You are liable – even without an IT department.
Responsibility for IT security lies with you, even if there is no IT department. You don’t need a technology battle. You need a trained team, solid proof and the peace of mind that the matter is dealt with.
This is how businesses like yours are being attacked right now.
I recreate these scenarios in realistic simulations, so your team recognises them when it counts instead of only understanding them after the damage is done.
Fraudsters pose as you and push accounting into an urgent, confidential bank transfer.
A supposed supplier reports a “new account number” – and the next payment goes to the attacker.
A single click paralyses your systems – production, billing and reputation come to a standstill.
This is what it looks like in practice.
Cockpit, team report, certificate and proof of training for a fictitious company with twelve people. All names and results are made up; the layout is exactly what you will see yourself later.
Groups, registered people and the cost if everyone completes. From here you start training, an initial test or a repeat run.
The team’s click and data-entry rates, a comparison with all test runs, participation in training. Anonymised.
Results at a glance and protection level with a recommendation. The PDF carries an authenticity QR code and is suitable for audits, insurers and NIS2 documentation.
Name, course, dates of training and practical test, reference to standards, signature and a verifiable certificate number with QR code.
All training carried out, with time stamps and participation rates, mapped to the requirements. Also for ISO 27001, GDPR, the AI Act and cyber insurance.
Each person sees only their own result: reaction to each test email, how the scam could have been spotted, and what their device gave away.
This is how my training works.
You want security without your own IT project and without the department you don’t have. That is exactly what my training is built for: I take the implementation off your hands, you keep the overview – and at the end there is time-stamped proof.
Three ways – you choose what suits you.
I train your team in person – on site or online, in conversation and with examples from your everyday work.
You run the training yourself: I provide the ready-made materials and you pass them on in-house – at your own pace.
Everyone learns online the way they prefer – by text or video, at their own pace, choosing the content.
Train first, then test – deliberately in that order.
-
Initial training
First I equip your team (or you do it with my materials). Everyone starts with the same basic knowledge.
-
Phishing test as a self-check
Only then does the simulated attack follow – not as an exam, but as a self-check: everyone sees whether what they learned holds up in everyday work.
-
A security culture, refreshed when needed
Training and testing grow into a constructive security culture in your business, which you simply repeat when the time comes.
Your status report is based on your team’s results after the training – it shows the level you set out to reach, not the unprotected starting point.
New team members can be added later with one click: they immediately receive the online training materials and a first self-test – and join the next joint session or training with the same prior knowledge.
The reverse order – and why I advise against it.
From a management perspective, it often seems logical to assess the situation with a test first and only then decide whether training is needed. Technically that works – I can set it up for you.
Especially as a manager, it is tempting to “put the team to the test” first. But people who are caught out before any training lose trust in their leadership – and you are left with a snapshot that makes nobody better. A test without prior training only measures the starting point at zero. My approach turns this around: equip first, then check.
No subscription, as and when you need it, and always with my personal support.
The AI literacy duty sits with management.
Since February 2025, every business that uses AI tools has to ensure its staff have sufficient AI literacy. That is an organisational duty of management. With my course, a certificate per person and the company-wide proof of training, it takes one hour per person and is documented.
- Required under Art. 4 of the EU AI Act, regardless of company size
- Company-wide proof for insurers, clients and supervisory authorities
- Model AI policy, so it is clear which tools are allowed
For your responsibility.
What law, standards and insurance require of you – and what this covers.
Standards comparison →ISO 27001, NIS2, GDPR and cyber insurance in an honest target-versus-actual comparison.
Proof in the Cockpit →How the audit-proof, time-stamped proof of training is created automatically.
Frequently asked questions
Is this a subscription?
What does it cost?
Does the effect of a one-off training actually last?
Do I need an IT department for this?
How does training with you work?
Will anyone on our team be singled out or monitored?
Does this cover GDPR, NIS2, ISO 27001 or insurance requirements?
What happens when staff change?
Do I get proof of training or a certificate?
Does this also cover AI fraud and deepfakes?
Are schools and non-profit associations really free of charge?
How quickly can I start?
Your question is not listed?
Ask me directly. You only need to give an email address if you want to receive my answer.
Set up in an hour – no IT department needed.
Choose a course, add your team, get started. Proof of training is generated automatically along the way.