Lucy Security logo

Lucy Security

by ThriveDX · Since 2015
No reviews yet
ActiveAvailable globallyCloud
Quick facts
VendorThriveDX
Year launched2015
StatusActive
LocationLucy Security AG Hammergut 6 6330 Cham Switzerland
Countries servedGlobal
Languages10
Integrations1+
Free tier
Free trial
Contact salesYES

About Lucy Security

Lucy Security is a cybersecurity training software from ThriveDX that focuses on promoting awareness and preventing cyber threats. It provides phishing simulations, security awareness training, and reporting analytics so organizations can measure employee resilience against cyber attacks. Lucy Security helps companies identify vulnerabilities and educate staff on best practices. The platform's interactive content and real-time assessments assist in building a culture of security within the organization. Key capabilities: phishing simulations security awareness training reporting analytics interactive content real-time assessments Best for: organizations that need to improve their cybersecurity awareness and mitigate risks associated with employee behavior.

Lucy Security, developed by ThriveDX, delivers a comprehensive and highly practical approach to security awareness, combining employee education with realistic attack simulations to create a dual-layered defense strategy. Designed for organizations seeking to fortify both their human and technical defenses, Lucy empowers companies to assess vulnerabilities across users and infrastructure through interactive testing and dynamic training. Its primary strength lies in blending phishing simulations with an extensive e-learning suite, enabling security teams to not only identify behavioral gaps but also address them immediately within the same ecosystem. With a focus on turning employees into informed participants in cybersecurity defense, Lucy offers a practical solution for managing risk in an evolving threat landscape. The platform’s interface is one of its most accessible features. Designed with a self-explanatory GUI, Lucy allows administrators to launch phishing simulations and training programs with minimal setup time or technical skill. Even complex simulated attacks—such as ransomware, smishing, or USB baiting—can be configured in minutes.

Pros & Cons

What users like
  • +Comprehensive Training Suite: Offers over 1,000 customizable modules in 130+ languages, covering phishing, malware, and social engineering.
  • +Realistic Simulations: Lets organizations simulate real-world attacks (email, SMS, file-based) to test employee readiness.
  • +Flexible Deployment: Available as on-premise, private cloud, or SaaS—ideal for privacy-conscious organizations.
  • +Integrated LMS & Reporting: Built-in learning management system with risk analysis and progress tracking.
  • +Strong Data Privacy Compliance: Designed to meet strict data protection regulations.
What users flag
  • Initial Setup Complexity: While flexible, deploying on-prem or integrating APIs may require technical expertise.
  • Interface Density: The wide range of features can feel overwhelming for smaller teams or first-time users.
  • Pricing Transparency: Tiered packages exist, but detailed pricing isn’t always clear without a demo or sales contact.

Features

Key features

Integrated Attack Simulations & Training (Test, Train, Engage)
Lucy uniquely combines realistic attack simulations (like phishing) with a comprehensive e-learning program to identify and resolve security awareness gaps.
Customizable Content Library
Offers over 1,000 customizable training modules and hundreds of ready-to-use attack simulations in 130+ languages, allowing for tailored campaigns.
Flexible Deployment Options
Supports on-premise, private cloud, or SaaS deployment, providing organizations with control over data privacy and infrastructure integration.
Advanced Attack Methodologies
Leverages know-how from ethical hackers to simulate a wide spectrum of attack methods beyond simple phishing, constantly updating content.
Employee Reporting System (Mail Phish Button)
Integrates a "Mail Phish Button" for employees to easily report suspicious emails, feeding into a central incident analysis console.
Technical Infrastructure Testing
Beyond human awareness, Lucy can also test the IT defense and identify technical vulnerabilities through various attack simulations.

Additional features

Award-Winning Security Awareness Training
Provides recognized training programs.
Phishing Simulation
Enables organizations to simulate various phishing attacks (e.g., data entry, double-barrel, spear phishing, website spoofing, file-based, USB, ransomware, smishing).
Employee Testing
Conducts attack simulations to identify security gaps.
Program Building
Allows for customized security awareness programs based on infrastructure analysis.
Employee Training
Offers an integrated Learning Management System (LMS) with extensive training content.
Progress Measurement
Provides risk and learning analysis to track employee progress.
Employee Integration
Includes a reporting system like the Mail Phish Button.
Data Protection
Ensures privacy compliance with strict data protection regulations, regardless of deployment.
Ethical Hacker Know-how
Continuously updates attack methods and learning content based on ethical hacking expertise.
Quick Installation
Can be set up in minutes.
Flexible Deployment
Supports local intranet, cloud-based SaaS (Unix, Windows), or dedicated server deployment.
Extensive API Integration
Supports Domain API, LDAP API, SMTP API, REST API for quick integration into existing infrastructure.
Unique Features (Test, Assess, Engage, Train, Report)
Offers functionalities not fully supported by competitors.
Customizable Campaigns
Allows for creating individual phishing attacks and training campaigns.
Pre-designed Examples
Provides many ready-made campaign examples.
Detailed Statistics and Risk Assessment
Generates comprehensive reports on campaign performance and employee risk levels.
Customizable Reports
Creates customized and automatic reports for various stakeholders.
Multi-language Support
Supports over 130 languages for training modules.
Built-in Email Server
Enables launching effective attack simulations using spoofed domains.
Employee Directory Integration
Quickly imports employee data from Active Directory, Azure, or other user directories using LDAP/API.
Real-Time Dashboards
Provides real-time insights on campaign stats, system status, and employee performance.
User and Group Level Insights
Tracks activity and completion rates for granular visibility.
Custom Report Templates
Allows creation of customized templates in PDF, Word, and Excel.
Advanced Security Features
Includes Certificate-Based Authentication, DMZ Installation, 2FA/SSO, data anonymity, and Hardened VPS for platform security.
Platform Customization
Offers white-labeling and visual adaptation to corporate branding.
Multi-Tenant Deployment
Supports deployment for multiple client organizations (Elite package).
Dedicated Awareness Engineer
Provides dedicated support (Elite package).
Full Data Anonymization
Ensures sensitive data privacy.
VIP Support
Offers enhanced customer support.
Services Credit
Licenses include credits for managed services like Spear Phishing/Vishing, Whaling, Template Translation/Customization, and On-Premise Installation.
Extensive Training Library
Provides a vast collection of training content.
HTML Content Editor
Allows editing of training content.
Localization
Supports content adaptation for different regions.
Microlearning Modules
Delivers short, focused training sessions.
Certificate Generator
Issues certificates for completed courses.
Compatible with any LMS
Can integrate with other Learning Management Systems.
Employee Training Portal
Provides a portal for users to access their training and view statistics.
Performance-Based Training
Assigns training modules based on phishing simulation results.
Application Security Training
Offers content from its market-leading AppSec training for programmers (e.g., OWASP Top 10, AWS Top 10 for Web).
Real-Time Event Notification
Provides alerts on security events.

Pricing

Free trial
Free version
Request a quote
Promo Offer

Countries & Languages

Global
Countries served
10
Interface languages
7
Billing currencies

Interface languages

EnglishSpanishFrenchGermanItalianPortugueseDutchRussianJapaneseChinese

Billing currencies

🇺🇸USD🇪🇺EUR🇬🇧GBP🇨🇭CHF🇦🇺AUD🇨🇦CAD🇯🇵JPY

No reviews yet

Be the first to drop a review

Alternatives to Lucy Security

S2Team logo

S2Team

S2Team is a human risk management platform for organizations. It excels by turning employee cybersecurity…

iOCO logo

iOCO

iOCO is one of Africa’s largest technology solutions and digital transformation companies, offering a broad…

Trend Vision One logo

Trend Vision One

Trend Vision One is a cybersecurity platform from Trend Micro that provides an AI-powered solution…

SOC360 logo

SOC360

SOC360 is a cybersecurity software platform from CyberSOC Africa that provides threat detection and response…

HackenProof logo

HackenProof

HackenProof is a cybersecurity platform from HackenProof, Inc. that focuses on vulnerability management. It includes…

Cypherleak logo

Cypherleak

Cypherleak is a risk monitoring platform from Cypherleak that helps protect the business. It combines…

Often compared with Lucy Security

Compare any two tools →
S2Team logo
S2Team
Cybersecurity
0.0
iOCO logo
iOCO
IT Management
0.0
Trend Vision One logo
Trend Vision One
Cybersecurity
0.0
SOC360 logo
SOC360
Managed Detection and Response (MDR)
0.0