Hacker surrounded by threats and icons representing the public sector.

What’s New: Keep Awareness Aligned With the Threats You Face

29 September 2026 · 4 min read

We’re helping teams turn real phishing attacks into relevant simulations, create custom scenarios with less effort, prepare employees for emerging threats such as ClickFix, support the shift towards passwordless authentication, and make everyday programme management more scalable.

What’s new

  • Recreate Attack to turn real phishing examples into relevant simulations faster
  • A new Template Studio for creating and tailoring simulations
  • New lesson: Recognizing and Responding to ClickFix Attacks
  • New lesson: Using Passkeys Securely and Recognizing Fraud
  • Personalised Learning progress transfer between campaigns
  • Bulk classification and stronger audit history in Threat Inbox
  • More granular admin roles for safer delegation
  • Lithuanian and Latvian support across key awareness experiences
  • A refreshed Learning Analytics experience

Adapt simulations to your risk reality

When a phishing email reaches your organisation, the insight should not stop with the incident. 

With Recreate Attack, upload a screenshot of a real phishing email and turn it into an editable simulation in minutes. Use it in the campaigns you already run, so employees can practise against the same tactics targeting your organisation.

This helps turn real-world threat intelligence into practical reinforcement, so employees can learn from what has already happened before a similar attack reaches the next inbox.

Available on Premium and Advanced plans and above.

Make relevant simulation creation scalable for lean security teams

Relevant simulations work best when they reflect the brands, suppliers, and situations employees actually encounter. But creating those scenarios manually can quickly become time-consuming.

Template Studio replaces the previous editor with a drag-and-drop builder, making it easier to create and adapt simulations around your organisation without adding unnecessary admin work.

Together, Recreate Attack and Template Studio help teams respond quickly to real attacks while also building tailored scenarios for the risks they already know matter.

Available on Professional and Core plans and above.

Help employees recognise attacks disguised as routine verification

Not every attack starts with a suspicious attachment or an obvious malicious link.

ClickFix attacks can use fake browser checks or CAPTCHA-style prompts to convince users to copy, paste, or execute malicious commands themselves. Because the interaction can look like a routine verification step, employees may not immediately recognise it as a threat.

The new lesson Recognizing and Responding to ClickFix Attacks helps employees understand how these attacks work, spot unusual instructions, and stop before taking an unsafe action.

The topic is increasingly relevant, ClickFix has been linked to recent attacks targeting Berlin authorities and has prompted an official warning from Germany’s Federal Office for Information Security (BSI).

Available on Professional and Core plans and above.

Prepare employees for secure authentication beyond passwords

As organisations move towards passkeys and passwordless authentication, employees are beginning to encounter sign-in and recovery experiences that look different from traditional passwords.

The new lesson Using Passkeys Securely and Recognizing Fraud helps employees understand what legitimate passwordless authentication looks like and recognise suspicious login, approval, or account-recovery requests.

For IT and security teams introducing passwordless initiatives, this helps ensure employee understanding keeps pace with the technology itself.

Available on Professional and Core plans and above.

Keep learner progress intact as Personalised Learning campaigns change

Learner progress can now carry over when you move employees into a new Personalised Learning campaign. Refresh or restructure campaigns as priorities change, without asking employees to repeat content they’ve already completed.

Triage reported threats in a fraction of the time

Threat reporting volumes can rise quickly after phishing waves or major incidents. Threat Inbox admins can now classify multiple reported emails at once instead of working through every report individually. That means teams can move through high-volume queues faster, spend less time repeating the same classification task, and focus more attention on reports that genuinely require investigation.

Available on Premium and Advanced plans and above.

Keep a full audit trail for every threat decision

Resolved reports now stay in Threat Inbox with their complete classification history, what was reported, how it was classified, and every change since. When new information surfaces, reclassify without reopening the case. When auditors or incident responders ask how a report was handled, the answer is already documented.

Available on Premium and Advanced plans and above.

Delegate administration with greater control

Large awareness programmes rarely sit with one administrator. New, more granular admin roles make it easier to separate responsibilities such as user management, campaign management, and analytics access.That allows organisations to distribute day-to-day programme ownership more safely, giving teams the access they need without unnecessarily broad permissions.

Reach more employees in their preferred language

Awareness programmes are more effective when employees can engage with them in a language they understand comfortably. Lithuanian and Latvian are now available across our new interactive E-Learning lessons, phishing templates, and the Phishing Report Button. 

Employees in the Baltics get the same experience as colleagues elsewhere, with no workarounds or fallback languages.

A more consistent view of learning performance

Learning Analytics now uses the same design system as the rest of the platform. Charts, colours and labels look different, but KPIs, data, filters and exports are unchanged, so your existing reporting keeps working. It also lays the groundwork for a more unified analytics experience across SoSafe.

Awareness that keeps pace with your organisation

The common thread across September’s releases is relevance. Security teams need training that reflects the threats their employees actually face, content that keeps pace with changing security practices, and operational workflows that do not become more burdensome as programmes grow. 

For questions about any of these updates, please contact your SoSafe representative or visit our Knowledge Base.

Do you want to stay ahead of the cyber game?

Sign up for our newsletter to receive the latest cyber security articles, events, and resources. No spam, only content that truly matters.

Newsletter visual
Hero Background

Experience our products first-hand

Use our online test environment to see how our platform can help you empower your team to continuously avert cyber threats and keep your organization secure.

SoSafe Security Awareness Training Leader Enterprise 2026 Sosafe Cyber security training platform top 50 award 2026 SoSafe Security Awareness Training Leader 2026 SoSafe Security Awareness Training Momentum Leader 2026 SoSafe Security Awareness Training Leader Mid-Market 2026 SoSafe Security Awareness Training Leader Europe 2026

This page is not available in English yet.

Diese Seite ist noch nicht in Ihrer Sprache verfügbar. Sie können auf Englisch fortfahren oder zur deutschen Startseite zurückkehren.

Cette page n’est pas encore disponible dans votre langue. Vous pouvez continuer en anglais ou revenir à la page d’accueil en français.

Deze pagina is nog niet beschikbaar in uw taal. U kunt doorgaan in het Engels of terugkeren naar de Nederlandse startpagina.

Esta página aún no está disponible en español. Puedes continuar en inglés o volver a la página de inicio en español.

Questa pagina non è ancora disponibile nella tua lingua. Puoi continuare in inglese oppure tornare alla home page in italiano.