We use cookies on this site to help provide the best possible online experience. By using this site you agree to our use of cookies.
Click to view our cookie policy and customize your cookie preferences.
OutThink is a UK-based, AI-powered human risk management platform built for the education sector. Through adaptive awareness training, autonomous phishing, real-time nudges, deepfakes, gamification, and deep behavioural analytics, it helps move beyond traditional cyber security training to proactively reduce human-driven risk.
Agreement start: 17 July 2026
Agreement end: 16 July 2029
1 year licence terms only.
Institutions may participate in the Agreement at any time during the agreement period, and are bound by its Terms and Conditions, including payments, until the end of the Institution’s chosen Commitment (Licence) Period.
Staff licences per user.
Student licences per user (only available where institutions also have Staff licenses).
Higher and Further Education and Research Councils in the United Kingdom, and to Universities and Colleges of Further Education in the Republic of Ireland. Other organisations supporting education, including research bodies and the public sector, may ask to participate in the Agreement. Chest will liaise with the Supplier about any such requests.
This agreement responds to sector demand for advanced cybersecurity human risk management. This agreement delivers preferential pricing and terms tailored to the budget and security priorities of UK education and research institutions.
Licensor: OutThink Limited, 80 Cheapside, London, EC2V 6EE, Company number 09643149
The education sector is a high-value target, rich in research, intellectual property, and the personal data of large, fast-moving populations of staff, researchers, and students.
OutThink goes beyond traditional awareness training and phishing. OutThink is an AI-native Human Risk Management (HRM) platform that reduces this risk by changing user behaviour through personalised, data-driven security awareness.
Consultation with CISOs and IT security teams across UK higher education identified critical needs: measurable risk reduction, deeper integrations, academic-specific content, high security and compliance standards, and solutions proven in education environments.
Fully WCAG 2.2 AA compliant, OutThink is built to be accessible to every member of your institution: because an effective security culture only works when everyone can take part.
See full product details, screenshots, and option breakdowns on OutThink's mini-site, specifically for Education customers via Chest.
Please note: This site is hosted by OutThink, not Jisc. Signing up will require you to provide personal details to them, please only sign up if you are happy to do so.
Traditional awareness tools tell you who clicked. OutThink tells you who is genuinely at risk, why, and what to do about it. Human Risk Intelligence analyses the behavioural factors behind user vulnerability, recommends targeted interventions, and produces a predictive Human Risk Index for every user.
Where legacy tools train and test on previous threats, OutThink focuses on today's, and gives you forward-looking, defensible scores you can act on.
OutThink is a cloud-based SaaS platform, accessed through a secure web portal and dashboard. Training reaches your people through the channels they already use — email, Microsoft Teams, or integrated directly into your existing LMS using OutThink's proprietary Smart SCORM files for seamless deployment.
ASAT — Adaptive Security Awareness Training (Core). AI-powered adaptive training, the full training library, phishing simulations, reporting, and automation. The modern replacement for traditional SAT tools.
HRM — Human Risk Management (Premium). Everything in ASAT, plus gamification, an autonomous phishing engine, deepfake simulations, behavioural nudges in Microsoft Teams, Human Risk Intelligence, and per-user risk scoring.
Extend protection to your student population, billed per student per year. Student licensing is only available to institutions with existing or concurrently purchasing Staff licenses. Two options are available for Student licensing:
This content is restricted to logged in members.
Licensor: OutThink Limited, 80 Cheapside, London, EC2V 6EE, Company number 09643149
The Chest Order, together with the Licence Terms and Conditions, and any exceptions listed below, create a legally binding contract between your institution, organisation or company and the Licensor. Therefore please read the terms and conditions carefully and only submit a Chest Order if its terms and conditions are acceptable to your institution, organisation or company and you have the authority to make the financial commitment shown.
This licence is subject to the terms and conditions for the Standard Software as a Service (SaaS) Licence (July 2024) This agreement contains variations to these terms and conditions which are available at the bottom of this page under the heading 'Exceptions to Terms and Conditions Content'.
Chest is an Enterprise of Jisc. All Purchase orders must be made out to Jisc Services Ltd, 4 Portwall Lane, Bristol, BS1 6NB to cover all charges plus VAT. Payments are due within thirty days of invoice date; recipients of late payments are entitled to interest in accordance with UK statutory provisions.
On receipt of a completed order, sites will be invoiced for their agreement. Invoices are payable within 30 days of the date of the invoice.
Please note that we will not accept orders without a PO, unless your institution does not require a PO
A new definition is added:
"Data Protection Legislation" means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications (EC Directive) Regulations 2003, and all other applicable laws and regulations relating to the processing of personal data and privacy that are in force from time to time in the United
Kingdom, together with any guidance and codes of practice issued by the Information Commissioner. UK GDPR means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (United Kingdom General Data Protection Regulation), as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018, and as defined in section 3(10) of the Data Protection Act 2018 and read with the
other provisions of that Act, in each case as amended or replaced from time to time (including by the Data (Use and Access) Act 2025).
A new definition is added:
"Licensee Data" means any content made available or shared by the Licensee and/or its Authorised Users via the Software including, but not limited to, documents, data, information and other materials.
5.1 (h) is amended and now reads:
“the Licensee is entitled to updates, fixes and maintenance releases made generally available to customers of the same subscription tier. The Licensor will use all reasonable endeavours to ensure that updates, fixes and maintenance releases do not reduce any material functionality or features of the Software, or result in material degradation of the Software. Access to new modules, premium functionality or separate product lines is not included in updates unless purchased by the Licensee. Provided that any new product line that predominantly contains the existing functionality and core features of the Software shall be treated as an update to the Software rather than a separate product line.
5.1 (i) is amended and now reads:
it will provide or arrange for a service provider to provide on its behalf, the support services set out in the Specification via phone and email. Support services for major incidents must be available for at least two normal business hours on normal business days in the UK. Support shall be provided during the Licensor’s standard business hours as per the Licensor’s Service Level Agreement which is incorporated into this Licence Agreement and provided in Appendix 2 to this Licence Agreement.
A new clause 5.5 is added and reads:
"The Licensor’s responsibilities in Clause 5.1(f) and 5.1(g) are subject to the support plan purchased by the Licensee."
A new clause 5.6 is added and reads:
“The Licensor may use anonymised and aggregated data derived from Licensee’s use of the Software for analytics, product improvement and statistical purposes, provided no individual or institution is identifiable. For the avoidance of doubt, the data shall be for the Licensor’s internal use only, and this clause does not require the Licensee or any Authorised User to participate in surveys or provide additional information."
A new clause 5.7 is added and reads:
"The Licensor maintains industry-standard technical and organisational security measures as described in its Security Documentation available on the Jisc Chest website, as updated by the Licensor from time to time."
OutThink security documentation can be found here: https://outthink.io/resource-center/trust-security/trust-center/
A new clause 7.3 is added which reads:
“The licensor’s liability under this clause 7 shall not apply where the claim arises from: (i) the Licensee’s use of the Software that is not in accordance with the documentation provided by the Licensor; (ii) modification of the Software by the Licensee; (iii) combination of the Software with systems that are not recommended by the Licensor; (iv) failure to install updates promptly provided by the Licensor to avoid infringement."
A new clause 7.4 is added and reads:
“The Licensor acknowledges that all proprietary and intellectual property rights in the Licensee Data are the exclusive property of the Licensee or its licensors or the Authorised Users and that this Licence Agreement does not assign or transfer to the Licensor any right, title or interest in such Licensee Data save
that the Licensee shall grant to the Licensor (or procure the grant to the Licensor) all rights necessary for the Licensor to access and use the Licensee Data to the extent necessary to provide access to and use of and to ensure functionality of the Software in the manner provided for in this Licence Agreement.”
Clause 8.1 is amended and now reads:
“Without prejudice to clauses 7, 8.2 and 8.3, the Licensor’s aggregate liability to the Licensee for direct loss or damage, whether arising in contract, law or tort, shall not exceed the lower of (i) 110% of the Fees paid or payable under this Licence Agreement or (ii) £1,000,000.”
Clause 9.4 is amended and now reads:
“Upon termination, the Licensee shall cease accessing the OutThink Human Risk Management Platform. The Licensor shall securely and permanently delete or return Licensee Data within 60 days of the termination date, and shall provide written confirmation of deletion to the Licensee upon request. Nothing in this clause shall require the Licensor to delete data where retention is required by applicable law or regulation."
Clause 11.1 is amended and now reads:
“Neither Party may assign or transfer all or part of the License Agreement, or any of its rights or obligations, or appoint any agent to perform such obligations, without prior written notice to the other Party. However, either Party may, by giving the other not less than sixty (60) days’ prior written notice to the other Party, transfer or assign all of its rights and obligations under this License Agreement to a wholly owned subsidiary, or to a wholly owned subsidiary of its parent company, to its parent company, or in connection with a merger, acquisition, corporate reorganisation or sale of all or substantially all of its
business or assets to which this License Agreement related, provided that in each case:
(a) the assignee is not a direct competitor of the other party;
(b) The assignee assumes all obligations under this Agreement in writing; and
(c) the assigning Party remains responsible for performance until such assumption takes effect.
For the avoidance of doubt, no consent shall be required for an assignment falling within this clause, subjectto the notice and conditions above.”
is added between Clause 17 (Legal Construction) and Clause 18 (Standard Jisc Licence for Software as a Service available on Jisc’s Chest Platform - Annex: Home Use Undertakings) it reads:
The Licensee is deemed the ‘Data Controller’ and the Licensor the ‘Data Processor’ as defined under the Data Protection Legislation. Any “Processing” of “Personal Data”, as each term is defined by the Data Protection Legislation, carried out pursuant to the Order will be governed by the Licensor’s Data Processing Agreement set out in Appendix 1 to this Licence Agreement.
Join our mailing list for the latest news, event information and resources