Proof of training for cyber insurance

Your insurer is asking for proof of training. Here it is.

Every risk questionnaire for a cyber policy has the line “Are all employees regularly trained on phishing, and is this documented?”. I provide the training, the phishing test and the time-stamped proof of training that you pass on to your broker or underwriter. No subscription, set up in ten minutes.

Example scene for Businesses with cyber insurance
“The broker needs proof by Friday, otherwise the policy stalls.”
“We have the policy, but in the event of a claim the insurer wants to see evidence.”
“The premium goes up if we tick “no”.”
Add your team See prices
Your obligations

What you have to do – and what this lets you tick off.

Your insurer’s terms are what count; the GDV (German Insurance Association) model conditions and the common questionnaires consistently require documented training. Each point states openly whether I cover it, partly support it or whether it lies with your IT – linked to the matching attack scenario.

✓ covered
Regular, verifiable phishing awareness for employees. · Policy obligation
↳ covers: Training + test

Course, phishing test and proof of training in one run; the Cockpit reminds you of the repeat after twelve months automatically.

✓ covered
Awareness training as part of the ISMS. · ISO/IEC 27001 Annex A.6.3
↳ covers: Certificate

The certificate explicitly states its alignment with A.6.3, so the auditor doesn’t have to make the mapping themselves.

✓ covered
Information security awareness and training. · BSI IT-Grundschutz ORP.3
↳ covers: Certificate

Content and proof of training are based on ORP.3 of the BSI (Germany’s Federal Office for Information Security); the module is listed on the evidence sheet.

– your IT
Minimum technical measures (MFA, backups, updates, antivirus). · Policy obligation

Not part of awareness training. This stays with you or your IT service provider.

You will find the full comparison with ISO 27001, NIS2 and cyber insurance under Obligations & standards. Businesses generate their time-stamped proof of training directly in the Cockpit.

The questionnaire

What Hiscox, HDI, AXA and Allianz ask – and what you answer.

The questionnaires differ in wording, not in substance. These five questions appear in almost every application. On the right is how you back up your answer.

Question in the questionnaireYour answer after the programmeEvidence
Are all employees regularly trained on IT security and phishing? Yes. Every person completes the awareness course; an annual repeat is planned at €22 per person. Certificate of participation per person, evidence sheet per business
Is the training documented (participants, date, content)? Yes. Every completion is logged with date, time and course content. Time-stamped proof-of-training PDF from the Cockpit
Are phishing simulations carried out and evaluated? Yes. The training is followed by an announced phishing test, evaluated as a team rate. Team report (anonymised), test run log
Is there a procedure for reporting suspicious emails? Yes. Reporting is part of the training; the reporting route is defined for each business. Course content “Recognise and report”, lesson record
Is the certificate genuine and verifiable? Yes. Every certificate carries a number and a QR code; the underwriter checks its authenticity themselves. Public authenticity check at /zertifikat-pruefen

Technical questions (MFA, backups, patch level, antivirus) are not covered by this proof. They remain with you or your IT service provider, and I mark this on the proof of training as well.

Examples

This is what it looks like in practice.

Cockpit, team report, certificate and proof of training for a fictitious company with twelve people. All names and results are made up; the layout is exactly what you will see yourself later.

Cockpit The business Cockpit

Groups, registered people and the cost if everyone completes. From here you start training, an initial test or a repeat run.

Team report Team report in the Cockpit

The team’s click and data-entry rates, a comparison with all test runs, participation in training. Anonymised.

Team report Evidence PDF, page 1

Results at a glance and protection level with a recommendation. The PDF carries an authenticity QR code and is suitable for audits, insurers and NIS2 documentation.

Certificate Certificate of participation

Name, course, dates of training and practical test, reference to standards, signature and a verifiable certificate number with QR code.

Compliance evidence NIS2 compliance evidence

All training carried out, with time stamps and participation rates, mapped to the requirements. Also for ISO 27001, GDPR, the AI Act and cyber insurance.

Individual report Personal report

Each person sees only their own result: reaction to each test email, how the scam could have been spotted, and what their device gave away.

All example views

How I work with you

This is how my training works.

You usually need the proof under time pressure. That’s why the path is short: add your team, unlock the training, the phishing test runs, the proof is in the Cockpit. For twenty people, it’s done within a week.

Three ways – you choose what suits you.

1 In person, by me

I train your team in person – on site or online, in conversation and with examples from your everyday work.

2 In-house with my materials

You run the training yourself: I provide the ready-made materials and you pass them on in-house – at your own pace.

3 Everyone online on their own

Everyone learns online the way they prefer – by text or video, at their own pace, choosing the content.

My recommendation

Train first, then test – deliberately in that order.

  1. Initial training

    First I equip your team (or you do it with my materials). Everyone starts with the same basic knowledge.

  2. Phishing test as a self-check

    Only then does the simulated attack follow – not as an exam, but as a self-check: everyone sees whether what they learned holds up in everyday work.

  3. A security culture, refreshed when needed

    Training and testing grow into a constructive security culture in your business, which you simply repeat when the time comes.

📊

Your status report is based on your team’s results after the training – it shows the level you set out to reach, not the unprotected starting point.

➕

New team members can be added later with one click: they immediately receive the online training materials and a first self-test – and join the next joint session or training with the same prior knowledge.

The reverse order – and why I advise against it.

From a management perspective, it often seems logical to assess the situation with a test first and only then decide whether training is needed. Technically that works – I can set it up for you.

A phishing test alone without training produces a rate, but no proof of training – and that is exactly what the insurer wants. Train first, then test, and you get both. A test without prior training only measures the starting point at zero. My approach turns this around: equip first, then check.

No subscription, as and when you need it, and always with my personal support.

FAQ

Frequently asked questions

Will my insurer accept the certificate?
The certificate shows who completed which course with a phishing test and when, and is explicitly based on ISO/IEC 27001 A.6.3 and BSI IT-Grundschutz ORP.3 (BSI: Germany’s Federal Office for Information Security). The usual questionnaires ask for exactly that: documented, regular training. Whether an individual insurer has additional requirements is stated in its terms; if in doubt, ask your broker before booking and show them the authenticity check.
How quickly will I have the proof of training?
Setup in ten minutes, training about an hour per person, phishing test within a few days. For a team of twenty people, the proof of training is typically in the Cockpit after one week.
Is a phishing test alone enough for the insurer?
No. The questionnaire asks for training with documentation. A test alone produces a click rate, but no proof of training. That’s why training and test always come as a package with me.
What about the annual repeat?
Insurers expect regular training, usually annual. After eleven months the Cockpit reminds you of the repeat; it costs €22 per person and produces new proof of training with a new date.
Is this a subscription?
No. There is no subscription and no contract term. You book training and tests as you need them – once or on a recurring basis, whatever suits you.
What does it cost?
For businesses, €49 net per person, one-off: training, first phishing test run, team report, Cockpit and six months of monthly refreshers. Further test runs cost €22 per person. For individuals, the training with certificate costs €29 incl. VAT, but without team report, Cockpit and refreshers, hence the lower price. An initial conversation and the self-tests are free. Compare all services on the pricing page →
Does the effect of a one-off training actually last?
Not on its own, which is why I don’t stop at the certificate. Everyone who completes the course receives a short interactive lesson by email every calendar month for six months: under five minutes, no login, a different current topic each time. Keeping it short is deliberate; the effect comes from spreading it over time. In the Cockpit you see your teams’ completion rate and the average score. This refresher is included in the business price at no extra cost.
Do I need an IT department for this?
No. Setup takes about an hour: choose a course, add your team, get started. The proof of training is created automatically. If you like, I’ll set it up together with you.
How does training with you work?
However you prefer: I train your team in person (on site or online), you run the training yourself with my ready-made materials, or each person learns online at their own pace. My recommendation: train first, then run the phishing test as a self-check – that builds a security culture instead of putting people on the spot.
Will anyone on our team be singled out or monitored?
No. There is no public shaming and no personal “who clicked” list for senior management. The team is evaluated as a whole. A wrong click is a learning moment, not an entry in someone’s personnel file.
Does this cover GDPR, NIS2, ISO 27001 or insurance requirements?
It covers the awareness and training part of these obligations – including proof of training with a timestamp. I state openly what belongs to your technology/IT. You’ll find the full comparison under “Obligations & standards”.
What happens when staff change?
You add new team members later with a click: they immediately receive the online training materials and a first self-test, and join the next joint training with the same level of knowledge.
Do I get proof of training or a certificate?
Yes. Proof of participation and completion with date and timestamp is created automatically for each person – as audit-proof evidence for audits, insurers or your own documentation.
Does this also cover AI fraud and deepfakes?
Yes. Current tactics such as AI-assisted phishing, fake voices and deepfakes are part of the courses and simulations – in line with the AI literacy requirement of the EU AI Act.
Are schools and non-profit associations really free of charge?
Yes. For schools and non-profit associations the offer is free of charge – this matters to me personally.
How quickly can I start?
Right away and without a call, if you like: you register your business or institution yourself at /registrieren, add your team, choose the course and phishing templates and start the test run – all on your own in the Cockpit, set up in about an hour. To get a feel for it, there are the free self-tests. And if you’d rather have support, just send me a short message; I’ll get back to you personally.

Your question is not listed?

Ask me directly. You only need to give an email address if you want to receive my answer.

A quick confirmation that a human is typing here, not a bot.

The proof – before the broker asks.

Add your team, start the training, proof in the Cockpit. €49 per person, one-off.

Add your team View prices

Set up in an hour, trained in a week.

Create a free account, add your team, unlock the course. You only pay when you start. Would you rather see what a test email looks like first? The self-test is free.

Add your team Test it yourself first