# Message test — https://www.knowbe4.com/

After reading your page, only 7 of 15 personas could name a reason to pick you over a similar option.

- **Page tested:** https://www.knowbe4.com/
- **Audience tested against:** Security awareness and IT security leaders
- **Personas:** 15 simulated
- **Report:** https://grader.wynter.com/r/knowbe4-secure-your-digital-workforce-human-ai-XO1DwIU

> These answers are generated by AI, scored on Wynter's B2B Message
> Layers framework using behaviorally-diverse simulated personas. The
> methodology is real and the critique is directional. What a simulated
> persona cannot have is a live budget, a renewal coming up, or a boss
> asking about this quarter.

---

## 01 · The scores

Every persona answered all four questions. These are four independent
proportions of the same panel, not stages of a funnel.

| Layer | Question | Cleared the bar | Strength | Of those who passed |
| --- | --- | --- | --- | --- |
| 1. Clarity | Do they understand what you do? | 15/15 | 79% | 1 without hesitation, 14 with reservations |
| 2. Relevance | Can they tell what it solves, and who it's for? | 15/15 | 79% | 1 without hesitation, 14 with reservations |
| 3. Value | Do they actually want it? | 11/15 | 63% | all with reservations |
| 4. Differentiation | Is there a reason to pick you over the alternatives? | 7/15 | 48% | all with reservations |

**Brand alignment** (a side metric, not one of the four layers) — 9/15, 56% strength (all with reservations). Does the page read like the company you actually are?

**Fix first: Differentiation.** Earliest failing layer, walking the sequence in order — not simply the lowest score.

---

## 02 · What to change, layer by layer

Ordered worst-first. Specific edits, not a restatement of the score.

### Differentiation

**Rewrite the Agent Risk Manager body to explain how detection and control work.**

"Real-time visibility, automated threat detection, and active AI agent control" names results without saying what it watches or does. Describe what it inspects, what triggers an alert, and what "control" means in practice.

*effort medium · impact high · tested against Concrete over abstract*

**Replace "Leading risk teams prefer KnowBe4" with a specific reason to choose.**

A preference claim any vendor could print gives no reason to pick this one. Say what only this platform does, such as covering employees and their AI agents in a single console.

*effort low · impact high · tested against Give a reason to choose you*

**Replace the subhead "Spot human risk before it strikes" with what the agents actually do.**

AI Defense Agents and Agent Risk Manager read as near-identical outcome copy, so the two products blur together. Make each subhead say concretely what it monitors and who uses it.

*effort low · impact medium · tested against Headings stand alone*

### Value

**Add one named customer result beside the Agent Risk Manager block.**

Every proof point on the page backs training and email security, so the AI agent claims stand alone. Name a customer using Agent Risk Manager and what it found or stopped.

*effort medium · impact high · tested against Proof next to the claim*

**Add a result metric under the Security Awareness Training block.**

"Change behavior. Build resilience." promises an outcome with no number attached. State the average drop in phish-prone percentage across customers and over what timeframe.

*effort low · impact high · tested against Specifics beat superlatives*

**Add a line under Agent Risk Manager on deployment effort and false positives.**

Buyers cannot tell what it takes to get agent monitoring running or how much noise it generates. Say what it connects to, how long setup takes, and the false-positive rate.

*effort medium · impact medium · tested against Answer the live objection*

### Clarity

**Add a product screenshot or sample alert beside the Agent Risk Manager block.**

The AI sections read as claims with nothing to look at, so readers treat them as a layer over the familiar training product. Show the agent inventory or an alert so readers see what exists today.

*effort medium · impact medium · tested against Show the product early*

### Brand alignment (side metric)

**Name organisation size and region in the persona tab intros.**

InfoSec, HR and Compliance read as generic buckets, so a buyer cannot tell if the product fits their size or regulatory setting. Add a line naming the company profile each tab is written for.

*effort low · impact medium · tested against Name the audience*

**Replace "Empower users with real-time coaching" with the concrete coaching moment.**

Empower, seamless and end-to-end could sit on any security vendor's page. Describe what the user sees, when it appears, and what happens next.

*effort low · impact medium · tested against Concrete over abstract*

---

## 03 · What is working

### The opening states the problem and audience clearly

Four respondents said the problem and intended audience are communicated upfront rather than buried, and that the persona sections helped HR and InfoSec readers locate themselves.

> the problem (human error/phishing susceptibility as the attack surface) within the first two lines. The audience is implied rather than named outright, but the persona tabs (InfoSec, Data Privacy & Compliance, Human Resources) further down make it explicit
> 
> — Chief Information Security Officer, Financial Services, 5000+

> It's fairly quick to tell — "Secure the Digital Workforce: Human + AI" and the line about reducing "human risk and secure your agents" gets you there in the first few seconds, and the segmented blurbs for InfoSec, Compliance, and HR spell out who it's for without me having to dig.
> 
> — VP of Information Security, Retail, 501-1000

> "detect risky actions and stop them cold with Agentic AI defense responses" doesn't tell me what's being detected or how — so while the category and audience were obvious immediately, the specific problem the AI Defense Agents solve was not
> 
> — Information Security Officer, Financial Services, 5000+

### Consolidation and agent visibility are the value respondents would buy if proven

Three respondents named the payoff clearly: collapsing fragmented security tools into one platform and catching rogue AI agents, each conditional on demonstrated proof.

> if "Agent Risk Manager" genuinely gives visibility into rogue AI agents acting inside our systems, that's a new problem I don't have a tool for today.
> 
> — VP of Information Security, Education, 201-500

> consolidate what's currently a patchwork of nothing-formal into one platform — training, phishing sims, email threat defense, and now a line of sight into whatever AI agents our teams start using, which is a gap we genuinely don't have covered today
> 
> — Security Awareness Manager, Retail, 501-1000

---

## 04 · What the personas said

### The AI agent capabilities are described in outcome words, never mechanisms

Nine respondents said the AI Defense Agents / Agent Risk Manager copy names results but never explains how detection, monitoring or control actually works, with no architecture, definition or concrete example.

> it's not clear if that's a real distinct product securing autonomous AI agents or just rebranded behavioral analytics with "agentic" in the name
> 
> — Chief Information Security Officer, Financial Services, 5000+

> The mechanism for the AI agent piece is still fuzzy to me — "behavior-based intelligence," "real-time insights," "active AI agent control" — I'd need an actual architecture diagram or a technical doc showing how it detects and intervenes on agent actions before I could explain how that part works.
> 
> — IT Security Leader, Financial Services, 5000+

> "agent" is never defined as software bots, RPA, LLM-based assistants, or something else entirely, and "workforce" implies scale and autonomy I don't have evidence for in a 300-person college context
> 
> — Director of Security Awareness, Education, 201-500

> those are all outcome words, not mechanism words, so I can't tell if it's monitoring API calls, scanning prompts, watching agent logs, or something else entirely
> 
> — Security Awareness Manager, Manufacturing, 1001-5000

> The "secure your AI agents" framing feels like a bolt-on repositioning for 2026 trends rather than a separate product category; I'd want a concrete definition of what an "AI Defense Agent" actually monitors or blocks before I'd call that anything other than marketing gloss on the same platform.
> 
> — Information Security Officer, Financial Services, 5000+

> the "AI agent" piece stays vague on mechanics — I'd need a concrete example of what an "AI Defense Agent" actually detects and stops before I'd trust it's more than a rebrand of existing features.
> 
> — Chief Information Security Officer, Healthcare, 51-200

> "detect risky actions and stop them cold with Agentic AI defense responses" doesn't tell me what's being detected or how — so while the category and audience were obvious immediately, the specific problem the AI Defense Agents solve was not
> 
> — Information Security Officer, Financial Services, 5000+

> whether the AI agent monitoring is mature or bolted-on marketing — "12 in-production security awareness agents" needs a concrete example before I'd treat it as more than a feature on a slide
> 
> — Security Awareness Manager, Retail, 501-1000

> the page gives zero specifics — no mention of what it actually monitors, what breaches it's caught, or how it integrates with what we have.
> 
> — Information Security Officer, Manufacturing, 1001-5000

### The AI agent claims carry no customer evidence while the core product does

Five respondents noted zero case studies, reference customers or proof points behind Agent Risk Manager, contrasting it with the proven training and email security side, and asked for false-positive rates and integration effort.

> the Agent Risk Manager pitch — "real-time visibility, automated threat detection, and active AI agent control" — has zero customer proof point attached to it anywhere on this page, no case study, no metric, nothing like the Cebu Pacific line
> 
> — IT Security Leader, Financial Services, 5000+

> One concrete technical reference call where a real customer our size describes what an AI Defense Agent actually caught, with some sense of false-positive rate and integration effort against our existing email/identity stack
> 
> — Chief Information Security Officer, Healthcare, 51-200

> the case studies they do show (Daytona Beach, Hood College, Cebu Pacific, Operation BBQ Relief) are all public-sector, education, or airline — zero retail, zero EU, which is precisely my segment and region
> 
> — Security Awareness Manager, Retail, 501-1000

### No numbers back the core phishing risk reduction claim

One respondent said the page offers no concrete metrics on how much phishing risk the training actually reduces.

> the page gives me logos and star badges, not a single number on phish-prone rate reduction or time saved
> 
> — Director of Security Awareness, Healthcare, 51-200

### The messaging is generic to mid-to-large enterprise with no sector or EU context

Three respondents found the tone undifferentiated across enterprises and missing EU retail regulatory framing, sector-specific context, or regional implementation proof.

> it reads like broad enterprise SaaS marketing copy stacked with badges and customer quotes rather than something addressing an EU retail security director's specific constraints; nothing here mentions GDPR, EU-specific regulation, or retail-sector risk profile, so it feels generic-enterprise
> 
> — Director of Security Awareness, Retail, 501-1000

> it's fairly impersonal: badges, logos, and a stat-heavy headline rather than anything that speaks directly to my specific pain as a healthcare security awareness director
> 
> — Director of Security Awareness, Healthcare, 51-200

> the case studies they do show (Daytona Beach, Hood College, Cebu Pacific, Operation BBQ Relief) are all public-sector, education, or airline — zero retail, zero EU, which is precisely my segment and region
> 
> — Security Awareness Manager, Retail, 501-1000

### The AI agent story reads as a bolt-on to a familiar phishing-training product

Five respondents identified the core offering as standard phishing simulation and awareness training with AI messaging layered on top, and read the AI framing as an established vendor repositioning to stay relevant.

> It's security awareness training, basically phishing simulations and employee cybersecurity training, with some bolt-on "AI agent security" messaging layered on top this time around.
> 
> — VP of Information Security, Education, 201-500

> KnowBe4's core business is training employees not to click phishing links and running simulated attacks, with email/collaboration security and an "Agent Risk Manager" layered on as new add-ons to catch the AI hype wave.
> 
> — Information Security Officer, Manufacturing, 1001-5000

> That's a company that's been selling broad horizontal compliance/security training to every industry and company size for a long time, now trying to bolt on an "AI agent" story to stay relevant.
> 
> — Chief Information Security Officer, Healthcare, 51-200

> It's security awareness training with phishing simulation, now bolted onto email/collaboration security and some new "AI agent" risk management angle.
> 
> — Chief Information Security Officer, Healthcare, 51-200

> Security awareness training with phishing simulations, bundled now with some AI-agent monitoring tacked on — basically they train employees not to click bad links, plus email/collaboration threat filtering, and they're trying to extend that into watching "AI agent" behavior too.
> 
> — VP of Information Security, Retail, 501-1000

### Buyer identity must be inferred from persona tabs rather than stated

Four respondents said the target buyer is implied by role groupings instead of named, and that the personas are generic buckets with no organisation size or regulatory specificity.

> the persona tabs - InfoSec, Data Privacy & Compliance, Human Resources - do the job of segmenting the reader for me, so I didn't have to hunt hard
> 
> — Director of Security Awareness, Healthcare, 51-200

> the "who's it for" framing is generic persona-bucket marketing rather than a real buyer profile (no mention of org size, sector, or regulatory context like EU financial services)
> 
> — IT Security Leader, Financial Services, 5000+

> Who it's for is never explicitly named as a title, but the "Leading risk teams prefer KnowBe4" block segmented by InfoSec / Data Privacy & Compliance / HR does the job of implying the buyer personas without me having to guess hard
> 
> — Security Awareness Manager, Manufacturing, 1001-5000

> it's fairly impersonal: badges, logos, and a stat-heavy headline rather than anything that speaks directly to my specific pain as a healthcare security awareness director
> 
> — Director of Security Awareness, Healthcare, 51-200

---

## 05 · The hardest read

An adversarial pass over the findings. Every claim below was checked
against the panel's own answers; unsupported ones were dropped.

- **The flagship AI agent story is unbuyable as written — no mechanism, no proof, nothing to evaluate.** *(high)*
  Eight respondents said the Agent Risk Manager copy names outcomes with no architecture, definition or example, and four found zero case studies or proof points behind it while the legacy product has them. The newest, highest-stakes claim is the least…
- **The absence of mechanism detail invites the conclusion that the AI capability is marketing veneer on an old product.** *(high)*
  Four respondents read the core offering as standard phishing simulation with AI layered on top and named it repositioning to stay relevant; eight found no explanation of how detection or control works. Silence on mechanism confirms the bolt-on reading.
- **The page states value that respondents want but never clears the proof bar needed to act on it.** *(high)*
  Three respondents named consolidation and rogue-agent visibility as the payoff — each explicitly conditional on demonstrated proof — while four asked for false-positive rates and integration effort that never appear. The page creates demand it cannot close.
- **The page quantifies nothing, so every claim rests on assertion.** *(medium)*
  No metrics support the core phishing risk reduction claim, no false-positive rates or integration effort for the agent product, and no regional implementation proof. Across old and new offerings alike, the page offers words where buyers expect numbers.
- **Strong opening clarity is wasted because the page never names who it is for.** *(medium)*
  Four respondents said the problem and audience land upfront, yet three said buyer identity must be inferred from generic persona buckets with no organisation size or regulatory specificity. Readers locate themselves by guesswork, not by invitation.
- **The messaging is interchangeable with any competitor's and gives no reason to choose this vendor.** *(medium)*
  Three respondents found the tone undifferentiated across enterprises with no sector, EU retail regulatory framing or regional proof, and three more said the personas are generic buckets lacking size or regulatory specificity. Nothing anchors the page to a…

---

## 06 · Who answered

| # | Role | Industry | Company size |
| --- | --- | --- | --- |
| 1 | Chief Information Security Officer | Financial Services | 5000+ |
| 2 | Director of Security Awareness | Healthcare | 51-200 |
| 3 | VP of Information Security | Education | 201-500 |
| 4 | Security Awareness Manager | Retail | 501-1000 |
| 5 | Information Security Officer | Manufacturing | 1001-5000 |
| 6 | IT Security Leader | Financial Services | 5000+ |
| 7 | Chief Information Security Officer | Healthcare | 51-200 |
| 8 | Director of Security Awareness | Education | 201-500 |
| 9 | VP of Information Security | Retail | 501-1000 |
| 10 | Security Awareness Manager | Manufacturing | 1001-5000 |
| 11 | Information Security Officer | Financial Services | 5000+ |
| 12 | IT Security Leader | Healthcare | 51-200 |
| 13 | Chief Information Security Officer | Education | 201-500 |
| 14 | Director of Security Awareness | Retail | 501-1000 |
| 15 | VP of Information Security | Manufacturing | 1001-5000 |

---

## 07 · Before you act on this

The methodology is real, and the critique is directional. What a
simulated persona cannot have is a live budget, a renewal coming up, or
a boss asking about this quarter. **Validate anything you're betting on
with real ICPs who are actually in-market.** Being wrong is more
expensive than you think. Finding out is cheaper than you'd guess.

Wynter runs message testing with verified B2B professionals — trusted
by HubSpot, RingCentral, Shopify, Cognism, Paddle, Veeam, Rippling and
Miro. <https://wynter.com>

This report is kept for 60 days from 2026-10-05, then deleted along with the personas and their answers.

