How it works

Set it up once. Then it runs.

You add your team, and everything else happens automatically: course invitations, reminders, the test runs and the evaluation.

At a glance

From setup to refresher.

You in the Cockpit Your team every participant Automatic runs without your involvement
Start

Setup

once, a few minutes

Add your team

You

At least three people, all with addresses on your company domain. From three people upwards, no conclusions can be drawn about individuals.

Choose a course and three phishing scenarios

You

For example “Office Awareness with Phishing Training”, “Using AI safely at work” or both as the Worry-Free Set, plus exactly three email templates for the test later on.

Start the training

runs for 4 weeks

From here on, everything runs by itself.

Part 1

Training

at their own pace

More ↓

Invitation by email

Automatic

Each person receives their personal access. Anyone who doesn’t start gets a reminder: after 3 days, then every 4 days, three times at most.

Introduction and choice of learning path

Your team

First a short introduction to what it is about. Then each person chooses:

Short & sweet

Quiz

12 questions from all chapters; after each question the answer with an explanation and a link to the relevant chapter.

In depth

full course

All chapters as video or text. Two short questions beforehand highlight personal focus areas.

Both routes lead to the same completion.

Course completed

Your team

On completion, part 2 begins for that person.

Part 2

Practical test

5 working days after completing the course

More ↓

Three simulated attacks

Automatic

Unannounced, at random times, each email crafted differently and using real names from the team. We measure: opened, clicked, data entered.

Anyone who falls for it learns on the spot

Your team

Instead of a login page, “Stop, this was an exercise” appears, along with the signs that would have given the email away. Entered passwords are never stored.

Result

Report and proof

any time in the Cockpit

More ↓

Personal report

Your team

Each person sees their own reaction to every test email, with an explanation. This result goes to them alone.

Anonymised team report

You

Completion rate, overall rating and trend over several runs, live in the Cockpit and as a time-stamped PDF. Nobody is singled out.

Certificate of participation

Automatic

For every person who has completed the course and the practical test, with a QR code to verify authenticity. The proof for audits, cyber insurance and NIS2. What it shows ↓

Completion and invoice

Automatic

Once everyone has finished or the runtime is over, the run ends. The invoice arrives by email, with a QR code for the bank transfer. The results remain available in the Cockpit.

Afterwards

Refresher

6 months

More ↓

A micro-lesson every month

under 5 min

By email, no login, right in the browser. Random topics per person, no repeats. In the Cockpit you see your teams’ completion rate.

Step 1

The awareness training

Each person completes the online course at their own pace, as video or as a text version to read. Using real examples from my practice, the course explains how attacks unfold and how to spot them.

No jargon and no abstract rules, but concrete questions: What does a forged sender address look like? How do you spot a manipulated link target? What do you do if you have clicked after all?

The last point matters most: a team that dares to report a wrong click straight away limits the damage. A team that is afraid of trouble stays silent, and that is exactly how an incident happens.

Course content

  • Which threats exist and how they work
  • How attackers operate and what they want to achieve
  • Types of malware, especially ransomware
  • Handling emails and websites safely
  • Warning signs, shown with concrete examples
  • What to do after a wrong click
New & included

AI security is included

AI fakes are the big topic right now, so they belong in every training. The course “Using AI safely at work” is included, with short interactive quiz questions in every lesson:

  • Recognising deepfakes & voice cloning
  • CEO fraud & vishing and the call-back rule that stops them
  • Prompt injection: when outside content takes control of the AI
  • Responsible use of AI prompts (what may go in)
  • Using AI agents in office software (Copilot & co.) safely
  • Checking results: responsibility stays with people

For school classes the topics are available in a child-friendly version, including “Fact check: real or AI fake?”.

How testing works

  • Three simulated attacks per person
  • Within five working days of completing the course
  • Random timing, different styles
  • Measured: opened, clicked, data entered
  • Entered passwords are never stored
Step 2

The test under real conditions

After the course, the exercise begins. The simulated emails arrive unannounced and look like real attacks, because a test you can see coming measures nothing.

Important: this is not about catching anyone out. It is about training the reflex to pause for a moment in everyday work. Anyone who falls for it once in a safe setting remembers it far longer than any slide.

Step 3

Reports and live Cockpit

In the Cockpit you always see where things stand: who has completed the course, how many tests have run and how the team performs overall.

Separated by recipient: the business only receives the team report in anonymised form. The individual result goes only to the person concerned. Nobody is singled out in front of their colleagues.

The history shows you, across several rounds, whether resilience is actually improving.

For the business

Anonymised team report with overall rating, trend over several runs and course completion rate.

For the individual

Personal report: own reaction to each test email, explanation of the warning signs, assessment of the result.

Step 4

The certificate of participation

Everyone who has completed the course and a test run receives a personalised certificate of participation, based on ISO/IEC 27001 A.6.3 and the BSI IT-Grundschutz module ORP.3 (BSI: Germany’s Federal Office for Information Security), and verifiable online.

For HR and data protection officers, this is the proof required in audits and under the NIS2 training obligation. It is produced automatically, without anyone having to keep lists.

What NIS2 actually requires

What the certificate shows

  • Name of the participant
  • Training content completed
  • Date of completion
  • Confirmation of the completed practical test
Examples

This is what it looks like in practice.

Cockpit, team report, certificate and proof of training for a fictitious company with twelve people. All names and results are made up; the layout is exactly what you will see yourself later.

Cockpit The business Cockpit

Groups, registered people and the cost if everyone completes. From here you start training, an initial test or a repeat run.

Team report Team report in the Cockpit

The team’s click and data-entry rates, a comparison with all test runs, participation in training. Anonymised.

Team report Evidence PDF, page 1

Results at a glance and protection level with a recommendation. The PDF carries an authenticity QR code and is suitable for audits, insurers and NIS2 documentation.

Certificate Certificate of participation

Name, course, dates of training and practical test, reference to standards, signature and a verifiable certificate number with QR code.

Compliance evidence NIS2 compliance evidence

All training carried out, with time stamps and participation rates, mapped to the requirements. Also for ISO 27001, GDPR, the AI Act and cyber insurance.

Individual report Personal report

Each person sees only their own result: reaction to each test email, how the scam could have been spotted, and what their device gave away.

All example views

Step 5

Six months of refreshers

The certificate fulfils the obligation, but the effect is not yet secured. That is why the training continues after completion: for six months, each person receives a short interactive lesson by email every calendar month. No login, right in the browser.

Less than five minutes per unit, and that is deliberate. A micro-lesson should fit between two appointments, not be one itself. What works is not length but spacing: six short touchpoints over half a year stick better than one long block that is sat through once and then forgotten.

Topics are chosen at random for each person and never repeat, and each person is contacted at a different time of the month. I keep adding new scams and removing outdated content.

In the Cockpit you see your teams’ completion rate and the average score. This shows that awareness is an ongoing effort in your business, not a once-a-year event.

What exactly is included

What the micro-lessons look like

  • Rate emails: phishing or genuine?
  • Judge situations: safe or unsafe?
  • A phone call, played through sentence by sentence
  • Report or not?
  • Using AI safely: what may go into the chat?
  • Immediate answer with an explanation after each response
  • Under five minutes per unit, around twenty minutes in total over six months
FAQ

Frequently asked questions

Is this a subscription?
No. There is no subscription and no contract term. You book training and tests as you need them – once or on a recurring basis, whatever suits you.
What does it cost?
For businesses, €49 net per person, one-off: training, first phishing test run, team report, Cockpit and six months of monthly refreshers. Further test runs cost €22 per person. For individuals, the training with certificate costs €29 incl. VAT, but without team report, Cockpit and refreshers, hence the lower price. An initial conversation and the self-tests are free. Compare all services on the pricing page →
Does the effect of a one-off training actually last?
Not on its own, which is why I don’t stop at the certificate. Everyone who completes the course receives a short interactive lesson by email every calendar month for six months: under five minutes, no login, a different current topic each time. Keeping it short is deliberate; the effect comes from spreading it over time. In the Cockpit you see your teams’ completion rate and the average score. This refresher is included in the business price at no extra cost.
Do I need an IT department for this?
No. Setup takes about an hour: choose a course, add your team, get started. The proof of training is created automatically. If you like, I’ll set it up together with you.
How does training with you work?
However you prefer: I train your team in person (on site or online), you run the training yourself with my ready-made materials, or each person learns online at their own pace. My recommendation: train first, then run the phishing test as a self-check – that builds a security culture instead of putting people on the spot.
Will anyone on our team be singled out or monitored?
No. There is no public shaming and no personal “who clicked” list for senior management. The team is evaluated as a whole. A wrong click is a learning moment, not an entry in someone’s personnel file.
Does this cover GDPR, NIS2, ISO 27001 or insurance requirements?
It covers the awareness and training part of these obligations – including proof of training with a timestamp. I state openly what belongs to your technology/IT. You’ll find the full comparison under “Obligations & standards”.
What happens when staff change?
You add new team members later with a click: they immediately receive the online training materials and a first self-test, and join the next joint training with the same level of knowledge.
Do I get proof of training or a certificate?
Yes. Proof of participation and completion with date and timestamp is created automatically for each person – as audit-proof evidence for audits, insurers or your own documentation.
Does this also cover AI fraud and deepfakes?
Yes. Current tactics such as AI-assisted phishing, fake voices and deepfakes are part of the courses and simulations – in line with the AI literacy requirement of the EU AI Act.
Are schools and non-profit associations really free of charge?
Yes. For schools and non-profit associations the offer is free of charge – this matters to me personally.
How quickly can I start?
Right away and without a call, if you like: you register your business or institution yourself at /registrieren, add your team, choose the course and phishing templates and start the test run – all on your own in the Cockpit, set up in about an hour. To get a feel for it, there are the free self-tests. And if you’d rather have support, just send me a short message; I’ll get back to you personally.

Your question is not listed?

Ask me directly. You only need to give an email address if you want to receive my answer.

A quick confirmation that a human is typing here, not a bot.

Set up in an hour, trained in a week.

Create a free account, add your team, unlock the course. You only pay when you start. Would you rather see what a test email looks like first? The self-test is free.

Add your team Test it yourself first