Vulnerability Check Basic
Uncover security gaps within 48 hours. A fast overview of potential weaknesses in your IT infrastructure.
ViewPackages & Subscriptions
The most expensive attacks of recent years rarely began with an unknown vulnerability. They began with an email somebody opened. Security Awareness Training Plus starts exactly there — not with one mandatory session a year, but with a programme that runs for twelve months.
The problem
The usual approach is quickly described: once a year an e-learning module, forty minutes, a multiple-choice questionnaire at the end. Attendance is a hundred per cent, the documentation is clean, the audit is satisfied.
Nothing has changed. Someone who learned in January what a forged invoice looks like will not recognise one in September — if only because the forgery looks different by then. Security awareness is not knowledge you acquire once. It is a behaviour, and behaviour comes from repetition, from practice under realistic conditions, and from feedback at the moment of the mistake.
That is why our programme is not built as a course but as an operation: small units at short intervals, real simulations instead of illustrations, and an evaluation that shows where the gaps remain.

The structure
The four blocks interlock: the modules teach, the simulations test, the workshops deepen, the evaluation shows where to adjust.
Every month a short, interactive unit on a current topic — from the forged payment instruction to handling private devices on the company network. The modules fit between two appointments and are adapted continuously to the actual threat picture, not to a syllabus written two years ago.
Four times a year we send messages modelled on current attack patterns — tailored to your organisation, with plausible senders and pretexts. Anyone who clicks gets no reprimand but an immediate explanation of how the forgery could have been spotted. The difficulty rises with the detection rate.
Twice a year our people come to you. In the group you practise what a screen cannot teach: the call supposedly from accounting; the visitor without an appointment; the question of who is told, and when. The content follows your industry — a law firm has different entry points than a machine builder.
You can see at any time where your organisation stands: detection rates per department, development over time, topics with recurring weaknesses. The reports are written for two audiences — one version for IT security, one for the board, both from the same data.
The process
It usually takes three to four weeks to the first module. After that the programme runs without you having to administer it.
Needs analysis — we establish the level of knowledge and the entry points that actually matter for your organisation. Without this step you train past reality.
which topics, in which order, for which roles. Accounting needs different content than engineering.
Setup — the platform is configured, your administrators briefed, the connection to your directory established.
Running operation — a new module every month, without anyone at your end having to remember it.
Practice — the quarterly phishing simulation, evaluated by department and role.
Deepening — the half-yearly on-site workshop, covering the topics the evaluation suggested.
Adjustment — once a year we review the development together and adapt the plan for the year ahead.
The outcome
The difference from a mandatory session lies not in the effort but in what you hold at the end. Instead of an attendance list you have a curve: how the detection rate changed across four simulations, which areas report reliably and which do not, and whether people report at all rather than merely not click — because a reported phishing email protects the whole organisation, an ignored one only its recipient.
That evidence is also what auditors want to see. The training obligations in ISO 27001 and NIS2 require not only that training took place but that its effectiveness is verified. That falls out of this programme as a by-product. If you want to place the result in an overall position, you will find it again in Sightadel under the governance domain.
The audience
The programme is made for organisations where security cannot be left to IT alone — because the attacks arrive in accounting, in sales and at reception.
Companies from around 30 employees, where a word in passing no longer reaches everyone.
Regulated industries with evidence obligations under NIS2, DORA or ISO 27001.
Organisations that have to demonstrate, after an incident, that something has changed.
Workplaces with high turnover, where an annual session misses half the staff.
In closing
No programme makes a workforce infallible. But it decides what happens after somebody has clicked: whether two hours pass until someone speaks up despite fearing trouble — or two minutes, because reporting is practised and nobody is punished for it.
Those two minutes are the real return. Talk to us about the fit for your organisation; the needs analysis is without obligation.
FAQ
About 15 minutes a month for the online module, plus half a day twice a year for the workshop. The phishing simulations cost no extra time — they run in the normal inbox.
Not if you prefer otherwise. By default we evaluate by department and role, not by person. This is not a formality: as soon as staff fear that a click goes on record, they report incidents late or not at all — and the programme loses precisely the effect it exists for. Works council involvement is settled before the start.
That person receives additional, shorter units on the topic in question — no report to their manager. Someone who clicks repeatedly has a knowledge problem, not a discipline problem.
For the part concerning training and awareness: yes. Both require not only that training happened but evidence of its effectiveness, and the evaluations provide that. The programme does not cover the remaining requirements of those standards — that is what ISMS implementation is for.
Yes, and that is the usual route. Often an area with elevated risk starts first — accounting, procurement, the board — and the programme is extended after the first cycle.
Packages & Subscriptions
Uncover security gaps within 48 hours. A fast overview of potential weaknesses in your IT infrastructure.
ViewHow red teaming realistically uncovers vulnerabilities, strengthens cyber resilience and helps companies meet DORA and …
ViewAn external CISO on a flexible subscription: ISO 27001 guidance, ISMS implementation, corporate security oversight, SOC…
ViewAn external CISO (vCISO) strengthens your IT security strategically and flexibly — with ISO 27001 consulting, complianc…
ViewWhy a strategic ISMS based on ISO/IEC 27001 is essential today. How companies reduce cyber risk and meet NIS2 requireme…
ViewSecurity operations center: keep control while we handle the essentials. 24/7 monitoring and expert support for optimal…
ViewContact
Talk to us before somebody else does. The first conversation is free and we reply the same business day.