CybersecTools API access is now live!Learn More
PhishFirewall Logo

PhishFirewall

Phishing simulation and security awareness training platform using AI and gamification.

Hybrid
Human Risk
Email Security
AI Security
API

450+ Data Points Per Product and Company

Track competitive landscapes, evaluate vendor risk for investments, or find the right security stack for your clients.

Request Access

PhishFirewall Description

PhishFirewall is a security awareness training platform focused on reducing human risk through phishing simulation and employee education. The company was founded by Joshua Crumbaugh, a former red team operator who conducted penetration testing and social engineering engagements for Fortune 50 companies, casinos, and the federal government over nearly two decades. The platform addresses what the company identifies as core failures in traditional security awareness training: infrequent training cycles, punitive "gotcha" phishing simulations, and lack of constructive feedback. PhishFirewall's approach centers on just-in-time training, which delivers real-time, contextual feedback to employees immediately after they interact with a simulated phishing email, rather than after the fact. The platform incorporates gamification elements, including point systems and team-based challenges, designed to increase employee engagement and reduce learned helplessness—a psychological state where repeated failure without guidance causes employees to disengage from security practices entirely. An AI agent named "Lora" is integrated into the platform, functioning as an autonomous security coach and virtual assistant available around the clock. The company targets organizations of various sizes, from small businesses (1–50 employees) to enterprises with over 1,000 employees. PhishFirewall positions its training methodology around fairness—simulating realistic but detectable phishing attempts—rather than maximally deceptive scenarios. The goal is to build a security-conscious workforce capable of identifying threats that technical controls may miss.