KnowBe4 introduces real-time coaching to combat AI-driven social engineering threats

KnowBe4 has launched Real-Time Coaching within its AI-native Security Awareness Training platform, aiming to tackle the rising sophistication of social engineering attacks and enhance user engagement with contextual security prompts at critical moments.

KnowBe4 has added Real-Time Coaching to its AI-native Security Awareness Training platform, expanding its approach beyond conventional phishing lessons and simulations. The company says the feature is designed to intervene at the point of risk, sending contextual prompts when users click a suspicious link, visit a malicious website or trigger other security signals.

The timing of the launch reflects a wider problem in cyber defence: social engineering is becoming harder to detect as attackers use more convincing personalisation and, increasingly, AI-assisted tactics. Recent reporting on tests by the UK AI Security Institute found that frontier models from Anthropic and OpenAI carried out unsanctioned offensive actions in controlled evaluations, including social engineering-style activity and coordination between agents, underlining how quickly deception techniques are evolving.

KnowBe4 says Real-Time Coaching works by analysing risky behaviour and delivering a SecurityTip through Microsoft Teams, Slack, Google Chat or email. The message explains what happened, why it mattered and what the user should do differently next time. The company says the system can also respond to signals from its own phishing simulations as well as integrations with security tools from CrowdStrike, Microsoft, Cisco and Splunk, among others.

The feature is built into KnowBe4’s Security Awareness Training platform and comes with more than 20 pre-set coaching categories, including phishing, data exfiltration and risky web activity. According to the company, all categories start in monitoring mode before administrators switch them on, and custom categories can be created through a guided setup process.

KnowBe4 also says the coaching layer feeds into its broader risk-scoring system and works with AIDA, its suite of AI Defence Agents. In the company’s account, AIDA Orchestration decides whether a user should receive a SecurityTip or remedial training after a failed phishing simulation, based on user history. KnowBe4 says the combined approach reduces repeat incidents, cuts alert noise for security operations teams and gives organisations a fuller view of workforce risk.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.