OutThink vs Hoxhunt: what comes after your reporting rate goes up
Most comparisons on this page type assume you are unhappy. If you are running Hoxhunt, you probably are not. Reporting is up, people engage with the training, and nobody is complaining. That is a real achievement and it is not nothing.
The question that brings people here is the next one. Reporting went up. Did risk go down? And if leadership asks which fifty people are most at risk today and why, does the platform answer.
Compliance training, phishing simulations, campaigns and awareness months. Table stakes, and not where human risk falls.
All four jobs – Motivate, Educate, Activate, Correct – running autonomously across the whole workforce.
Human risk quantified from real behavioral signal in your security stack, and fed back into SOC, IAM and GRC decisions.
Risk-based access controls, user self-remediation, and behavioral governance extended to AI agents.
Hoxhunt straddles L1 and L2: it does Educate and parts of Motivate well through adaptive phishing and gamification, and it earns real engagement doing it. The open questions are Activate beyond the inbox and what triggers Correct. Apply the four tests to both vendors.
Before you build the comparison grid
- The question that decides this is not whether people engage. It is whether anyone can tell you which fifty people are most at risk today and why. Reporting rate cannot answer that, because it measures one behavior in one channel and says nothing about access, targeting, device posture or the other 80% of security behaviors.
- What changing looks like: RelateCare’s click rate fell from 8% to 1%, reporting doubled from 17% to 34%, and credential submission halved.1
- What you keep: your report button, your LMS, your reporting rate as a scored behavior, and the gamification, since CyberQ has leaderboards and progression too.
- What Hoxhunt does better: engagement mechanics, and it is not close. Their adaptive difficulty engine is real and their simulation pipeline is genuinely threat-grounded.
- Who we are: founded in 2019 by CISOs who lived this problem, seven years of purpose-built HRM engineering, 100+ enterprise deployments.
Both platforms drive engagement. The difference is whether that engagement is converted into a risk position designed to be consumed by your SOC, IAM and GRC teams, or whether engagement is where the measurement stops.
First, what Hoxhunt does well
We compete with Hoxhunt. Discount our opinion accordingly, so here is the part we have no incentive to write.
- Their engagement mechanics are the strongest we have seen, and the adaptive difficulty engine adjusting per user is real. The result is a training experience people opt into rather than endure, which is not a small achievement in this category.
- Their simulation pipeline is real. Simulations updated continuously from actual phishing that bypassed enterprise filters, drawn from a very large live dataset. This is genuine threat-grounded testing, not a template library with a refresh cycle.
- Localization is deep. Broad multilingual coverage, and not a gap we would claim against them.
- Their content gap has closed. The 2026 launch of an AI content studio turning policy documents into multilingual custom lessons removed what used to be a real weakness, and it repositioned their own SAT argument from content quantity to content relevance.
- The SOC-automation add-on is credible, with AI triage of reported email for teams that need report-volume handled.
- They are analyst-recognized on customer experience, including Gartner Peer Insights Customers' Choice. Their Gartner Peer Insights and G2 pages are worth reading before you read ours.
If your program’s problem is that nobody engages, Hoxhunt solves that problem and solves it well. This page is for the reader whose problem is what happens next.
On employee experience, since that is usually the objection
The assumption behind most Hoxhunt evaluations is that depth costs you the employee. It is a fair assumption, because for twenty years it was true. It is not what our deployments look like.
- People get a score they own. CyberQ gives every person a personal cyber-competence score they can see, understand and improve, the same way they own any other professional skill. Each month they get a snapshot of their own security behaviors and month-on-month progress they can actually feel.
- Learning becomes a pull, not a push. People choose to take more training from inside CyberQ, to climb the leaderboard and hold the top level, and Cyber Ranges join that from late 2026. Voluntary learning is the point, not a side effect.
- Less training, not more. Dynamic content allocation sends each person the modules their risk actually calls for, instead of pushing the full module set at everyone. Relevance goes up and volume goes down at the same time.
- The training asks, not just tells. As people go through it they can say what is not working, what is hard to comply with, and where they need support. Across thousands of employees that turns the workforce into a listening network, and it means people are being consulted rather than tested.
- It fits your culture, not ours. Choose illustrated and playful or live-action and serious. Culture fit is what earns attention.
- It reaches everyone. WCAG 2.2 compliant, with characters of all ages, races, genders and abilities.
- And there is a version of this people take home. Free security training for children aged 6 to 18, offered as an employee benefit. Many people care more about protecting their children online than about anything a security team says to them at work.
- Recognition comes from their manager, not from us. The manager view lets a line manager congratulate or nudge their own team on cyber behaviors, and a message from your own manager carries weight a security team you have never met cannot.
Gamification is one way to earn attention. It is not the only one, and on its own it reaches the people who are willing to play.
Where the platforms diverge: the four jobs
Across more than 100 enterprise deployments we identified four critical jobs that every successful human risk program shares: Motivate, Educate, Activate, Correct. All four, running continuously and autonomously across the entire workforce.
They are not a menu. They are a system. Motivating without targeted education and people forget the content in three weeks. Educating without correcting at the moment of risk and knowledge never becomes behavior. Correcting without understanding the person and it feels like surveillance. Each job depends on the other three, so the missing pieces undermine the ones you have – which is why the useful question is job by job rather than a total.
EducateBoth platforms do this, differently
Hoxhunt adapts phishing difficulty per person. We generate the training content itself per person, from their role, their behavior, what motivates them and the choices they make as they go, across every security topic rather than the inbox alone. Roles are pre-mapped with AI from your directory and validated by each user.
Ask both vendors the same question: does the platform adapt what the person is taught, or how hard the test is? Both are legitimate. They are not the same thing.
MotivateThe job most platforms skip
Engagement mechanics motivate the people who respond to competition. They do not tell you what motivates everyone else.
A short baseline assessment inside the first campaign tells us who responds to personal relevance, who to professional pride, who needs their confidence rebuilt, and who is already a champion. Every downstream interaction is then tailored to that. Separately, as people work through training they self-report their ability and motivation to perform the behaviors they have just learned, mapped to the Fogg behavior model, which is the strongest available signal on whether the training landed.
This is the difference between a platform that makes security engaging and a platform that knows why each person does or does not act. Both matter. Only one of them tells you what to fix.
ActivatePractice beyond the inbox
If practice stops at phishing simulations, the other 80% of security behaviors remain untested and untrained.
Today that means non-phishing behaviors covered in adaptive training and in nudges triggered by real data-handling, browsing and endpoint events from your security stack, so the behavior is addressed where it actually happens rather than only in a module.
From late 2026, Cyber Ranges add immersive, branching, self-adapting practice across deepfake CEO video, vishing, smishing, data sharing and handling, secure browsing, endpoint security, social media, and physical security and clean desk, with the first eight ranges deploying. Vishing and smishing are rehearsed safely in-platform rather than by calling or texting employees' personal mobiles.
Ask what is trained outside the inbox on both sides, and ask what is shipping versus roadmap. We have told you ours.
CorrectWhat triggers the intervention
Real-time correction needs three things working together: live behavioral data from your security systems, an AI engine that understands the context of each event, and a delivery mechanism that reaches the right person at the right moment. Most platforms have at most one of the three.
Our nudges fire from live signal in your EDR, DLP, web filter and IAM systems, and land in Teams or Slack when the person is actually active. A nudge triggered by a simulation result is correction after a test. A nudge triggered by a real risky action is correction at the moment of risk.
And then Level 3, which needs all four
At Level 3, human risk becomes quantified on real behavior from your security systems, the attitudes driving it, level of access, how targeted the person is, device security, and workplace factors such as email fatigue and collaboration networks.
Every vendor now claims a risk score, so the only question that separates them is what data feeds it. Hoxhunt publishes individual, organization and SOC-level dashboards built on engagement and reporting behavior. Ask which inputs to their score originate outside their own product. A score built largely from a platform’s own reporting and simulation results is a closed loop, and reporting rate is an input rather than an outcome.
A closed-loop score
- Simulation clicks and reports
- Training completion and quiz results
- Time spent in the vendor’s own modules
- Engagement inside the awareness console
- Vendor-supplied threat intelligence
Measures how people behave inside the vendor’s product. Useful for running the program. Hard for a SOC, IAM or GRC team to act on.
A stack-fed score
- EDR and endpoint events
- DLP and data-handling events
- Web gateway and browsing decisions
- Email and authentication / IAM signal
- Attitudes, access level, how targeted the person is, device security
- Workplace factors: email fatigue, collaboration networks
Measures how people behave at work. Defensible enough to feed access approvals, policy exceptions and incident triage.
The four tests that settle it
Do not take our comparison table on faith, ours or anyone’s. These are the four questions to put to every vendor on your shortlist, including us.
If the answer to the L2, L3 and L4 questions is yes, you have found a genuine HRM platform. If not, you are looking at part of a program rather than a platform for one.
There isn’t one. If the program is built around phishing simulations, generic training campaigns, newsletters, posters and Cybersecurity Awareness Month activities, it is L1.
Can the platform execute all four L2 critical jobs – Motivate, Educate, Activate and Correct – autonomously, across the entire organization, and across the full spectrum of security behaviors?
Is the risk quantification built on actual behavioral data from security systems, or on simulation results and training completion?
Does it surface actionable intelligence from user interactions, generate prioritized improvement actions across people, process and technology, and feed human risk intelligence into SOC, GRC, ticketing and identity systems?
Can the platform adjust access controls from human risk scores, integrating directly with identity providers? Can it enable user self-remediation that shifts responsibility from the SOC to the individual? Is it architected to extend behavioral governance to AI agents, not just human users?
OutThink and Hoxhunt, side by side
The Hoxhunt column contains only statements traceable to their own public material or published third-party sources. Where we cannot verify something, the cell says so and tells you to ask them.
| What to ask | OutThink | Hoxhunt (public information, July 2026) |
|---|---|---|
| Coverage of the four L2 jobs | All four run autonomously across the workforce: Motivate on attitudes and motivational segmentation, Educate through per-person generated content, Activate through Cyber Ranges beyond phishing, Correct from live security-stack signal. | Educate is strong and Motivate is partial through engagement mechanics. Ask what covers Activate outside the inbox, and what triggers Correct other than a simulation result. |
| What the platform knows about a person before it trains them | A short baseline assessment produces four motivational segments within days, and every downstream interaction is tailored to them. Plus self-reported ability and motivation per behavior, mapped to the Fogg model. | Engagement and reporting behavior. Ask whether attitudes and motivation are captured at all, and how the platform personalizes for someone who never engages. |
| What adapts | The training content itself, generated per person from role, behavior, motivational driver and in-flow choices, across every security topic. | An adaptive difficulty engine that adjusts simulation difficulty per user. Ask whether the platform adapts what the person is taught or how hard the test is. |
| Simulation content source | Broad parity, and worth saying so. Both platforms test on real attacks caught in the wild rather than static templates. Ours arrive via the Real-Time Threats Engine, enriched with OSINT and threat intelligence and scored against the NIST Phish Scale. | Continuously updated from real phishing that bypassed enterprise filters, from a very large live dataset. The differentiator is not the source. It is what happens after the click. |
| What happens after someone clicks | Automated root-cause analysis diagnoses why that person clicked, whether URL literacy, authority bias, click speed or email fatigue, and auto-enrolls them in remediation matched to that specific weakness. | In-the-moment feedback and learning. Ask whether remediation is differentiated by the reason for the click, or by the fact of it. |
| Practice beyond phishing | Cyber Ranges across deepfake video, vishing, smishing, data handling, browsing, endpoint, social media and physical security, rehearsed safely in-platform. First eight deploying late 2026. | Ask what is trained outside the inbox, whether deepfake and voice scenarios are self-serve or delivered as a managed engagement, and whether voice and text simulations contact employees' personal mobiles. |
| What triggers correction | Live signal from EDR, DLP, web filter and IAM systems, delivered in Teams or Slack when the person is active, plus urgent broadcast for a live incident. | Their published material describes nudges and feedback around simulations and reported email, and a SOC-automation module for report triage. Ask which of your own security systems can trigger an intervention. |
| What feeds the risk score | Human Risk Intelligence ingests behavior from EDR, DLP, web, email and IAM, plus attitudes, level of access, how targeted the person is, device security and workplace factors. | Engagement and reporting behavior across individual, organization and SOC dashboards. Ask which inputs originate outside their own product. |
| Whether the score is one HR would use | CQ is a cyber-competence score spanning every relevant security behavior, defensible enough to feed HR systems for appraisal and recognition where governance allows. A customer who wants phishing weighted heavily can simply enable the three phishing behaviors. | A phishing and engagement-derived score. Ask whether HR would build performance criteria on it. |
| The manager layer | A manager view that lets line managers nudge and congratulate their own teams on cyber behaviors. In a large enterprise, engaged managers outnumber the security team many times over. | Leaderboards and team views. Ask to see what a line manager can do, not what a leaderboard shows. |
| Reaching the least engaged | Dynamic allocation, multi-channel nudges, and delivery to frontline and OT populations without corporate email. In one deployment, 100% coverage including OT workers with no email, in four languages. | Their model is built on voluntary engagement and habit formation, which is what makes it work. Ask what the program does for your highest-risk, least-engaged employees, and how users without a mailbox are enrolled and evidenced. |
| Localization | 40+ languages across content, the full end-user experience, nudges, and Cyber Ranges from late 2026. | Strong multilingual coverage. Ask whether the language count covers the end-user interface and notifications or module content only, on both sides. |
| Employee experience, and what it predicts | Both platforms are strong here and we are not going to pretend otherwise. Ours runs on a personal competence score people own, voluntary learning, less training rather than more, content-style choice, WCAG 2.2 accessibility, a two-way channel where people tell us what is not working, and free family training as an employee benefit. The score people engage with is the same score your board sees. | Strong gamification and habit formation, and analyst-recognized on customer experience. The question is what the engagement is attached to: ask your employees what would change if the same experience also told you where your organization’s risk actually sits. |
| Independent ratings and review base | Fewer public reviews than they have. See OutThink on Gartner Peer Insights. | Hoxhunt holds one of the largest public review bases in the category. See Hoxhunt on G2 and on Gartner Peer Insights. If peer validation at volume is a procurement requirement, weigh it. |
| Implementation effort | Directory and SSO in week one, first campaign and baseline inside week four. The security-stack integrations that feed L3 are scoped separately and sequenced after the program is running. | Ask how long to first campaign, and separately how long until risk data flows from your own security tools rather than from their product. |
| Support model | Named CSM, technical specialists and HRM program expertise, with managed-service options where the team is small. | Ask what is included, and specifically who runs the program day to day if your team is one person. |
| Commercial shape | No public list price. Packaging mirrors the maturity model, L1 Reactive through L4 Predictive, so expansion follows your own journey rather than unbundled modules. L1 includes compliance training, delivery evidence and phishing simulation rather than gating simulation as an add-on. See Plans. Human Risk Intelligence, the Real-Time Threats Engine and CyberQ are available from 2,001 licensed users. | No public pricing either. Ask what the individualized-training model costs at your seat count, and what the SOC-automation module adds on top. |
Sources for the Hoxhunt column. Hoxhunt product and platform pages, their 2026 content-studio launch announcement, their published threat-reporting research, and Gartner Peer Insights and G2 category listings. All accessed July 2026.

Building a Culture of Cyber Resilience Across a Global Workforce
VINCI partnered with OutThink to move beyond tick-box compliance, deploying adaptive, role-based security awareness across 270,000 employees in 120 countries - reducing human risk at enterprise scale.
Switching from Hoxhunt: you do not lose what your people built
The honest objection to moving off an engagement-led platform is not commercial. It is that your employees finally like the training and you do not want to restart from zero. Fair. Here is what happens to each piece.
- Your reporting rate carries over as a signal. Phishing reporting is one of the behaviors CyberQ scores. It stops being the headline number and becomes one input into a score that spans every relevant behavior.
- The gamification does not go away. If your program’s energy comes from leaderboards and progression, CyberQ has them, and a customer who wants phishing weighted heavily can simply enable the three phishing behaviors. What changes is what the points are attached to.
- Keep your report button. You have spent years training people on the button they recognize, and OutThink integrates with it rather than asking you to retrain the reflex.
- Keep your LMS. OutThink works alongside major LMS platforms and returns behavioral telemetry rather than completion status.
- If you rely on their triage automation, say so early. Report-volume handling is a real operational dependency and it should be scoped explicitly rather than discovered at cutover.
- Start at your actual level. Packaging follows the maturity model, so if you are already partway through L2 you do not start at L1.
- Know what the first month looks like. Directory and SSO connection in week one, first campaign and baseline inside week four. The security-stack integrations that feed the risk score are scoped separately and sequenced after the program is running, because a risk score is only worth building once people are engaged. That phase is where your team’s time goes, and we scope it against your actual stack.
Frequently asked questions
Yes, and organizations move between them. But if your program is genuinely working on engagement, “alternative” is the wrong frame. The question is whether engagement is the outcome you were asked to deliver, or the input to one.
They position themselves as one. HRM is being adopted as a label across the market, by email security vendors, awareness platforms and simulation-first tools alike. The label matters less than the capability behind it, which is what the four tests are for.
You might not need to yet. The question worth asking is what happens when leadership asks whether human risk fell, or which fifty people are most at risk today and why. A reporting rate cannot answer either, because it measures a behavior in one channel and says nothing about access, targeting, device posture or the other 80% of security behaviors.
Yes, through CyberQ, but around a different object. Gamifying reporting rewards a behavior in one channel. CyberQ gamifies a defensible cyber-competence score across every relevant behavior, which is also the only kind of score HR will build performance criteria on.
For a contract tail, yes. It is not a destination. Running two programs splits the behavioral signal that makes adaptive training and risk quantification work, which costs you the thing you were buying.
By what feeds it. HRI ingests behavior from your EDR, DLP, web, email and IAM systems, plus attitudes, access level, how targeted the person is, device security and workplace factors. A score computed from a vendor’s own reporting and simulation data is a closed loop, and the SOC, IAM and GRC teams who would act on it know that.
Pricing follows the maturity model and depends on seat count, level and term. See Plans, or talk to us.
Find your level, then decide
You do not need a position on OutThink versus Hoxhunt to make progress this quarter. You need to know which of the four jobs your program actually runs, and which of them nobody currently owns.
Reporting is how it starts. Risk reduction is how it is measured.
Footnotes
- Outcome figures are each organization’s own results, measured against their own starting point, and are not a benchmark to expect. Starting maturity, sector, workforce profile and program design change the result materially. ↩
Disclaimer
This comparison is an independent analysis by OutThink. Statements about Hoxhunt are drawn from their own public material and published third-party sources, current as of July 2026. Product capabilities change, and you should confirm anything decision-relevant with the vendor directly. Where we could not verify a capability from public sources, we have said so rather than guessed.
OutThink competes with Hoxhunt in human risk management and security awareness training. We have a commercial interest in your conclusion, which is why this page gives you an evaluation framework you can apply without us.
This page is informational and is not legal, financial or professional advice.