Set it up once. Then it runs.
You add your team, and everything else happens automatically: course invitations, reminders, the test runs and the evaluation.
From setup to refresher.
Setup
once, a few minutes
Add your team
YouAt least three people, all with addresses on your company domain. From three people upwards, no conclusions can be drawn about individuals.
Choose a course and three phishing scenarios
YouFor example “Office Awareness with Phishing Training”, “Using AI safely at work” or both as the Worry-Free Set, plus exactly three email templates for the test later on.
Start the training
runs for 4 weeksFrom here on, everything runs by itself.
Invitation by email
AutomaticEach person receives their personal access. Anyone who doesn’t start gets a reminder: after 3 days, then every 4 days, three times at most.
Introduction and choice of learning path
Your teamFirst a short introduction to what it is about. Then each person chooses:
Short & sweet
Quiz12 questions from all chapters; after each question the answer with an explanation and a link to the relevant chapter.
In depth
full courseAll chapters as video or text. Two short questions beforehand highlight personal focus areas.
Both routes lead to the same completion.
Course completed
Your teamOn completion, part 2 begins for that person.
Three simulated attacks
AutomaticUnannounced, at random times, each email crafted differently and using real names from the team. We measure: opened, clicked, data entered.
Anyone who falls for it learns on the spot
Your teamInstead of a login page, “Stop, this was an exercise” appears, along with the signs that would have given the email away. Entered passwords are never stored.
Personal report
Your teamEach person sees their own reaction to every test email, with an explanation. This result goes to them alone.
Anonymised team report
YouCompletion rate, overall rating and trend over several runs, live in the Cockpit and as a time-stamped PDF. Nobody is singled out.
Certificate of participation
AutomaticFor every person who has completed the course and the practical test, with a QR code to verify authenticity. The proof for audits, cyber insurance and NIS2. What it shows ↓
Completion and invoice
AutomaticOnce everyone has finished or the runtime is over, the run ends. The invoice arrives by email, with a QR code for the bank transfer. The results remain available in the Cockpit.
A micro-lesson every month
under 5 minBy email, no login, right in the browser. Random topics per person, no repeats. In the Cockpit you see your teams’ completion rate.
The awareness training
Each person completes the online course at their own pace, as video or as a text version to read. Using real examples from my practice, the course explains how attacks unfold and how to spot them.
No jargon and no abstract rules, but concrete questions: What does a forged sender address look like? How do you spot a manipulated link target? What do you do if you have clicked after all?
The last point matters most: a team that dares to report a wrong click straight away limits the damage. A team that is afraid of trouble stays silent, and that is exactly how an incident happens.
Course content
- Which threats exist and how they work
- How attackers operate and what they want to achieve
- Types of malware, especially ransomware
- Handling emails and websites safely
- Warning signs, shown with concrete examples
- What to do after a wrong click
AI security is included
AI fakes are the big topic right now, so they belong in every training. The course “Using AI safely at work” is included, with short interactive quiz questions in every lesson:
- Recognising deepfakes & voice cloning
- CEO fraud & vishing and the call-back rule that stops them
- Prompt injection: when outside content takes control of the AI
- Responsible use of AI prompts (what may go in)
- Using AI agents in office software (Copilot & co.) safely
- Checking results: responsibility stays with people
For school classes the topics are available in a child-friendly version, including “Fact check: real or AI fake?”.
How testing works
- Three simulated attacks per person
- Within five working days of completing the course
- Random timing, different styles
- Measured: opened, clicked, data entered
- Entered passwords are never stored
The test under real conditions
After the course, the exercise begins. The simulated emails arrive unannounced and look like real attacks, because a test you can see coming measures nothing.
Important: this is not about catching anyone out. It is about training the reflex to pause for a moment in everyday work. Anyone who falls for it once in a safe setting remembers it far longer than any slide.
Reports and live Cockpit
In the Cockpit you always see where things stand: who has completed the course, how many tests have run and how the team performs overall.
Separated by recipient: the business only receives the team report in anonymised form. The individual result goes only to the person concerned. Nobody is singled out in front of their colleagues.
The history shows you, across several rounds, whether resilience is actually improving.
For the business
Anonymised team report with overall rating, trend over several runs and course completion rate.
For the individual
Personal report: own reaction to each test email, explanation of the warning signs, assessment of the result.
The certificate of participation
Everyone who has completed the course and a test run receives a personalised certificate of participation, based on ISO/IEC 27001 A.6.3 and the BSI IT-Grundschutz module ORP.3 (BSI: Germany’s Federal Office for Information Security), and verifiable online.
For HR and data protection officers, this is the proof required in audits and under the NIS2 training obligation. It is produced automatically, without anyone having to keep lists.
What the certificate shows
- Name of the participant
- Training content completed
- Date of completion
- Confirmation of the completed practical test
This is what it looks like in practice.
Cockpit, team report, certificate and proof of training for a fictitious company with twelve people. All names and results are made up; the layout is exactly what you will see yourself later.
Groups, registered people and the cost if everyone completes. From here you start training, an initial test or a repeat run.
The team’s click and data-entry rates, a comparison with all test runs, participation in training. Anonymised.
Results at a glance and protection level with a recommendation. The PDF carries an authenticity QR code and is suitable for audits, insurers and NIS2 documentation.
Name, course, dates of training and practical test, reference to standards, signature and a verifiable certificate number with QR code.
All training carried out, with time stamps and participation rates, mapped to the requirements. Also for ISO 27001, GDPR, the AI Act and cyber insurance.
Each person sees only their own result: reaction to each test email, how the scam could have been spotted, and what their device gave away.
Six months of refreshers
The certificate fulfils the obligation, but the effect is not yet secured. That is why the training continues after completion: for six months, each person receives a short interactive lesson by email every calendar month. No login, right in the browser.
Less than five minutes per unit, and that is deliberate. A micro-lesson should fit between two appointments, not be one itself. What works is not length but spacing: six short touchpoints over half a year stick better than one long block that is sat through once and then forgotten.
Topics are chosen at random for each person and never repeat, and each person is contacted at a different time of the month. I keep adding new scams and removing outdated content.
In the Cockpit you see your teams’ completion rate and the average score. This shows that awareness is an ongoing effort in your business, not a once-a-year event.
What the micro-lessons look like
- Rate emails: phishing or genuine?
- Judge situations: safe or unsafe?
- A phone call, played through sentence by sentence
- Report or not?
- Using AI safely: what may go into the chat?
- Immediate answer with an explanation after each response
- Under five minutes per unit, around twenty minutes in total over six months
Frequently asked questions
Is this a subscription?
What does it cost?
Does the effect of a one-off training actually last?
Do I need an IT department for this?
How does training with you work?
Will anyone on our team be singled out or monitored?
Does this cover GDPR, NIS2, ISO 27001 or insurance requirements?
What happens when staff change?
Do I get proof of training or a certificate?
Does this also cover AI fraud and deepfakes?
Are schools and non-profit associations really free of charge?
How quickly can I start?
Your question is not listed?
Ask me directly. You only need to give an email address if you want to receive my answer.