) starts from £5,000. Self-service awareness-training platforms such as KnowBe4, Proofpoint, Hoxhunt, Cofense, MetaCompliance, and usecure generally price per seat per year on a quote-only basis, and none publish a full public rate card.

A phishing simulation service, delivered by a CREST-accredited provider such as Precursor, is a human-led engagement: an analyst builds bespoke pretexts from OSINT reconnaissance on your organisation, runs the campaign, and follows every click through to a teachable moment and a board-ready report tied to real attack paths. An awareness-training platform, such as KnowBe4, Proofpoint, Hoxhunt, Cofense, MetaCompliance, or usecure, is self-service software your own team configures: you select templates from a library and run campaigns yourselves on a continuous basis. Services suit organisations that want a tested, evidence-grade outcome; platforms suit organisations that want an always-on training tool. Many organisations use both.

A point-in-time phishing simulation test, run annually or after significant organisational change, gives you an evidence-grade snapshot for auditors and insurers. Continuous awareness-training platforms are typically run monthly, since infrequent testing leads to skill decay and organisations running only quarterly campaigns tend to see their phish-prone percentage plateau. Many organisations pair an annual CREST-accredited test with a continuous platform-based programme running throughout the year.

Yes, when the simulation is followed through with a teachable moment and measured over time. Phishing remains the primary delivery mechanism for ransomware and data breaches, and organisations running a managed simulation programme with quarterly review cycles typically see their phish-prone percentage fall from an average starting point in the high twenties to under 5% within 12 months. The reduction in risk comes from the follow-through (the teachable moment and the trend reporting), not from sending the email alone.

The leading providers serving UK organisations in 2026 are Precursor Security (CREST-accredited human-led testing), KnowBe4, Proofpoint Security Awareness, Hoxhunt, Cofense, MetaCompliance, and usecure (self-service awareness-training platforms). Precursor is the only human-led testing service among these; the other six are self-service SaaS platforms your own team configures and runs.