---
title: "How security awareness vendors win customers from AI search"
description: "By being named, with checkable proof, when IT leads, MSPs and CISOs ask AI which training meets their insurer, auditor and budget."
canonical: "https://underneath.agency/resources/security-awareness-training-customers-ai-search"
published: 2026-10-07
updated: 2026-10-08
publisher: "Underneath (https://underneath.agency/agent)"
entity: "https://underneath.agency/.well-known/entity.json"
---
Guide · AI search

# How do security awareness training vendors win customers through AI search?

By being the vendor an AI assistant names, with proof the buyer can check, when an IT lead, an MSP or a CISO asks which training will satisfy their insurer, their auditor and their budget. Security awareness training is bought in high volume at modest contract values, often under a compliance deadline, so a place in the answer matters more than a click. The evidence that AI search shapes this specific category is still indirect, and we say where.

## The short version

1. Many purchases start with an insurer or an auditor. [Marsh](https://www.marsh.com/en-gb/about/media/incident-response-planning-emerges-key-cybersecurity-control-reducing-cyber-risk.html), studying the 12 controls cyber insurers track, ranked awareness training and phishing testing among the four most linked to fewer claims, and [Coalition](https://www.coalitioninc.com/announcements/2025-cyber-claims-report) traced 60% of its 2024 cyber insurance claims to email fraud.
2. Contracts are modest, so volume matters: the median buyer of KnowBe4 pays $7,763 a year, according to [Vendr’s data](https://www.vendr.com/marketplace/knowbe4) from 682 purchases.
3. The market is concentrated. KnowBe4 was bought for [$4.6 billion](https://www.vistaequitypartners.com/news/knowbe4-to-be-acquired-by-vista-equity-partners-for-4-6-billion/) in 2022, and a challenger’s CEO claims it holds over 80% of the market. For challengers, the shortlist is the battle.
4. The category is being renamed: Gartner predicts 80% of enterprises will run a staffed human risk management program by 2030, up from 20% in 2022. New names bring new buyer questions.
5. In our studies, 24.2% of the “best X” lists AI engines cited ranked their own publisher first, and adding “on a tight budget” to a question kept the original first brand only 15.3% of the time.

## Who signs up for security awareness training, and what does one account pay?

Mostly IT and security teams buying per-seat subscriptions, from small offices to global enterprises, often through managed service providers.

Who holds the budget depends on headcount. In a small firm it is the IT manager or an outside managed service provider (MSP). In a large one it is a security awareness lead inside the CISO’s team, working with HR, which owns training records, and internal communications. That lead is usually stretched. The [SANS Institute’s 2025 Security Awareness Report](https://www.sans.org/press/announcements/security-awareness-report-2025), based on more than 2,700 practitioners, found lack of time and staffing are the two biggest challenges. SANS says it takes at least 2.8 dedicated full-time staff to meaningfully influence behavior.

Contract values are modest by enterprise software standards. Vendr’s transaction data put the median KnowBe4 buyer at $7,763 a year, in a range from $1,929 to $19,419. Pricing is per user, per year, with volume discounts at seat thresholds and multi-year terms. A single customer is rarely a large deal. The business is built on many of them renewing.

The leader’s numbers show the scale of that model. When [Vista Equity Partners agreed to buy KnowBe4](https://www.helpnetsecurity.com/2022/10/12/vista-equity-partners-knowbe4/) for $4.6 billion in 2022, it served more than 52,000 organizations. Its [press page](https://www.knowbe4.com/press/knowbe4-report-reveals-security-training-reduces-global-phishing-click-rates-by-86) now says it is trusted by more than 70,000.

Small and large buyers have different problems, which matters for what they ask. In KnowBe4’s 2025 benchmark, organizations with more than 10,000 employees started with 40.5% of staff likely to fall for a simulated phish, against 24.6% for organizations with up to 250 employees.

## Why do companies buy it: compliance, insurance or real risk?

All three, and compliance or insurance deadlines often decide when the purchase happens.

**The risk is real.** The [2025 Verizon Data Breach Investigations Report](https://news.clearancejobs.com/2025/04/30/60-of-breaches-still-tied-to-human-mistakes-what-the-2025-dbir-means-for-fsos-and-leaders/) analyzed 22,052 security incidents and found the human element involved in 60% of them, as summarized by ClearanceJobs. In the SANS survey, 80% of organizations ranked social engineering as their number one human risk.

**Insurers ask about it.** Coalition found that 60% of its 2024 claims came from business email compromise and funds transfer fraud, both of which usually start with a deceived employee. [Marsh](https://www.marsh.com/na/services/cyber-risk/insights/cyber-resilience-twelve-key-controls-to-strengthen-your-security.html) says insurers now require specific cybersecurity controls, “placing insurability at stake.” Its 2025 analysis of the 12 controls the insurance industry tracks ranked awareness training and phishing testing among the four most linked to fewer breach-based claims.

**Rules require it.** Payment card rules, as [SecurityMetrics explains](https://maintenance.securitymetrics.com/blog/security-awareness-training), now require training to cover phishing and social engineering threats (PCI DSS requirement 12.6.3.1), mandatory since March 31, 2025. In Europe, [Article 20 of the NIS2 Directive](https://www.springlex.eu/en/packages/nis2/nis2-directive/article-20/) requires board members of covered companies to follow cybersecurity training and asks countries to encourage regular training for employees.

The practical effect, we infer, is that many buyers arrive with a deadline and a checklist: a renewal questionnaire, an audit date, a board requirement. They want a vendor that clearly meets it, quickly.

## At what point do awareness training buyers turn to AI assistants?

At the research step, where buyers turn a compliance requirement into a shortlist, though no study measures this category alone.

Across software as a whole, the shift is clear. Of 1,076 software buyers polled by the review platform [G2](https://company.g2.com/news/g2-research-the-answer-economy) in March 2026, 51% said that when research starts, they now reach for an AI chatbot more often than for Google. G2 profits from selling visibility to vendors, and its sample spans all software rather than phishing simulation and training tools.

Google itself nearly always adds an AI layer to software searches. Of the 1,248 US searches in [our AI Overview study](https://underneath.agency/research/ai-overviews-frequency-study), the B2B software and technology keywords carried an AI Overview, Google’s summary above the links, most often: 96.0% of them, the top rate among eight industries.

Two features of this market make AI research likely, we infer. Buyers are short of time, as SANS found. And many purchases are small and fast: in [Capterra’s 2025 survey](https://capterra.com/resources/tech-trends-successful-buyer-purchase-journey/) of 3,500 software buyers, most successful buyers (57%) took 3 months or less to evaluate their options. An IT manager with an insurance form due Friday is the kind of buyer who asks an assistant for a short list and acts on it.

## Which questions do security awareness buyers ask AI assistants?

Compliance, insurance, alternatives, comparisons, new threats and price. The sample prompts in this table are our own, written for an IT manager, CISO or MSP; none was taken from an actual buyer.

| Buyer and stage | Illustrative prompt |
|---|---|
| Small business, compliance | “What security awareness training meets PCI DSS 4.0 phishing requirements for a 60-person retailer?” |
| Insurance renewal | “What phishing training does my cyber insurer expect, and which tools produce the reports they ask for?” |
| Alternatives | “What are cheaper alternatives to KnowBe4 for a 200-person company?” |
| Enterprise comparison | “Hoxhunt or Proofpoint for 15,000 employees in 12 languages?” |
| New threats | “Which platforms train staff to spot deepfake voice calls from executives?” |
| MSP | “Best security awareness platform for an MSP managing 80 small clients?” |
| Board and HR | “What does NIS2 require for board cybersecurity training?” |

Each prompt carries a constraint: a rule, a size, a budget, a language, a channel. Constraints change the answer. In [our rewording study](https://underneath.agency/research/ai-prompt-phrasing-study), adding “on a tight budget” kept the original first brand only 15.3% of the time, and adding “I run a small business with about 10 employees” 40.6%. A vendor named for the enterprise version of a question may be missing from the small business version.

The emerging-threat questions are a real opening. [Proofpoint’s 2024 State of the Phish](https://www.proofpoint.com/us/newsroom/press-releases/proofpoints-2024-state-phish-report-68-employees-willingly-gamble) found only 23% of organizations educate users on generative AI safety. Buyers looking to close that gap are asking questions where no incumbent has yet earned the answer.

## How does an AI answer turn into a security awareness customer?

Through one of three short paths: a self-serve trial, an enterprise evaluation or an MSP partnership.

1. **Small business, direct.** An assistant names three or four platforms. The buyer runs a free phishing test or a trial with one or two, then signs an annual per-seat contract that renews if the reports satisfy the insurer and auditor.
2. **Enterprise.** The awareness lead uses AI answers to build a long list, then runs a formal evaluation with security, HR and procurement. The win is a multi-year contract, often expanded later to email security or other modules.
3. **MSP.** An MSP asks which platform suits many small clients. One decision can bring a vendor dozens of client accounts, we infer, which makes MSP-phrased questions unusually valuable.

The amounts per customer are modest, so the channel must work at volume and at low cost. AI answers may suit that: the assistant does the first round of qualification before the buyer arrives, we expect. Whether it does is not yet measured, and the click rarely shows in analytics; see [what lost clicks mean for pipeline](https://underneath.agency/resources/ai-answers-pipeline-revenue).

## Why might an assistant recommend one phishing training platform over another?

No platform documents how it picks vendors; studies point to reviews and published rankings, and buyers want measurable outcomes.

**What Google discloses.** A question about awareness training can become several searches: Google says AI Overviews and AI Mode [may use a “query fan-out” technique](https://developers.google.com/search/docs/appearance/ai-features) that issues multiple related searches. No platform, Google included, publishes how training vendors are chosen.

**Observed in our studies.** In [our hidden-searches study](https://underneath.agency/research/ai-hidden-searches-study), ChatGPT searched for reviews in 46.2% of its answers and for a named publication, ranking or award in 43.8%. And when [our reputation study](https://underneath.agency/research/is-it-legit-ai-reputation-study) asked “Is this brand legit?”, a review or complaint platform appeared among the sources in 88.0% of answers.

“Best security awareness training” lists deserve a warning. Many are published by vendors in the category. In [our study of self-ranking lists](https://underneath.agency/research/self-promoting-best-lists-study), 24.2% of the numbered “best X” lists AI engines cited put their own publisher first. Such lists made up only 1.1% of all citations, so they are not a shortcut. We cover the wider pattern in [why “best of” lists shape AI recommendations](https://underneath.agency/resources/best-of-lists-ai-recommendations).

**What this market rewards.** Buyers and analysts are moving from completion rates to measured behavior. Gartner, as quoted by [Hoxhunt](https://hoxhunt.com/blog/gartner-names-hoxhunt-a-security-behavior-and-culture-change-program-representative-provider), predicts that by 2030 control frameworks will measure behavior change rather than compliance-based training. Benchmarks already circulate: KnowBe4 reports a baseline of 33.1% of employees falling for simulations, falling to 4.1% after 12 months of training. That is vendor-reported, from 67.7 million simulations.

**Our inference.** A reasonable expectation is that vendors with public, specific proof are easier for assistants to name and for buyers to trust. That proof includes compliance mapping, outcome data with a method, independent reviews and analyst mentions. Nobody has yet tested that for awareness training vendors.

## What does an awareness training vendor lose when assistants leave it out?

Mostly shortlist places in a concentrated market, though no one has put a dollar figure on it.

- **Leaders get named by default.** In a [BankInfoSecurity interview](https://www.bankinfosecurity.com/adaptive-security-gets-81m-series-b-for-ai-deepfake-defense-a-30332), Adaptive Security’s CEO said KnowBe4 holds over 80% of the market. That is a competitor’s claim, not audited data. Still, assistants often default to market leaders, as we explain in [do AI assistants favor big brands](https://underneath.agency/resources/do-ai-assistants-favor-big-brands). A challenger that is not named loses before it can compete on price or design.
- **Being named is not a fixed state.** Ask ChatGPT the same question five times, as [our consistency study](https://underneath.agency/research/ai-recommendation-consistency-study) did, and only 25.2% of the brands it names turn up in every run.
- **Missed moments recur yearly.** Insurance renewals, audits and annual training cycles come round every 12 months. A vendor missing from the answer at renewal waits a year, we infer.
- **New money is going to new threats.** [SecurityWeek](https://www.securityweek.com/adaptive-security-raises-81-million-in-series-b-funding/) reports Adaptive raised $81 million in a Series B to train staff against deepfakes and AI-driven scams. Funded entrants are competing for the same new questions.

## What does GEO look like for a phishing and awareness training vendor?

It puts your compliance mapping and outcome data where assistants and buyers can check them, with no guaranteed placement.

1. **Name the category consistently.** Decide how you describe yourself: security awareness training, human risk management or both. Use the same words on your site, review profiles, partner directories and analyst briefings. Mixed labels confuse an IT manager and an assistant alike, and our guide to [fixing wrong brand information in AI answers](https://underneath.agency/resources/fix-wrong-brand-information-in-ai-answers) shows how to clean them up.
2. **Publish compliance mapping in plain pages.** One page each for PCI DSS, HIPAA, NIS2, insurance questionnaires and common frameworks, saying exactly which reports and records you produce.
3. **Publish outcome data with its method.** Benchmark reports are cited widely. Say how the numbers were measured and what they cannot show.
4. **Earn independent reviews and coverage.** Ask customers for detailed reviews on platforms buyers use, by company size and use case. Pursue analyst recognition and security press, not self-ranked lists. Our piece on [building authority for AI search](https://underneath.agency/resources/how-brands-build-authority-for-ai-search) covers those routes in more detail.
5. **Serve each buyer separately.** Write honest pages for small businesses, enterprises and MSPs, plus alternatives and comparison pages; see [whether comparison pages help](https://underneath.agency/resources/do-comparison-pages-help-b2b-ai-citations).
6. **Measure with real constraints.** Track several assistants with budget, size, MSP and regulation wording, asking each question more than once.

## What don’t we know yet about AI search in security awareness buying?

Two things: how many training buyers ask AI assistants, and whether being named sells more seats.

- **No category survey.** The AI-use figures here cover software buyers in general.
- **Vendor data dominates.** The phishing benchmarks come from vendors, the 80% share claim from a competitor, and the pricing from a procurement platform’s sample.
- **Seat sales are unproven.** Among the 45 studies of AI search optimization reviewed by [Martinez](https://arxiv.org/abs/2607.14035), the evidence tying it to traffic and conversions was the thinnest.
- **Answers change.** Results vary between runs, wordings and assistants, so one test proves little.

## How can an awareness training vendor check its standing before the next renewal cycle?

Test the questions IT managers, CISOs and MSPs ask, with their budget and compliance limits, and note who gets named.

Write 20 to 30 prompts across the three paths: small business, enterprise and MSP, each with compliance, insurance, budget and new-threat wording. Run each several times across ChatGPT, Google AI Overviews and AI Mode, Gemini, Perplexity, Copilot and Claude. Note who is named, which sources are cited and what is said about your compliance coverage and results. The broader security software picture is in [how cybersecurity software firms earn revenue from AI search](https://underneath.agency/resources/cybersecurity-software-revenue-from-ai-search).

To go through the results with people who run these checks every week, [ask us for a review of your awareness training visibility](https://underneath.agency/contact). We will show which buyer questions name you, which name competitors instead, and which gaps in your public proof are most likely costing you trials, MSP partners and seat renewals. Our [generative engine optimization service](https://underneath.agency/services/generative-engine-optimization) page describes the follow-on work, such as compliance mapping pages, outcome data with its method and separate pages for each buyer.

## Frequently asked questions

### Do small businesses use AI to choose security awareness training?

No study isolates them. Across software, 51% of buyers in G2’s survey start research with AI chatbots more often than Google, and small buyers decide fast.

### Should we publish our phishing click-rate results?

Yes, with the method. Buyers and insurers ask for measured results, and KnowBe4’s widely cited 33.1% baseline shows how often benchmark data gets repeated.

### Do “best security awareness training” lists on our own blog help?

Probably little. Self-ranking lists were 1.1% of AI citations in our study; independent reviews and rankings are the stronger evidence.

### Should we position as human risk management instead?

Use both terms if both fit. Gartner expects 80% of enterprises to run human risk management programs by 2030, but many small buyers still search for awareness training.

### How quickly can AI visibility turn into customers here?

Faster than in most security categories, we expect, because most successful software buyers decide within 3 months. It is not yet measured.

## Sources

- Marsh (n.d.), [Cyber resilience: twelve key controls to strengthen your security](https://www.marsh.com/na/services/cyber-risk/insights/cyber-resilience-twelve-key-controls-to-strengthen-your-security.html)
- Marsh (2025-08-27), [Incident response planning emerges as key cybersecurity control in reducing cyber risk](https://www.marsh.com/en-gb/about/media/incident-response-planning-emerges-key-cybersecurity-control-reducing-cyber-risk.html)
- Coalition (2025-05-07), [Coalition 2025 Cyber Claims Report](https://www.coalitioninc.com/announcements/2025-cyber-claims-report)
- Vendr (2026), [KnowBe4 software pricing and plans](https://www.vendr.com/marketplace/knowbe4)
- Vista Equity Partners (2022-10-12), [KnowBe4 to be acquired by Vista Equity Partners for $4.6 billion](https://www.vistaequitypartners.com/news/knowbe4-to-be-acquired-by-vista-equity-partners-for-4-6-billion/)
- Help Net Security (2022-10-12), [Vista Equity Partners acquires KnowBe4 for $4.6 billion in cash](https://www.helpnetsecurity.com/2022/10/12/vista-equity-partners-knowbe4/)
- KnowBe4 (2025-05-13), [KnowBe4 report reveals security training reduces global phishing click rates by 86%](https://www.knowbe4.com/press/knowbe4-report-reveals-security-training-reduces-global-phishing-click-rates-by-86)
- SANS Institute (2025-08-13), [Security Awareness Report 2025](https://www.sans.org/press/announcements/security-awareness-report-2025)
- ClearanceJobs (2025-04-30), [60% of breaches still tied to human mistakes: what the 2025 DBIR means](https://news.clearancejobs.com/2025/04/30/60-of-breaches-still-tied-to-human-mistakes-what-the-2025-dbir-means-for-fsos-and-leaders/)
- SecurityMetrics (n.d.), [New PCI requirements: security awareness training](https://maintenance.securitymetrics.com/blog/security-awareness-training)
- European Union, via Springlex (2022-12-27), [NIS2 Directive, Article 20](https://www.springlex.eu/en/packages/nis2/nis2-directive/article-20/)
- Hoxhunt, quoting Gartner (2022), [Gartner names Hoxhunt a Security Behavior and Culture Program Representative Provider](https://hoxhunt.com/blog/gartner-names-hoxhunt-a-security-behavior-and-culture-change-program-representative-provider)
- Proofpoint (2024-02-27), [2024 State of the Phish report](https://www.proofpoint.com/us/newsroom/press-releases/proofpoints-2024-state-phish-report-68-employees-willingly-gamble)
- BankInfoSecurity (2025), [Adaptive Security gets $81M Series B for AI deepfake defense](https://www.bankinfosecurity.com/adaptive-security-gets-81m-series-b-for-ai-deepfake-defense-a-30332)
- SecurityWeek (2025), [Adaptive Security raises $81 million in Series B funding](https://www.securityweek.com/adaptive-security-raises-81-million-in-series-b-funding/)
- G2 (2026-04-15), [In the Answer Economy, don’t win the click, win the answer](https://company.g2.com/news/g2-research-the-answer-economy)
- Capterra (2025), [Capterra’s 2025 Tech Trends Report](https://capterra.com/resources/tech-trends-successful-buyer-purchase-journey/)
- Google Search Central (2025), [AI features and your website](https://developers.google.com/search/docs/appearance/ai-features)
- Martinez (2026), [Optimizing Visibility in Generative Engines: A Critical Survey of Generative Engine Optimization (2023-2026)](https://arxiv.org/abs/2607.14035), arXiv:2607.14035.
- Underneath (2026), [When does Google show an AI Overview? 1,248 US searches](https://underneath.agency/research/ai-overviews-frequency-study)
- Underneath (2026), [Does rewording a question change AI brand recommendations?](https://underneath.agency/research/ai-prompt-phrasing-study)
- Underneath (2026), [The hidden searches AI assistants run before they answer](https://underneath.agency/research/ai-hidden-searches-study)
- Underneath (2026), [“Is this brand legit?” How AI assistants build a reputation](https://underneath.agency/research/is-it-legit-ai-reputation-study)
- Underneath (2026), [How many “best of” lists cited by AI rank their own brand first?](https://underneath.agency/research/self-promoting-best-lists-study)
- Underneath (2026), [Ask an AI the same question 5 times: do the brands change?](https://underneath.agency/research/ai-recommendation-consistency-study)

---

This is the Markdown twin of https://underneath.agency/resources/security-awareness-training-customers-ai-search. The HTML page is canonical. Publisher: Underneath, https://underneath.agency/agent. Site index: https://underneath.agency/llms.txt.
