Startup Diligence
Diligence report cybersecurity PE-backed private / unicorn 2026-07-10

KnowBe4

Scaled human-risk-management platform with strong customer proof, but leverage, workflow competition, and private-company opacity keep the underwriting case incomplete.

Research more: KnowBe4 has real scale, strong customer proof, and high-quality recurring revenue, but elevated leverage, active risk clustering, and limited private-company disclosure keep the current valuation case only fair rather than clearly attractive.

Cover facts

Current customers 03
70000 accounts+ [CO005, CU001]
Current risk view 06
High [CR041]

Company profile

KnowBe4 is a Clearwater-based cybersecurity company founded by Stu Sjouwerman in 2010 that built a category-leading security-awareness and phishing-simulation platform and later expanded into human-risk management, email response, and cloud email security. Public evidence supports real scale, broad customer adoption, and durable recurring revenue, but the company now sits inside a leveraged sponsor-owned structure with much less disclosure than it offered as a public company.

Website
www.knowbe4.com
Founded
2010-01-01
Founders
Stu Sjouwerman
Founding location
Clearwater, Florida, USA
Headquarters
Clearwater, Florida, USA
Product
Security-awareness training, phishing simulation, risk scoring, response tooling, and cloud email-security products aimed at reducing human-driven cyber risk.
Customers
SMB, mid-market, enterprise, public sector, and education organizations that need scalable human-risk and phishing-defense workflows.
Business model
Recurring subscription software with expansion into adjacent modules such as PhishER, SecurityCoach, and Egress-derived email security.
Stage
PE-backed private / unicorn
Funding status
Taken private by Vista Equity Partners in February 2023 at a roughly $4.6 billion headline valuation; refinanced approximately $1.46 billion of debt in July 2025.
[CO001, CO002, CO005, CO007, CO008, CI021, CI026, CU001]

Executive summary

Top strengths

  • KnowBe4 has one of the strongest public customer-proof sets in private cybersecurity, including 70,000+ customers, broad vertical diversity, and many named case studies with measurable outcomes.
  • The revenue model still appears premium: Fitch says more than 99% of revenue is recurring and retention metrics remain stable.
  • The platform has expanded beyond classic SAT into response, coaching, and cloud email security, which helps defend against pure point-solution compression.
  • The 2025 refinancing shows lenders still underwrite KnowBe4 as a scaled sponsor-backed software asset rather than as a distressed special situation.

Top risks

  • Email-security-native and AI-native vendors can displace or compress standalone awareness-training workflows.
  • Leverage remains high and sponsor incentives may not prioritize fast deleveraging, which narrows equity margin of safety.
  • The North Korea fake-hire incident showed that workforce-integrity and hiring-process risk is not theoretical even for a security vendor.
  • Merger-related litigation and broader governance / disclosure issues still create legal overhead.
  • Current audited private-company financials, NRR, and post-refinancing equity details are not public.

Open gaps

  • Current audited revenue, EBITDA, free cash flow, and net debt after the 2025 refinancing.
  • Segment-level renewal, churn, NRR, attach-rate, and CAC data by SMB, enterprise, and geography.
  • Full debt documents, equity ownership waterfall, and any sponsor recap or distribution constraints.
  • Quantified lost-deal / displacement evidence versus email-security-native challengers.
  • Likely settlement economics and insurance coverage for the active securities litigation.

Contents

Chapter 01

01Company Overview

1.1 Identity, scale, and operating model

KnowBe4’s current public identity is much broader than the security-awareness vendor label that defined the company during its IPO era. The homepage, platform page, and review surfaces all position the company around human risk management and increasingly around securing AI agents as well as human employees. Official pages describe a platform that combines awareness and compliance training, phishing simulation, crowdsourced anti-phishing, real-time coaching, cloud email security, and newer AI-defense agents. The headline scale signal is consistent across several recent sources: the homepage says the company has 15+ years of behavior data and 70,000 global customers, the 2025 CEO-transition release says the company had grown to serve over 70,000 customers, and Fitch also describes a base of more than 70,000 customers globally. That scale is materially higher than the 56,000-organization figure disclosed in the February 2023 take-private closing release, which indicates continued post-buyout expansion. Public location evidence is also consistent: KnowBe4 is based in Clearwater, Florida, and its headquarters address is listed as 33 N Garden Ave, Suite 1200.[CO001, CO002, CO003, CO004, CO005, CO006]

Snapshot KPI table
metricvalue/statusdateconfidencegap
Founded2010 by Stu Sjouwerman2026-07-10high
Headquarters33 N Garden Ave, Ste 1200, Clearwater, FL 337552026-07-10high
Ownership statusPrivate; owned by Vista Equity Partners2026-07-10high
Current CEOBryan Palma (effective May 5, 2025)2026-07-10high
Founder roleStu Sjouwerman is executive chairman2026-07-10high
Customer count70,000+ organizations globally2026-07-10high
Historical customer count at take-private close56,000+ organizations2023-02-01highOlder disclosure trails current scale claims.
Credit ratingFitch IDR B / Stable2025-07-17high
Refinancing1.46bn first-lien term loan plus 200m revolver2025-07-22high
Exact current headcountNot officially disclosed2026-07-10mediumThird-party directories suggest roughly 1.0k-1.4k+ employees but disagree.

Mixes official company disclosures, SEC merger materials, and Fitch credit commentary; exact 2026 revenue, ARR, and headcount remain undisclosed publicly.

[CO001, CO002, CO004, CO006, CO007, CO008]
FO002: Company snapshot logic

The current platform narrative links training, coaching, email security, and AI agents into one human-risk operating stack.

[CO003, CO014, CO026, CO030, CO040]
FO003: Snapshot KPIs

Public KPIs confirm large customer scale and leveraged ownership, while employee count and exact revenue remain unconfirmed.

[CO004, CO011, CO021, CO023, CO040]

1.2 Leadership transition, global footprint, and governance signals

Leadership is one of the biggest changes since the company went private. KnowBe4’s April 2025 release appointed Bryan Palma as president and chief executive officer effective May 5, 2025, while founder Stu Sjouwerman moved into the executive-chairman role. Palma’s background matters because the company is no longer run day to day by the founder who built its original awareness-training category position; the new CEO is a scaled-enterprise operator whose most recent prior role was leading Trellix. Sjouwerman nonetheless remains strategically important, both because he founded KnowBe4 in 2010 and because he was explicitly tasked with helping guide artificial-intelligence innovation after the transition. The company’s visible footprint is global but only partly quantified. A workplace-awards release shows Great Place to Work certifications across 11 countries and explicitly names offices or operating presence across the United States, United Kingdom, South Africa, Australia, UAE, Singapore, Netherlands, Japan, India, Germany, and Brazil. What the public package still does not provide is a clean 2026 board roster, investor-control map, or exact headcount. Third-party directories place the workforce somewhere in the low-thousands, but the company does not publish a definitive count on its official pages.[CO007, CO008, CO009, CO010, CO023, CO024]

Leadership and founder table
personrolebackgroundfounder-market fit or functional coveragekey-person dependency
Stu SjouwermanFounder; Executive ChairmanFounded KnowBe4 in 2010 and led it through VC funding, IPO, M&A, and take-privateFounder vision, category creation, AI-transition oversighthigh
Bryan PalmaPresident and CEOFormer Trellix CEO with 25+ years across Cisco, Boeing, EDS, PepsiCo, and US Secret ServiceScaled-enterprise operations, profitable growth, customer experiencehigh
Ani BanerjeeChief Human Resources OfficerQuoted in workplace-awards release on global employee experienceSignals global people-operations maturity across 11-country footprintmedium
Marco MutoSVP of StrategySpokesperson on 2026 partner-awards releaseVisible channel and ecosystem strategy ownermedium
Board / independent directorsNot publicly enumerated in fetched 2026 source setPrivate-company governance detail is sparse after Vista take-privateImportant governance blind spot for later diligencehigh

Public leadership evidence is strongest on the founder-to-CEO transition and much weaker on full board composition or investor-control rights.

[CO001, CO007, CO008, CO009, CO010, CO023]

1.3 Ownership, credit structure, and milestone chronology

The capital story is unusually important because KnowBe4’s public-equity chapter ended with a sponsor acquisition and later refinancing. SEC merger materials and closing releases show Vista agreed to pay $24.90 per share in cash, a 44% premium to the unaffected September 16, 2022 close, and completed the acquisition on February 1, 2023, taking KnowBe4 off Nasdaq. Since then, the company has continued to reshape its platform and capital stack. The about-us history highlights a 2019 KKR-led $300 million round and the April 2021 IPO, while official product history shows launches such as PhishER, SecurityCoach, AIDA, and Agent Risk Manager. Strategic scope widened again when KnowBe4 completed its acquisition of Egress in July 2024 to add adaptive cloud email security. By July 2025 the business had also moved through a major refinancing: Fitch initiated coverage at B/Stable, later affirmed the issuer at B while noting an upsized $1.46 billion first-lien term loan and a $200 million revolver, and Private Equity Wire reported a materially lower spread than the prior private-credit debt. That combination points to a scaled, recurring-revenue software asset owned and governed with private-equity leverage rather than public-market transparency.[CO011, CO012, CO013, CO014, CO015, CO018]

Stakeholder or investor map
stakeholderrolecontrol or economic importancediligence ask
Vista Equity PartnersPrivate-equity ownerControls the company after the February 2023 take-privateRequest ownership chain, board rights, and return-horizon expectations.
KKREarlier growth investor and merger-related shareholderAbout-us history cites 2019 round; litigation alleges KKR rollover details mattered in merger processRequest rollover economics and any continuing ownership or governance rights.
JPMorgan and KKR Capital MarketsLead arrangers on 2025 syndicated refinancingStructured the first-lien debt that reset borrowing costs and maturity profileRequest lender presentation, covenants, and post-refi leverage targets.
Blue Owl / Blackstone / Carlyle lender groupPrior private-credit lenders per refinancing coverageShows pre-2025 dependence on sponsor-style private-credit financingRequest payoff schedule and economics of the retired facility.
EgressAcquired platform assetAdds adaptive cloud email security and product adjacency beyond trainingRequest integration milestones and revenue mix contribution.
Public minority shareholders / class-action plaintiffsAdverse stakeholder groupContinue to challenge merger disclosure quality and sale-process fairnessMonitor litigation posture, settlement exposure, and document-production risk.

Stakeholder map blends official ownership and M&A disclosures with lender and litigation evidence; it is not a substitute for a cap table or credit agreement package.

[CO011, CO014, CO021, CO022, CO027, CO034]
Milestone table
dateeventtypeamount/valuation/statusparticipantsimplication
2010-06KnowBe4 foundedfoundingCompany createdStu SjouwermanStart of security-awareness category build.
2017-10Series B investment led by Goldman Sachsfinancing$30mGoldman SachsFirst major institutional growth capital highlighted in company history.
2019-06KKR round at unicorn valuationfinancing$300m; ~1bn valuationKKRMarked step-up in scale and external validation before IPO.
2019-01PhishER introducedproductNew product line liveKnowBe4Expanded beyond training into reported-email triage.
2021-04KnowBe4 IPOgovernancePublic listing completedKnowBe4 / NasdaqOpened brief public disclosure window later useful for diligence.
2022-11SecurityCoach launchedproductReal-time coaching product introducedKnowBe4Broadened product scope beyond awareness modules.
2023-02-01Vista take-private closesgovernance$24.90 per share cashVista / KnowBe4Ended public listing and moved governance behind PE ownership.
2024-07Egress acquisition completedpartnershipClosed M&A integration eventKnowBe4 / EgressAdded cloud email security adjacency.
2025-05Bryan Palma appointed CEO; Sjouwerman becomes executive chairmangovernanceLeadership transitionKnowBe4Material management change after take-private.
2025-07Fitch initiation and later upsized refinancing affirmationfinancingB/Stable; 1.46bn first-lien plus 200m revolverFitch / lender groupShows leveraged-capital structure and syndicated-loan market access.
2026-02AIDA Orchestration launched as 8th agentproductAutomated phishing orchestration milestoneKnowBe4Signals AI-agent expansion in platform narrative.
2026Americas partner awards publicizedpartnershipActive channel programSHI, CDW, Optiv, othersConfirms ecosystem-based distribution and influence.

This is the chapter chronology of record for founding, financing, governance, product, and partner milestones visible in the fetched public package.

[CO001, CO007, CO011, CO014, CO021, CO025]
FO001: Company milestone timeline

KnowBe4’s public chronology runs from 2010 founding to IPO, take-private, Egress expansion, leveraged refinancing, and AI-agent rollout.

[CO007, CO011, CO014, CO021, CO025, CO028]

1.4 Adverse signals, evidence quality, and what remains opaque

The cleanest adverse signal in the current evidence set is not product failure or regulatory sanction but merger-process litigation. Stanford’s securities-class-action clearinghouse shows an ongoing case centered on alleged omissions in KnowBe4’s 2022 proxy materials for the Vista sale, and the amended complaint summarized by Entwistle & Cappucci claims investors were misled about share value, KKR’s rollover behavior, and advantages allegedly given to Vista during the process. That does not prove wrongdoing, but it means the take-private is still being contested in court. Product-adoption evidence is also directionally positive rather than decisive. TrustRadius and PeerSpot reviews praise the training library and phishing simulations, yet they also flag recurring limitations around ROI quantification, reporting friction, and how realistic or “tricky” some simulations feel. The largest diligence gaps are still financial and governance disclosures. Fitch offers helpful credit commentary, but neither official company pages nor the current fetched set provide exact 2026 revenue, ARR, EBITDA, board composition, or a reconciled employee count. Later chapters can safely treat KnowBe4 as a scaled and sticky category leader, but not as a fully transparent private software issuer.[CO016, CO017, CO019, CO020, CO034, CO035]

1.5 Exhibits

Chapter 02

02Market Analysis

2.1 Market boundary and what is actually being bought

The first analytical task is defining the market correctly, because “security awareness training” is not identical to “phishing simulation,” “human risk management,” or “email security.” The broadest market lens, used by Mordor Intelligence and syndicated by Research and Markets, covers security awareness training as a mix of software platforms and managed services that educate employees, run simulations, track behavior, and support compliance. Narrower lenses focus on awareness-plus-phishing-simulation suites or even more tightly on phishing attack training programs. Official and semi-official guidance from CISA and NIST supports this boundary logic: the core spend category is not just classroom content, but an operating layer that teaches users to recognize phishing across email, text, voice, social media, and other channels, then measures whether behaviors improve over time. That means pure email gateways, generic learning-management systems, or static compliance libraries are only adjacent unless they include active simulation, measurement, and response loops. For KnowBe4, the relevant market is therefore a human-risk and phishing-simulation stack sitting between compliance training and technical email-security controls.[CM001, CM004, CM005, CM006, CM026, CM030]

Market definition table
segment/categoryincluded spendexcluded spendbuyer/payerrelevance
Security awareness training (broad SAT)Training platforms, simulations, analytics, managed services, compliance contentPure email gateways without user training; generic LMS without security workflowsCISO, security-awareness, compliance, ITBroadest denominator for KnowBe4’s core category.
Security awareness + phishing simulationRole-based education plus realistic phishing tests and reporting metricsStatic annual training with no testing loopSecurity, risk, and audit buyersCloser fit to KnowBe4’s historical value proposition.
Phishing attack training programsFocused phishing simulation, exercises, and response learningBroader human-risk or email-security suitesIT/security teams, managed providersUseful narrow subsegment lens for SMB and focused buyers.
Human risk management suitesBehavior analytics, continuous nudges, simulations, risk scoring, integrated controlsPure content libraries with no behavior layerCISO, GRC, security operationsMatches the direction of KnowBe4’s current positioning.
Adjacent cloud email security and identity controlsThreat blocking, posture enforcement, phishing-resistant MFA, inbox securityAwareness-only spend if no integrated control loopSecurity engineering, email teams, IAM teamsImportant adjacency but not always counted inside SAT TAM.

The category boundary is definition-sensitive; rows distinguish what analysts, regulators, and vendors variously package together versus what they treat as adjacent controls.

[CM001, CM004, CM005, CM006, CM030, CM040]
FM001: Market sizing lens

Public market estimates narrow sharply from broad security-awareness-training spend to focused phishing-training-program spend.

This is a boundary-bracketing figure, not an additive TAM/SAM/SOM waterfall. The layers use different analyst definitions and mixed base years, so they show scope compression rather than a literal nested market stack.

[CM009, CM015, CM019, CM032]

2.2 Sizing lenses, deployment mix, and segment economics

Public market sizing is usable, but only if the reader preserves the differences in scope. Mordor’s broad SAT lens estimates a 2026 market size of USD 6.74 billion growing to USD 14.66 billion by 2031 at a 16.82% CAGR, with North America the largest region, cloud delivery the dominant mode, and SMEs growing faster than large enterprises from a smaller base. Virtue Market Research’s narrower awareness-and-phishing-simulation lens starts much lower at USD 1.45 billion in 2025 and projects roughly USD 3.02 billion by 2030 at a 15.8% CAGR. Intel Market Research’s phishing-attack-training-program niche is narrower again, projecting USD 489 million in 2026 and USD 735 million by 2034. Those differences are not contradictions so much as definitional choices. They also imply that investors should avoid claiming a single clean TAM for KnowBe4 without specifying whether they are valuing a compliance-training platform, a simulation-and-behavior suite, or a broader human-risk and cloud-email-security stack. The deployment and buyer mix nonetheless points in a clear direction: cloud-first delivery, large-enterprise purchasing today, and faster SMB adoption where insurance, regulations, and subscription pricing reduce barriers.[CM009, CM010, CM011, CM012, CM013, CM014]

TAM/SAM/SOM or sizing lens table
publisheryeargeographyvalueCAGRmethodology / limitationconfidence
Mordor Intelligence2026GlobalUSD 6.74B SAT market16.82% to 2031Broad security awareness training category; includes software and servicesmedium
Research and Markets / Mordor2026GlobalUSD 6.74B SAT market16.82% to 2031Syndicated version of Mordor framework rather than independent estimatemedium
Virtue Market Research2025 base / 2030 forecastGlobalUSD 1.45B to USD 3.02B15.8% to 2030Narrower security-awareness + phishing-simulation scope than broad SATmedium
Intel Market Research2026 base / 2034 forecastGlobalUSD 489M to USD 735M7.3% to 2034Even narrower phishing-attack-training-program lenslow
Mordor Intelligence2025 segment mixGlobalCloud 73.65%; large enterprise 72.55%18.72% cloud; 19.64% SME growthSegment shares describe the broad SAT category, not KnowBe4 revenue mixmedium
Mordor Intelligence2025 regional / vertical mixGlobalNorth America 37.78%; BFSI 28.15%APAC 18.61%; healthcare 18.83%Useful for demand direction, not a clean product-level TAM for every vendormedium

Market-size lenses are intentionally non-additive: each row uses a different category boundary, so the table is for bracketing, not summing, opportunity.

[CM009, CM010, CM011, CM012, CM013, CM014]
FM002: Market estimate range

Depending on definition, the addressable market spans from focused phishing training to a far broader security-awareness-training category.

The figure compares category definitions, not synchronized same-scope estimates. It is useful for valuation framing precisely because the three points use different market boundaries.

[CM009, CM015, CM019, CM044]

2.3 Buyer, user, payer, and adoption path

The buyer map is more complex than “security team buys training for employees.” In large enterprises, the budget owner is often the CISO or security-awareness leader, but procurement can be triggered by audit findings, cyber-insurance requirements, or board pressure after breaches. In regulated sectors such as BFSI and healthcare, compliance, privacy, and operational-resilience teams also shape requirements because training records and reporting outcomes are part of the evidence package. SMEs often buy differently: a smaller IT or managed-service team looks for cloud-based, low-administration subscriptions that satisfy insurer or customer demands without needing a full awareness staff. The actual users are employees, contractors, and increasingly partners or agents using collaboration tools, while the payers are enterprise budgets tied to security, risk, IT, or governance functions. This is why NIST and CISA emphasize outcome metrics and realistic simulations rather than one-time completion statistics. The adoption path typically moves from broad awareness messaging, to baseline phishing tests, to role-based simulations, to continuous nudges, reporting workflows, and ecosystem integration. For KnowBe4, that structure favors platforms that can serve both checkbox-compliance buyers and mature teams that want measurable behavior change.[CM002, CM003, CM004, CM006, CM007, CM031]

Segment / buyer map
segmentbuyeruserpayerworkflowbudget owneradoption trigger
Large enterprise security programCISO or security-awareness leadEmployees and contractorsCorporate security budgetBaseline testing, role-based campaigns, reporting, integrationsCISO / security operationsBreach history, board pressure, or program maturity goals
Regulated BFSI or healthcare organizationSecurity plus compliance / privacy stakeholdersEmployees with privileged data accessSecurity and compliance budgetTraining tied to audit evidence, resilience, and policy acknowledgementCISO / risk / complianceRegulatory obligations and insurer requirements
SMB / mid-market buyerSmall IT or managed security teamGeneral workforceIT operating budget or MSP-bundled subscriptionCloud deployment with low admin overhead and packaged templatesIT manager / ownerNeed to satisfy cyber-insurance and customer security questionnaires
Public sector or educationIT, risk, and institutional leadershipStaff, faculty, administrators, and sometimes studentsDepartmental or central IT budgetBroad awareness plus repeat simulations and reportingIT / risk / administrationHigh phishing exposure and public accountability
Security-operations-led buyerSOC or incident-response teamUsers reporting suspicious contentSecurity operations budgetReported-email triage, coaching, incident escalation, and analyticsSOC leadershipNeed to connect human reporting to faster containment

Buyer and payer roles vary by sector maturity; end users almost never control spend even though their behavior is the measured outcome.

[CM004, CM006, CM031, CM037, CM041, CM042]
FM003: Buyer / segment map

Buyer types differ mainly on who controls budget, what compliance pressure exists, and whether the deployment goal is broad awareness or operational reporting.

[CM031, CM037, CM041, CM042, CM043, CM029]
FM004: Adoption funnel or value-chain map

The market increasingly moves from broad awareness messaging to continuous simulation, reporting, and integrated human-risk controls.

Stage values are ordinal indices that show program narrowing and maturity progression, not audited conversion rates for the whole market.

[CM004, CM006, CM031, CM039, CM043]

2.4 Growth drivers, constraints, and strategic implications for KnowBe4

The structural demand case is strong. Mordor ties market growth to ransomware and BEC losses, cyber-insurance training proof, SaaS adoption by SMEs, zero-trust programs, ISO 27001 people-centric controls, and generative-AI phishing kits. IBM, Verizon, Microsoft, and CISA all reinforce the same qualitative point from different angles: human error and social engineering remain persistent breach pathways, while AI makes lures faster, cheaper, and more realistic. However, the market is not frictionless. Mordor highlights user fatigue, budget reallocation toward XDR and SASE, privacy constraints on analytics, and localization bottlenecks. Intel and PMarket add lower participation rates, ROI-measurement difficulty, and training disruption risk. Competitive buyer guides also suggest that the category is being judged less on “who has content” and more on who can show measurable reporting-rate improvement, lower click rates, better personalization, and integration into broader security workflows. For KnowBe4 this is strategically favorable in one sense, because the company already offers scale and product breadth, but challenging in another, because market leadership must increasingly be proven through effectiveness and operating leverage, not just customer count or module-library size.[CM008, CM016, CM020, CM021, CM022, CM023]

Growth drivers and constraints table
driver/constraintdirectiontimingimplicationdiligence ask
Ransomware, BEC, and social-engineering lossesdrivercurrentKeeps training and simulation in the core control stack rather than optional compliance spendAsk vendors or buyers for evidence that simulations measurably improve reporting or click-rate outcomes.
Cyber-insurance and audit proof of employee educationdrivercurrent to medium termSupports repeat budgets, especially for SMEs and regulated industriesTest how often insurance questionnaires or contracts explicitly require simulation metrics.
Generative-AI phishing kits and new social-engineering channelsdrivercurrentRaises demand for more realistic and continuously updated simulationsRequest examples of how vendors refresh content for AI-driven lures, smishing, and collaboration attacks.
Remote and hybrid work plus SaaS sprawldrivercurrentBroadens attack surface and favors cloud-delivered, always-on programsAsk for role-based and channel-based simulation coverage beyond classic email.
User fatigue and punitive-program backlashconstraintcurrentOver-frequent or generic training can reduce participation and ROIInspect completion, repeat-clicker, and employee-sentiment data rather than assuming more campaigns are better.
Budget competition from XDR, SASE, identity, and other controlsconstraintcurrentSecurity leaders may deprioritize training if effectiveness is not measurableTest whether the vendor can tie behavior data into broader SOC or GRC metrics.
Privacy, localization, and analytics restrictionsconstraintcurrent to medium termLimits how deeply vendors can personalize or benchmark globallyReview how regional data and content-localization rules affect product capability.
Definition-sensitive TAM claimsconstraintcurrentDifferent market-lens choices can overstate or understate the addressable market for a single vendorDemand a valuation model that clearly states which market boundary is being used.

Rows combine analyst market reports, regulator guidance, and threat-report implications; they are ecosystem drivers and constraints, not company-specific disclosures.

[CM008, CM020, CM021, CM022, CM023, CM024]

2.5 Exhibits

Chapter 03

03Competitors

3.1 The category is no longer just phishing simulation software

KnowBe4 still sits at the center of the classic security-awareness-training market, but the competitive landscape in 2026 is broader than the company’s own comparison framing suggests. Official KnowBe4 materials emphasize unlimited phishing testing, a large content catalog, AI-assisted campaign management, and add-on expansion into PhishER, SecurityCoach, and Compliance Plus. That bundle makes KnowBe4 the clearest incumbent for organizations that want one cloud console to run training, phishing, reporting, and baseline human-risk scoring at scale. Independent review sources reinforce that positioning by highlighting KnowBe4’s strength in large-enterprise usage, broad content, and generally easy deployment. The more important competitive shift is that many rivals are no longer selling just “training.” Proofpoint and Mimecast package awareness inside wider email-security and human-risk platforms. Hoxhunt, SoSafe, and CybSafe market themselves around behavior change, adaptive interventions, and real-time risk analytics rather than course completion. Cofense extends farther into post-delivery detection and remediation, treating user reporting as a SOC input rather than only a training metric. SANS remains a credible substitute for organizations that want expert-led program design or educational content without committing to a full human-risk platform. In practice, buyers are now comparing KnowBe4 not only against direct SAT peers but against broader human-risk, secure-email, and internal-program alternatives.[CP001, CP002, CP006, CP010, CP012, CP014]

Competitor profile table
competitorcategoryscale / funding signaltarget segmentdifferentiationlimitation
KnowBe4Direct incumbent / HRM platform70,000+ customers per official company sources; PE-ownedSMB through large enterpriseBroad content library, unlimited phishing tests, mature admin tooling, add-on expansionBehavior-change narrative is less differentiated than newer HRM challengers
Proofpoint ZenGuideBundle competitor / email-security incumbent2.7M customers protected; 80+ of Fortune 100 use ProofpointLarge enterprise, especially existing Proofpoint estatesThreat-informed simulations, role/risk scoring, reporting button, strong ecosystem tie-inAwareness value proposition partly depends on broader Proofpoint stack
HoxhuntAdaptive HRM challengerOfficial site highlights customer-reported resilience gains and large simulation volumesEnterprise teams prioritizing engagement and reporting behaviorGamified adaptive simulations and human-threat-intelligence framingPublic evidence on self-serve multi-channel depth and pricing remains limited
Mimecast EngageBundle competitor / email-risk suite42k+ customers and 300+ integrations across broader Mimecast platformExisting Mimecast and regulated email-heavy organizationsAwareness tied to email-security and human-risk positioningMay be chosen as a bundle convenience rather than a best-of-breed awareness tool
SoSafeEU-first HRM challengerPan-European scale with 34+ languages and EU-hosting/privacy positioningEuropean enterprises with works-council or NIS2 / DORA sensitivityBehavioral science, multilingual delivery, privacy-aware reporting and compliance mappingLess public evidence of content-library breadth than KnowBe4
MetaComplianceCompliance-first challenger10M+ people trained; 44+ languages claimedCompliance-led programs and Microsoft-centric deliveryPolicy management, Teams delivery, strong support positioningPublic positioning leans more compliance-first than deep threat telemetry
CofenseSOC-linked adjacent competitorFocused post-delivery phishing-defense brand rather than broad SAT scale messagingSecurity-operations-led organizationsCampaign-level remediation, reporting-loop integration, phishing-specific AILess obviously a full-spectrum awareness platform than KnowBe4
CybSafe / SANS substitutesBehavioral and program-design substitutesCybSafe emphasizes behavioral database; SANS offers expert-led resourcesOrganizations seeking behavior analytics or expert-led internal programsAlternative path away from classic phishing-click metricsCan require more internal program ownership or adjacent tooling

Scale signals mix company-claimed customer or user counts with platform reach descriptors. They are useful for competitive orientation, not normalized audited market-share estimates.

[CP001, CP006, CP007, CP012, CP014, CP017]
FP001: Competitive positioning index

A breadth-first view favors KnowBe4 and bundle incumbents, while behavior-led challengers close the gap through specialization rather than content scale.

Values are evidence-backed ordinal scores derived from disclosed breadth across content, simulation, reporting, integrations, and adjacent workflow ownership. They are not market-share data.

[CP002, CP010, CP012, CP014, CP019, CP022]

3.2 Capability differences increasingly center on workflow and telemetry, not baseline training content

There is clear feature overlap across the field: all material vendors promise phishing simulation, awareness content, reporting, and some form of personalization. That convergence matters because it weakens any argument that KnowBe4 has an uncontested feature monopoly in the core SAT workflow. The more durable distinctions now come from where each vendor connects awareness to adjacent systems. Proofpoint uses live threat intelligence, suspicious-message reporting, and email-security context to make training threat-informed. Mimecast similarly argues that awareness should sit inside a broader human-risk and email-defense stack. Cofense differentiates by connecting reporting behavior and post-delivery remediation, which is appealing to organizations where the SOC owns the awareness program. KnowBe4’s competitive answer is breadth and configuration. Its official pricing and features pages show support for unlimited phishing tests, AI-selected templates, user-event APIs, smart groups, executive reporting, SCIM and SSO, optional real-time coaching through SecurityCoach, and add-on anti-phishing through PhishER Plus. That is a wide control surface. But challengers are attacking specific weaknesses in the classic KnowBe4 playbook. Hoxhunt markets gamification and adaptive simulations as more effective for sustained engagement, SoSafe emphasizes behavioral science and European privacy or works-council fit, and CybSafe frames most legacy tools as overly focused on click rates rather than real behavior data. The result is a market where capability breadth favors KnowBe4, but narrative momentum in behavior-led HRM favors several challengers.[CP003, CP004, CP005, CP008, CP009, CP015]

Feature / capability matrix
buying criterionKnowBe4bundle incumbentsbehavior-led challengersSOC-linked / substitute options
Baseline phishing simulationStrong; unlimited tests and broad template libraryStrong; Proofpoint and Mimecast both support simulationsStrong; Hoxhunt and SoSafe position this as coreMixed; Cofense stronger when tied to reporting, SANS is not simulation-first
Adaptive personalization and risk scoringStrong; AIDA, SmartRisk, AI-selected templatesStrong; Proofpoint risk scoring and threat-informed enrollmentStrongest narrative; Hoxhunt, SoSafe, CybSafe all lead with adaptive behavior changeModerate; more workflow-specific than broad HRM
Email-security telemetry integrationModerate; APIs and SecurityCoach extensionsStrongest; Proofpoint and Mimecast own adjacent email controlsModerate; depends on integrations rather than native email stack ownershipStrong for Cofense; limited for SANS
Compliance and audit workflow supportStrong; reporting, executive views, compliance add-onsModerate to strong depending on suite adoptionModerate; often framed through risk reduction rather than audit breadthStrong for MetaCompliance and SANS program resources
User engagement / gamificationModerate to strong; gamification exists but is not sole messageModerate; engagement is present but secondary to ecosystemStrongest; Hoxhunt and SoSafe explicitly center engagement and habitsMixed
Post-delivery detection / remediation linkageModerate via PhishER Plus and reporting loopsStrong via broader secure-email stackModerate unless connected through integrationsStrongest for Cofense

Cells summarize the main public message and disclosed features in the fetched sources. They are directional and should be verified in demos for exact deployment scope.

[CP002, CP004, CP005, CP008, CP009, CP010]
FP002: Feature breadth / capability map

KnowBe4 is strongest on breadth, while challengers cluster around specific wedges such as behavior science, email-stack integration, or remediation.

Cells reflect public-evidence strength rather than audited technical test results. “High” means multiple disclosed features or a central market narrative in fetched sources.

[CP028, CP030, CP037, CP039, CP041, CP043]

3.3 Pricing opacity and bundle leverage are major competitive variables

Public pricing remains one of the least transparent parts of the category. KnowBe4 discloses tier structure and included capabilities more clearly than most peers through its SAT pricing page, but even that page is still packaging transparency rather than clean realized-seat economics. Most rivals, including Proofpoint, Hoxhunt, SoSafe, MetaCompliance, Cofense, and Mimecast, foreground demo-led sales motions rather than public list-price tables. That means competition often depends less on catalog price and more on who already controls adjacent budget, especially email-security budget, identity integrations, and security-operations workflows. This matters because Proofpoint and Mimecast can compete with KnowBe4 using distribution power rather than only SAT features. A buyer already running those vendors for email security may accept an awareness module that is merely good enough if it reuses threat telemetry, procurement relationships, and reporting infrastructure. Cofense has a similar advantage in organizations where phishing-report workflows already feed incident response. By contrast, KnowBe4’s route to defensibility is to make the independent platform decision worthwhile through richer content, easier rollout, stronger reporting, and expansion add-ons. Independent review sources suggest the strategy works for many customers, but they also surface pressure points including repetitive content, localization gaps, and difficulty quantifying ROI. Those issues could make bundle-driven alternatives more attractive when awareness becomes a line item under scrutiny.[CP020, CP027, CP031, CP032, CP033, CP034]

Pricing / packaging comparison
vendorpublic pricing visibilitycontract motionincluded capabilities signalunknowns / discountingimplication
KnowBe4Moderate: public tier packaging and feature inclusion, but no realized seat economicsAnnual subscription by user tier with optional add-onsFoundation / Advanced tiers plus SecurityCoach, Compliance Plus, PhishER PlusActual seat price, discounting, and enterprise bundle economics remain privateMore transparent packaging than peers helps early evaluation
ProofpointLow: demo-led public pagesPlatform / suite-led enterprise salesAwareness increasingly presented with human-risk and email-stack contextCross-sell economics and module attach rates are undisclosedInstalled-base leverage may outweigh transparent list pricing
HoxhuntLow: demo-led public pagesEnterprise consultative motionAdaptive simulation and HRM narrative dominate packaging messagePricing, module splits, and managed-service components are not publicBuyer must validate whether premium engagement gains justify spend
MimecastLow: demo-led public pagesSuite-led motion with email-security adjacencyAwareness positioned as one part of a broader human-risk platformRealized bundle discounts and attach rates are undisclosedExisting Mimecast customers may face lower switching friction
SoSafe / MetaComplianceLow: demo-led public pagesConsultative enterprise motionEmphasis on localization, compliance, and behavior programsRealized pricing by geography, works-council constraints, and modules is not publicStrong fit can trump price transparency in Europe or compliance-heavy buyers
CofenseLow: demo-led public pagesSecurity-operations-oriented consultative motionValue tied to remediation workflow, reporting, and managed defenseAwareness-only price versus remediation-bundle price is not publicCan win where SOC ROI matters more than generic training cost

The main public difference is packaging transparency, not list-price comparability. Most vendors require a demo or quote, so procurement leverage is likely shaped by adjacent product relationships.

[CP003, CP020, CP021, CP031, CP032, CP039]
FP003: Switching-cost and moat ladder

KnowBe4’s defensibility narrows from broad deployment familiarity toward harder-to-prove economic lock-in and independently verified outcome superiority.

Stage values are ordinal durability weights, not measured conversion or retention percentages.

[CP026, CP031, CP032, CP040, CP041, CP042]

3.4 KnowBe4’s moat is real, but it is a breadth moat rather than an unassailable innovation moat

The strongest case for KnowBe4 is that it remains the category-scale incumbent with unusually broad disclosed functionality, large-enterprise adoption, and a long list of adjacent modules that increase account expansion potential. For compliance-heavy or mid-market buyers, that combination is hard to displace because it reduces implementation friction and supports a one-vendor program. The company’s official positioning around SmartRisk, AIDA, SecurityCoach, and PhishER Plus shows an effort to migrate from legacy SAT into broader human-risk management before the market fully commoditizes. The weaker case is that several competitors are attacking the exact areas where a scale incumbent can become vulnerable: engagement fatigue, commodity phishing templates, and insufficient linkage between awareness metrics and real security outcomes. Hoxhunt, SoSafe, and CybSafe all argue that behavior change, personalization, and adaptive interventions matter more than content-library size. Proofpoint and Mimecast can use platform bundling to erode pure-play pricing power. Cofense can win accounts that want awareness to feed remediation rather than just compliance. There is also a diligence gap around independent win-loss, churn, and renewal evidence across the sector. Absent that data, the prudent view is that KnowBe4’s moat looks durable in breadth and installed-base familiarity, but less durable if buyers increasingly privilege integrated telemetry, EU governance, or provable behavior change over sheer content scale.[CP026, CP027, CP028, CP030, CP036, CP037]

Moat durability / competitive risk register
moat claimthreatseveritymitigation / diligence ask
Broad content and phishing breadthFeature convergence makes content libraries less differentiated over timemediumRequest competitive win-loss data and renewal reasons from large enterprise cohorts
Independent best-of-breed platformEmail-security incumbents bundle awareness into existing spendhighModel attach-rate pressure from Proofpoint and Mimecast installed bases
Human-risk platform expansion via add-onsOptional modules may signal that some higher-value controls are not core tier entitlementsmediumCheck add-on penetration, ARPU uplift, and renewal by module
Global enterprise usability and scaleLocalization and engagement challengers attack fatigue and repetitive-content concernsmediumReview churn or NPS by geography and by training-completion maturity cohort
Proof of program effectivenessIndependent standardized outcome benchmarks are scarce across the markethighAsk for customer cohort studies showing real reporting-rate or incident-rate change versus peers

This register translates the public evidence into diligence issues that matter for share stability and pricing power.

[CP027, CP028, CP031, CP034, CP040, CP041]

3.5 Exhibits

Chapter 04

04Financials

4.1 The last public numbers showed premium SaaS economics with strong recurrence

KnowBe4 entered its 2023 take-private as a business with unusually attractive public-market operating signals for a cybersecurity education platform. The company reported 42.6% year-over-year revenue growth and 44.1% ARR growth in Q3 2021, then reached $367.7 million of ARR and $89.9 million of quarterly revenue in its preliminary Q4 2022 release. Gross margins consistently stayed in the mid-80s, while free cash flow remained positive even as the company continued spending on sales, marketing, and product expansion. Those metrics matter because they explain why Vista could justify a premium private-market entry multiple relative to slower-growth cyber peers. Equally important, the quality of revenue looked stronger than the headline growth rate alone suggests. The Q3 2022 10-Q states that substantially all revenue came from subscription services, that customers are generally invoiced annually in advance, and that deferred revenue was a major source of operating cash. Fitch later reinforced that credit picture by stating that more than 99% of revenue is recurring and retention metrics remain strong. In other words, the public record supports the view that KnowBe4 was not simply a content vendor with volatile project revenue; it was a recurring SaaS platform with predictable billings, upfront cash collection, and meaningful upsell potential.[CI001, CI002, CI003, CI004, CI005, CI006]

Revenue streams table
streammechanismunitcurrent public value / statusqualitydiligence ask
Core SAT subscriptionAnnual or multi-year subscription access to cloud-based training and phishing platformARR / subscription revenuePrimary disclosed revenue engine; substantially all public-company revenue came from subscriptionsHigh-quality recurring SaaS revenueRequest current ARR by product and cohort after privatization
Downloadable content / LMS exportsContent access and downloadable modules allocated within contractsRecognized revenue component10-Q states downloadable content is a separate performance obligationRecurring but accounting treatment differs from hosted subscription deliveryRequest current mix between hosted use and downloadable content
Add-on modulesSecurityCoach, Compliance Plus, PhishER / PhishER Plus and related upsell modulesSeat-based or add-on subscriptionPublic pricing and product pages show optional add-on structure, but no revenue split is disclosedPotentially higher-ARPU expansion pathRequest attach rates and gross margin by module
Email-security adjacencyEgress and cloud-email-security expansion after 2024 acquisitionSubscription / bundled cross-sellPublicly disclosed as strategic diversification, but no financial contribution disclosedCould reduce SAT concentration if scaledRequest Egress revenue, growth, and integration economics
Services / otherImplementation or ancillary support activityLimited / likely immaterialNo major public evidence that services dominate the modelLow relevance versus software revenueConfirm services mix and professional-services margin

Table separates contractual revenue mechanisms from disclosed product packaging; it does not imply audited current mix after privatization.

[CI001, CI007, CI008, CI010, CI018, CI034]
Pricing / monetization table
price / contract modellist vs realized pricingdiscounts / unknownssource-backed signalimplication
Per-user subscription tiersPublic tier packaging is visible on SAT pricing pagesRealized seat price is privateKnowBe4 monetizes largely through subscription tiers and add-onsSupports predictable billings but hides enterprise discounting
Annual advance billingPublic filings say subscription customers are typically invoiced annually in advanceContract cadence by segment is not disclosedAdvance billing lifts deferred revenue and operating cash flowCash conversion likely stronger than usage-based SaaS models
Add-on upsell motionOptional modules are packaged separately from base SAT tiersAttach-rate and bundle discounting unknownCross-sell appears central to monetization expansionExpansion revenue may be more important than headline logo growth
Pricing-packaging realignmentFitch says the company implemented a strategic pricing and packaging realignment in 2024Magnitude of uplift undisclosedSuggests deliberate ARPU optimization post-take-privatePotential sponsor lever for EBITDA growth
International and enterprise pricingInternational growth and enterprise mix were discussed publicly before privatizationRegional pricing structure now opaqueCould materially affect realized ARPU and churnNeed cohort pricing by geography and segment

Public evidence is strong on packaging mechanics and weak on realized pricing.

[CI008, CI012, CI024, CI035]
FI001: Revenue model bridge

KnowBe4 converts contracted seat subscriptions and add-ons into deferred revenue, recurring recognition, and cash generation through advance billing.

[CI007, CI010, CI011, CI012]
FI003: Financial estimate range

Public revenue signals stepped up from FY2021 actual revenue toward a higher late-2022 annualized run rate before disclosure stopped.

The mid and high figures annualize partial-period disclosed revenue and are not audited full-year results. They show trajectory, not management guidance.

[CI001, CI002, CI004, CI005]

4.2 Unit-economics proxies were favorable, but current realized efficiency is no longer visible

KnowBe4’s public filings gave a reasonably strong unit-economics sketch even before privatization. Q3 2021 free cash flow margin was 28.1%, and the Q3 2022 10-Q showed $80.1 million of operating cash flow over the first nine months of 2022. The company explicitly tied cash generation to annual advance billing, growing deferred revenue, and an efficient sales model. Q3 2021 commentary also highlighted rising multi-product attach rates and nearly 100% international revenue growth, both of which suggest improving customer-level monetization rather than pure logo growth. By Q4 2022, the business still showed positive operating cash flow and free cash flow despite acquisition-related noise and pending-take-private disruption. The problem for underwriters is that these are now legacy signals. After February 2023, investors lost visibility into current CAC efficiency, payback, NRR, realized pricing, and gross margin by product line. Fitch gives a partial substitute by projecting EBITDA margin expansion toward the low-40s and forecasting positive free cash flow starting in FY26, but that is still a ratings-agency lens rather than audited GAAP disclosure. The best defensible conclusion is that historical public metrics point to favorable software-style economics, while the current degree of operating leverage can only be inferred indirectly through debt-market behavior and lender confidence.[CI011, CI012, CI013, CI014, CI015, CI016]

Unit economics table
metricvalue / nullconfidencewhy it mattersdiligence ask
Q3 2021 free cash flow margin28.1%highShows strong cash conversion before privatizationRequest FY2023-FY2025 FCF margins
Q4 2022 GAAP gross margin85.4%highSupports premium software economicsRequest current gross margin by product
Q4 2022 non-GAAP operating margin13.0%highIndicates operating leverage once SBC and public-company effects are normalizedRequest audited EBITDA bridge
Net revenue retentionHigh / not quantified by FitchmediumCritical for compounding and debt service durabilityRequest numeric NRR by segment
Multi-product attach rate19% in Q3 2021 commentarymediumEarly signal that cross-sell can raise ARPU and retentionRequest current attach rate after Egress and PhishER expansion
Capex intensityAbout 1% of revenue in Fitch forecastsmediumLow capex supports debt service and software valuationRequest actual capex and capitalization policy post-private

The current post-private picture depends on lender projections more than audited company reporting.

[CI011, CI013, CI014, CI015, CI024, CI028]
FI002: Unit economics bridge

Historical public metrics suggest software-like economics: high gross margin, low capex intensity, and cash generation supported by advance billing.

[CI003, CI011, CI013, CI014, CI030]

4.3 The post-Vista story is dominated by leverage, refinancing, and lender confidence

Financial analysis of KnowBe4 after the take-private is mostly a capital-structure exercise. The October 2022 deal announcement fixed the headline equity value at roughly $4.6 billion and the per-share consideration at $24.90, while the merger support agreements showed that Vista, KKR, Elephant Partners, and founder-linked holders were willing to roll equity rather than fully cash out. Fitch later reported that leverage had been high since the 2023 take-private and would only delever gradually through revenue growth and operating leverage, not aggressive debt paydown. That already implied a sponsor-owned business optimized for equity returns rather than early balance-sheet conservatism. The key public turning point came in July 2025, when KnowBe4 refinanced into a larger broadly syndicated first-lien structure. Fitch’s July ratings and Private Equity Wire’s transaction summary show the capital structure moving to a $1.46 billion first-lien term loan and a $200 million revolver, while eliminating the previously contemplated second-lien tranche. The debt cost fell sharply versus the prior private-credit structure, and Fitch expected interest coverage to improve above 2x from 2026 onward. That refinancing is important not because it solves leverage risk, but because it indicates the debt market still views KnowBe4 as a durable recurring-revenue software credit despite elevated sponsor leverage.[CI021, CI022, CI023, CI024, CI025, CI026]

Capital adequacy table
cash on handmonthly burn / FCFrunway months / adequacyplanned use of fundsdebt obligations / trigger
$117M cash at Dec. 31 2024Fitch expects FCF generation starting FY26Adequate near-term liquidity per Fitch, not a venture-style runway storySupport operations, integration, and sponsor-backed growth under new debt stack$1.46B first-lien term loan plus $200M revolver; leverage still elevated
Undrawn revolver availability$200M facility maturing 2030Adds liquidity cushion if execution softensWorking capital and acquisition flexibilitySpringing covenant detail not publicly disclosed
No near-term maturities after refinanceTerm loan due 2032Removes refinancing cliff in near termAllows management to focus on growth and margin expansionStill leaves high absolute debt burden
Interest burden reduced materially in 2025Savings inferred from repricing from private-credit levels to syndicated levelsImproves coverage and sponsor equity valueLower cash interest supports FCF improvementNeed exact interest schedule and fees
Equity cushion opaqueSponsor and rollover equity contributions undisclosedCannot fully underwrite residual equity valueImportant for exit math and downside protectionRequest original sources-and-uses and current debt waterfall

Capital adequacy is evaluated as a leveraged software credit, not as a cash-burning startup.

[CI021, CI023, CI025, CI026, CI027, CI029]
FI004: Capital intensity / cash-flow map

The 2025 refinancing likely improved free-cash-flow conversion by reducing interest burden while preserving a leveraged first-lien capital structure.

Values are ordinal impact weights, not actual dollar savings or leverage turns.

[CI023, CI025, CI026, CI027, CI029]

4.4 The financial verdict is positive on quality, but incomplete on current value creation

On the evidence available, KnowBe4 appears to be a financially attractive software asset with strong recurring revenue, healthy gross margins, and meaningful operating leverage potential. The public-company record and Fitch’s later credit work both support that view. The company also appears to benefit from annual billing, low capex intensity, and expansion opportunities through pricing-packaging realignment and adjacent modules. Those are exactly the features that private-equity owners and lenders want in a sponsor-backed software platform. The caution is that the public now sees only fragments. There are no audited FY2023 or FY2024 financials, no verified current ARR, no disclosed churn or NRR, no clean bridge from GAAP to Fitch-adjusted EBITDA, and no disclosed sponsor equity contribution or current mark. As a result, the right underwriting stance is not bearish on business quality, but humble about valuation precision. Revenue quality likely remains strong; margin direction likely improved; leverage is still meaningful; and the largest diligence blockers now come from disclosure opacity rather than obvious financial distress. Any investor or acquirer would still need confidential lender materials or management access to convert that favorable quality view into a high-confidence valuation view.[CI032, CI033, CI034, CI035, CI036, CI037]

Public financial gaps table
missing private metricimpactexact diligence path
FY2023-FY2024 audited revenue and EBITDAPrevents clean valuation and leverage modelingObtain lender materials, management presentations, or confidential information memorandum
Current ARR and NRRObscures revenue durability and growth qualityRequest monthly recurring-revenue bridge and retention cohort data
Realized pricing by segmentPrevents accurate gross-to-net and CAC-payback analysisReview price books, discount policies, and sample contracts
Egress financial contributionLimits visibility into diversification beyond core SATRequest acquired revenue, retention, and integration-margin data
Sponsor sources-and-uses / current equity markBlocks precise private-equity return analysisRequest original LBO model and latest board valuation materials

These are the minimum information requests required to move from qualitative confidence to investable financial underwriting.

[CI032, CI033, CI037, CI038, CI039, CI040]

4.5 Exhibits

Chapter 05

05Product & Technology

5.1 KnowBe4 sells a workflow, not just a course catalog

KnowBe4’s product is best understood as a continuous employee-risk workflow rather than a one-time training library. The onboarding materials, SAT feature pages, and AIDA materials all describe a sequence that starts with user provisioning, establishes a phishing baseline, runs ongoing tests, assigns training, and then adds automated remediation or real-time coaching. That workflow is reinforced by the learner app, the ModStore content library, and SmartRisk-linked orchestration. The result is a platform designed to move from baseline awareness to repeated measurement and intervention. The company’s breadth is visible in how many adjacent modules feed the same workflow. SecurityCoach turns third-party security events into just-in-time user coaching. PhishER Plus turns reported phishing emails into prioritized response queues, quarantine actions, and even re-usable training. AIDA attempts to automate much of the admin burden across campaign creation, refreshers, and phishing personalization. Egress extends the workflow farther into cloud email security and adaptive policy. This breadth is a real product advantage, but it also means the customer experience depends on how well identity systems, email platforms, and external security tools are connected.[CE001, CE002, CE003, CE004, CE005, CE006]

Product module / asset matrix
module / assetuserstatus / maturitydifferentiationdiligence gap
SAT core platformAwareness admin / workforceMature GA productLarge content library, phishing simulation, reporting, risk scoringNeed current module attach and usage by cohort
AIDA / AIDA OrchestrationProgram adminsRapidly expanding GA / current roadmap centerpieceAutomates campaign creation, refreshers, and personalized interventionsModel architecture and data-boundary disclosure is incomplete
SecurityCoachSecurity + IT teamsMature add-on with growing integrationsReal-time coaching from third-party security eventsValue depends on external telemetry quality and supported vendor depth
PhishER PlusSOC / mailbox defense teamsMature response layerTransforms reported phish into prioritization, quarantine, and training loopsNeed parity details across Microsoft 365 and Google Workspace
Learner App / ModStoreEnd users / distributed workforceMature extension surfaceMobile access, optional training, large multilingual content baseNeed current mobile engagement and completion by segment
Egress integrationEmail/security teamsEarly integrated phase after acquisitionExtends HRM into adaptive cloud email securityCurrent integration scope is narrow and packaging is premium-gated

Rows distinguish mature modules from areas where public product detail is still roadmap-like or integration-limited.

[CE001, CE002, CE004, CE006, CE007, CE008]
Workflow / use-case table
user jobcurrent workflowcompany solutionmeasurable benefitlimitation
Provision and maintain usersSync workforce identities into consoleADI / GUP / SCIM provisioning and SAML SSOReduces manual user management and keeps campaigns currentSCIM is one-way and alias-email support is limited
Establish baseline phishing riskRun initial tests and create starting benchmarkBaseline phishing plus initial Phish-prone Percentage measurementCreates program benchmark and segmentation starting pointDepends on whitelisting and mail-delivery setup
Run ongoing educationAssign and refresh training over timeAIDA Orchestration plus ModStore contentCuts admin effort and keeps content personalizedAI logic and targeting transparency are not fully public
Coach risky behavior in real timeTurn live events into micro-interventionsSecurityCoach with vendor detection rulesMoves training from annual events to in-the-flow nudgesRequires supported external security-tool telemetry
Triage reported suspicious emailPrioritize, quarantine, and learn from user-reported phishPhishER Plus, PhishML, PhishRIP, PhishFlipPotentially faster response and closed-loop trainingBest functionality appears strongest on Microsoft 365

The platform is best analyzed through how it fits the customer workflow, not by content-count alone.

[CE003, CE010, CE011, CE012, CE013, CE014]
FE001: Product architecture map

KnowBe4 layers provisioning, simulation, training, response, and analytics into a single human-risk workflow.

[CE001, CE002, CE003, CE004, CE008, CE009]
FE002: Customer workflow / operating flow

A typical deployment moves from provisioning and baseline measurement to ongoing phishing, training, coaching, and reporting.

[CE010, CE011, CE012, CE013, CE014]

5.2 The operating model is cloud-first, identity-led, and integration-dependent

KnowBe4’s architecture is operationally pragmatic rather than exotic. The support documentation shows that user identity is synchronized from external systems via ADI, Google provisioning, or SCIM, with SCIM acting as a one-way identity feed into the KSAT console. SAML SSO is supported, and the onboarding guide makes clear that implementation begins with domain verification, user provisioning, whitelisting, and phishing deliverability checks. In other words, deployment depends on identity hygiene and mail-flow configuration more than on customer-side code changes. The more advanced layers depend heavily on third-party security telemetry. CrowdStrike, Zscaler, and similar integrations feed SecurityCoach detection rules and real-time coaching. PhishER Plus depends on Microsoft 365 or Google Workspace for quarantine and remediation workflows, and its community intelligence claims depend on network effects from a large user base. This architecture is powerful because it lets KnowBe4 connect learning to live security behavior, but it also creates clear dependency risk: customers with thin security stacks get less value, customers on different email ecosystems may see uneven functionality, and roadmap success depends on maintaining many outside integrations.[CE011, CE012, CE013, CE014, CE015, CE016]

Technology / operating architecture table
layer / componentroledependencyrisk
Identity syncProvision users and groupsSCIM / ADI / GUP / IdP configurationDirectory errors or alias constraints can impair user-state accuracy
Mail-flow setupEnable phishing delivery and trackingWhitelisting and email-environment compatibilityMisconfiguration can distort baseline and ongoing simulation accuracy
SecurityCoach integrationsIngest security events for coachingCrowdStrike, Zscaler, Splunk and other external vendorsOutside API or telemetry changes can degrade functionality
PhishER Plus remediationRemove or prioritize malicious messagesMicrosoft 365 / Google Workspace integrations and syslog/API connectionsCross-platform parity may be uneven
Analytics and reportingShow user and program outcomesInternal dashboards plus reporting API surfacePublic developer surface appears stronger for reporting than full write automation
Cloud infrastructure and release pipelineOperate SaaS product safely at scaleAWS / Azure, CI/CD, monitoring, QA, loggingArchitecture is described operationally, but no deep public design spec exists

The major architecture insight is dependence on identity, mail, and telemetry integrations rather than customer-side code customization.

[CE011, CE012, CE013, CE017, CE019, CE021]
FE003: Critical dependency map

KnowBe4’s higher-value modules depend on identity providers, email suites, and third-party security telemetry.

[CE015, CE016, CE017, CE018, CE019, CE020]

5.3 Trust posture is mature, but some technical detail remains opaque

The publicly visible trust posture is stronger than the average awareness vendor. KnowBe4’s security statement describes CI/CD, peer review, staging separation, centralized encrypted logging, monthly vulnerability scanning, formal remediation timelines, and a private bug bounty program. The same materials also reference third-party audits and compliance programs including FedRAMP, ISO 27001, and SOC 2. The product-side signal matters because KnowBe4 increasingly touches production workflows such as real-time coaching, user provisioning, suspicious-message handling, and integrated email response. At the same time, some of the most strategically important technical details remain vague. AIDA is clearly central to KnowBe4’s roadmap, but the public pages do not explain model providers, inference boundaries, data residency for AI processing, or how much of the system is deterministic automation versus generative AI. The developer surface is also constrained: a reporting API is visible, but public material is far clearer on read/reporting access than on broad write automation. That combination supports a verdict of mature operational controls and broad product functionality, paired with incomplete visibility into the deepest AI and programmatic architecture layers.[CE021, CE022, CE023, CE024, CE025, CE026]

Trust / quality / compliance table
control / certification / quality metricstatusscopegap
FedRAMP Moderate authorizationPublicly listedApplies to PhishER / KSAT marketplace listing contextExact module-by-module scope is not fully explained in public-facing text
ISO / SOC / security auditsPublicly referencedRisk management and trust programs across productsGranular mapping by feature or region is not fully public
One-year backups / three-year logsPublicly statedOperational resilience and forensics postureNeed region-specific data-retention mapping for all products
Monthly vulnerability scanningPublicly statedWeb, OS, container, IaC, and dependency scanningNo public aggregate defect-rate or MTTR disclosure
Bug bounty and private testingPublicly statedOngoing vetted third-party security testingNo public summary metrics on findings or closure cadence

Trust posture is stronger than average marketing copy because it includes operational detail, but still stops short of full architecture transparency.

[CE022, CE023, CE024, CE025, CE026, CE027]
Roadmap / release / development-stage table
date / stagefeature / milestonestatusimplicationsource
2024Egress acquisition closesCompletedExpands platform into adaptive cloud email security and raises integration scopeOfficial press
2024AIDA suite expands around SmartRisk and remediationCompleted / commercializedSignals AI-native admin automation pushAIDA product pages / press
2025AIDA expands to seven production agents and deepfake training agentCommercialized / claimedShows roadmap priority around AI-driven simulations and contentAIDA page / PR
2026AIDA Orchestration launched as eighth agentCurrent release-state claimStrengthens automation narrative for ongoing training and phishingAIDA page
OngoingUnified customer experience across KnowBe4 and EgressIn progressPlatform breadth rises, but unification risk remainsOfficial Egress close / integration guide

Roadmap evidence is strongest where product pages and support docs agree; weaker where only high-level AI marketing claims exist.

[CE006, CE007, CE015, CE016, CE028, CE033]
FE004: Product maturity / capability map

Core SAT is mature, while platform leverage increasingly depends on automation, integrations, and post-acquisition unification.

[CE021, CE022, CE028, CE030, CE033, CE037]

5.4 Differentiation comes from breadth and data loops, but the roadmap still has integration and parity risks

KnowBe4’s clearest product differentiation is breadth linked to workflow data. The content library, learner app, AI orchestration, SmartRisk scoring, real-time coaching, and PhishER Plus response tooling are all more valuable together than alone. For many buyers, especially those replacing a narrower SAT point tool, that breadth can feel like a category-leading operating system for human risk management. The company’s acquisition of Egress also strengthens the strategic case that KnowBe4 wants to connect awareness, user-risk scoring, and cloud email security. The flip side is that the roadmap now has more moving parts and more product-risk surface. Several capabilities are tier-gated or add-on-gated. Some integrations depend on external vendor APIs or special deployment conditions such as whitelisting or Cloud NSS support. Public documentation also suggests the Egress integration is narrow in current data scope, which implies that the unified-customer-experience promise is still progressing rather than complete. The overall product verdict is therefore positive on breadth and maturity, but not yet fully proven on deep platform unification or transparent AI architecture disclosure.[CE030, CE031, CE032, CE033, CE034, CE035]

5.5 Exhibits

Chapter 06

06Customers

6.1 The customer base is broad, diversified, and still anchored in North America

KnowBe4's customer evidence is strongest on breadth. Fitch said the company serves a diversified base of industries and geographies with no customer concentration, while KnowBe4's own 2025-2026 materials put the installed base above 70,000 customers. That scale matters because the public-company era already showed more than 44,000 customers in 2021 and 56,867 in late 2022, implying continued expansion under Vista. At the same time, the revenue profile is not globally balanced. Fitch says most ARR still comes from North America, and BankInfoSecurity reported that nearly 83% of first-half 2022 sales were North American. The mix also still includes meaningful SMB exposure: Fitch says about one-third of ARR comes from SMB customers. That creates some macro sensitivity, but it also means KnowBe4 is not dependent on a handful of giant accounts. The best synthesis is that KnowBe4 now has real enterprise and public-sector reach, but its monetization base still skews US-heavy and partly SMB-driven.[CU001, CU002, CU003, CU004, CU005, CU006]

Customer segment mix and economics (public-evidence estimate)
segmentestimated share of ARRcontract styletypical buying motionchurn / quality signal
SMB~1/3 of ARRsubscription, often annualinside sales, MSP, resellerHigher macro sensitivity per Fitch but still mission-critical
Mid-marketMeaningful but undisclosedsubscription, annual / multi-yeardirect plus channel-assistLarge review footprint suggests durable adoption
EnterpriseLikely largest revenue poolmulti-product, often multi-yeardirect sales with implementation supportGartner and named-logo evidence imply stickier deployments
Public sector / educationSmaller share but visibleannual budgets / framework buyingdirect and specialist partnersCase studies show embedded compliance and onboarding use
Cross-sell email security / responseGrowing attachment layermodule upsell onto installed basecustomer-success-led expansionImproves ACV and embeds product deeper into workflow

Only the SMB share is explicitly disclosed; the rest is estimated from public customer proof, reviews, and case studies.

[CU005, CU006, CU027, CU032, CU035]
Geographic customer distribution (public-evidence estimate)
regionestimated customer / ARR sharepublic evidenceconfidence
North AmericaMajority of ARRFitch says majority ARR is in North America; 2022 revenue mix was ~83% North AmericaHigh
EMEAMeaningful secondary regionUK customer logos plus EMEA partner-award activityMedium
APACGrowing but smaller than NA/EMEACebu Pacific and regional partner activityMedium
LATAM / emergingPresent but less evidencedGlobal customer claims but few named public logos in current packLow
Global / multi-region accountsImportant for enterprise motionIdeagen global workforce and KnowBe4's 70k-customer claimMedium

Only North America is directly quantified in the evidence pack.

[CU003, CU004, CU009, CU030, CU036]

6.2 Acquisition appears hybrid: direct core, partner-assisted expansion, MSP access at the edge

KnowBe4 does not publish CAC, payback, or segment-level sales-efficiency data, so channel structure is the best public proxy. The company's partner page explicitly courts resellers, consultants, and MSPs, while the ConnectWise marketplace listing shows KnowBe4 can be distributed through an MSP-centric procurement surface. Regional award releases in the Americas and EMEA suggest that partner coverage is not decorative; it is organized, renewed, and important enough to merit annual recognition. That matters because the product is often purchased by IT, security, managed-service, or compliance teams that already buy through channel relationships. Public evidence still suggests direct sales dominate the larger-account story, especially for enterprise or multi-product deployments, but the partner ecosystem likely reduces acquisition friction in SMB, cross-border, and specialist-vertical motions. The partner footprint also improves reach without forcing KnowBe4 to build a fully local direct team in every region, which is consistent with its customer-scale claims and the visible spread of case studies outside the US.[CU007, CU008, CU009, CU035, CU036]

Customer acquisition channels and CAC proxies
channel / motionvisible evidencelikely economics signalwhere it seems strongest
Direct enterprise salesEnterprise and global case studiesHigher CAC but larger ACV and stronger cross-sellEnterprise / global accounts
Inside sales / web conversionLarge review surface and broad SMB installed baseLower ACV, scalable repeatable motionSMB and lower mid-market
MSP marketplaceConnectWise marketplace listingChannel margin offset by lower direct-sales costSMB and outsourced IT buyers
Reseller / consultant channelPartner page plus regional awardsPartner-assisted CAC and faster regional entryEMEA, Americas, specialist verticals
Customer expansion / module upsellPhishER, Prevent, Defend, Protect case studiesBest unit economics because CAC is sunkExisting SAT accounts

CAC is not disclosed; this table uses publicly visible motion structure as a proxy.

[CU007, CU008, CU009, CU027, CU032]
FU001: Customer acquisition and expansion funnel

The visible motion starts with digital proof and partners, lands via direct or MSP-led sale, and expands into adjacent modules.

[CU007, CU008, CU010, CU016, CU022, CU027]

6.3 Named customer proof is unusually concrete and often tied to measurable behavior change

The quality of public customer proof is a genuine strength. KnowBe4's case studies are not just logo pages; many include before-and-after metrics, user counts, and deployment details. Cebu Pacific said phish-prone percentage dropped from 81% to 6% while rolling out training across more than 6,000 employees and later 2,000 more subsidiary users. The City of Daytona Beach reported 100% policy acceptance, a 12% to 2% phish-prone improvement, and 90% faster email recalls with PhishER Plus. Bridgewater State University cut its phish-prone rate from 15% to 4% across more than 8,000 users and embedded training into onboarding. RWK Goodman, South Ayrshire Council, Ideagen, Shields Health Solutions, and Crawford show that KnowBe4 can expand from SAT into email encryption, misdirected-email prevention, response, or Microsoft-365-centric cloud email security. This pattern matters because it suggests the product is not only landing as annual compliance content; it is often becoming part of daily security operations and cross-sell motion.[CU020, CU021, CU022, CU023, CU024, CU025]

Named customer proof table
customersegment / geographyevidence typekey outcomeconfidence
Cebu PacificAviation / PhilippinesOfficial case studyPPP reduced 81% -> 6%; 6,000 core users plus 2,000 expansion usersHigh
City of Daytona BeachLocal government / USOfficial case study100% policy acceptance; PPP 12% -> 2%; email recalls 90% fasterHigh
Bridgewater State UniversityEducation / USOfficial case studyPPP 15% -> 4%; onboarding training for new employeesHigh
RWK GoodmanLegal / UKOfficial case studyEncryption + Prevent workflow; analytics used to prove ROIHigh
South Ayrshire CouncilGovernment / UKOfficial case study1,000+ users; stronger network standard and more user reportingMedium
IdeagenSoftware / globalOfficial case studyLower admin burden; faster targeted feedback after acquisitionsMedium
Shields Health SolutionsHealthcare / USOfficial case study2,000-user rollout of Defend / Prevent / Protect on Microsoft 365High

The company publishes many more references, but these seven are enough to show cross-vertical and cross-geo breadth.

[CU016, CU020, CU023, CU025, CU027, CU032]
FU003: Land-expand customer journey map

Public case studies show a repeated path from baseline training into deeper security workflow embedding.

[CU020, CU022, CU023, CU025, CU027, CU032]

6.4 Independent satisfaction evidence is strong overall, but not uniformly positive

Review data makes the customer-quality story more believable, but it is not perfectly clean. G2 is the strongest proof point: more than 2,300 reviews, a 4.6-star average, and a heavily positive rating distribution. TrustRadius and PeerSpot also support the picture of broad adoption and generally favorable product sentiment. Gartner adds enterprise-specific texture, with both favorable commentary and usable criticism around dashboard complexity, training workflows, and risk-score interpretation. The main adverse counter-signal comes from Trustpilot, where the small but visible review set skews negative and focuses on false positives, confusing tests, and poor end-user experience. That split is not fatal, but it is important. It suggests buyers and administrators often like the platform more than end users do. Combined with Fitch's comment that retention metrics remain stable, the most defensible customer verdict is positive but incomplete: the company looks diversified and sticky, yet outside observers still lack numeric churn, NRR by segment, and CAC efficiency after privatization.[CU010, CU011, CU012, CU013, CU014, CU015]

Customer satisfaction evidence by review platform
platformvisible scaleheadline score / signalwhat it is best foradverse note
G22,304 reviews4.6/5; 81% five-starScaled admin satisfaction and product breadthSelf-selection and vendor-campaign bias remain possible
Official G2 release1,893 reviews at release date96/100 score; 21 quarters #1Confirms company emphasis on review leadershipCompany-curated framing
TrustRadius1,163 reviews/ratingsLarge review volumeFeature-level buyer detailLess headline-simple than G2
PeerSpot18 reviews8.6/10Security-practitioner comparison contextMuch smaller sample
FeaturedCustomers130 references; 63 case studiesBreadth of referencesNamed customer proof aggregationReference listings are not all equal-quality
Gartner Peer InsightsEnterprise qualitative signalMixed but credible enterprise commentaryUsability and deployment nuanceDashboard and VRO-score criticism appears repeatedly
Trustpilot28 reviews1.6/5 adverse signalEnd-user friction and complaintsSmall sample and consumer-style audience

The review stack is strongest when G2, TrustRadius, Gartner, and named customer proof all point in the same direction.

[CU010, CU011, CU012, CU013, CU014, CU015]
Revenue-quality, concentration, and expansion readout
quality dimensionpublic signalreading
Customer concentrationFitch says no customer concentrationPositive
SMB exposure~1/3 of ARR from SMBMixed
RetentionFitch says retention metrics are stablePositive
Cross-sell depthPhishER / Prevent / Defend / Protect appear in case studiesPositive
End-user sentiment riskTrustpilot complaints and Gartner UX critiqueMixed
North America dependencyMajority of ARR remains NA-ledMixed

This table summarizes the practical revenue-quality verdict from the full customer evidence set.

[CU003, CU005, CU006, CU013, CU017, CU019]
FU002: Customer satisfaction comparison matrix

B2B review sites are broadly positive, while Trustpilot is the main adverse outlier.

[CU010, CU014, CU015, CU017, CU019]

6.5 Exhibits

Chapter 07

07Risks

7.1 The biggest strategic risk is not training demand collapse but workflow displacement

KnowBe4 still benefits from a large installed base and a real market need, yet the strategic threat has shifted. The most relevant competitive evidence is Abnormal's replacement case study, where a global manufacturer explicitly chose not to renew KnowBe4 after deciding that separate phishing training, reporting, and support loops created too much operational noise. That matters because it reframes the debate: the threat is not whether awareness matters, but whether awareness remains a standalone budget line or gets absorbed into broader email-security and response workflows. SMB survey data sharpens the point. Buyers are spending more on cybersecurity, but they are also under AI pressure, rely heavily on MSPs, and increasingly want robust, consolidated protection. Mordor's market work suggests that awareness budgets can be squeezed as organizations move dollars toward automated detection and XDR-style stacks. For KnowBe4, that means the bull case depends on continuing to expand beyond SAT into coaching, response, and email security quickly enough to prevent point-solution compression.[CR001, CR002, CR003, CR004, CR005, CR006]

Strategic and market risk register
risklikelihoodseverityevidencemitigation path
Workflow displacement by email-security-native vendorsHighHighAbnormal replacement case; XDR budget pressureExpand bundled workflow value and prove lower admin burden
SMB budget / MSP trust fragilityMedium-HighMediumConnectWise and Devolutions survey evidenceLean harder on partner enablement, simpler packaging, and ROI proof
Awareness-budget squeeze from tool consolidationMediumHighMordor cites training-fund cuts for XDRBundle SAT with response, coaching, and email-security outcomes
Cross-sell failure beyond SAT coreMediumHighNeed to prove Egress and PhishER deepen moatPush unified roadmap and module attach into installed base

The market risk is less about raw demand disappearance and more about architecture substitution and wallet-share compression.

[CR001, CR003, CR011, CR012, CR036]
FR002: Competitive-risk cascade

Workflow displacement begins at buyer preference and propagates into retention, cross-sell, and valuation pressure.

[CR001, CR003, CR011, CR036]

7.2 The North Korea incident was contained, but it remains a serious operating-warning signal

KnowBe4 deserves credit for catching the fake-hire incident quickly, but the event is still material. The company said it hired a worker using a stolen identity after multiple interviews, reference checks, and background checks, then saw malware activity begin as soon as the laptop was received. EDR and SOC controls worked, yet the fact pattern is still uncomfortable because it shows how even a security vendor can be penetrated through HR and identity-control weaknesses. The broader U.S. enforcement record makes the risk harder to dismiss. DOJ, FBI, Treasury, State, and IC3 materials all describe DPRK-linked remote-worker schemes as active, adaptive, and tied not only to wage diversion but also to data theft and extortion. That means the reputational lesson is wider than one anecdote: workforce integrity, hiring verification, device-shipping controls, and privileged-access segmentation are now board-level security issues. For a company selling human-risk management, a repeat episode would be disproportionately damaging even if the technical blast radius were contained again.[CR013, CR014, CR015, CR016, CR017, CR018]

Operational and workforce-integrity risk register
risklikelihoodseverityevidencemitigation path
Remote-worker identity fraud / insider accessMediumHighKnowBe4 fake-hire incident; DOJ/FBI alertsHarder ID verification, device controls, least privilege
AI-accelerated phishing and social engineeringHighMedium-High83% of SMBs say AI raised threat levelRefresh content faster and shift to in-flow coaching
End-user fatigue / workflow frictionMediumMediumTrustpilot/Gartner complaints and Abnormal critiqueReduce false positives, improve UX, prove workflow simplicity
Integration / incident-response complexityMediumMediumCross-sell into new modules increases operating surfaceStandardize Microsoft 365 and multi-product deployment playbooks

Operational risk is unusually visible because the company publicly disclosed its own infiltration attempt.

[CR005, CR013, CR015, CR016, CR018, CR020]
FR003: Debt and governance risk cascade

Leverage, litigation, and leadership transition can compound into a tighter execution envelope.

[CR021, CR026, CR028, CR031, CR033, CR038]

7.3 Legacy merger litigation and elevated leverage keep the downside profile high

KnowBe4's legal and capital-structure risks are both meaningful. The amended Florida securities complaint and the continuing Delaware merger-litigation trail show that the take-private process remains under scrutiny long after closing. Even if these matters do not impair operations directly, they consume management attention and can force settlement, disclosure, or governance concessions. More immediately, Fitch's credit work makes clear that leverage is still high. KnowBe4 was rated B at the issuer level, its first-lien debt package was eventually marked down to B+ recovery terms after upsizing, and Fitch still expects leverage below 7.5x only gradually. The most important line in the rating commentary is not the rating itself but Fitch's view that private-equity ownership may prioritize return maximization over debt prepayment. That creates a classic sponsor-backed software risk: even with strong recurring revenue, the equity story can be pressured by leverage, refinancing cycles, and optionality around acquisitions rather than deleveraging.[CR021, CR022, CR023, CR024, CR025, CR026]

Debt and capital-structure risk table
facility / issuecurrent readriskcomment
$1.46B first-lien term loanActiveHigh leverage remainsUpsized in July 2025 and drove first-lien downgrade to B+ recovery terms
$200M revolverAvailable liquidity backstopMediumHelps liquidity but does not reduce leverage
Issuer rating B / stableSponsor-backed sub-investment-grade profileHighSignals resilience but still meaningful balance-sheet risk
PE ownership / ROE maximizationStructural incentive issueHighFitch explicitly warns debt prepayment may not be prioritized
Interest coverage >2x from 2026Improving but not comfortableMediumLower financing cost helps, but leverage remains elevated

The refinancing improved cost of debt but not the underlying sponsor-backed leverage story.

[CR026, CR027, CR028, CR029, CR030, CR038]
Regulatory / legal risk register
jurisdiction / areaissuestatusowner
US employment / identity controlsDPRK-linked remote-worker infiltration riskActive sector-wide threatHR + Security + IT
US sanctions / enforcementTreasury / State / DOJ actions around DPRK schemesActive and escalatingLegal + Security
US corporate governanceLegacy merger-disclosure and proxy litigationActiveBoard + Legal
Global data / behavior analyticsTraining, reporting, and user-scoring governanceOngoing compliance burdenProduct + Legal
Leadership transitionFounder to hired CEO handoffActive 2025-2026 transition phaseBoard + Executive team

Not all exposure is unique to KnowBe4, but several items are unusually salient because of the company's brand and recent history.

[CR019, CR021, CR025, CR031, CR033, CR037]
FR001: Risk likelihood × severity matrix

KnowBe4's heaviest risks cluster in competition, debt, and workforce integrity.

[CR012, CR020, CR026, CR033, CR039, CR040]

7.4 The business can manage through these risks, but the stack is crowded

Bryan Palma did not inherit an unproven company; he inherited a scaled, sponsor-owned platform with over 70,000 customers, a founder who remains executive chairman, and a business already extending beyond classic SAT. That gives the company mitigation capacity. Egress broadens the product set, the company responded transparently to the fake-hire incident, and recurring revenue still provides some resilience. The problem is simultaneity. Competitive workflow pressure, debt, litigation, leadership transition, and AI-era threat acceleration are all active at once. In isolation, each issue is manageable. In combination, they raise execution risk materially, because management cannot solve them with a single lever. The board and sponsor need to manage capital structure, product integration, hiring controls, and go-to-market evolution together. That is why the right conclusion is not panic but prioritization: KnowBe4 looks like a viable company with high operating risk, not a broken one. The difference matters for underwriting because it argues for close monitoring rather than an outright dismissal of the business.[CR031, CR032, CR033, CR035, CR039, CR040]

Risk prioritization and kill criteria
risk clusterwhat would worsen itwhat would improve itthesis impact
Competitive displacementMore public non-renewal stories or falling attach ratesProof of rising module attachment and renewal durabilityHigh
North Korea / workforce integrityRepeat infiltration or data-loss eventClean follow-through on hiring controls and no repeatsHigh
Litigation / governanceAdverse ruling, discovery issues, or costly settlementDismissal or immaterial settlementMedium-High
Debt / sponsor extractionAdditional leverage, dividend recap, or weak FCFVisible deleveraging and FCF improvementHigh
Leadership transitionSales slowdown, talent churn, or integration missesStable execution under Palma with founder supportMedium

This table translates abstract risk into practical thesis-monitoring triggers.

[CR028, CR033, CR034, CR036, CR038, CR039]

7.5 Exhibits

Chapter 08

08Valuation

8.1 The 2023 take-private remains the main hard anchor, but 2025 debt matters too

Valuation starts with the facts that are actually observable. Vista agreed to acquire KnowBe4 for about $4.6 billion at $24.90 per share, a premium transaction that set the last truly hard external value marker. The 2022 disclosure set also showed a business that had reached roughly $90 million of quarterly revenue and $367.7 million of ARR by late 2022. That is enough to establish that KnowBe4 was a scaled recurring-revenue software company going into the take-private. The more recent 2025 refinancing matters because it confirms lender willingness to support a large sponsor-backed credit, and it meaningfully cut borrowing cost. But it is not a new equity valuation. In other words, the refi supports business viability and some enterprise-value resilience, yet it also reminds investors that capital structure is now central to the story. The clean read is that $4.6 billion is a real anchor, but it is a dated anchor and should not be mistaken for a self-updating mark.[CV001, CV002, CV003, CV004, CV005, CV010]

Historical anchor data used in scenarios
period / eventrevenueARRother anchor
Q3 2021$64.1M quarter$262.2M ARR44,000+ customers
Q2 2022$80.8M quarter$328.3M ARR52,000+ orgs per SiliconANGLE
Q4 2022 preliminary$89.9M quarter$367.7M ARR56,867 customers
2023 take-private$4.6B EV / equity headlinen/a$24.90 per share; 44% premium
2025 refinancingn/an/a$1.46B debt refi at 375 bps over SOFR

These are the principal hard datapoints available without private-company financial disclosure.

[CV001, CV002, CV004, CV005, CV006, CV010]
FV001: KnowBe4 valuation range vs market anchors

The base-case range sits below the 2023 take-private mark, while the bullish case can still approach or exceed it.

[CV015, CV024, CV025, CV026, CV039]

8.2 Today's market argues for a premium, but not for ignoring compression or leverage

The valuation tension is straightforward. On one hand, Fitch says more than 99% of revenue is recurring, retention remains stable, and margins should improve materially. Those are exactly the characteristics that justify a premium revenue multiple. On the other hand, DealMatrix shows cybersecurity medians around 3.8x EV/Sales as of March 2025, with North America typically the richest region but still far below the most exuberant cyber periods. The refinancing also kept leverage high enough that Fitch still expects only gradual deleveraging and explicitly warns that private-equity ownership may not prioritize debt paydown. That means KnowBe4 cannot simply be valued like a clean public SaaS name with no debt overhang. The right framework is to award some premium over the sector median for quality and scale, then subtract for opacity and balance-sheet risk. That pushes the exercise toward a fair-value range rather than a point estimate and explains why the 2023 headline should now be treated as an upper reference rather than a default base case.[CV007, CV008, CV009, CV013, CV014, CV015]

Key valuation assumptions and discounts
assumption / factorcurrent readwhy it mattersdirectional effect
Recurring revenue quality>99% recurring; stable retention per FitchSupports premium multiplePositive
GrowthMid-teen growth framing from FitchDetermines whether old deal price is still reachablePositive / mixed
LeverageStill high; gradual deleveraging onlyReduces equity margin of safetyNegative
Sponsor incentivesDebt prepayment may not be prioritizedRaises extraction / recap riskNegative
Customer breadth70k+ customers and low concentrationSupports resilience and lender supportPositive
Disclosure opacityNo current audited post-private revenue / EBITDAForces wide valuation rangeNegative

These assumptions explain why fair is the right stance even though the business itself appears solid.

[CV007, CV008, CV013, CV014, CV023, CV029]
FV002: Valuation sensitivity matrix

Small changes in growth confidence and multiple support materially change implied value.

[CV023, CV024, CV025, CV026, CV039]

8.3 Comparable companies prove the category is real, but none solves the pricing question alone

The comp set is useful mainly for framing, not for precision. Proofpoint and Mimecast are the closest people-and-email security references, while SailPoint offers a private-equity cybersecurity software benchmark, Rubrik offers a recent public cyber appetite marker, and Abnormal plus Hoxhunt show where adjacent AI-native or people-risk platforms have been financed. Together they demonstrate that KnowBe4 belongs in a legitimate cyber-software valuation neighborhood rather than in a compliance niche. But the comparables also resist oversimplification. Proofpoint is larger and broader; SailPoint is identity-centric; Rubrik is data security with public market liquidity; Abnormal is AI-native email security; Hoxhunt is a smaller people-layer specialist. The takeaway is not that one peer determines KnowBe4's price, but that the company deserves to be triangulated against both premium cyber platforms and more mature sponsor-backed assets. That triangulation supports a multi-billion-dollar enterprise value, yet it does not prove that the old $4.6 billion mark is obviously cheap today.[CV017, CV018, CV019, CV020, CV021, CV022]

Comparable valuation table
companyvaluation eventheadline valuerevenue / ARR evidence in current packreadthrough for KnowBe4
Proofpoint2021 Thoma Bravo take-private$12.3BNot included in current packScaled private cyber platform comp with people / compliance overlap
SailPoint2022 Thoma Bravo take-private$6.9BNot included in current packPrivate-equity security-software benchmark
Rubrik2024 IPO pricing$6.6B FDVNot included in current packShows public appetite for scaled cyber names
Abnormal Security2022 Series C$4.0BNot included in current packAI-native email-security peer that pressures KnowBe4 strategically
Mimecast2022 Permira take-privatePrivate-email-security referenceNot included in current packUseful adjacent comp, but not SAT-led
Hoxhunt2022 Series B$40M round size, much smaller scaleNot included in current packShows capital support for human-risk specialists at smaller scale

The comp set is directional. The current evidence pack is stronger on headline value than on fully aligned revenue data for every peer.

[CV017, CV018, CV019, CV020, CV021, CV022]
Comparable fit table
peerhow similarwhy imperfect
ProofpointHighBigger and broader compliance / email footprint
SailPointMediumIdentity-led rather than SAT-led
RubrikMediumPublic data-security platform, not human-risk
AbnormalMedium-HighCloser email-security workflow rival than valuation twin
MimecastMediumEmail security closer than SAT heritage
HoxhuntLow-MedSmaller people-layer specialist

The comparable set is useful but imperfect.

[CV017, CV018, CV019, CV020, CV021, CV022]
FV004: Comparable-fit matrix

KnowBe4 sits between classic security-software comps and email / human-risk specialists.

[CV017, CV019, CV020, CV022, CV028, CV029]

8.4 The most defensible stance is research-more with a fair valuation view

Because current audited numbers are unavailable, scenario analysis is the only honest way to close the chapter. A downside case using roughly public-market-like sector multiples on a $550-580 million revenue base points to low-to-high $2 billions of enterprise value. A middle case using a quality premium but still acknowledging leverage points to roughly $3.6-4.3 billion. A bullish case, which assumes stronger private growth, attach, and premium-quality persistence, can still reach or exceed the old $4.6 billion anchor. The practical implication is that KnowBe4 likely remains a unicorn and may still be worth about what Vista paid, but the public evidence does not establish a margin of safety. Debt, sponsor optionality, and disclosure opacity all narrow conviction. That is why the right recommendation is research-more rather than buy: the company looks good enough to matter, but not transparent enough to underwrite aggressively on public information alone.[CV023, CV024, CV025, CV026, CV027, CV030]

KnowBe4 valuation scenarios
scenarioassumed revenue baseEV / revenue bandimplied EV rangeconfidence
Downside$550-580M4.0x-5.0x$2.2B-$2.9BMedium
Base case$600-620M6.0x-7.0x$3.6B-$4.3BMedium
Upside$630-650M7.5x-8.5x$4.7B-$5.5BLow-Med
2023 hard anchor~$360M public run-rate at announcementImplied by deal, not used as current trading multiple$4.6BHigh as history, low as current mark

Scenario ranges are underwriting estimates, not audited current-company disclosures.

[CV023, CV024, CV025, CV026, CV027, CV039]
Debt risk table
factorcurrent stateequity implication
Issuer ratingB / stableRisk remains meaningful
LeverageBelow 7.5x only graduallyCaps equity upside
Refinancing cost375 bps over SOFRImproves interest burden
Sponsor incentivesDebt paydown not guaranteedSupports discount

Debt is central to current valuation underwriting.

[CV010, CV011, CV013, CV014, CV036]
FV003: Enterprise-value bridge from 2023 anchor to today's stance

Value support and value discounts push the current stance below the old transaction anchor.

[CV007, CV013, CV015, CV029, CV039, CV040]

8.5 Exhibits

Disclaimer

This report is a public-information diligence snapshot prepared as of 2026-07-10. It is not investment advice. KnowBe4 is a private sponsor-owned company, and several underwriting-critical items remain undisclosed, including current audited financials, cohort retention, and the post-refinancing equity waterfall.

Evidence index

Claims
IDStatementConfidenceSources
CO001 KnowBe4 was founded in 2010 by Stu Sjouwerman. High SO002, SO017, SO025
CO002 KnowBe4’s headquarters is 33 N Garden Ave, Suite 1200, Clearwater, Florida 33755. High SO003, SO024
CO003 KnowBe4 currently markets itself as a platform for securing both humans and AI agents, not only as a phishing-training vendor. High SO001, SO011
CO004 KnowBe4’s homepage says the company has 15+ years of behavior data and 70,000 global customers. Medium SO001
CO005 The April 2025 CEO-transition release says KnowBe4 had grown to serve over 70,000 customers. Medium SO006
CO006 KnowBe4’s February 2023 take-private closing release described the platform as serving more than 56,000 organizations worldwide at that time. High SO007, SO017
CO007 Bryan Palma became KnowBe4 president and chief executive officer effective May 5, 2025. High SO002, SO006
CO008 Stu Sjouwerman transitioned from chief executive officer to executive chairman when Palma was appointed. High SO002, SO006
CO009 Before joining KnowBe4, Bryan Palma most recently served as chief executive officer of Trellix. Medium SO006
CO010 The CEO-transition release says Sjouwerman led KnowBe4 through venture funding, a public offering, and strategic acquisitions before becoming executive chairman. Medium SO006
CO011 Vista Equity Partners completed its acquisition of KnowBe4 for $24.90 per share in cash on February 1, 2023. High SO007, SO012, SO017
CO012 KnowBe4’s shares ceased trading on Nasdaq when the Vista acquisition closed. High SO007, SO017
CO013 KnowBe4’s definitive merger proxy says the $24.90 per share price represented a 44 percent premium to the unaffected closing price on September 16, 2022. Medium SO016
CO014 KnowBe4 completed the acquisition of Egress in 2024 to add adaptive cloud email security capabilities to its platform. High SO008, SO013
CO015 Fitch assigned KnowBe4 a first-time Long-Term Issuer Default Rating of B with a Stable Outlook in July 2025. High SO013, SO014
CO016 Fitch said over 99 percent of KnowBe4’s revenue is recurring. Medium SO013
CO017 Fitch said KnowBe4 has a high net retention rate. Medium SO013
CO018 Fitch said more than half of KnowBe4’s ARR still comes from Security Awareness Training offerings. Medium SO013
CO019 Fitch said about one third of KnowBe4’s ARR comes from SMB customers. Medium SO013
CO020 Fitch projected KnowBe4’s EBITDA margins to reach the low 40s by 2028. Medium SO013
CO021 Fitch’s July 2025 affirmation said KnowBe4’s capital structure included an upsized $1.46 billion first-lien term loan and a $200 million revolving credit facility. High SO014, SO015
CO022 Private Equity Wire reported that KnowBe4’s new seven-year first-lien loan priced at 375 basis points over SOFR with a 99.75 issue price, down from 775 basis points on prior private debt. Medium SO015
CO023 KnowBe4’s workplace-awards release said the company had Great Place to Work certifications across 11 countries. Medium SO009
CO024 The same workplace-awards release named public presence across the United States, United Kingdom, South Africa, Australia, UAE, Singapore, Netherlands, Japan, India, Germany, and Brazil. Medium SO009
CO025 KnowBe4’s 2026 Americas Partner Program Awards named SHI, Assertiva, CDW, Optiv, Banyax, ePlus, and CYLK among notable channel partners. Medium SO010
CO026 KnowBe4’s platform page says the company combines awareness and compliance training, cloud email security, real-time coaching, crowdsourced anti-phishing, and AI-driven risk controls. High SO001, SO011
CO027 KnowBe4’s history page says KKR led a $300 million financing round in 2019 that valued the company at unicorn level. Medium SO002
CO028 KnowBe4’s history page says the company completed its IPO in April 2021. High SO002, SO018
CO029 KnowBe4’s history page says SecurityCoach launched in November 2022. Medium SO002
CO030 KnowBe4’s official history says the company launched AIDA in 2024 and Agent Risk Manager in 2026. Medium SO002
CO031 LeadIQ describes KnowBe4 as a 1,001-5,000 employee company serving more than 70,000 organizations worldwide. Low SO024
CO032 Mergr lists KnowBe4 as having 1,366 employees and being owned by Vista Equity Partners. Low SO025
CO033 KnowBe4’s official pages in the fetched source set do not publish an exact 2026 employee count. Medium SO005, SO009
CO034 Stanford’s Securities Class Action Clearinghouse listed the KnowBe4 merger-disclosure case as ongoing as of late June 2025. High SO019, SO020
CO035 The amended complaint summary said plaintiffs allege the proxy and related solicitation materials misled investors about KnowBe4’s true value and the fairness of the sale process. High SO019, SO020
CO036 The original complaint was dismissed without prejudice on June 9, 2025 and an amended complaint was filed on June 13, 2025. High SO019, SO020
CO037 KnowBe4 was still filing quarterly public-company reports with the SEC in late 2022 before the Vista transaction closed in 2023. High SO016, SO018
CO038 TrustRadius and PeerSpot reviews consistently praise KnowBe4’s large training library and phishing-simulation capabilities. Medium SO021, SO023
CO039 The same review sources also surface recurring complaints about ROI measurement, reporting complexity, or how realistic some simulations feel to users. Medium SO021, SO023
CO040 Official disclosures moved from 56,000+ organizations at the 2023 acquisition close to 70,000+ customers in 2025-2026 sources, implying continued growth under Vista ownership. High SO001, SO006, SO007
CO041 Fitch said KnowBe4 generates the majority of its ARR in North America and has no customer concentration. Medium SO013
CO042 Neither the official company pages nor the current fetched set publicly disclose a precise 2026 revenue or ARR figure. Medium SO001, SO002, SO013
CO043 The public source set does not provide a full 2026 board roster, committee structure, or investor-rights summary for private-company governance. Low
CO044 The merger proxy set the special meeting for January 31, 2023 and the record date at December 7, 2022. Medium SO016
CO045 The 2025 founder-to-operator CEO transition makes key-person dependence on Sjouwerman lower operationally but still strategically relevant for product vision and AI positioning. Medium SO006, SO002
CM001 The broad security awareness training market includes training platforms, simulations, analytics, and managed services rather than only static course libraries. Medium SM009, SM010
CM002 The 2026 Verizon DBIR ecosystem commentary says the human element remained involved in 62% of breaches. Medium SM022, SM023
CM003 Keepnet’s summary of Verizon’s 2025 DBIR said the human element was involved in about 60% of breaches. Medium SM024
CM004 CISA’s phishing guidance says all organizations, including SMBs, should pair technical controls with user training and reporting practices. Medium SM002
CM005 NIST’s phishing guidance says phishing can arrive via email, text, phone calls, social media, and other channels. Medium SM003
CM006 NIST’s Phish Scale is designed to help organizations rate the difficulty of phishing emails used in awareness training or simulations. Medium SM004
CM007 IBM’s 2025 breach commentary recommends continuous education and training on emerging AI threats. Medium SM006
CM008 Microsoft’s 2025 Digital Defense Report frames AI, cybercrime-as-a-service, and new social-engineering methods as major drivers of the threat environment. Medium SM007
CM009 Mordor Intelligence estimates the global security awareness training market at USD 6.74 billion in 2026 and USD 14.66 billion by 2031, implying a 16.82% CAGR. Medium SM009, SM011
CM010 Research and Markets publishes the same 2026-2031 broad SAT forecast as a syndicated market report rather than an independent estimate. Medium SM011
CM011 Mordor says cloud-based offerings captured 73.65% of the SAT market in 2025. Medium SM009
CM012 Mordor says large enterprises held 72.55% of SAT spending in 2025 while the SME segment was growing at 19.64% CAGR. Medium SM009, SM011
CM013 Mordor says BFSI accounted for 28.15% of broad SAT spending in 2025 and healthcare was the fastest-growing vertical at 18.83% CAGR. Medium SM009
CM014 Mordor says North America held 37.78% of the broad SAT market in 2025 while Asia-Pacific was projected to grow at 18.61% CAGR. Medium SM009, SM011
CM015 Virtue Market Research sizes the narrower security awareness and phishing simulation market at USD 1.45 billion in 2025 and roughly USD 3.02 billion by 2030, a 15.8% CAGR. Medium SM012, SM013
CM016 Virtue says over 90% of successful cyberattacks globally involve phishing or social engineering. Medium SM012
CM017 Virtue says cloud-based deployment accounts for more than 65% of new security awareness platform implementations. Medium SM012
CM018 Virtue says large enterprises contribute nearly 58% of total revenue in the awareness-and-phishing-simulation subsegment. Medium SM012
CM019 Intel Market Research projects the phishing attack training program market to grow from USD 489 million in 2026 to USD 735 million by 2034 at a 7.3% CAGR. Medium SM019
CM020 Intel says organizations reported a 65% surge in phishing attempts and that over 78% of enterprises now include mandatory phishing simulations in their security protocols. Medium SM019
CM021 Intel says the average cost of a phishing attack has risen to USD 4.91 million per incident. Medium SM019
CM022 Intel says 62% of organizations struggle with employee participation in phishing training and only 28% can directly correlate training with reduced phishing success rates. Medium SM019
CM023 PMarketResearch says remote work, breach costs, regulatory mandates, and AI/ML realism are accelerating adoption of phishing-simulation training. Medium SM025
CM024 PMarketResearch says only about 34% of employees consistently participate in awareness training and up to 70% of firms lack clear post-training KPI metrics. Medium SM025
CM025 APWG maintains recurring phishing-trend reporting, reinforcing that phishing remains a live and measured threat domain rather than a one-off compliance topic. Medium SM021
CM026 Gartner maintains a dedicated Security Awareness Computer-Based Training review category, indicating a distinct buyer category for the market. Medium SM016
CM027 Hoxhunt’s competitor analysis says the market is shifting from checkbox compliance toward measurable human risk reduction and behavior change. Medium SM017
CM028 KnowBe4’s own comparison page frames competition around content breadth, phishing simulation, administration, personalization, and pricing rather than just course availability. Medium SM001
CM029 Independent buyer guides repeatedly cite Proofpoint, Hoxhunt, Mimecast, Cofense, SoSafe, and CybSafe as important alternatives in this category. Medium SM018, SM020
CM030 MarkWide defines SAT software as programmatic instruction using simulated attack vectors, behavioral metrics, and compliance tracking. Medium SM010
CM031 MarkWide says cloud delivery and automated administration are growing because buyers want lower overhead and more easily refreshed scenarios. Medium SM010
CM032 The broad SAT market reports are more useful for bounding category size than for producing a clean vendor-specific SAM for KnowBe4. Medium SM009, SM011, SM012
CM033 Mordor’s main growth drivers include ransomware and BEC losses, cyber-insurance training proof, SaaS adoption by SMBs, zero-trust programs, ISO 27001 people-centric controls, and generative-AI phishing kits. Medium SM009
CM034 Mordor’s main restraints include end-user fatigue, budget reallocations toward XDR and SASE, privacy-driven analytics limits, and localization talent shortages. Medium SM009
CM035 IBM says the 2025 global average data-breach cost fell to USD 4.44 million because organizations contained breaches faster with AI-powered defenses. Medium SM006
CM036 IBM says 97% of organizations that experienced an AI-related breach lacked proper AI access controls and 63% lacked AI governance policies. Medium SM006
CM037 Verizon’s DBIR landing page still presents employee training, defense testing, and incident-response preparation as core breach-prevention recommendations. Medium SM008
CM038 SecurityWeek’s 2026 DBIR coverage said vulnerability exploitation overtook credential theft as the top breach vector, meaning phishing remains important but is not the only budget claimant. Medium SM023
CM039 Across CISA, NIST, IBM, and market reports, the common recommendation is continuous or repeated training rather than annual one-off awareness sessions. High SM002, SM003, SM006, SM009
CM040 The relevant market excludes pure email-security controls and generic learning systems unless they are bundled with behavior change, simulation, or reporting workflows. High SM002, SM003, SM009, SM010
CM041 Security-awareness software is usually purchased by security, risk, or compliance leaders rather than by the end users being trained. Medium SM002, SM009, SM010
CM042 SMB adoption is rising because cloud delivery and insurance or compliance pressure reduce the overhead of starting a program. Medium SM009, SM010, SM019
CM043 The market increasingly measures value through click-rate reduction, reporting behavior, and role-based outcomes rather than training completion alone. Medium SM004, SM017, SM025
CM044 The market denominator for KnowBe4 is definition-sensitive because broad SAT, awareness-plus-simulation, and phishing-training estimates are separated by multiple billions of dollars. Medium SM009, SM012, SM019
CM045 Remote and hybrid work remain durable demand drivers because awareness platforms can reach distributed workers more consistently than classroom-based training. Medium SM012, SM025
CM046 North America is currently the most important demand region on public lenses, but faster growth is projected in Asia-Pacific and among SMEs. Medium SM009, SM019
CP001 KnowBe4 publicly positions its platform as a human risk management platform rather than only a phishing-testing product. High SP001, SP003
CP002 KnowBe4's official platform and feature pages show an integrated bundle spanning training content, phishing simulation, reporting, risk scoring, and integrations. High SP001, SP003
CP003 KnowBe4's public SAT pricing page exposes tier packaging and optional add-ons including SecurityCoach, Compliance Plus, and PhishER Plus. Medium SP002
CP004 KnowBe4 publicly advertises unlimited phishing tests, a phishing-reporting button, and broad admin controls inside its SAT platform. High SP002, SP003
CP005 KnowBe4 markets AIDA, AI-selected templates, and SmartRisk as automation and personalization layers on top of the base SAT workflow. High SP002, SP003
CP006 Proofpoint frames ZenGuide as a human-risk product meant to move beyond traditional awareness training. High SP006, SP007
CP007 Proofpoint states that it protects 2.7 million customers and serves more than 80 of the Fortune 100, showing a much broader installed base than a pure-play SAT vendor. Medium SP005
CP008 Proofpoint ZenGuide discloses behavioral and role-based risk insights, threat-informed risk scoring, and suspicious-message reporting across email and mobile. Medium SP006
CP009 Proofpoint says ZenGuide can turn real attacks into learning content and use AI-driven agents to recommend or automate targeted programs. High SP006, SP007
CP010 Proofpoint can bundle awareness with email and collaboration protection, giving it procurement and telemetry advantages in accounts already standardized on its stack. High SP006, SP008
CP011 Proofpoint's public phishing benchmark blog says customers ran more than 55,000 campaigns and sent more than 212 million messages in 2024. Medium SP007
CP012 Hoxhunt publicly differentiates through gamified, engaging simulations and human-threat-intelligence language rather than a pure compliance narrative. High SP009, SP010
CP013 Hoxhunt customer examples on its official site cite resilience-ratio improvements above 500% and more than 10,000 monthly simulations in some programs. Medium SP009
CP014 SoSafe emphasizes behavioral science, gamified awareness, multilingual delivery, and privacy-aware European operating controls as core parts of its differentiation. Medium SP015
CP015 SoSafe publicly highlights one-click reporting, a central threat inbox, AI copilot support, and behavioral audit exports mapped to NIS2 and DORA. Medium SP015
CP016 MetaCompliance positions itself around security awareness plus compliance, policy, and analytics workflows rather than awareness content alone. High SP016, SP017
CP017 MetaCompliance states that its platform has trained more than 10 million people and supports more than 44 languages worldwide. Medium SP016
CP018 MetaCompliance publicly advertises Teams delivery, SSO or user-sync options, phishing simulation, customizable campaigns, and reporting. Medium SP017
CP019 Mimecast treats awareness as a component of a broader human-risk-management platform rather than a stand-alone annual training program. High SP012, SP013
CP020 Mimecast states that its broader platform serves more than 42,000 customers and supports more than 300 integrations. Medium SP012
CP021 Mimecast's awareness and email-security pages imply that its strongest competitive edge is bundle leverage across human-risk and email-defense workflows. High SP012, SP013, SP014
CP022 Cofense differentiates by treating reported email threats and post-delivery remediation as a central part of the product, not just an awareness afterthought. Medium SP011
CP023 Cofense claims campaign-level remediation, less-than-one-minute auto-quarantine from a confirmed signal, and higher employee resilience from real-phish workflows. Medium SP011
CP024 CybSafe positions itself as a behavioral-security platform that uses live user data, adaptive interventions, and metrics beyond click rates. Medium SP018
CP025 SANS functions more as an expert-led training and program-design substitute than as a direct like-for-like phishing-simulation platform. High SP019, SP026
CP026 Across official pages and review sources, KnowBe4 appears strongest in broad content coverage, phishing scale, administrative maturity, and safe-default enterprise suitability. Medium SP001, SP002, SP003, SP022, SP023
CP027 Proofpoint and Mimecast are the clearest bundle competitors because both tie awareness to larger email-security estates and broader security budgets. High SP006, SP008, SP012, SP013, SP014
CP028 Hoxhunt, SoSafe, and CybSafe most directly attack the legacy SAT model by emphasizing adaptive behavior change over static completion-driven training. Medium SP009, SP015, SP018, SP024
CP029 MetaCompliance skews more compliance-first and policy-centric than vendors whose main pitch begins with phishing telemetry or secure-email context. Medium SP016, SP017, SP024
CP030 Cofense skews toward SOC-linked organizations that want reporting behavior and remediation outcomes tightly linked. Medium SP011, SP024
CP031 Public pricing is opaque across most vendors in the category because the common sales motion is still demo-led and quote-led rather than list-price-led. Medium SP006, SP009, SP011, SP012, SP015, SP017
CP032 KnowBe4 is more transparent on public packaging than most rivals because it publishes tiered feature inclusion even though realized enterprise pricing remains undisclosed. Medium SP002, SP022, SP023
CP033 Independent review sources say users most value KnowBe4 for content breadth, phishing simulations, ease of use, automation, and measurable reporting. High SP022, SP023
CP034 Independent review sources also surface recurring concerns around repetitive content, localization, spam-filter realism, login friction, and ROI measurement. High SP022, SP023
CP035 PeerSpot indicates that KnowBe4 interest is especially concentrated in the large-enterprise segment among users researching the category. Medium SP023
CP036 Gartner's category pages explicitly state that peer-review content is end-user opinion rather than verified fact, limiting how much weight should be placed on ratings alone. High SP020, SP021
CP037 Independent comparison guides consistently map Hoxhunt to engagement and adaptivity, Proofpoint to email-stack integration, SoSafe to EU governance, MetaCompliance to compliance, and Cofense to remediation. Medium SP024, SP025
CP038 Multi-homing remains feasible because most platforms disclose directory, SSO, API, or ecosystem integrations rather than hard application lock-in to a single operating system or ERP stack. Medium SP002, SP003, SP006, SP012, SP017
CP039 Bundle vendors can still create higher effective switching costs by embedding awareness into email-security workflows, reporting buttons, and security-operations data flows. High SP006, SP008, SP011, SP013, SP014
CP040 The most defensible current view is that KnowBe4's moat is strongest in breadth and installed-base familiarity, but weaker in EU-governance fit, bundle economics, and behavior-science differentiation. Medium SP015, SP021, SP022, SP023, SP024, SP025
CP041 Commoditization risk is real because core promises such as phishing simulation, personalized training, reporting, and basic integrations now appear across nearly every serious vendor page. Medium SP001, SP006, SP009, SP013, SP015, SP017
CP042 KnowBe4's optional-module architecture supports land-and-expand economics, but it also means some differentiated workflow capabilities sit outside the base product entitlement. High SP001, SP002
CP043 Behavior-led challengers pressure KnowBe4 most when programs have already lowered initial click rates and buyers start asking for stronger engagement or proof of sustained change. Medium SP010, SP018, SP024, SP025
CP044 Status-quo substitutes include expert-led internal awareness programs and lighter-weight training resources, meaning not every buyer must adopt a full dedicated HRM platform. High SP019, SP026
CP045 A lack of normalized public win-loss, churn, attach-rate, and independently audited outcome data remains the biggest unresolved diligence gap in underwriting competitive durability. Medium SP020, SP021, SP024, SP025
CI001 KnowBe4 reported Q3 2021 GAAP revenue of $64.1 million, up 42.6% year over year. Medium SI005
CI002 KnowBe4 reported nine-month 2022 revenue of $241.6 million, implying a materially higher annualized revenue run rate than FY2021. Medium SI004
CI003 KnowBe4 reported Q4 2022 preliminary revenue of $89.9 million. Medium SI012
CI004 KnowBe4 reported FY2021 ARR of roughly $285.4 million and Q4 2022 ARR of $367.7 million, showing continued growth into the take-private. High SI005, SI012
CI005 Q3 2021 customer count exceeded 44,000 and Q4 2022 customer count reached 56,867. High SI005, SI012
CI006 Q4 2022 GAAP gross margin was 85.4%, consistent with strong software-style gross economics. Medium SI012
CI007 KnowBe4 stated in its Q3 2022 10-Q that substantially all revenue came from subscription services fees. Medium SI004
CI008 The 10-Q states that subscription customers are typically invoiced annually in advance, making deferred revenue a major source of operating cash. Medium SI004
CI009 Deferred revenue at September 30, 2022 was $329.6 million, including $227.7 million current. Medium SI004
CI010 Fitch later said more than 99% of KnowBe4's revenue is recurring, reinforcing the public-company picture of high revenue visibility. High SI007, SI008
CI011 Q3 2021 free cash flow was $18.0 million with a 28.1% free cash flow margin. Medium SI005
CI012 Net cash provided by operating activities in the first nine months of 2022 was $80.1 million. Medium SI004
CI013 The 10-Q attributes strong cash generation to annual prepayments, deferred revenue growth, and an efficient sales model. Medium SI004
CI014 Q3 2021 management commentary cited multi-product attach rates of 19% and international revenue growth of 99% year over year. Medium SI005
CI015 Q4 2022 preliminary operating cash flow and free cash flow remained positive despite merger-related disruption. Medium SI012
CI016 Fitch forecasts EBITDA margins expanding toward the low-40% range by 2028. High SI007, SI008
CI017 Fitch expects free cash flow generation to improve beginning in FY26 as one-time cash outflows dissipate. High SI007, SI008
CI018 More than half of ARR still remained concentrated in SAT offerings according to Fitch, even after Egress broadened the product set. High SI007, SI008
CI019 About a third of ARR comes from SMB customers according to Fitch, creating macro sensitivity but also diversification. High SI007, SI008
CI020 Fitch characterized retention metrics as stable and the company value proposition as mission-critical despite SMB exposure. High SI007, SI008
CI021 The October 2022 transaction valued KnowBe4 at approximately $4.6 billion on an equity value basis and offered $24.90 per share in cash. High SI001, SI010, SI023
CI022 The offer represented a 44% premium to the unaffected closing price on September 16, 2022. High SI001, SI010, SI023
CI023 Vista, KKR, Elephant Partners, and founder-linked holders agreed to support the deal and roll some equity into the acquiring company. High SI001, SI002, SI023
CI024 Fitch says KnowBe4 implemented a strategic pricing and packaging realignment in 2024. High SI007, SI008
CI025 Fitch assigned KnowBe4 a first-time B IDR in July 2025 and rated the new first-lien debt BB- initially before the upsized structure was later downgraded to B+ recovery terms. High SI007, SI008, SI009
CI026 The July 2025 refinancing produced a $1.46 billion first-lien term loan and a $200 million revolver while eliminating the contemplated second-lien tranche. High SI008, SI009, SI013
CI027 Private Equity Wire reported that the new syndicated loan materially reduced borrowing costs relative to the prior private-credit structure. Medium SI013
CI028 Fitch expects EBITDA leverage to decline to under 7.5x in 2025 and remain below that level thereafter, mainly through revenue growth and operating leverage. High SI007, SI008
CI029 At December 31, 2024, KnowBe4 had $117 million of cash and pro forma access to a $200 million revolver after refinancing. High SI007, SI008, SI009
CI030 Fitch expects EBITDA interest coverage to improve above 2x starting in 2026. High SI007, SI008
CI031 Fitch expects no near-term maturities after refinancing, with the revolver maturing in 2030 and the term loan in 2032. High SI007, SI008, SI009
CI032 The public now lacks audited FY2023 and FY2024 financial statements for KnowBe4. High SI006, SI025
CI033 Current ARR, NRR, and realized pricing can only be inferred indirectly from Fitch commentary and sponsor actions rather than audited disclosure. Medium SI007, SI008, SI016
CI034 KnowBe4's public pricing page shows a tiered and add-on-heavy monetization model, but not realized enterprise seat economics. Medium SI016
CI035 The add-on structure implies expansion revenue is likely important to monetization, but public financial contribution by module is undisclosed. Medium SI016, SI017
CI036 Capital adequacy should be read as a leveraged software credit problem rather than a startup runway problem because liquidity is supplemented by a revolver and recurring cash generation. Medium SI007, SI008, SI009
CI037 The largest blocker to equity underwriting is not evidence of operating collapse but the lack of current private-company disclosures. Medium SI007, SI008, SI025
CI038 Any valuation view on KnowBe4 now depends heavily on lender-facing information or confidential management materials that are not public. Medium SI006, SI007, SI025
CI039 Review platforms and company-profile sites still discuss pricing, scale, and ROI qualitatively, but they cannot substitute for audited financial reporting. Medium SI019, SI020, SI021, SI022
CI040 The most defensible financial verdict is that revenue quality likely remains strong, leverage remains meaningful, and valuation precision is currently impossible without private information. Medium SI007, SI008, SI012
CE001 KnowBe4 defines its platform as a human-risk-management workflow spanning awareness, simulation, analytics, and response rather than a single training module. High SE001, SE002
CE002 The core SAT product combines phishing simulation, training content, risk scoring, reporting, and user management within one SaaS console. High SE001, SE002, SE003
CE003 The onboarding workflow is explicit: add users, enable SSO or provisioning, run a baseline phishing test, then move to ongoing training and phishing. Medium SE012
CE004 AIDA is presented as a suite of AI agents that automates administration and content personalization for ongoing phishing and training. High SE004, SE012
CE005 KnowBe4 says AIDA is included with SAT Advanced, making automation a packaging-level differentiator rather than a separate standalone product. High SE004, SE012
CE006 PhishER Plus is positioned as a post-delivery phishing-response layer that can prioritize, quarantine, and convert real attacks into training. High SE006, SE007
CE007 The learner app extends training access to mobile devices and non-desk users, broadening how KnowBe4 can reach the workforce. Medium SE009
CE008 KnowBe4's content library infographic states there were 1,271 total courses and 1,910 total pieces of training content as of May 2023. Medium SE010
CE009 The same infographic states the core library covered 35 languages and averaged a 91.1% completion rate. Medium SE010
CE010 The onboarding guide recommends at least monthly phishing campaigns if the customer manages them manually. Medium SE012
CE011 SCIM provisioning is one-way from the identity provider into the KSAT console. Medium SE011
CE012 KnowBe4's SCIM documentation says alias email addresses are not supported. Medium SE011
CE013 The SAT onboarding guide states that KnowBe4 supports SAML 2.0 SSO and multiple provisioning methods including Google provisioning, ADI, and SCIM. High SE011, SE012
CE014 The onboarding guide makes baseline phishing deliverability dependent on whitelisting KnowBe4 infrastructure in the customer mail environment. Medium SE012
CE015 SecurityCoach depends on third-party security-vendor integrations to deliver real-time coaching from detected events. High SE005, SE013, SE014
CE016 The CrowdStrike integration uses API credentials and exposes event data inside SecurityCoach reports and detection rules. Medium SE013
CE017 The Zscaler integration relies on Nanolog Streaming Service or Cloud NSS and therefore depends on external logging configuration outside KnowBe4 itself. Medium SE014
CE018 Zscaler's legacy NSS mode does not support TLS, while Cloud NSS does, creating a documented deployment-quality difference. Medium SE014
CE019 PhishER Plus integrates with Microsoft 365 and Google Workspace for remediation workflows, but Microsoft 365 receives the explicit Global Blocklist emphasis in official feature copy. Medium SE007
CE020 PhishER Plus also exposes API and syslog integration points to connect with SIEM, ticketing, and threat-intelligence tooling. High SE007, SE015
CE021 KnowBe4's security statement describes one year of database backups and three years of audit and application log retention. Medium SE008
CE022 The security statement describes CI/CD deployments, peer review, staging separation, and centralized encrypted logging. Medium SE008
CE023 KnowBe4 states that it performs monthly vulnerability scanning across web applications, operating systems, containers, infrastructure as code, and dependencies. Medium SE008
CE024 KnowBe4 publicly states remediation timelines of under 30 days for critical or high vulnerabilities once confirmed reachable and exploitable. Medium SE008
CE025 KnowBe4 participates in a private bug bounty or ongoing vetted third-party testing program. Medium SE008
CE026 FedRAMP Marketplace shows a public authorization entry for KnowBe4-related product scope, providing a higher-trust compliance signal than generic marketing claims alone. Medium SE018
CE027 Fitch says KnowBe4 has evolved from a single-product SAT provider to a broader human-risk-management platform, but more than half of ARR still comes from SAT. Medium SE024
CE028 KnowBe4 says it completed the Egress acquisition in July 2024 and planned to integrate products and operations over the following months. Medium SE017
CE029 The Egress integration guide shows that the current integration scope is narrow and data-exchange specific rather than a fully unified product surface. Medium SE016
CE030 KnowBe4 differentiates itself partly through workflow breadth: content, phishing, mobile learning, coaching, response, and AI administration all sit around the same user-risk loop. Medium SE001, SE004, SE005, SE006, SE009
CE031 The product appears strongest when customers connect identity, email, and security telemetry into the same operating flow. Medium SE012, SE013, SE014, SE016
CE032 Third-party review sources consistently praise content breadth, phishing simulations, reporting, and usability. High SE019, SE020, SE021
CE033 Third-party product comparisons frame KnowBe4 as breadth-leading but expose parity questions around advanced multi-channel realism, telemetry depth, or AI-native alternatives. Medium SE022, SE023
CE034 PR Newswire coverage of KnowBe4's deepfake-training launch shows AI-powered social-engineering defense becoming a visible product-roadmap priority. High SE025, SE004
CE035 The learner app infographic reports 87,000 course completions and 25,000 monthly unique users, suggesting real adoption of mobile training rather than a merely optional shell. Medium SE009
CE036 PhishER Plus official copy says its community intelligence draws on 13+ million users, indicating that data-network effects are part of the product claim. Medium SE007
CE037 The deepest AIDA technical details—model provenance, inference boundary, and data-residency specifics—are not disclosed in the public materials reviewed. Medium SE004, SE008
CE038 The most defensible product verdict is that KnowBe4 is a mature, broad HRM platform whose remaining risk lies less in basic feature absence and more in integration dependence and partial roadmap opacity. Medium SE001, SE008, SE016, SE024
CU001 KnowBe4 publicly said in 2025-2026 materials that it serves more than 70,000 customers globally. High SU003, SU026
CU002 Public disclosures show customer count expanding from more than 44,000 in Q3 2021 to 56,867 in Q4 2022 and then to over 70,000 by 2025-2026. High SU026, SU027
CU003 Fitch said KnowBe4 generates the majority of ARR in North America. Medium SU026
CU004 BankInfoSecurity reported that nearly 83% of first-half 2022 sales came from North America, which supports the view that the installed base and revenue remain US-led. Medium SU027
CU005 Fitch said about one-third of KnowBe4 ARR comes from SMB customers. Medium SU026
CU006 Fitch also described the customer base as diversified across industries and geographies with no customer concentration. Medium SU026
CU007 KnowBe4's partner program publicly targets resellers, managed service providers, and consultants, indicating a multi-channel acquisition model rather than pure direct sales. Medium SU002
CU008 The ConnectWise marketplace listing confirms that KnowBe4 sells through MSP-oriented distribution as well as direct enterprise sales. Medium SU025
CU009 Americas and EMEA partner-award releases show repeated recognition of regional channel partners, which is evidence of a maturing international partner ecosystem. Medium SU003, SU004, SU005
CU010 G2 shows 2,304 reviews for KnowBe4 Security Awareness Training and a 4.6 out of 5 star rating. Medium SU008
CU011 The same G2 page shows an unusually positive distribution, with 81% five-star and 16% four-star reviews. Medium SU008
CU012 KnowBe4's own G2 leadership release says the company ranked #1 in security awareness training for 21 consecutive quarters with a 96/100 satisfaction score based on 1,893 reviews at publication time. Medium SU006, SU007
CU013 That same release says PhishER led the SOAR category for the 14th consecutive quarter with 318 reviews and 93% recommendation, supporting cross-sell beyond the SAT core. Medium SU006, SU007
CU014 TrustRadius shows 1,163 reviews and ratings for KnowBe4, which adds another large independent review surface beyond G2. Medium SU014
CU015 PeerSpot rates KnowBe4 8.6 out of 10 from 18 reviews and ranks it as the #1 security awareness training solution on that site. Medium SU015
CU016 FeaturedCustomers lists 130 customer references tied to KnowBe4, including 65 reviews, 63 case studies, and 2 customer videos. Medium SU016
CU017 Trustpilot rates KnowBe4 1.6 out of 5 from 28 reviews, providing a visible adverse counter-signal to the stronger B2B review sites. Medium SU012
CU018 Trustpilot complaints are concentrated around false positives, confusing assessments, spamminess, and poor end-user experience rather than around core procurement economics. Medium SU012
CU019 Gartner peer reviews include criticism that the dashboard can be complex, the training-request process tedious, and the VRO score skewed by incomplete-product usage and new-user onboarding. Medium SU009, SU010
CU020 Cebu Pacific said it reduced its phish-prone percentage from 81% to 6% and trained more than 6,000 employees across geographies. Medium SU018
CU021 Cebu Pacific reported 96% completion of its proficiency assessment and 97% completion of security awareness training, indicating program engagement as well as deployment breadth. Medium SU018
CU022 Cebu Pacific later expanded KnowBe4 to two subsidiaries representing about 2,000 additional users, which is direct evidence of land-and-expand behavior inside an account. Medium SU018
CU023 The City of Daytona Beach said it moved to 100% security-policy acceptance, reduced phish-prone percentage from 12% to 2%, and cut email recalls by 90% using PhishER Plus. Medium SU019
CU024 Daytona Beach's CIO described himself as a KnowBe4 customer for at least 12 years, which is a rare public longevity signal. Medium SU019
CU025 Bridgewater State University said its phish-prone percentage fell from 15% to 4% across more than 8,000 students and staff after adopting KnowBe4. Medium SU020
CU026 Bridgewater State also made KnowBe4 part of mandatory onboarding for new employees, suggesting the product can become embedded in institutional processes. Medium SU020
CU027 RWK Goodman uses KnowBe4 Protect and Prevent for encryption and misdirected-email prevention and said the analytics layer helped prove ROI to the business. Medium SU017
CU028 South Ayrshire Council said more than 1,000 users adopted KnowBe4 tools and that the organization redirected security-enclave budget toward wider enterprise coverage. Medium SU021
CU029 South Ayrshire also reported that positive user feedback and more frequent suspicious-email reporting helped reinforce behavior change, not just compliance. Medium SU021
CU030 Ideagen uses KnowBe4 across a global workforce after acquisitions and said SecurityCoach and AIDA helped lower administrative workload and support faster user response. Medium SU022
CU031 Ideagen said post-acquisition phish-prone percentage temporarily rose from 5.5% to about 9% because the platform exposed newly visible risk, which suggests the tooling is used for measurement as well as training. Medium SU022
CU032 Shields Health Solutions deployed KnowBe4 cloud email security across 2,000 users on Microsoft 365 after a pilot. Medium SU023
CU033 Shields said Defend banners and Prevent prompts contributed to a dramatic decrease in click rate, showing expansion beyond courseware into real-time email behavior. Medium SU023
CU034 The Crawford case-study PDF shows KnowBe4 is also used in insurance-sector email-security workflows, broadening the named-logo set beyond SAT-only deployments. Medium SU024
CU035 The case-study portfolio spans legal, aviation, government, education, software, healthcare, and insurance, which supports a diversified vertical customer mix. Medium SU014, SU017, SU018, SU019, SU020, SU021, SU022, SU023, SU024
CU036 Customer proof is geographically broad across the US, UK, and Philippines, but revenue evidence still suggests North America remains the center of gravity. High SU018, SU021, SU026, SU027
CU037 The strongest publicly visible customer-quality signals are breadth of logos, multi-year platform usage, stable third-party retention commentary, and measurable phishing-outcome improvement in case studies. Medium SU016, SU018, SU019, SU020, SU026
CU038 The main public weak spots are sparse disclosure on CAC and churn, user-experience complaints on some review sites, and limited transparency on segment-level net retention. Medium SU009, SU012, SU026
CR001 Abnormal published a case study in which a global manufacturer chose not to renew KnowBe4 and consolidated phishing reporting and coaching onto Abnormal. Medium SR015
CR002 That replacement story framed KnowBe4-style awareness tooling as a fragmented workflow rather than a unified defense experience. Medium SR015
CR003 The same Abnormal case study said the buyer eliminated an estimated 20-30 manual tickets per month tied to user-reported messages. Medium SR015
CR004 Fitch says about one-third of KnowBe4 ARR still comes from SMB customers, which means a meaningful portion of the base is price-sensitive and macro-sensitive. Medium SR029
CR005 ConnectWise reported that 83% of SMBs believe AI has raised the cybersecurity threat level. Medium SR016
CR006 ConnectWise also said only 51% of SMBs have implemented AI security policies and practices. Medium SR016
CR007 ConnectWise said 58% of SMBs spent more than planned on cybersecurity in 2024 and 57% now say cybersecurity is their top priority. Medium SR016
CR008 ConnectWise also found that 73% of SMBs are not fully confident their MSP could protect them in an attack and 47% would switch providers for stronger cybersecurity. Medium SR016
CR009 Devolutions found that while 71% of SMBs feel confident handling a major cyber incident, only 22% say they have an advanced security posture. Medium SR018, SR019
CR010 Devolutions reported that 52% of SMBs still manage privileged access manually and 63% increased cybersecurity budgets, but 29% still allocate less than 5% of IT spend to security. Medium SR018, SR019
CR011 Mordor Intelligence says large enterprises held 72.55% of the SAT market in 2025 and that some CISOs are shifting budget toward automated detection suites, creating pressure on awareness-only spend. Medium SR020
CR012 Mordor also says 36% of CISOs report cuts to training funds to finance converged XDR stacks, which is a direct macro risk to SAT budgets. Medium SR020
CR013 KnowBe4 said it hired a fake North Korean IT worker using a valid but stolen U.S. identity after multiple interviews, reference checks, and background checks. High SR001, SR002
CR014 KnowBe4 said the worker's Mac workstation began loading malware immediately upon receipt. Medium SR001
CR015 KnowBe4 said its EDR and SOC detected the activity quickly, contained the device, and involved Mandiant and the FBI. Medium SR001
CR016 KnowBe4 described the use of an IT-mule laptop farm and warned that the scheme can place hostile workers inside legitimate payroll and network access paths. High SR001, SR002
CR017 DOJ said North Korean IT worker schemes rely on stolen identities, front companies, fraudulent websites, and laptop farms to access U.S. businesses remotely. High SR004, SR005
CR018 FBI alerts in 2025 said North Korean IT workers are linked not only to wage fraud but also to data theft and extortion against employers. High SR006, SR007
CR019 Treasury and State actions in 2026 show the U.S. government still treats DPRK IT worker infiltration as an active sanctions and national-security problem. High SR008, SR009, SR010, SR011
CR020 The reputational issue is therefore not the single KnowBe4 incident itself but the possibility that sophisticated remote-worker identity fraud remains an ongoing operating hazard even for security vendors. Medium SR003, SR004, SR006, SR019
CR021 Business Wire said the amended securities class action was filed in the Southern District of Florida as Water Island Event-Driven Fund v. KnowBe4, Inc., No. 25-cv-22574, alleging Exchange Act and proxy-rule violations. Medium SR021
CR022 PacerMonitor tracks the same Florida action as In re KnowBe4, Inc. Securities Litigation in the Southern District of Florida. Medium SR023
CR023 PacerMonitor also shows Finger v. KnowBe4, Inc. et al. in Delaware District Court, preserving evidence that the merger process generated multi-forum litigation. Medium SR024
CR024 The Stanford securities litigation page provides an independent registry reference for the current securities action, increasing confidence that the litigation is active enough to track institutionally. Medium SR022
CR025 The SEC merger proxy remains the primary filing record for the transaction process and the kinds of disclosure defendants are being asked to defend. Medium SR026, SR027
CR026 Fitch assigned KnowBe4 a B issuer rating in July 2025 and later downgraded the upsized first-lien instruments to B+ recovery terms after the debt package was enlarged. High SR028, SR029, SR030
CR027 Fitch says KnowBe4's EBITDA leverage has been high since the 2023 take-private and is only expected to fall to below 7.5x in 2025. High SR028, SR029
CR028 Fitch says private-equity ownership may prioritize return-on-equity maximization over debt prepayment, limiting deleveraging even if the business performs well. High SR028, SR029
CR029 Fitch expects interest coverage to improve above 2x starting in 2026, but that still implies a business that remains meaningfully debt-burdened in the near term. High SR028, SR029
CR030 At December 31, 2024 KnowBe4 had $117 million of cash and expected access to a $200 million revolver after the refinancing. High SR028, SR029
CR031 Bryan Palma became CEO effective May 5, 2025 while founder Stu Sjouwerman moved to executive chairman. Medium SR031
CR032 The CEO-transition release said KnowBe4 had grown to over 70,000 customers, meaning Palma inherited a large scaled platform rather than an early-stage turnaround. Medium SR031
CR033 Leadership transition risk is still real because the company is simultaneously integrating acquisitions, managing leverage, and defending the core SAT franchise against workflow-consolidation challengers. Medium SR015, SR029, SR031, SR033
CR034 KnowBe4 mitigated the North Korea incident with fast endpoint detection and published process changes such as stronger identity verification and fingerprinting suggestions. Medium SR001, SR002
CR035 The Egress acquisition broadened the platform into cloud email security, which is a partial mitigation against the risk that SAT alone becomes too narrow. Medium SR033
CR036 The core competitive risk is therefore not that awareness training disappears, but that buyers increasingly prefer bundled detection, reporting, coaching, and email-security workflows over a standalone SAT-led architecture. Medium SR015, SR020, SR033
CR037 The legal and regulatory risk is meaningful because KnowBe4 sits at the intersection of labor controls, sanctions exposure, data governance, and public-company legacy litigation. Medium SR004, SR010, SR021, SR026
CR038 The debt and sponsor-ownership risk is meaningful because leverage remains elevated even after refinancing and because sponsor incentives do not necessarily align with rapid deleveraging. High SR028, SR029
CR039 The most likely near-term risks are competitive displacement, SMB budget pressure, and execution friction from leadership and product integration. Medium SR015, SR016, SR031, SR033
CR040 The most severe downside risks are a debt-driven value squeeze, an adverse litigation outcome or settlement burden, and a repeat workforce-integrity incident that damages reputation. Medium SR001, SR021, SR028, SR029
CR041 Overall risk is high rather than existential: the business still has scale and mitigation capacity, but too many operating, capital-structure, and market risks are active at the same time. Medium SR015, SR019, SR021, SR029, SR031
CV001 The cleanest hard valuation anchor is Vista's approximately $4.6 billion take-private agreement for KnowBe4. High SV001, SV002, SV003
CV002 The transaction offered $24.90 per share in cash. High SV001, SV003
CV003 The offer represented roughly a 44% premium to the unaffected closing price according to company and deal coverage, with SiliconANGLE citing a 46% premium to the September 16 close. High SV003, SV005, SV006, SV015
CV004 KnowBe4 reported second-quarter 2022 revenue of $80.8 million and annualized recurring revenue of $328.3 million. High SV011, SV015
CV005 KnowBe4 reported preliminary fourth-quarter 2022 revenue of $89.9 million and ARR of $367.7 million, implying a roughly $360 million revenue run-rate at the time of the deal. Medium SV014
CV006 Q3 2021 evidence shows ARR of $262.2 million and more than 44,000 customers, illustrating the pre-private scaling path into the final transaction. Medium SV013
CV007 Fitch says more than 99% of KnowBe4 revenue is recurring and that the company still has stable retention metrics. High SV008, SV009
CV008 Fitch says revenue growth has moderated but remains strong, with mid-teen growth and EBITDA margins expected to rise toward the low-40% range by 2028. High SV008, SV009
CV009 Fitch also says the company implemented a strategic pricing and packaging realignment in 2024, supporting some post-private monetization improvement. High SV008, SV009
CV010 The July 2025 refinancing replaced private credit with a seven-year first-lien term loan priced at 375 basis points over SOFR, down from prior pricing around 775 basis points. Medium SV007
CV011 The refinancing involved approximately $1.46 billion of debt and eliminated the contemplated second-lien tranche. High SV007, SV009
CV012 Refinancing supports the view that lenders still underwrite KnowBe4 as a viable sponsor-backed software credit, but it does not eliminate leverage risk. Medium SV007, SV009
CV013 Fitch rated KnowBe4 B at the issuer level and still expects leverage only gradually to fall below 7.5x, which is a meaningful discount factor for equity holders. High SV008, SV009, SV010
CV014 Fitch explicitly warns that private-equity ownership may prioritize return maximization over debt prepayment, limiting organic deleveraging. High SV008, SV009
CV015 DealMatrix shows a cybersecurity sector benchmark around 3.8x EV/Sales and 18.1x EV/EBITDA as of March 31, 2025, with North America typically carrying the highest multiples. Medium SV016
CV016 The DealMatrix range by region shows EV/Sales spanning about 2.9x to 4.4x, which implies that a premium-quality North American asset can trade above the median but not infinitely above it. Medium SV016
CV017 Proofpoint's 2021 take-private at approximately $12.3 billion remains the most relevant scaled people-centric email / compliance software comp. High SV017, SV018
CV018 SailPoint's take-private at roughly $6.9 billion is another private-equity reference point for identity-adjacent security software. Medium SV019
CV019 Rubrik's 2024 IPO priced at $32 per share and implied a fully diluted market value of about $6.6 billion. High SV020, SV021
CV020 Abnormal Security was valued at $4 billion in 2022 after a $210 million Series C round, showing the scale investors were willing to pay for AI-native email security. Medium SV022
CV021 Hoxhunt's $40 million Series B in 2022 shows that human-risk and phishing-awareness specialists can attract capital, but at a much smaller scale than KnowBe4. Medium SV023, SV024
CV022 Mimecast's Permira take-private remains directionally relevant as a private email-security comp, though it is less directly comparable to KnowBe4's SAT-led heritage. Medium SV025, SV026
CV023 KnowBe4's current revenue run-rate is not publicly disclosed, but a defensible private-market underwriting range is roughly $550-650 million based on the 2022 base, mid-teen growth commentary, acquisitions, and pricing changes. Medium SV008, SV009, SV014
CV024 Applying a downside multiple band around 4.0x-5.0x to a $550-580 million revenue base implies enterprise value roughly in the $2.2-2.9 billion range. Medium SV016
CV025 Applying a base-case multiple band around 6.0x-7.0x to a $600-620 million revenue base implies enterprise value roughly in the $3.6-4.3 billion range. Medium SV007, SV008, SV009, SV016
CV026 Applying an upside multiple band around 7.5x-8.5x to a $630-650 million revenue base implies enterprise value roughly in the $4.7-5.5 billion range. Medium SV008, SV009, SV016
CV027 The 2023 $4.6 billion deal price now sits closer to a bullish-than-base outcome unless KnowBe4 has sustained stronger growth and attach expansion than the public record can verify. Medium SV001, SV007, SV016
CV028 Because current sector medians are lower than 2021-style cyber highs and leverage remains elevated, the equity story should not assume that the headline 2023 transaction multiple automatically still applies today. High SV007, SV013, SV016
CV029 The best fair-value stance is therefore not cheap: KnowBe4 probably still deserves a premium to the cyber median because of recurrence, scale, and customer breadth, but leverage and opacity offset that premium. Medium SV008, SV009, SV016
CV030 Post-private valuation precision is impossible without current audited revenue, EBITDA, and net-debt data, so any investment recommendation must remain research-more rather than a conviction buy. High SV008, SV009, SV014
CV031 The strongest bull argument is that 99% recurring revenue, stable retention, and meaningful cross-sell into broader human-risk and email-security workflows could justify a premium multiple despite debt. Medium SV008, SV009, SV015
CV032 The strongest bear argument is that sponsor-owned leverage plus cybersecurity multiple compression can make even a good business an unattractive equity underwriting case at too high an entry value. High SV007, SV013, SV016
CV033 The most defensible valuation verdict today is fair rather than attractive: there is enough evidence to support real enterprise value, but not enough disclosure to prove a margin of safety. Medium SV007, SV008, SV009, SV016
CV034 Proofpoint, SailPoint, Rubrik, Abnormal, Hoxhunt, and Mimecast together show that KnowBe4 sits in a legitimate cyber-software comp set, but none is a perfect one-for-one comparable. Medium SV017, SV019, SV020, SV021, SV022, SV023, SV025
CV035 The largest unresolved valuation swing factor is whether current module attachment, pricing realization, and post-Egress monetization moved the revenue base materially above what Fitch's mid-teen growth framing would imply. Medium SV008, SV009, SV009
CV036 For underwriting purposes, debt should be treated as a reason to widen the valuation range and to favor enterprise-value reasoning over simplistic equity headline comparisons. Medium SV007, SV009
CV037 KnowBe4 still benefits from a better customer-scale proof set than many private cybersecurity peers, which helps explain why lenders continue to support the business. Medium SV009, SV003
CV038 Even so, the current evidence set supports only a medium-confidence recommendation because the decisive post-private data room items remain unavailable publicly. High SV008, SV009, SV014
CV039 A reasonable current enterprise-value midpoint for discussion purposes is about $4.0-4.5 billion, with meaningful downside if public-style multiples dominate and modest upside if growth and attach prove stronger. Medium SV007, SV008, SV009, SV016
CV040 That midpoint keeps KnowBe4 within unicorn territory but does not obviously create a bargain relative to debt, sponsor incentives, and compressed sector multiples. Medium SV007, SV016
Sources
IDPublisherTitleQuote
SO001 KnowBe4 KnowBe4 | Secure Your Digital Workforce: Human + AI
SO002 KnowBe4 About Us | KnowBe4
SO003 KnowBe4 Contact Us | KnowBe4
SO004 KnowBe4 KnowBe4 Legal, Privacy and Security | KnowBe4
SO005 KnowBe4 Careers | KnowBe4
SO006 KnowBe4 KnowBe4 Appoints Bryan Palma as President and CEO
SO007 KnowBe4 Vista Equity Partners Completes Acquisition of KnowBe4
SO008 KnowBe4 KnowBe4 Completes Acquisition of Egress
SO009 KnowBe4 KnowBe4 Honored for Global Employee Experience Across Multiple Workplace Awards
SO010 KnowBe4 KnowBe4 Names 2026 Americas Partner Program Award Winners
SO011 KnowBe4 Products | KnowBe4 Platform
SO012 Vista Equity Partners Vista Equity Partners Completes Acquisition of KnowBe4
SO013 Fitch Ratings Fitch Assigns KnowBe4, Inc. First-Time IDR of 'B'; Outlook Stable
SO014 Fitch Ratings Fitch Affirms KnowBe4, Inc.'s IDR at 'B'; Downgrades Upsized First-Lien Instruments
SO015 Private Equity Wire Vista’s KnowBe4 lowers debt costs with $1.46bn syndicated loan refinancing
SO016 U.S. Securities and Exchange Commission DEFM14A
SO017 U.S. Securities and Exchange Commission EX-99.1 Vista Equity Partners Completes Acquisition of KnowBe4
SO018 U.S. Securities and Exchange Commission knbe-20220930
SO019 Stanford Securities Class Action Clearinghouse Securities Class Action Clearinghouse: Case Page
SO020 Business Wire Entwistle & Cappucci LLP Files Amended Securities Class Action Complaint Against KnowBe4, Inc. and Related Defendants
SO021 TrustRadius KnowBe4 Security Awareness Training Reviews & Ratings 2026 | TrustRadius
SO022 Gartner Peer Insights KnowBe4 Reviews, Ratings & Features 2026 | Gartner Peer Insights
SO023 PeerSpot KnowBe4 Reviews, Competitors and Pricing
SO024 LeadIQ KnowBe4 Company Overview, Contact Details & Competitors | LeadIQ
SO025 Mergr KnowBe4: Company Profile, Ownership & M&A Activity | Mergr
SM001 KnowBe4 Best Security Awareness Training Products | KnowBe4
SM002 CISA Phishing Guidance: Stopping the Attack Cycle at Phase One | CISA
SM003 NIST Phishing
SM004 NIST NIST Phish Scale User Guide
SM005 IBM Cost of a data breach 2025 | IBM
SM006 IBM 2025 Cost of a Data Breach Report: Navigating the AI rush without sidelining security
SM007 Microsoft 2025 Microsoft Digital Defense Report (MDDR) | Security Insider
SM008 Verizon 2026 Data Breach Investigations Report (DBIR)
SM009 Mordor Intelligence Security Awareness Training Market Size, Share & 2031 Growth Trends Report
SM010 MarkWide Research Global Security Awareness Training Software Market Size, Share, and Industry Trends Forecast 2026-2036
SM011 Research and Markets Security Awareness Training - Market Share Analysis, Industry Trends & Statistics, Growth Forecasts (2026-2031)
SM012 Virtue Market Research Global Security Awareness & Phishing Simulation Market | Size, Overview, Growth Trends, and Forecast | 2026–2030
SM013 Virtue Market Research Security Awareness & Phishing Simulation Market
SM014 Business Research Insights Phishing Simulator Market Size, Growth | Report [2026-2035]
SM015 Global Growth Insights Phishing Simulation Market Size, Share 2035 | CAGR 8.46%
SM016 Gartner Peer Insights Best Security Awareness Computer-Based Training Reviews 2026 | Gartner Peer Insights
SM017 Hoxhunt Top KnowBe4 Competitors (2026): Enterprise Security Awareness Platforms Compared
SM018 Ciphers Security Best Security Awareness Training Platforms 2026
SM019 Intel Market Research Phishing Attack Training Program Market 2026-2034
SM020 Brightside AI Best Security Awareness Training Platforms for 2026: What CISOs Should Compare | Brightside AI Blog
SM021 APWG APWG
SM022 Abnormal AI 62% of Breaches Involved the Human Element: Key Takeaways From Verizon 2026 DBIR | Abnormal AI
SM023 SecurityWeek Verizon DBIR 2026: Vulnerability Exploitation Overtakes Credential Theft as Top Breach Vector
SM024 Keepnet Labs 2025 Verizon DBIR (Archived) | See 2026 Edition
SM025 PMarketResearch Worldwide Phishing Attack Simulation Training Market 2026
SP001 KnowBe4 KnowBe4 Platform
SP002 KnowBe4 Security Awareness Training Pricing
SP003 KnowBe4 Security Awareness Training Features
SP004 KnowBe4 Leading Security Awareness Training Comparison
SP005 Proofpoint Proofpoint Home
SP006 Proofpoint Mitigate Human Risk
SP007 Proofpoint Phish Tests Reveal Human-Targeted Threats Are Evolving
SP008 Proofpoint Email Protection
SP009 Hoxhunt Hoxhunt Home
SP010 Hoxhunt KnowBe4 Alternatives Compared (2026)
SP011 Cofense Cofense Home
SP012 Mimecast Mimecast Home
SP013 Mimecast Mimecast Engage Awareness Training
SP014 Mimecast Email Security
SP015 SoSafe SoSafe Home
SP016 MetaCompliance MetaCompliance Home
SP017 MetaCompliance Automated Security Awareness
SP018 CybSafe CybSafe Home
SP019 SANS Security Awareness Training
SP020 Gartner Security Awareness Computer-Based Training Market
SP021 Gartner KnowBe4 in Security Awareness Computer-Based Training Reviews
SP022 TrustRadius KnowBe4 Reviews
SP023 PeerSpot KnowBe4 Reviews
SP024 Brightside Best Security Awareness Training Platforms for 2026
SP025 Ciphers Security Best Security Awareness Training Platforms
SP026 SANS SANS Home
SI001 SEC KnowBe4 to be Acquired by Vista Equity Partners For $4.6 Billion
SI002 SEC DEFA14A for KnowBe4 take-private transaction
SI003 SEC Vista Equity Partners Completes Acquisition of KnowBe4 (Exhibit 99.1)
SI004 SEC KnowBe4 Q3 2022 Form 10-Q
SI005 SEC KnowBe4 Announces Third Quarter 2021 Financial Results
SI006 SEC KnowBe4 EDGAR filing page
SI007 Fitch Ratings Fitch Assigns KnowBe4, Inc. First-Time IDR of B; Outlook Stable
SI008 Fitch Ratings Fitch Affirms KnowBe4, Inc. IDR at B; Downgrades Upsized First Lien Instruments
SI009 Fitch Ratings KnowBe4, Inc. entity page
SI010 Vista Equity Partners KnowBe4 to be acquired by Vista Equity Partners for $4.6 billion
SI011 Vista Equity Partners Vista Equity Partners Completes Acquisition of KnowBe4
SI012 Yahoo Finance / GlobeNewswire KnowBe4 announces preliminary fourth quarter 2022 results
SI013 Private Equity Wire Vista’s KnowBe4 lowers debt costs with $1.46bn syndicated loan refinancing
SI014 PitchBook KnowBe4 completes $1.46b syndicated loan to refinance private credit
SI015 Mergr KnowBe4 – Company Overview
SI016 KnowBe4 Security Awareness Training Pricing
SI017 KnowBe4 KnowBe4 Platform
SI018 KnowBe4 About Us
SI019 TrustRadius KnowBe4 reviews
SI020 PeerSpot KnowBe4 reviews
SI021 Gartner KnowBe4 in Security Awareness Computer-Based Training Reviews
SI022 LeadIQ KnowBe4 company profile
SI023 Business Wire KnowBe4 to be Acquired by Vista Equity Partners For $4.6 Billion
SI024 KnowBe4 Press Release Closing Acquisition by Vista
SI025 SEC EDGAR search
SE001 KnowBe4 KnowBe4 Platform
SE002 KnowBe4 Security Awareness Training Features
SE003 KnowBe4 Security Awareness Training Pricing
SE004 KnowBe4 AIDA
SE005 KnowBe4 SecurityCoach
SE006 KnowBe4 PhishER Plus
SE007 KnowBe4 PhishER Plus Features
SE008 KnowBe4 Security Statement
SE009 KnowBe4 Blog Learner App by the Numbers Infographic
SE010 KnowBe4 Blog Content Library by the Numbers Infographic
SE011 KnowBe4 Support SCIM Configuration Guide
SE012 KnowBe4 Support SAT Advanced Onboarding Guide
SE013 KnowBe4 Support CrowdStrike Integration Guide for SecurityCoach
SE014 KnowBe4 Support Zscaler Integration Guide for SecurityCoach
SE015 KnowBe4 Developer KnowBe4 API Documentation
SE016 Egress Support Egress and KnowBe4 Integration
SE017 KnowBe4 KnowBe4 completes acquisition of Egress
SE018 FedRAMP FR2201340492 marketplace entry
SE019 Gartner KnowBe4 in Security Awareness Computer-Based Training Reviews
SE020 TrustRadius KnowBe4 reviews
SE021 PeerSpot KnowBe4 reviews
SE022 Brightside Best Security Awareness Training Platforms for 2026
SE023 Ciphers Security Best Security Awareness Training Platforms
SE024 Fitch Ratings Fitch Assigns KnowBe4, Inc. First-Time IDR of B; Outlook Stable
SE025 PR Newswire KnowBe4 unveils new deepfake training to combat AI-powered social engineering
SU001 KnowBe4 Case Studies
SU002 KnowBe4 Partner Program
SU003 KnowBe4 KnowBe4 names 2026 Americas partner award winners
SU004 KnowBe4 KnowBe4 announces 2024 EMEA partner programme award winners
SU005 PRWeb KnowBe4 recognizes 2025 Americas partner program award winners
SU006 KnowBe4 KnowBe4 leads SAT for over five years straight and PhishER leads SOAR
SU007 PR Newswire KnowBe4 reinforces market leadership streak in G2 Fall 2024 report
SU008 G2 KnowBe4 Security Awareness Training Reviews
SU009 Gartner KnowBe4 Security Awareness Training Reviews & Ratings 2026
SU010 Gartner KnowBe4 user review sample 6238430
SU011 Gartner KnowBe4 user review sample 6237972
SU012 Trustpilot KnowBe4 Trustpilot profile
SU013 TrustRadius KnowBe4 reviews
SU014 TrustRadius KnowBe4 likelihood to recommend reviews
SU015 PeerSpot KnowBe4 reviews 2026
SU016 FeaturedCustomers KnowBe4 customer reviews & references
SU017 KnowBe4 RWK Goodman case study
SU018 KnowBe4 Cebu Pacific case study
SU019 KnowBe4 City of Daytona Beach case study
SU020 KnowBe4 Bridgewater State University case study
SU021 KnowBe4 South Ayrshire Council case study
SU022 KnowBe4 Ideagen case study
SU023 KnowBe4 Shields Health Solutions case study
SU024 KnowBe4 Crawford case study PDF
SU025 ConnectWise Marketplace KnowBe4 marketplace listing
SU026 Fitch Ratings Fitch affirms KnowBe4 IDR at B
SU027 BankInfoSecurity Vista, KnowBe4 agree to $4.6B take-private purchase
SR001 KnowBe4 How a North Korean fake IT worker tried to infiltrate us
SR002 KnowBe4 KnowBe4 issues warning after hiring fake North Korean employee
SR003 Security Boulevard KnowBe4 unknowingly hires fake North Korean IT worker
SR004 DOJ Justice Department announces coordinated nationwide actions to combat North Korean remote IT worker schemes
SR005 DOJ Justice Department announces nationwide actions to combat illicit North Korean government schemes
SR006 FBI North Korean IT worker threats to U.S. businesses
SR007 FBI North Korean IT workers conducting data extortion
SR008 US Treasury Treasury press release SB0416
SR009 US Treasury Treasury press release SB0230
SR010 US State Department Sanctions to disrupt DPRK IT worker schemes defrauding U.S. businesses
SR011 US State Department Updated advisory on addressing North Korean IT worker risks
SR012 IC3 IC3 January 2025 North Korean worker alert PDF
SR015 Abnormal AI Why one global manufacturer replaced KnowBe4 with Abnormal AI
SR016 ConnectWise SMB cybersecurity statistics and trends
SR017 ConnectWise Why SMB cybersecurity is still a massive opportunity for MSPs
SR018 Devolutions State of IT security in SMBs survey blog
SR019 Devolutions State of IT Security Report 2025
SR020 Mordor Intelligence Security awareness training market
SR021 Business Wire Entwistle Cappucci amended securities class action complaint
SR022 Stanford Securities Class Action Clearinghouse KnowBe4 securities filing case
SR023 PacerMonitor In re KnowBe4, Inc. Securities Litigation
SR024 PacerMonitor Finger v. KnowBe4, Inc. et al
SR025 JD Supra Delaware Court of Chancery dismisses control group claims
SR026 SEC KnowBe4 definitive merger proxy (DEFM14A)
SR027 SEC KnowBe4 merger exhibit 99.1
SR028 Fitch Ratings Fitch assigns KnowBe4 first-time IDR of B
SR029 Fitch Ratings Fitch affirms KnowBe4 IDR at B and downgrades upsized first-lien instruments
SR030 Fitch Ratings KnowBe4 entity page
SR031 KnowBe4 KnowBe4 appoints Bryan Palma as President and CEO
SR032 KnowBe4 Vista Equity Partners completes acquisition of KnowBe4
SR033 KnowBe4 KnowBe4 completes acquisition of Egress
SV001 Vista Equity Partners KnowBe4 to be acquired by Vista Equity Partners for $4.6 billion
SV002 Vista Equity Partners Vista Equity Partners completes acquisition of KnowBe4
SV003 KnowBe4 Investor Relations KnowBe4 to be acquired by Vista Equity Partners for $4.6 billion
SV004 Wilson Sonsini Wilson Sonsini advises KnowBe4 on $4.6B buyout
SV005 BankInfoSecurity Vista, KnowBe4 agree to $4.6B take-private purchase
SV006 Reuters Vista Equity Partners to buy KnowBe4 in $4.6B deal
SV007 Private Equity Wire Vista’s KnowBe4 lowers debt costs with $1.46bn syndicated loan refinancing
SV008 Fitch Ratings Fitch assigns KnowBe4 first-time IDR of B
SV009 Fitch Ratings Fitch affirms KnowBe4 IDR at B and downgrades upsized first-lien instruments
SV010 Fitch Ratings KnowBe4 entity page
SV011 SEC KnowBe4 Q2 2022 10-Q
SV012 SEC KnowBe4 Q3 2022 10-Q
SV013 SEC KnowBe4 Q3 2021 earnings release
SV014 Yahoo Finance KnowBe4 preliminary fourth quarter 2022 results
SV015 SiliconANGLE Cybersecurity training provider KnowBe4 to be acquired for $4.6B
SV016 DealMatrix Cyber security valuation multiples
SV017 Proofpoint Thoma Bravo completes acquisition of Proofpoint
SV018 Thoma Bravo Thoma Bravo completes acquisition of Proofpoint
SV019 SailPoint Thoma Bravo completes acquisition of SailPoint
SV020 Rubrik Rubrik announces pricing of upsized IPO
SV021 Renaissance Capital Rubrik prices upsized IPO at $32 above the range
SV022 Abnormal AI Abnormal Security Series C funding at $4B valuation
SV023 Hoxhunt Hoxhunt raises $40M to solve the hardest part of cybersecurity: people
SV024 Cision / Hoxhunt Hoxhunt raises $40M to solve the hardest part of cybersecurity: people
SV025 Mimecast Permira completes acquisition of Mimecast
SV026 Mimecast IR Permira completes acquisition of Mimecast
SV027 SEC KnowBe4 definitive merger proxy (DEFM14A)
SV028 SEC KnowBe4 merger exhibit 99.1
SV029 SEC KnowBe4 merger exhibit 99.1 initial bid related filing
SV030 SEC KnowBe4 preliminary proxy filing