Reduce human risk measurably

Phishing remains the most common entry point into corporate networks. Our Security Awareness and Phishing Simulation service equips your employees to recognise attacks, report them correctly and react properly when in doubt.

We combine realistic simulation campaigns with interactive training — GDPR-compliant, without singling out individuals, and evaluated at group level.

Baseline campaign

The first simulation delivers click and report rates as your starting point.

Role-based training

Short learning units for business teams, executives and IT.

Evidence for audits

Reports and participation rates for NIS2, DORA and ISO 27001.

What we deliver

Phishing simulation

Realistic email campaigns — optionally including smishing and QR-code scenarios, tailored to your industry.

Spear-phishing scenarios

Targeted scenarios for exposed roles such as management, finance and procurement, including CEO-fraud patterns.

Awareness training

Interactive modules in English and German, kept short and delivered right after a simulation.

Reporting reflex

We establish the “report instead of delete” habit and connect reports cleanly to your SOC or incident response process.

Reporting & KPIs

Click rate, report rate, repeat-clicker rate and trend over time — per department, without individual rankings.

Executive briefing

Management summary with risk assessment and concrete recommendations for the next programme year.

How an awareness programme runs

01

Scoping

Define target groups, scenarios, schedule and the data protection framework together.

02

Baseline

A first simulation campaign provides reliable starting values.

03

Training

Targeted content for the groups with the greatest need.

04

Repeat

Recurring campaigns show progress and keep the topic present.

Evaluations are made at group level in line with data protection rules. The goal is not to test individuals but to raise the protection level of the organization.

Works well together with

Awareness works best inside a defended environment: reported phishing mails go straight to analysts who verify and classify them.

Managed SOC

Reported mails are verified and classified in 24x7 monitoring.

Red Teaming

Social engineering as part of full attack simulations.

Consulting

Embedding awareness into your security programme and compliance evidence.

Next step: baseline campaign

We align scenarios and the data protection framework with you and deliver a concrete training plan after the first campaign.

General enquiries: +49 6109 500 324 1
Email: [email protected]

Request an awareness programme

Frequently asked questions

Answers to the questions our customers ask most often.

How often should phishing simulations run?
After a baseline campaign we recommend continuous simulations every four to eight weeks with varying scenarios.
Are employees exposed or blamed?
No. Reporting is aggregated and privacy-compliant; the goal is learning, not punishment. Works council and GDPR requirements are addressed early.
Does awareness training support NIS2?
Yes. NIS2 requires regular cyber hygiene training — our campaigns provide audit evidence.
What topics are covered?
Phishing and social engineering, safe handling of data and passwords, reporting paths for suspicious cases and role-specific modules.

Question not answered here? Ask us