Deutsch

Packages & Subscriptions

Security Awareness Training Plus

The most expensive attacks of recent years rarely began with an unknown vulnerability. They began with an email somebody opened. Security Awareness Training Plus starts exactly there — not with one mandatory session a year, but with a programme that runs for twelve months.

01

The problem

Why the annual mandatory session changes nothing

The usual approach is quickly described: once a year an e-learning module, forty minutes, a multiple-choice questionnaire at the end. Attendance is a hundred per cent, the documentation is clean, the audit is satisfied.

Nothing has changed. Someone who learned in January what a forged invoice looks like will not recognise one in September — if only because the forgery looks different by then. Security awareness is not knowledge you acquire once. It is a behaviour, and behaviour comes from repetition, from practice under realistic conditions, and from feedback at the moment of the mistake.

That is why our programme is not built as a course but as an operation: small units at short intervals, real simulations instead of illustrations, and an evaluation that shows where the gaps remain.

The dark facade of a large office building at night, hundreds of unlit windows in a strict grid. Exactly one window in the middle is brightly lit and casts its light onto the panes around it.
02

The structure

Four building blocks running all year

01

The four blocks interlock: the modules teach, the simulations test, the workshops deepen, the evaluation shows where to adjust.

02

Monthly online modules

Every month a short, interactive unit on a current topic — from the forged payment instruction to handling private devices on the company network. The modules fit between two appointments and are adapted continuously to the actual threat picture, not to a syllabus written two years ago.

03

Quarterly phishing simulations

Four times a year we send messages modelled on current attack patterns — tailored to your organisation, with plausible senders and pretexts. Anyone who clicks gets no reprimand but an immediate explanation of how the forgery could have been spotted. The difficulty rises with the detection rate.

04

Half-yearly workshops on site

Twice a year our people come to you. In the group you practise what a screen cannot teach: the call supposedly from accounting; the visitor without an appointment; the question of who is told, and when. The content follows your industry — a law firm has different entry points than a machine builder.

05

Progress you can see

You can see at any time where your organisation stands: detection rates per department, development over time, topics with recurring weaknesses. The reports are written for two audiences — one version for IT security, one for the board, both from the same data.

The process

From the first conversation to running operation

It usually takes three to four weeks to the first module. After that the programme runs without you having to administer it.

  1. 01

    Needs analysis — we establish the level of knowledge and the entry points that actually matter for your organisation. Without this step you train past reality.

  2. 02

    Tailoring — the analysis becomes a plan

    which topics, in which order, for which roles. Accounting needs different content than engineering.

  3. 03

    Setup — the platform is configured, your administrators briefed, the connection to your directory established.

  4. 04

    Running operation — a new module every month, without anyone at your end having to remember it.

  5. 05

    Practice — the quarterly phishing simulation, evaluated by department and role.

  6. 06

    Deepening — the half-yearly on-site workshop, covering the topics the evaluation suggested.

  7. 07

    Adjustment — once a year we review the development together and adapt the plan for the year ahead.

03

The outcome

What you can demonstrate after twelve months

The difference from a mandatory session lies not in the effort but in what you hold at the end. Instead of an attendance list you have a curve: how the detection rate changed across four simulations, which areas report reliably and which do not, and whether people report at all rather than merely not click — because a reported phishing email protects the whole organisation, an ignored one only its recipient.

That evidence is also what auditors want to see. The training obligations in ISO 27001 and NIS2 require not only that training took place but that its effectiveness is verified. That falls out of this programme as a by-product. If you want to place the result in an overall position, you will find it again in Sightadel under the governance domain.

The audience

Who the programme is for

The programme is made for organisations where security cannot be left to IT alone — because the attacks arrive in accounting, in sales and at reception.

01

Companies from around 30 employees, where a word in passing no longer reaches everyone.

02

Regulated industries with evidence obligations under NIS2, DORA or ISO 27001.

03

Organisations that have to demonstrate, after an incident, that something has changed.

04

Workplaces with high turnover, where an annual session misses half the staff.

04

In closing

People stay the entry point — or become the alarm

No programme makes a workforce infallible. But it decides what happens after somebody has clicked: whether two hours pass until someone speaks up despite fearing trouble — or two minutes, because reporting is practised and nobody is punished for it.

Those two minutes are the real return. Talk to us about the fit for your organisation; the needs analysis is without obligation.

FAQ

Frequently asked questions

How much time does this cost my staff?

About 15 minutes a month for the online module, plus half a day twice a year for the workshop. The phishing simulations cost no extra time — they run in the normal inbox.

Are results attributed to individual employees?

Not if you prefer otherwise. By default we evaluate by department and role, not by person. This is not a formality: as soon as staff fear that a click goes on record, they report incidents late or not at all — and the programme loses precisely the effect it exists for. Works council involvement is settled before the start.

What happens if someone repeatedly falls for simulations?

That person receives additional, shorter units on the topic in question — no report to their manager. Someone who clicks repeatedly has a knowledge problem, not a discipline problem.

Is this enough as evidence for ISO 27001 or NIS2?

For the part concerning training and awareness: yes. Both require not only that training happened but evidence of its effectiveness, and the evaluations provide that. The programme does not cover the remaining requirements of those standards — that is what ISMS implementation is for.

Can we start with part of the organisation?

Yes, and that is the usual route. Often an area with elevated risk starts first — accounting, procurement, the board — and the programme is extended after the first cycle.

Packages & Subscriptions

More in this area

Vulnerability Check Basic

Uncover security gaps within 48 hours. A fast overview of potential weaknesses in your IT infrastructure.

View

Red Teaming

How red teaming realistically uncovers vulnerabilities, strengthens cyber resilience and helps companies meet DORA and …

View

vCISO

An external CISO on a flexible subscription: ISO 27001 guidance, ISMS implementation, corporate security oversight, SOC…

View

External CISO

An external CISO (vCISO) strengthens your IT security strategically and flexibly — with ISO 27001 consulting, complianc…

View

ISMS Implementation

Why a strategic ISMS based on ISO/IEC 27001 is essential today. How companies reduce cyber risk and meet NIS2 requireme…

View

SOC Co-Managed

Security operations center: keep control while we handle the essentials. 24/7 monitoring and expert support for optimal…

View

Contact

Reputation takes years. Destruction takes seconds.

Talk to us before somebody else does. The first conversation is free and we reply the same business day.