Riot
A Paris-based human risk management platform delivering continuous phishing simulation and chat-native security awareness training through Slack and Microsoft Teams.
Visit Website ↗ + Add to CompareOverview
Riot is a Paris-based human risk management platform, founded in 2020, that runs continuous phishing simulations, bite-sized security-awareness training, and real-time employee vulnerability monitoring through a chatbot-style interface integrated into Slack and Microsoft Teams. The company’s framing is that most successful attacks start with human error, so security awareness needs to feel more like an ongoing, low-friction habit than an annual compliance training module employees click through once a year.
Riot has raised $44 million across three rounds, including a $12 million Series A led by Base10 Partners and a $30 million Series B in February 2025, funding that the company has tied explicitly to defending against AI-era social engineering (deepfake voice/video pretexting, AI-generated phishing) rather than only traditional email phishing. That funding trajectory places Riot among the better-capitalized players in the security-awareness-training category, competing directly with incumbents like KnowBe4 and newer entrants such as Dune Security.
Riot’s differentiation is delivery mechanism and cadence — chat-native, continuous micro-training rather than a periodic LMS-style course — which is a real behavioral-design bet, though independent, vendor-neutral evidence that this cadence produces measurably better security outcomes (versus simply higher completion rates) is not established in public reporting. CISOs evaluating Riot should weigh its Series B-stage traction and AI-threat-specific roadmap against the broader question every awareness-training vendor faces: whether training completion translates into fewer successful social-engineering incidents in their specific environment.
Innovation Matrix Assessment
Riot has evolved from basic phishing simulation toward a chatbot-native, continuous training model and an explicit roadmap addressing AI-era social engineering (deepfakes, AI-generated pretexting), a reasonable pace of product evolution backed by fresh Series B capital.
Integration directly into Slack and Microsoft Teams lowers deployment friction versus standalone LMS-style training platforms, making rollout and ongoing engagement operationally simpler for security teams.
Riot has raised $44M across three rounds, including a $30M Series B in February 2025, a strong and recent funding trajectory relative to peers in the security-awareness-training category.
Chat-native, continuous micro-training is a genuine behavioral-design departure from the periodic LMS-course model that dominates security awareness training, though the underlying category (phishing simulation plus training) is well established.
No independent, vendor-neutral study linking Riot's training cadence to measurably reduced social-engineering incident rates was found; available efficacy evidence is limited to the company's own marketing and funding-round press coverage.
Human-targeted social engineering, increasingly amplified by AI-generated phishing and deepfake pretexting, remains one of the most common initial-access vectors, making continuous human-risk management directly relevant to current threat trends.
Why CISOs Should Care
CISOs frustrated with low engagement from annual compliance-style security training may find Riot's continuous, chat-native cadence a more realistic way to keep phishing awareness top of mind, particularly against AI-era pretexting.
What Makes It Different
Riot delivers training and phishing simulation natively inside Slack/Teams on a continuous basis, rather than through a periodic standalone LMS course, explicitly targeting AI-era social engineering threats in its recent roadmap.
The Matrix Verdict
60/100 — INCREMENTAL INNOVATOR
A well-funded, fast-growing human risk management vendor with a genuinely different delivery model; the AI-threat-specific positioning is timely, but like the broader awareness-training category, its actual impact on incident rates lacks independent validation.
Editorial Note: Claims vs. Verified Findings
Claims about training engagement and effectiveness against AI-era threats are vendor-sourced from Riot's own site and blog. Independently confirmed via SecurityWeek, VentureBeat, and Riot's own funding announcement: the $12M Series A led by Base10 and the $30M Series B in February 2025, totaling $44M raised.
Sources
Alternatives to Riot
Abnormal AI
AI-native behavioral security platform that analyzes sender identity and communication patterns, rather than message content alone, to stop…
Palo Alto Networks Cortex XSIAM
Palo Alto Networks' AI-driven 'autonomous SOC' platform that unifies SIEM, EDR, SOAR, and attack-surface data into a single…
Fenix24
Chattanooga-based ransomware recovery specialist that has restored operations after 500+ real-world incidents, including 30 Fortune 500 companies.
Torq
AI-native hyperautomation platform positioning itself as an 'agentic SOC,' using a multi-agent system to autonomously execute large volumes…
Tines
No-code security automation platform letting SOC teams build and share automated workflows ('Stories') without proprietary scripting or vendor…
Microsoft Sentinel
Microsoft's cloud-native SIEM, deeply integrated with Azure and Microsoft 365 telemetry, now layering agentic AI (Security Copilot/Sentinel agents)…