2,000,000+ employees protectedFounded 2020$30M Series B33 languagesFive-minute lessons2,000+ organizations

Company profile / Cybersecurity

The Five-Minute War Against the Perfect Phish

Riot began with a rude discovery: clever security systems still lose when a hurried employee clicks. Six years later, its five-minute coach has grown into a live defense layer for more than two million people.

The first useful thing Riot discovered was embarrassing. Benjamin Netter was helping run October, the European business lender he had co-founded, when the company was attacked. The lesson was not that its security machinery was cheap or careless. The lesson was that criminals are practical. Why pick a lock when someone inside may simply hand you the key?

Netter tried the proposition himself. He sent a fake phishing message around the company and roughly one employee in five took the bait. The technical system had not failed first; attention had. That result became the germ of Riot, which Netter began building on weekends before entering Y Combinator and leaving October after five and a half years.

The brief, before your next suspicious email

  • Riot trains and protects employees through short conversations, realistic simulations and live alerts.
  • Its coach, Albert, works inside Slack, Microsoft Teams and Google Chat instead of a separate classroom.
  • The platform now spans awareness, phishing tests, breach intelligence, mail triage, file-sharing audits and email defense.
  • Public pricing starts at $6.89 per employee per month, billed annually; larger companies receive custom pricing.
  • The useful idea to copy is cadence: measure, coach immediately, repeat, and make reporting easier than ignoring.

A lesson short enough to survive the workday

Riot launched in 2020 with fake phishing campaigns and awareness training. The face of the product was Albert, a chat-based cyber coach. Albert did not ask employees to visit a learning portal, locate a password and surrender an afternoon. He appeared inside the communication software already open on their screens. A lesson might take five minutes. A remedial session after a failed simulation might take three.

That is a small design choice with an immodest consequence. Traditional awareness software is commonly bought by the security team but consumed under mild protest by everyone else. Riot changed the place, length and tone of consumption. The employee was no longer a student summoned to detention. The coach came to the employee.

Riot dashboard showing employee security scores and actions such as activating two-factor authentication and reporting phishing
Good behavior gets points. Bad behavior gets a nudge. The dashboard turns a vague idea called “culture” into a list of things people actually did.

The earliest proof was not subtle. Groupe Le Monde, still marked by a 2015 attack that had seized social accounts and its publishing platform, sent staff a playful simulation built around a fake restaurant voucher. Two-thirds opened it. Many gave up login credentials. “Exceptional,” its security chief called the result, “but in a bad way.” A joke had produced a baseline.

The e-bike maker Cowboy offers the more flattering end of the story. After invoice fraud cost it money, the company adopted monthly simulations and continuing training. Its co-founder Tanguy Goretti said completion passed 85%, vulnerability fell below 4%, and automation saved the equivalent of half a full-time role. These are customer-reported outcomes, not a randomized trial. They are still more informative than a certificate saying everybody watched the video.

“Every time we raise funds, we get attacked.”Tanguy Goretti, co-founder of Cowboy

The training company that changed its mind

Then the phish improved. Generative AI made polished language cheap, personalized research fast and clumsy scams less clumsy. Riot's conclusion was blunt: awareness could no longer move as quickly as the threats. Training people to recognize yesterday's tricks was necessary, but no longer sufficient.

So the company widened the product. Breaches watches for exposed corporate and personal credentials, then asks employees to act. Inbox collects suspicious messages reported by staff and classifies them. Sonar audits files and permissions across Google and Microsoft workspaces, pushing routine clean-up to the person who understands the relationship. Slash, introduced in 2026, analyzes mail after delivery, adds warnings inside suspicious messages and can pull a confirmed threat from every company mailbox.

AwarenessShort conversations and tailored lessons through Albert.
SimulationRealistic phishing exercises, metrics and instant remediation.
BreachesExposure monitoring with guided credential clean-up.
InboxA suspicious-email hotline with AI classification.
SonarPermission-drift and data-sharing audits.
SlashPost-delivery detection, warning and removal.

This is the distinction Riot now wants buyers to notice. KnowBe4 and the rest of the large awareness category sell libraries, simulations and compliance. Riot still does those jobs, but calls its broader idea “employee security posture management.” A single Karma score gathers training, behavior and remedial action into a view of company risk. Where a course records that somebody finished, posture tries to record whether the person is safer today.

Members of Riot's team talking and working in the company's office
The people protecting the people, photographed in capsules that look suspiciously like very comfortable browser tabs.

The business of a second thought

Riot sells annual subscriptions per employee. Its posted rate is $6.89 a month for each person, with custom pricing beyond 200 seats. Directory records sync from Google, Microsoft, Slack and Okta; the content is available in 33 languages; security and compliance teams can export the data. The low-maintenance promise is central because a product designed to save security labor cannot require a curator standing beside it.

$6.89

Per employee, per month, billed annually.
That is about $8,268 a year for 100 employees at the public rate, before any custom terms.

The model found momentum. Riot says it trained about 100,000 people in 2022 and now protects more than two million employees at over 2,000 organizations. Its customer strip includes Mistral AI, Deel, Intercom, Sorare, Deezer, L'Occitane and Y Combinator. In 2024 it passed $10 million in annual revenue. A $30 million Series B led by Left Lane Capital followed in February 2025, at a reported post-money valuation north of $170 million. Total disclosed funding is about $45 million.

2M+employees protected
2,000+organizations
33content languages

There is an attractive symmetry here. Hackers scale attention with software; Riot tries to scale judgment with software. Yet the symmetry should not be mistaken for magic. Slash currently needs read and write access to Google or Microsoft mailboxes. Sonar likewise depends on Google or Microsoft workspace data. Any buyer should weigh those permissions, residency and privacy requirements against the benefit of intervention.

The bargain has conditions

Riot is also not an endpoint agent, identity provider or replacement for upstream mail security. The company says so in the architecture: Slash works after mail arrives and alongside anti-spam tools. No training product can rescue weak access controls, unmanaged devices or a culture that punishes people for reporting mistakes. If employees believe every simulation is a trap set by management, they may learn secrecy rather than caution.

Nor should every result be compared as if it came from the same experiment. Le Monde's 66% opening rate, Netter's 20% origin test and Cowboy's sub-4% vulnerability reflect different companies, messages and moments. Their value is diagnostic. Measure your own baseline, improve against yourself, and resist turning a human being into a league table.

What a security team can copy on Monday

  1. Run a humane baseline simulation before buying more content.
  2. Give failed clicks immediate, three-to-five-minute coaching.
  3. Deliver reminders inside the tools employees already use.
  4. Repeat monthly, vary the scenario and reward fast reporting.
  5. Track behavior over time without publicly shaming individuals.
A bright grid-like view through Riot's office showing meeting rooms and work areas
Riot's office resembles a permission matrix designed by an architect: mostly clean squares, with the occasional human granted access.

The deeper wager is not that employees are the weakest link. It is that neglected employees are. Give a person context at the moment of risk, let them practice before the invoice fraud arrives, and make the safe action the easy action. A firewall cannot wonder whether the chief executive really needs gift cards before lunch. A colleague can.

That is what Riot actually sells: the second thought between a plausible message and an expensive click. Five minutes is not much time. In cybersecurity, it may be lavish.