Your insurer is asking for proof of training. Here it is.
Every risk questionnaire for a cyber policy has the line “Are all employees regularly trained on phishing, and is this documented?”. I provide the training, the phishing test and the time-stamped proof of training that you pass on to your broker or underwriter. No subscription, set up in ten minutes.
What you have to do – and what this lets you tick off.
Your insurer’s terms are what count; the GDV (German Insurance Association) model conditions and the common questionnaires consistently require documented training. Each point states openly whether I cover it, partly support it or whether it lies with your IT – linked to the matching attack scenario.
Course, phishing test and proof of training in one run; the Cockpit reminds you of the repeat after twelve months automatically.
The certificate explicitly states its alignment with A.6.3, so the auditor doesn’t have to make the mapping themselves.
Content and proof of training are based on ORP.3 of the BSI (Germany’s Federal Office for Information Security); the module is listed on the evidence sheet.
Not part of awareness training. This stays with you or your IT service provider.
You will find the full comparison with ISO 27001, NIS2 and cyber insurance under Obligations & standards. Businesses generate their time-stamped proof of training directly in the Cockpit.
What Hiscox, HDI, AXA and Allianz ask – and what you answer.
The questionnaires differ in wording, not in substance. These five questions appear in almost every application. On the right is how you back up your answer.
| Question in the questionnaire | Your answer after the programme | Evidence |
|---|---|---|
| Are all employees regularly trained on IT security and phishing? | Yes. Every person completes the awareness course; an annual repeat is planned at €22 per person. | Certificate of participation per person, evidence sheet per business |
| Is the training documented (participants, date, content)? | Yes. Every completion is logged with date, time and course content. | Time-stamped proof-of-training PDF from the Cockpit |
| Are phishing simulations carried out and evaluated? | Yes. The training is followed by an announced phishing test, evaluated as a team rate. | Team report (anonymised), test run log |
| Is there a procedure for reporting suspicious emails? | Yes. Reporting is part of the training; the reporting route is defined for each business. | Course content “Recognise and report”, lesson record |
| Is the certificate genuine and verifiable? | Yes. Every certificate carries a number and a QR code; the underwriter checks its authenticity themselves. | Public authenticity check at /zertifikat-pruefen |
Technical questions (MFA, backups, patch level, antivirus) are not covered by this proof. They remain with you or your IT service provider, and I mark this on the proof of training as well.
Three documents created automatically after the run.
You don’t have to write any of them yourself. After the last completion in the team, the documents are in the Cockpit.
How an underwriter checks in ten seconds whether a submitted certificate is genuine.
📋 Obligations check: cyber insuranceWhich policy obligations the run covers, and which remain with your IT.
💶 Prices without subscription€49 per person, one-off; repeat €22. No minimum order, no sales call.
This is what it looks like in practice.
Cockpit, team report, certificate and proof of training for a fictitious company with twelve people. All names and results are made up; the layout is exactly what you will see yourself later.
Groups, registered people and the cost if everyone completes. From here you start training, an initial test or a repeat run.
The team’s click and data-entry rates, a comparison with all test runs, participation in training. Anonymised.
Results at a glance and protection level with a recommendation. The PDF carries an authenticity QR code and is suitable for audits, insurers and NIS2 documentation.
Name, course, dates of training and practical test, reference to standards, signature and a verifiable certificate number with QR code.
All training carried out, with time stamps and participation rates, mapped to the requirements. Also for ISO 27001, GDPR, the AI Act and cyber insurance.
Each person sees only their own result: reaction to each test email, how the scam could have been spotted, and what their device gave away.
This is how my training works.
You usually need the proof under time pressure. That’s why the path is short: add your team, unlock the training, the phishing test runs, the proof is in the Cockpit. For twenty people, it’s done within a week.
Three ways – you choose what suits you.
I train your team in person – on site or online, in conversation and with examples from your everyday work.
You run the training yourself: I provide the ready-made materials and you pass them on in-house – at your own pace.
Everyone learns online the way they prefer – by text or video, at their own pace, choosing the content.
Train first, then test – deliberately in that order.
-
Initial training
First I equip your team (or you do it with my materials). Everyone starts with the same basic knowledge.
-
Phishing test as a self-check
Only then does the simulated attack follow – not as an exam, but as a self-check: everyone sees whether what they learned holds up in everyday work.
-
A security culture, refreshed when needed
Training and testing grow into a constructive security culture in your business, which you simply repeat when the time comes.
Your status report is based on your team’s results after the training – it shows the level you set out to reach, not the unprotected starting point.
New team members can be added later with one click: they immediately receive the online training materials and a first self-test – and join the next joint session or training with the same prior knowledge.
The reverse order – and why I advise against it.
From a management perspective, it often seems logical to assess the situation with a test first and only then decide whether training is needed. Technically that works – I can set it up for you.
A phishing test alone without training produces a rate, but no proof of training – and that is exactly what the insurer wants. Train first, then test, and you get both. A test without prior training only measures the starting point at zero. My approach turns this around: equip first, then check.
No subscription, as and when you need it, and always with my personal support.
For your broker.
Frequently asked questions
Will my insurer accept the certificate?
How quickly will I have the proof of training?
Is a phishing test alone enough for the insurer?
What about the annual repeat?
Is this a subscription?
What does it cost?
Does the effect of a one-off training actually last?
Do I need an IT department for this?
How does training with you work?
Will anyone on our team be singled out or monitored?
Does this cover GDPR, NIS2, ISO 27001 or insurance requirements?
What happens when staff change?
Do I get proof of training or a certificate?
Does this also cover AI fraud and deepfakes?
Are schools and non-profit associations really free of charge?
How quickly can I start?
Your question is not listed?
Ask me directly. You only need to give an email address if you want to receive my answer.
The proof – before the broker asks.
Add your team, start the training, proof in the Cockpit. €49 per person, one-off.