Lucy Security logo

Lucy Security

by ThriveDX · Since 2015
No reviews yet
ActiveAvailable globallyCloud
Quick facts
VendorThriveDX
Year launched2015
StatusActive
LocationLucy Security AG Hammergut 6 6330 Cham Switzerland
Countries servedGlobal
Languages10
Integrations1+
Free tierN/A
Free trialN/A
Contact salesYES

About Lucy Security

Lucy Security is a cybersecurity training software from ThriveDX that focuses on promoting awareness and preventing cyber threats. It provides phishing simulations, security awareness training, and reporting analytics so organizations can measure employee resilience against cyber attacks. Lucy Security helps companies identify vulnerabilities and educate staff on best practices. The platform's interactive content and real-time assessments assist in building a culture of security within the organization. Key capabilities: phishing simulations security awareness training reporting analytics interactive content real-time assessments Best for: organizations that need to improve their cybersecurity awareness and mitigate risks associated with employee behavior.

Lucy Security, developed by ThriveDX, delivers a comprehensive and highly practical approach to security awareness, combining employee education with realistic attack simulations to create a dual-layered defense strategy. Designed for organizations seeking to fortify both their human and technical defenses, Lucy empowers companies to assess vulnerabilities across users and infrastructure through interactive testing and dynamic training. Its primary strength lies in blending phishing simulations with an extensive e-learning suite, enabling security teams to not only identify behavioral gaps but also address them immediately within the same ecosystem. With a focus on turning employees into informed participants in cybersecurity defense, Lucy offers a practical solution for managing risk in an evolving threat landscape. The platform’s interface is one of its most accessible features. Designed with a self-explanatory GUI, Lucy allows administrators to launch phishing simulations and training programs with minimal setup time or technical skill. Even complex simulated attacks—such as ransomware, smishing, or USB baiting—can be configured in minutes.

Pros & Cons

Pros
  • Comprehensive Training Suite: Offers over 1,000 customizable modules in 130+ languages, covering phishing, malware, and social engineering.
  • Realistic Simulations: Lets organizations simulate real-world attacks (email, SMS, file-based) to test employee readiness.
  • Flexible Deployment: Available as on-premise, private cloud, or SaaS—ideal for privacy-conscious organizations.
  • Integrated LMS & Reporting: Built-in learning management system with risk analysis and progress tracking.
  • Strong Data Privacy Compliance: Designed to meet strict data protection regulations.
Cons
  • Initial Setup Complexity: While flexible, deploying on-prem or integrating APIs may require technical expertise.
  • Interface Density: The wide range of features can feel overwhelming for smaller teams or first-time users.
  • Pricing Transparency: Tiered packages exist, but detailed pricing isn’t always clear without a demo or sales contact.

Features

Key features

Integrated Attack Simulations & Training (Test, Train, Engage)

Lucy uniquely combines realistic attack simulations (like phishing) with a comprehensive e-learning program to identify and resolve security awareness gaps.

Customizable Content Library

Offers over 1,000 customizable training modules and hundreds of ready-to-use attack simulations in 130+ languages, allowing for tailored campaigns.

Flexible Deployment Options

Supports on-premise, private cloud, or SaaS deployment, providing organizations with control over data privacy and infrastructure integration.

Advanced Attack Methodologies

Leverages know-how from ethical hackers to simulate a wide spectrum of attack methods beyond simple phishing, constantly updating content.

Employee Reporting System (Mail Phish Button)

Integrates a "Mail Phish Button" for employees to easily report suspicious emails, feeding into a central incident analysis console.

Technical Infrastructure Testing

Beyond human awareness, Lucy can also test the IT defense and identify technical vulnerabilities through various attack simulations.

Additional features

Award-Winning Security Awareness Training

Provides recognized training programs.

Phishing Simulation

Enables organizations to simulate various phishing attacks (e.g., data entry, double-barrel, spear phishing, website spoofing, file-based, USB, ransomware, smishing).

Employee Testing

Conducts attack simulations to identify security gaps.

Program Building

Allows for customized security awareness programs based on infrastructure analysis.

Employee Training

Offers an integrated Learning Management System (LMS) with extensive training content.

Progress Measurement

Provides risk and learning analysis to track employee progress.

Employee Integration

Includes a reporting system like the Mail Phish Button.

Data Protection

Ensures privacy compliance with strict data protection regulations, regardless of deployment.

Ethical Hacker Know-how

Continuously updates attack methods and learning content based on ethical hacking expertise.

Quick Installation

Can be set up in minutes.

Flexible Deployment

Supports local intranet, cloud-based SaaS (Unix, Windows), or dedicated server deployment.

Extensive API Integration

Supports Domain API, LDAP API, SMTP API, REST API for quick integration into existing infrastructure.

Unique Features (Test, Assess, Engage, Train, Report)

Offers functionalities not fully supported by competitors.

Customizable Campaigns

Allows for creating individual phishing attacks and training campaigns.

Pre-designed Examples

Provides many ready-made campaign examples.

Detailed Statistics and Risk Assessment

Generates comprehensive reports on campaign performance and employee risk levels.

Customizable Reports

Creates customized and automatic reports for various stakeholders.

Multi-language Support

Supports over 130 languages for training modules.

Built-in Email Server

Enables launching effective attack simulations using spoofed domains.

Employee Directory Integration

Quickly imports employee data from Active Directory, Azure, or other user directories using LDAP/API.

Real-Time Dashboards

Provides real-time insights on campaign stats, system status, and employee performance.

User and Group Level Insights

Tracks activity and completion rates for granular visibility.

Custom Report Templates

Allows creation of customized templates in PDF, Word, and Excel.

Advanced Security Features

Includes Certificate-Based Authentication, DMZ Installation, 2FA/SSO, data anonymity, and Hardened VPS for platform security.

Platform Customization

Offers white-labeling and visual adaptation to corporate branding.

Multi-Tenant Deployment

Supports deployment for multiple client organizations (Elite package).

Dedicated Awareness Engineer

Provides dedicated support (Elite package).

Full Data Anonymization

Ensures sensitive data privacy.

VIP Support

Offers enhanced customer support.

Services Credit

Licenses include credits for managed services like Spear Phishing/Vishing, Whaling, Template Translation/Customization, and On-Premise Installation.

Extensive Training Library

Provides a vast collection of training content.

HTML Content Editor

Allows editing of training content.

Localization

Supports content adaptation for different regions.

Microlearning Modules

Delivers short, focused training sessions.

Certificate Generator

Issues certificates for completed courses.

Compatible with any LMS

Can integrate with other Learning Management Systems.

Employee Training Portal

Provides a portal for users to access their training and view statistics.

Performance-Based Training

Assigns training modules based on phishing simulation results.

Application Security Training

Offers content from its market-leading AppSec training for programmers (e.g., OWASP Top 10, AWS Top 10 for Web).

Real-Time Event Notification

Provides alerts on security events.

Pricing

Free trial
Free version
Request a quote
Promo Offer

Countries & Languages

Global
Countries served
10
Interface languages
7
Billing currencies

Interface languages

EnglishSpanishFrenchGermanItalianPortugueseDutchRussianJapaneseChinese

Billing currencies

🇺🇸USD🇪🇺EUR🇬🇧GBP🇨🇭CHF🇦🇺AUD🇨🇦CAD🇯🇵JPY

No reviews yet

Be the first to drop a review

Alternatives to Lucy Security

iOCO logo

iOCO

iOCO is one of Africa’s largest technology solutions and digital transformation companies, offering a broad…

Trend Vision One logo

Trend Vision One

Trend Vision One is a cybersecurity platform from Trend Micro that provides an AI-powered solution…

SOC360 logo

SOC360

SOC360 is a cybersecurity software platform from CyberSOC Africa that provides threat detection and response…

HackenProof logo

HackenProof

HackenProof is a cybersecurity platform from HackenProof, Inc. that focuses on vulnerability management. It includes…

Cypherleak logo

Cypherleak

Cypherleak is a risk monitoring platform from Cypherleak that helps protect the business. It combines…

Cybervergent logo

Cybervergent

Cybervergent is an AI-native platform from Cybervergent that provides real-time posture visibility, automated remediation, and…

Spot something wrong or outdated?

Suggest a correction — a reviewer verifies every change.

Often compared with Lucy Security

Compare any two tools →
iOCO logo
iOCO
IT Management
0.0
Trend Vision One logo
Trend Vision One
Cybersecurity
0.0
SOC360 logo
SOC360
Managed Detection and Response (MDR)
0.0
HackenProof logo
HackenProof
Vulnerability Management
0.0