The layer to buy alongside training · Verified 18 August 2026
Bitdefender GravityZone — Bitdefender GravityZone — the endpoint control that catches the click training did not prevent
No public list price; quoted at checkout by endpoint count
Awareness training reduces the click rate. It never takes it to zero, and it does nothing at all about a zero-click compromise or a credential already for sale. GravityZone is the control that has to hold when a busy registrar clicks anyway: consistently a top performer in independent AV-Comparatives and AV-TEST business endpoint testing, with EDR, risk analytics and device policy in one console rather than three. Bitdefender does not publish a list price — it is quoted at checkout by endpoint count, and we only publish figures we have read off a vendor page — so get the quote with your real device count and compare it against your training spend. If you buy only one of the two this year, buy the one that works while nobody is watching.
See GravityZone pricing Opens on the vendor’s site · CASRAI referral link
Compare against pure-play awareness vendors — KnowBe4, Proofpoint Security Awareness and Hoxhunt are the category leaders on content library depth and simulation tooling, and you should shortlist them for the human layer. They are not endpoint security and do not claim to be.
Editorial disclosure: CASRAI has commercial referral arrangements with some of the vendors named on this page, and may earn a commission if you subscribe to them. We name them here regardless of whether a link is present. We only recommend tools our editorial team has independently researched. Read our full disclosure policy.
In summary
- A credible programme has four parts: a module library, recurring phishing simulation, completion tracking that survives an audit, and role-based content. Anything missing one of those is a video library, not a programme.
- KnowBe4, Proofpoint Security Awareness and Hoxhunt lead the category on library depth and simulation realism. Shortlist them honestly — a page that pretends they do not exist is wasting your time.
- Phishing is how research organisations actually get breached: shared inboxes, grant correspondence from strangers, preprint and peer-review lures, and finance staff who are paid to open invoices.
- Verified 18 August 2026: Bitdefender GravityZone has no public list price — it is quoted at checkout by endpoint count. It is consistently a top performer in independent AV-Comparatives and AV-TEST business endpoint testing.
- Do not buy awareness training expecting it to satisfy CMMC or NIST 800-171 endpoint requirements. It satisfies the awareness and training family and nothing else.
The two layers, and what each one actually covers
Awareness training and endpoint security solve adjacent problems. Institutions that buy one and assume it covers the other are the ones that end up writing an incident report.
| Dimension | Awareness training (KnowBe4, Proofpoint, Hoxhunt) | Bitdefender GravityZone |
|---|---|---|
| Stops a convincing phishing email being clicked | Reduces click rate measurably over repeated cycles | No — it acts after the click, not before it |
| Stops the payload once someone has clicked | No | Yes — this is the core job: malware, ransomware behaviour, malicious scripts |
| Covers a zero-click or drive-by compromise | No — there is no human decision to influence | Yes — exploit and behavioural detection run regardless of user action |
| Produces evidence an auditor accepts | Completion records, simulation results, per-user history | Policy state, patch and risk posture, detection and response logs |
| Maps to CMMC / NIST 800-171 | Awareness and training family only | System and information integrity, configuration, audit and accountability |
| Published pricing | Quoted per seat; we do not publish figures we have not read off a vendor page | No public list price — quoted at checkout by endpoint count |
Verified 18 August 2026. We publish only prices we have read directly from a vendor page, which is why no competitor figures appear here.
What a real security awareness training programme contains
If you are solution-aware you already know you need this. The gap is usually scoping: you have been handed a mandate and asked what it will cost, and you cannot price something you cannot describe. Four components separate a programme from a folder of videos.
1. Module library and coverage
The library is where the category leaders genuinely earn their reputation, and it is the first thing to interrogate. Look for depth on phishing and business email compromise, credential hygiene and multi-factor fatigue, data handling and classification, removable media, physical and tailgating risk, social engineering by phone, and secure remote working. For a research organisation, add two that generic vendors treat as afterthoughts: handling of identifiable participant data, and the confidentiality rules around peer review and unpublished manuscripts. Ask for the actual module index before you sign anything, not the marketing summary.
2. Phishing simulation, on a cadence
A single annual simulation tells you almost nothing except who was on leave. Monthly or fortnightly is the range that changes behaviour, with templates that escalate in difficulty and — critically — a reporting button in the mail client so that reporting a suspicious message is one click rather than an email to a helpdesk address nobody remembers. The metric worth tracking is not click rate alone but the ratio of reports to clicks. A department where twelve people reported and one clicked is in a far better state than one where nobody clicked and nobody reported.
3. Completion tracking that survives an audit
Per-user completion records with dates, automatic reminders, and export you can hand to an assessor or an insurer without reformatting. If your organisation already runs a learning platform, check whether the vendor integrates with it or insists on being a second system of record — running two is how completion data drifts. Our note on choosing a healthcare learning management system covers that integration question in more detail.
4. Role-based content
This is where generic products fall down in institutional settings. A clinician needs content about patient data on shared devices and messages that impersonate a colleague on a ward. A lab technician needs content about instrument PCs that cannot be patched, and USB transfer between air-gapped kit. A finance or research-office administrator needs invoice fraud and payment-diversion content, because they are the ones paid to open attachments from people they have never met. A single all-staff module delivered identically to all three groups will bore two of them into clicking through it.
Why phishing is how research organisations actually get breached
Universities, hospital trusts and independent institutes have a threat profile that generic corporate training material does not describe well. Three structural features make the sector unusually exposed to social engineering.
Inbound mail from strangers is the job. A commercial company can plausibly train staff to distrust unexpected attachments from unknown senders. A research office cannot. Grant correspondence, collaboration requests, conference invitations, manuscript submissions and reviewer requests all arrive unsolicited from people the recipient has never met, often with a document attached. The heuristic that protects most organisations is unavailable here, so the training has to be specific enough to teach discrimination rather than blanket suspicion.
Shared and role-based accounts blur accountability. Departmental inboxes, rota accounts and shared lab logins mean the person who clicked is frequently not identifiable from the logs. That undermines both incident response and the per-user completion evidence your programme is supposed to generate. Fix the account model in parallel with the training or your reporting will always contain a gap.
Turnover is constant and seasonal. Rotating clinical staff, fixed-term postdocs, visiting researchers and cohorts of students arrive continuously. An annual training cycle systematically misses whoever joined in month two. Onboarding-triggered enrolment matters more here than in a stable workforce.
Layer onto that the sector’s attractiveness as a target — pre-publication data, clinical trial records, participant identifiers, and payment flows large enough that a diverted invoice is worth the effort — and phishing stops being a compliance box and becomes the actual attack path. Which is precisely why the technical layer beneath it is not optional.
Where awareness training stops working
Every credible study of awareness programmes shows the same shape: repeated simulation reduces click rate substantially, and then it plateaus above zero. It never reaches zero, and the residual is not a training failure. It is a structural property of asking thousands of busy people to make a security judgement under time pressure, hundreds of times a week, forever. A registrar between patients, a grants officer on a submission deadline and a technician mid-protocol will all eventually click something.
There are also whole attack classes with no human decision to influence:
- Zero-click compromise. An exploit that fires on message rendering or from a compromised site presents no choice to the user. No amount of training changes the outcome.
- Credentials stolen elsewhere. If a password was reused and leaked from a third-party breach, the attacker never needs to phish anyone.
- Supply chain and legitimate-tool abuse. A malicious update or an attacker using signed administrative tooling looks like normal activity to a trained user.
- Unpatchable instrument PCs. Common in labs, frequently running an operating system nobody will approve an update for, and often not attended by a trainable human at all.
This is the argument for buying the endpoint layer alongside the training rather than instead of it. Bitdefender GravityZone is where we point research organisations because it is consistently a top performer in independent AV-Comparatives and AV-TEST business endpoint testing, and because prevention, EDR, risk analytics and policy sit in one console — which matters when the security function is one person with a fraction of their week. Our GravityZone review goes through the console in detail, and EDR versus antivirus explains what the detection-and-response tier adds over signature scanning if that distinction is new to you.
What training does and does not satisfy for CMMC and NIST 800-171
If a federal contract or subaward has put CMMC or NIST 800-171 in front of you, be precise about what awareness training buys. It addresses the awareness and training control family. That is a real and required part of the framework, and you cannot pass without it.
It does not address the endpoint requirements — malicious code protection, system monitoring, flaw remediation, configuration baselines, audit logging — which sit in entirely separate families and are assessed separately. An assessor presented with completion certificates and nothing else will note the gap immediately. This is the single most common misunderstanding we see: an organisation buys a well-regarded training platform, ticks what it believes is the cyber requirement, and discovers at assessment that the majority of the practice count was never touched.
We have written the control-by-control walkthrough separately rather than restating it here — see CMMC compliance for research institutions for the scoping and evidence detail. For the adjacent question of what an audit costs when your funder or a commercial partner asks for a report instead, SOC 2 compliance cost has the numbers we could verify.
The practical sequence for most institutions: patch and endpoint posture first because it carries the most control weight and the most real risk reduction, awareness training in parallel because it is cheap and mandated, and the evidence layer joined up so one export answers both. If patching is the weak link, patch management software is the piece to read next.
How to choose, and who should not buy this
Shortlist the pure-play awareness vendors for the human layer. KnowBe4 has the largest content library in the category and the most mature simulation tooling. Proofpoint Security Awareness benefits from being tied to a threat-intelligence business, so its simulation templates track what is actually circulating. Hoxhunt takes a more adaptive, individualised approach that tends to hold attention better in workforces that resent mandatory e-learning. We do not publish their prices because we have not read them off a vendor page, and we will not estimate. Ask all three for a per-seat quote at your headcount and for the module index; the quotes will differ more than you expect at institutional scale.
Then buy the endpoint layer separately and deliberately. Bitdefender does not publish a list price either — GravityZone is quoted at checkout by endpoint count — so the comparison is quote against quote. Get both numbers in front of your finance lead in the same week. When budget is tight and you must sequence, sequence the technical control first: it is the one that works at 2am when nobody is available to make a good decision.
Do not buy this if
Do not buy a security awareness platform if you have fewer than about twenty-five staff and no compliance mandate. At that size the per-seat economics are poor, the reporting apparatus is overhead you will not use, and you will get more risk reduction per pound from enforced multi-factor authentication, a password manager and endpoint protection. Revisit it when a funder, an insurer or a contract actually asks — and until then spend the money on endpoint security sized for a small organisation.
Equally, do not buy training as your answer to a CMMC or NIST 800-171 mandate. It is one control family. Buying it and stopping is the most expensive way to fail an assessment, because you will pay twice: once for the platform, and again for the remediation programme after the gap analysis.
Get the endpoint quote before you sign the training contract
Bitdefender GravityZone has no public list price — it is quoted at checkout by your endpoint count, so the only way to know whether it fits beside your training budget is to price it. It is consistently a top performer in independent AV-Comparatives and AV-TEST business endpoint testing, and it covers the compromises that no amount of awareness training will prevent: zero-click exploits, reused credentials, unpatchable lab instruments. Price it with your real device count, then decide the sequencing.
Per-device annual licensing — see current offer
Price GravityZone by endpoint count Opens on the vendor’s site · CASRAI referral link
Frequently asked questions
What should cyber security awareness training for employees actually include?
Four things, and a product missing any of them is a video library rather than a programme. A module library with genuine depth on phishing, business email compromise, credential hygiene, data classification and social engineering. Recurring phishing simulation on at least a monthly cadence, with a one-click report button in the mail client. Per-user completion tracking with dates, reminders and clean export for auditors. And role-based content, so a clinician, a lab technician and a finance officer each see the lures aimed at them rather than one identical all-staff module. For a research organisation, also insist on coverage of participant data handling and peer-review confidentiality.
How does this compare with KnowBe4, Proofpoint Security Awareness or Hoxhunt?
Those three are the category leaders and you should shortlist them. KnowBe4 has the deepest content library and the most mature simulation tooling. Proofpoint benefits from an underlying threat-intelligence business, so its templates reflect campaigns actually in circulation. Hoxhunt is the most adaptive and tends to hold attention best in workforces that resist mandatory e-learning. We do not quote their prices because we only publish figures we have read directly off a vendor page. They are not competitors to Bitdefender GravityZone — they solve the human layer, GravityZone solves the technical one, and a serious programme buys both.
How much does Bitdefender GravityZone cost?
Verified 18 August 2026: there is no public list price. GravityZone is quoted at checkout based on your endpoint count, which is genuinely how it is sold rather than an evasion — a 40-device institute and a 4,000-device trust are not comparable line items. We will not publish an estimate we have not read off a vendor page. Run the checkout quote with your actual device count, including lab instrument PCs and any managed laptops that live off-site, and put that figure next to your per-seat training quote before you commit to either. If you want the console detail before pricing it, our GravityZone review walks through what you get.
How often should we run phishing simulations?
Monthly or fortnightly for most institutions. Annual simulation measures who was at their desk that week and changes almost nothing. Escalate template difficulty over the cycle rather than repeating the same obvious lure, and track the report-to-click ratio rather than click rate alone — a team that reports heavily is in a better state than one that neither clicks nor reports, because the second team is simply deleting things silently. Where you have seasonal intake of students, rotating clinical staff or visiting researchers, trigger enrolment on onboarding as well, or you will systematically miss everyone who joined between cycles.
Does security awareness training satisfy CMMC or NIST 800-171?
It satisfies the awareness and training control family and nothing beyond it. The endpoint requirements — malicious code protection, system monitoring, flaw remediation, configuration baselines, audit logging — sit in separate families and are assessed separately. Presenting completion certificates as your cyber evidence is the most common and most expensive misunderstanding we see, because the gap surfaces at assessment rather than at budget time. Our CMMC compliance guide for research institutions covers the scoping and evidence requirements control by control.
Our staff already get a lot of unsolicited email. Does training even work here?
It works, but it has to be written for the reality. Research offices, journals and grant teams receive attachments from strangers as a normal part of the job, so blanket “do not open unexpected attachments” guidance is unusable and staff learn to ignore it. Training for this sector has to teach discrimination — verifying a sender domain against the institution it claims, recognising payment-detail changes on an invoice, spotting reviewer and manuscript lures — rather than blanket suspicion. Pair it with a shared-inbox model that keeps individual accountability intact, otherwise your logs will never tell you who clicked.
If we can only fund one thing this year, training or endpoint security?
Endpoint security, unless a contract explicitly requires the training and gives you no choice. Awareness training reduces click rate and then plateaus above zero; it does nothing about zero-click exploits, credentials leaked in a third-party breach, supply-chain compromise, or the unpatchable instrument PC in the corner of the lab that has no trainable human attached to it. Bitdefender GravityZone covers those, is consistently a top performer in independent AV-Comparatives and AV-TEST business endpoint testing, and is quoted by endpoint count so a small institute is not priced like a hospital trust. Get the quote, then add the training layer as soon as budget allows — the two are complements, not alternatives.







