Filters stop most of it.Your team stops the rest.
Conbool Awareness rehearses the real thing before it happens. Realistic phishing simulations, short training right afterwards, and reports you can put in front of an auditor.
The remaining gap
One click is enough
Technical defences catch the bulk of it. What gets through is the well made attempt, and it lands with a person who is under time pressure.
What technology handles
MailGuard reliably removes mass waves, known senders and malicious attachments before they reach a mailbox.
What is left
Targeted messages with no attachment and no known signature. They look like ordinary work and are addressed to one specific person.
What it consists of
What Awareness covers
Practise, explain, repeat, prove.
Phishing simulation
Realistic test messages to selected groups, evaluated without singling anyone out.
- Audience freely chosen per round
- Sending spread across days, not bundled
- Evaluation by group, not by person
Training
Short units that land exactly when a simulation has revealed something.
- A short unit right after the reaction
- Content matches the technique observed
- No report to managers
Programmes
A plan across several months instead of a one off campaign. Set it up once and it keeps running.
- A plan across several months
- Set it up once and it keeps running
- Rounds can be adjusted without rebuilding
Reports
Progress per department and per period, as evidence for auditors and management.
- Progress per department and period
- Separate for employees and management
- Export for audit and internal review
Capabilities
What makes a programme hold up.
Six points that separate effect from activity.
Templates from real cases
Messages follow techniques that are actually in circulation. Obvious test mails only confirm a false sense of safety, because attackers do not send obvious test mails.
Spread over time
Sending across days so the simulation does not announce itself.
Group level evaluation
Results per department, with no ranking of individual employees.
Evidence that satisfies an audit
Reports show content, periods and the development across rounds. An attendance list cannot, and that is exactly what an audit asks for.
Agreement with the works council
Limiting evaluation to groups removes the hardest point from that discussion.
Operated in Germany or on your premises
Either from German data centres or entirely inside your own environment, training content included.
How it runs
One programme, four steps
Effect comes from repetition, not from the one big training session each year.
Choose the audience
You decide who takes part. Departments, groups or the whole company.
Simulation runs
Test messages go out spread over time so they are not recognised as a campaign.
Training follows
Anyone who reacted gets a short explanation of that exact technique.
Next round
The programme repeats and the report shows how things develop over time.
Evidence
Training you can prove
NIS2 requires cyber hygiene and security training in Article 21 paragraph 2 point g. What is required is not only running it, but being able to show it.
- Participation and progress traceable per person and per department.
- Reports across any period, exportable for audit and internal review.
- Evaluation at group level so nobody is put on the spot.
- Operated in Germany or entirely in your own data centre.
The difference
The message that gets through the filter
What happens next decides the damage.
With an annual briefing
- The session was in January, the message arrives in September.
- Nobody knows how staff would actually react.
- Whoever falls for it would rather not report it.
- The auditor is handed an attendance list.
With an awareness programme
- Practised across the year, so the attention holds.
- The reaction is measured, in daily work rather than a training room.
- A reaction is met with an explanation, not a report to management.
- The auditor is handed content, periods and a development over time.
How to start
Into the programme in three steps
From the first agreement to the first report, without your own project team.
Agree the audience
You decide who takes part and involve the works council. Group level evaluation removes the hardest point from that conversation.
Set up the programme
We configure the first round together, with schedule, techniques and training units.
Review the result
After the first round you see the report and decide how to continue. From then on it runs by itself.
A first round is set up within days. The development becomes meaningful from the second round, which is why a programme spans months.
Enterprise infrastructure and security
Certified protection, seamless integration, and full transparency.
Monitoring and audit logs
Integration and compatibility
Seamless integration into your existing system landscape.
Infrastructure, Performance & Deployment
Highly available architecture for maximum reliability.
Infrastructure and architecture
- ISO 27001 hostingGeo redundant servers in Germany (the EU and Berlin).
- Active active clusterFor maximum resilience and load distribution.
Performance and reliability
- SLA guarantee99.9% guaranteed system availability.
- High performance routingMinimal latency (< 50ms) for email processing.
Deployment & Multi-Tenancy
- ISO 27001 certified hostingHosting in ISO 27001 certified EU data centers (Germany)
- Flexible service packagesCustom service packages per tenant
Support and documentation
Benefit from a broad range of support services
24/7 ticketing
Guaranteed response times around the clock
Phone support
Personal contact through prioritized phone support
Documentation and FAQs
Comprehensive documentation, step by steps, and FAQs
Frequently asked questions
Does the simulation expose individual employees?
No. Evaluation is designed around groups. Anyone who reacts to a simulation gets an explanation, not a report to their manager.
How often should we simulate?
Effect comes from repetition spread across the year. A programme with several rounds achieves far more than a single campaign.
Does the works council need to be involved?
Usually yes, as soon as behaviour is evaluated. Group level evaluation exists for exactly that reason and makes the agreement easier.
Does it work without MailGuard?
Yes. Awareness can be used on its own. Together with MailGuard the effect is stronger, because technology and people are prepared for the same techniques.
Which plan includes Awareness?
Awareness is part of the largest plan. It can also be booked separately where that fits better.
Related pages
More on training and phishing.
NIS2 im Überblick
Richtlinie, Umsetzungsgesetz und BSIG: wer betroffen ist und was gilt.
Learn moreSecurity Awareness Training
Schulung, die sich gegenüber einer Prüfung belegen lässt.
Learn morePhishing-Simulation
Den Ernstfall üben, ohne Einzelne vorzuführen.
Learn moreNIS2-Schulungspflicht
Was Paragraf 30 und Paragraf 38 BSIG konkret verlangen.
Learn morePhishing-Schutz
Die technische Abwehr, bevor eine Nachricht den Menschen erreicht.
Learn moreNIS-2 E-Mail-Sicherheit
Alle E-Mail-Anforderungen nach Paragraf 30 BSIG im Überblick.
Learn moreRehearse the real thing before it happens
We set up the first programme with you and go through the results together after the first round.