Security where nobody is singled out.
Awareness must not turn into performance monitoring. With me there is no public shaming and no personal “who clicked” list for senior management. The team is evaluated as a whole – as protection, not surveillance.
What you have to do – and what this lets you tick off.
The yardstick is § 87 BetrVG and the GDPR. Both can be settled cleanly with a short works agreement. Each point states openly whether I cover it, partly support it or whether it lies with your IT – linked to the matching attack scenario.
A phishing simulation can fall under co-determination. I provide the model works agreement and the information sheet so that the works council can approve before the start. The decision itself is yours.
The team report only shows rates per group. There is no “who clicked” list for management, and no result ends up in the personnel file.
The information sheet for staff explains on one page what happens, what doesn’t happen and which data is generated.
Only what is needed for the proof and the team report is stored; click data of individual people is archived after the run and not evaluated.
Training first, then an announced test. The order is part of the product, not up for negotiation.
You will find the full comparison with ISO 27001, NIS2 and cyber insurance under Obligations & standards. Businesses generate their time-stamped proof of training directly in the Cockpit.
Two documents that settle approval in a single meeting.
I provide both templates free of charge, without registration. They are deliberately short, written in plain German, and tailored to data processing at secureIT. Your own adjustments are explicitly welcome.
This is what it looks like in practice.
Cockpit, team report, certificate and proof of training for a fictitious company with twelve people. All names and results are made up; the layout is exactly what you will see yourself later.
Groups, registered people and the cost if everyone completes. From here you start training, an initial test or a repeat run.
The team’s click and data-entry rates, a comparison with all test runs, participation in training. Anonymised.
Results at a glance and protection level with a recommendation. The PDF carries an authenticity QR code and is suitable for audits, insurers and NIS2 documentation.
Name, course, dates of training and practical test, reference to standards, signature and a verifiable certificate number with QR code.
All training carried out, with time stamps and participation rates, mapped to the requirements. Also for ISO 27001, GDPR, the AI Act and cyber insurance.
Each person sees only their own result: reaction to each test email, how the scam could have been spotted, and what their device gave away.
This is how my training works.
With me, fairness is not an add-on but built in: training comes first, then practice – announced and without a pillory. A wrong click is a learning moment, not an entry in the personnel file. That way, security grows with the team, not against it.
Three ways – you choose what suits you.
I train your team in person – on site or online, in conversation and with examples from your everyday work.
You run the training yourself: I provide the ready-made materials and you pass them on in-house – at your own pace.
Everyone learns online the way they prefer – by text or video, at their own pace, choosing the content.
Train first, then test – deliberately in that order.
-
Initial training
First I equip your team (or you do it with my materials). Everyone starts with the same basic knowledge.
-
Phishing test as a self-check
Only then does the simulated attack follow – not as an exam, but as a self-check: everyone sees whether what they learned holds up in everyday work.
-
A security culture, refreshed when needed
Training and testing grow into a constructive security culture in your business, which you simply repeat when the time comes.
Your status report is based on your team’s results after the training – it shows the level you set out to reach, not the unprotected starting point.
New team members can be added later with one click: they immediately receive the online training materials and a first self-test – and join the next joint session or training with the same prior knowledge.
The reverse order – and why I advise against it.
From a management perspective, it often seems logical to assess the situation with a test first and only then decide whether training is needed. Technically that works – I can set it up for you.
A surprise test without prior training is exactly what you rightly warn against: people are tricked before they could have known better. That damages trust and the working atmosphere – and is delicate under co-determination law. A test without prior training only measures the starting point at zero. My approach turns this around: equip first, then check.
No subscription, as and when you need it, and always with my personal support.
AI tools are subject to co-determination. Here is a template for that.
Copilot, transcription, chatbots: as soon as AI tools can evaluate behaviour or performance, the works council has a right of co-determination under § 87 para. 1 No. 6 BetrVG (German Works Constitution Act). My model works agreement on AI sets out the principles, so that not every tool has to be negotiated separately: no performance monitoring, no AI decisions about people, training during working hours.
- Model works agreement on AI, free of charge as a PDF
- Training duty under Art. 4 of the EU AI Act as part of the agreement
- AI course with certificate, without evaluating individual answers
Frequently asked questions
Does the works council have to approve a phishing simulation?
Does management see who clicked?
What happens to the data after the test?
Can the works council agree to “training only, test later”?
Is this a subscription?
What does it cost?
Does the effect of a one-off training actually last?
Do I need an IT department for this?
How does training with you work?
Will anyone on our team be singled out or monitored?
Does this cover GDPR, NIS2, ISO 27001 or insurance requirements?
What happens when staff change?
Do I get proof of training or a certificate?
Does this also cover AI fraud and deepfakes?
Are schools and non-profit associations really free of charge?
How quickly can I start?
Your question is not listed?
Ask me directly. You only need to give an email address if you want to receive my answer.
Set up in an hour – no IT department needed.
Choose a course, add your team, get started. Proof of training is generated automatically along the way.