Examples

What you have in hand after the training.

These views come from a run of the fictitious “Musterfirma GmbH”: twelve people in administration, an initial test in spring, then training and a practical test. All names and results are made up. Layout, figures and documents are exactly as you will later see them in your own Cockpit.

Register your business and get started How it works

1 · Cockpit

The Cockpit: progress visible at all times.

The business sees progress and key figures, but never who clicked. The business controls the run: pause, resume, send reminders.

Cockpit The business Cockpit

Groups, registered people and the cost if everyone completes. From here you start training, an initial test or a repeat run.

Cockpit Training in progress

Who has started the course, who has finished, how long access remains. People who haven’t finished can be reminded with one click.

Cockpit Phishing run at a glance

Key figures across all participants, the sending history per person and controls for the run. The business deliberately does not see individual clicks here.

2 · Reports

Team report and personal report.

The business receives the anonymised team report as a page in the Cockpit and as an evidence PDF with an authenticity QR code. The individual result goes only to the person concerned.

Team report Team report in the Cockpit

The team’s click and data-entry rates, a comparison with all test runs, participation in training. Anonymised.

Team report Evidence PDF, page 1

Results at a glance and protection level with a recommendation. The PDF carries an authenticity QR code and is suitable for audits, insurers and NIS2 documentation.

Team report Evidence PDF, page 2

How the team is distributed and what an attacker would know about the business after this run: systems, browsers, effective lures.

Individual report Personal report

Each person sees only their own result: reaction to each test email, how the scam could have been spotted, and what their device gave away.

3 · Certificate

The certificate of participation.

Two pages per person: the certificate with a verifiable number and an evidence sheet that directly answers the questions of insurers and auditors. Every number can be checked publicly.

Certificate Certificate of participation

Name, course, dates of training and practical test, reference to standards, signature and a verifiable certificate number with QR code.

Certificate Evidence sheet for the certificate

Page 2 answers the questions from risk questionnaires: what was trained, when, how it was tested, against which standard. Ready to attach without further explanation.

4 · Evidence

The compliance evidence.

One PDF per context, generated from the actual runs: NIS2, ISO 27001, GDPR, EU AI Act, cyber insurance or simply your own peace of mind.

Compliance evidence NIS2 compliance evidence

All training carried out, with time stamps and participation rates, mapped to the requirements. Also for ISO 27001, GDPR, the AI Act and cyber insurance.

Compliance evidence Generating evidence in the Cockpit

One click per context. The evidence is generated from the actual runs; nothing has to be maintained by hand.

Set up in an hour, without any sales call.

Register your business, add your team, choose course and templates, start. If you would rather have guidance, just drop me a line.

Register now See prices

FAQ

Frequently asked questions

Is this a subscription?
No. There is no subscription and no contract term. You book training and tests as you need them – once or on a recurring basis, whatever suits you.
What does it cost?
For businesses, €49 net per person, one-off: training, first phishing test run, team report, Cockpit and six months of monthly refreshers. Further test runs cost €22 per person. For individuals, the training with certificate costs €29 incl. VAT, but without team report, Cockpit and refreshers, hence the lower price. An initial conversation and the self-tests are free. Compare all services on the pricing page →
Does the effect of a one-off training actually last?
Not on its own, which is why I don’t stop at the certificate. Everyone who completes the course receives a short interactive lesson by email every calendar month for six months: under five minutes, no login, a different current topic each time. Keeping it short is deliberate; the effect comes from spreading it over time. In the Cockpit you see your teams’ completion rate and the average score. This refresher is included in the business price at no extra cost.
Do I need an IT department for this?
No. Setup takes about an hour: choose a course, add your team, get started. The proof of training is created automatically. If you like, I’ll set it up together with you.
How does training with you work?
However you prefer: I train your team in person (on site or online), you run the training yourself with my ready-made materials, or each person learns online at their own pace. My recommendation: train first, then run the phishing test as a self-check – that builds a security culture instead of putting people on the spot.
Will anyone on our team be singled out or monitored?
No. There is no public shaming and no personal “who clicked” list for senior management. The team is evaluated as a whole. A wrong click is a learning moment, not an entry in someone’s personnel file.
Does this cover GDPR, NIS2, ISO 27001 or insurance requirements?
It covers the awareness and training part of these obligations – including proof of training with a timestamp. I state openly what belongs to your technology/IT. You’ll find the full comparison under “Obligations & standards”.
What happens when staff change?
You add new team members later with a click: they immediately receive the online training materials and a first self-test, and join the next joint training with the same level of knowledge.
Do I get proof of training or a certificate?
Yes. Proof of participation and completion with date and timestamp is created automatically for each person – as audit-proof evidence for audits, insurers or your own documentation.
Does this also cover AI fraud and deepfakes?
Yes. Current tactics such as AI-assisted phishing, fake voices and deepfakes are part of the courses and simulations – in line with the AI literacy requirement of the EU AI Act.
Are schools and non-profit associations really free of charge?
Yes. For schools and non-profit associations the offer is free of charge – this matters to me personally.
How quickly can I start?
Right away and without a call, if you like: you register your business or institution yourself at /registrieren, add your team, choose the course and phishing templates and start the test run – all on your own in the Cockpit, set up in about an hour. To get a feel for it, there are the free self-tests. And if you’d rather have support, just send me a short message; I’ll get back to you personally.

Your question is not listed?

Ask me directly. You only need to give an email address if you want to receive my answer.

A quick confirmation that a human is typing here, not a bot.

Set up in an hour, trained in a week.

Create a free account, add your team, unlock the course. You only pay when you start. Would you rather see what a test email looks like first? The self-test is free.

Add your team Test it yourself first