Phishing training with proof · for businesses without an IT department

You are liable when your staff click. I make sure that click never happens.

I train your team online, then test it with realistic phishing emails and deliver the document that insurers and data protection authorities want to see. €49 per person, one-off, no subscription.

Free account, you only pay when you start. No installation, no sales call.

45 min
per person, online
49 €
one-off, no subscription
PDF
time-stamped proof of training
Servers in Germany GDPR-compliant Proof for NIS2 and GDPR No subscription, no minimum term
Participant in the Alliance for Cyber Security (BSI) Participant in the Allianz für Cyber-Sicherheit run by the BSI, Germany’s Federal Office for Information Security
The result

What changes after the training.

Knowledge

In an online course, your team learns how to recognise phishing emails, at their own pace and without taking time away from the business.

Culture

Your team becomes more confident and more alert: suspicious messages get reported instead of clicked, and double-checking before a bank transfer becomes normal. The three phishing tests per person show you that this culture has taken hold.

Proof

Certificate of participation, anonymised team report and a documented history, ready for NIS2, GDPR and your insurer.

How it works

A trained team in four steps.

You need no IT department and no preparation. Book, add your team, done.

Book

Choose the number of people, pay, done. No sales call, no contract with a minimum term.

Set up your team

Enter names and email addresses or import them as a list. Everyone receives a personal access link.

Training in progress

Each person completes the online course at their own pace, as video or text. You follow progress in the Cockpit.

Test + report

Three simulated phishing emails within five working days. Then: a personal report and a certificate of participation.

Fully automated

Add the participants once; after that, course invitations, reminders, phishing tests and evaluation run fully automatically. You look at the Cockpit when you want to, not because you have to.

See how it works in detail →

Who it’s for

Made for businesses that carry the liability but have no IT department.

Management

“I am personally liable, but I have no IT department.”

You need a solution that works without IT knowledge and produces the proof your insurer or auditor wants to see.

For management →

Medical practices & clinics

“The German IT security guideline for medical practices (KBV) requires training, and I have no time for it.”

Patient data, telematics, prescription fraud: I train your practice team in 45 minutes per person and deliver the proof required under Section 390 of the German Social Code Book V, without touching your telematics infrastructure.

For medical practices →

Law and tax firms

“I am liable for confidentiality, even when the front office clicks.”

Client files, payroll data, client trust accounts: lawyers and tax advisers get the proof for their supervisory body, professional liability insurer and cyber insurer, plus a decision paper for the partners’ meeting.

Lawyers → · Tax advisers →

HR and data protection

“I have to be able to prove that training took place.”

You have to document that training took place, who took part and when. All of this is generated automatically, with a certificate of participation and an anonymised team report.

For HR and data protection →

IT managers, works councils, schools and individuals will find their own page in the “Who it is for” menu and in the footer.

Price

€49 per employee. One-off.

Awareness training and the first phishing test run always go together, because a test without prior training only proves that people click.

Book further test runs later: €22 per person, straight from your Cockpit. No subscription, no automatic renewal.

What is included

  • Online course as video or text version
  • Three automated phishing tests per person
  • Personal results report for each person
  • Anonymised team report for the business
  • Certificate of participation as proof of training
  • Company account with live Cockpit and history
Obligation and resilience

Awareness training is no longer optional.

NIS2 explicitly requires the management bodies of entities in scope to take part in cybersecurity training. The GDPR requires practically every business to take technical and organisational measures. Training your staff is one of them.

Even if you are not regulated, it is in your interest: cyber insurers increasingly ask for documented awareness measures before they pay out.

Which obligations apply to you

What you need to prove

  • That training took place
  • Who took part
  • When it happened
  • That it is repeated regularly

With me, all four proofs are produced automatically as a by-product of the training.

Frequently asked questions

What businesses want to know before booking.

Are employees who fall for the test exposed?
No. The business only receives an anonymised team report. It sees how the team performs as a whole, not who clicked. The personal result goes only to the person concerned. That keeps it a learning tool, not a surveillance instrument.
What does the works council say?
The anonymisation is exactly the argument: there is no monitoring of individual employees’ performance or behaviour, because the employer never receives personal results. I provide a description of the procedure and a template works agreement for the consultation with employee representatives.
Do you store passwords if someone enters them during the test?
No. If something is entered on a simulated login page, I only log that something was entered. The password itself is never stored. Everything runs on servers in Germany in line with the GDPR.
How much effort is it for my business?
You add the participants once, individually or as a list. After that everything runs automatically: course invitations, reminders, the phishing tests and the evaluation. You look at the Cockpit when you want to, not because you have to.
Why can’t I book a phishing test without training?
Because it improves nothing. A test without prior training only measures that people click, and leaves them feeling trapped. After the first round your team is trained. From then on you can book individual test runs for €22 per person as often as you like.
My business has more than 200 employees.
Then I will prepare a quote with volume pricing and, if you wish, several sites or subsidiaries under one roof. Get in touch.
Is this also available for schools?
Yes. There are dedicated courses for pupils from grade 5, in age-appropriate language and with suitable phishing templates. The teacher guides the course. Schools and non-profit organisations can apply for free access. Create an account for schools.

Your question is not listed?

Ask me directly. You only need to give an email address if you want to receive my answer.

A quick confirmation that a human is typing here, not a bot.

Set up in an hour, trained in a week.

Create a free account, add your team, unlock the course. You only pay when you start. Would you rather see what a test email looks like first? The self-test is free.

Add your team Test it yourself first