Nobody would hand over car keys to someone who has just passed the written test. We all know that knowing the highway code and knowing how to drive are two different things. We know that in between there are hours of practice, an instructor, a progression.

Cybersecurity awareness, though, often stops at the written test. One module, one quiz, one certification, and we decide the employee knows how to drive.

This is not a content problem. It is a programme problem.

What the market sells, and what it does very well

KnowBe4, MetaCompliance, Proofpoint and the others have built something solid: massive catalogues, dozens of languages, varied formats, built-in phishing simulations, usable reporting and an audit trail that holds up in front of an auditor. Proofpoint advertises more than 40 languages, KnowBe4 a library of several thousand pieces of content.

On that ground, there is nothing to hold against them. These platforms do exactly what they were designed to do: cover broadly and document.

So the question is not the quality of the tool.

The all-in-one promise, the stack in practice

These suites are sold on a promise of consolidation: awareness, phishing, policies, compliance and risk, all in a single tool.

Now look at the reality of a large enterprise. Phishing simulations are often run by the SOC or a service provider, with their own tooling. Training records live in the HR LMS, because that is the system of reference for audit. Internal campaigns go through the intranet and the group's communication channels. The awareness platform occupies one box in the middle of all that.

In other words, consolidation stays theoretical. In practice, organisations stack. The real buying criterion is therefore not "who can do everything", but "what slots cleanly into what already exists and brings what is missing".

The missing link: instructional design

An awareness platform delivers two things: an inventory of content and an assignment engine. What it does not deliver is the programme.

Selecting what matters for your organisation, sequencing it, spacing it across the year. Building a progression. Deciding what you measure and why. That work exists, it has a name, it is instructional design, and it is transferred to the client without anyone saying so.

Yet the cyber team receiving the credentials has neither an instructional designer nor time. It has a budget, a compliance deadline and three projects already running late. What happens next is entirely predictable: pick one or two pieces of content, push them once a year, tick the box. A platform bought for its breadth ends up consumed at a few percent.

This is not negligence. It is the logic of the model. Some vendors themselves mention, in their commercial documentation, training time in the order of "one to two hours per user per year". Awareness time is designed as an annual allowance to be consumed, not as a practice to be installed. Everything else follows from that.

Generic content against your own rules

There is an even more concrete problem, familiar to anyone who has worked with these platforms.

Your password policy is specific. So is your strong authentication method: perhaps a push application, perhaps physical keys, rarely the SMS code you see in the modules. Your procedure for reporting a suspicious email goes through a dedicated button, not a forward to the IT service desk.

Generic content that teaches something other than your rule does not do nothing, it does worse. It contradicts your policy, it plants doubt, and the employee remembers the wrong version.

The vendors' answer is customisation. It genuinely exists, and it has limits. The documentation describes a customisation centre that lets you edit text, screens, images, questions and answers, and reorder content, with the stated goal of aligning modules with your policies. For video modules, customisation covers what surrounds the video, not the video itself.

Let us translate. The vendor acknowledges that generic content does not fit your organisation, and its answer is that you do the work. You rewrite, you produce, you validate. In a solution sold as turnkey.

Why a catalogue cannot solve this

Behind all of this sits an economic problem.

When the teaching unit is the module, adaptation is expensive. Re-recording a video for every client is impossible, so the vendor produces generic content and hands the editing back to you.

When the teaching unit is the action, adaptation costs almost nothing. "Today, turn on two-factor authentication" becomes "today, enrol your security key on the internal portal", and the challenge stays accurate. Same teaching effort, same progression, but aligned with your environment. It is a question of format.

What a challenge changes

Billow does not offer a module about passwords. Billow offers: today, change your mailbox password for a stronger one.

The action is real, immediate, visible to the person themselves. It holds at the office as much as at home, which is precisely what anchors a habit. Formats vary, something to do, a short piece of content to listen to, proof to upload, but every challenge ends on something you do, never on something you watch. It runs on for thirty days, because a reflex is built through short, regular repetition. Then it extends across the year, at two challenges a month, so that cyber culture does not collapse in February.

And the programme stays alive. A threat identified in your sector, a CEO fraud attempted last week, a change in internal policy: we publish a news item or a dedicated challenge within days, not at the next annual cycle.

It is the difference between an app that gets you walking a little every day and a gym membership used twice in January. The second sells very well. The first gets people moving.

What about measurement?

A fair question, and the answer comes in three levels rather than one.

Some challenges ask for proof: a screenshot, a document to upload. As soon as the action leaves a usable trace, that trace is provided.

Others rest on the person's own declaration, and we own that. Changing the password of a personal mailbox cannot be proven, and that is exactly what makes the challenge useful: it steps outside the professional perimeter, where habits settle for good.

On top of that come scored quizzes. But situation quizzes, not recall quizzes. What we assess is the judgement call in a realistic context, not the ability to spot the right definition among four options. The nuance is not cosmetic: a knowledge quiz measures what someone remembered yesterday, a situation quiz measures what they would do tomorrow.

Finally, none of this lives alone. These signals cross-check with the indicators you already own: MFA activation rates, volume of suspicious email reports, password manager adoption. That is where the real effect of a programme shows, far more than in a completion rate.

Where Billow sits in your organisation

If you are a large enterprise that is already equipped, Billow replaces nothing. It sits on top, as the engagement and practice layer your programme is missing. Your phishing simulations continue, your LMS keeps the records, and your employees gain a regular appointment that turns knowledge into reflex. That is also what carries weight in an NIS2 audit: a living, documented programme, not a box ticked in December.

If you are a mid-sized company that wants to move fast, Billow constitutes the complete programme, ready to deploy, without tying up six months of internal design work.

In both cases, what we deliver is not access to a library. It is a path already selected, sequenced and thought through, aligned with your rules and adjustable during the year.

You can buy the ingredients anywhere; what the market is missing is the recipe, and someone who knows it.

Frequently asked questions (FAQ)

Does Billow replace my current platform?

Not necessarily. In a large enterprise that is already equipped, Billow is added as the engagement and practice layer. In a mid-sized organisation, it constitutes the complete programme.

How do challenges adapt to my internal rules?

A challenge is about an action, not a presentation. We align it with your policy, your tools and your reporting procedures, which is fast and inexpensive when the teaching unit is the action rather than the video.

How do you know a challenge was actually completed?

It depends on the challenge: proof to upload when the action leaves a trace, a screenshot for example, a self-declaration we own up to when it belongs to someone's personal life, and scored quizzes built around situations rather than recall. All of it cross-checks against your own indicators: multi-factor authentication activation, suspicious email reports, adoption of the tools you have rolled out.

Article based on public information available in July 2026 about the major security awareness platforms on the market.