Filters stop most of it.Your team stops the rest.

Conbool Awareness rehearses the real thing before it happens. Realistic phishing simulations, short training right afterwards, and reports you can put in front of an auditor.

Simulations on a scheduleTraining right afterwardsAlso in your own data centre

The remaining gap

One click is enough

Technical defences catch the bulk of it. What gets through is the well made attempt, and it lands with a person who is under time pressure.

What technology handles

MailGuard reliably removes mass waves, known senders and malicious attachments before they reach a mailbox.

What is left

Targeted messages with no attachment and no known signature. They look like ordinary work and are addressed to one specific person.

What it consists of

What Awareness covers

Practise, explain, repeat, prove.

Phishing simulation

Realistic test messages to selected groups, evaluated without singling anyone out.

  • Audience freely chosen per round
  • Sending spread across days, not bundled
  • Evaluation by group, not by person

Training

Short units that land exactly when a simulation has revealed something.

  • A short unit right after the reaction
  • Content matches the technique observed
  • No report to managers

Programmes

A plan across several months instead of a one off campaign. Set it up once and it keeps running.

  • A plan across several months
  • Set it up once and it keeps running
  • Rounds can be adjusted without rebuilding

Reports

Progress per department and per period, as evidence for auditors and management.

  • Progress per department and period
  • Separate for employees and management
  • Export for audit and internal review

Capabilities

What makes a programme hold up.

Six points that separate effect from activity.

Templates from real cases

Messages follow techniques that are actually in circulation. Obvious test mails only confirm a false sense of safety, because attackers do not send obvious test mails.

Spread over time

Sending across days so the simulation does not announce itself.

Group level evaluation

Results per department, with no ranking of individual employees.

Evidence that satisfies an audit

Reports show content, periods and the development across rounds. An attendance list cannot, and that is exactly what an audit asks for.

Agreement with the works council

Limiting evaluation to groups removes the hardest point from that discussion.

Operated in Germany or on your premises

Either from German data centres or entirely inside your own environment, training content included.

How it runs

One programme, four steps

Effect comes from repetition, not from the one big training session each year.

1

Choose the audience

You decide who takes part. Departments, groups or the whole company.

2

Simulation runs

Test messages go out spread over time so they are not recognised as a campaign.

3

Training follows

Anyone who reacted gets a short explanation of that exact technique.

4

Next round

The programme repeats and the report shows how things develop over time.

Evidence

Training you can prove

NIS2 requires cyber hygiene and security training in Article 21 paragraph 2 point g. What is required is not only running it, but being able to show it.

  • Participation and progress traceable per person and per department.
  • Reports across any period, exportable for audit and internal review.
  • Evaluation at group level so nobody is put on the spot.
  • Operated in Germany or entirely in your own data centre.

The difference

The message that gets through the filter

What happens next decides the damage.

With an annual briefing

  • The session was in January, the message arrives in September.
  • Nobody knows how staff would actually react.
  • Whoever falls for it would rather not report it.
  • The auditor is handed an attendance list.

With an awareness programme

  • Practised across the year, so the attention holds.
  • The reaction is measured, in daily work rather than a training room.
  • A reaction is met with an explanation, not a report to management.
  • The auditor is handed content, periods and a development over time.

How to start

Into the programme in three steps

From the first agreement to the first report, without your own project team.

1

Agree the audience

You decide who takes part and involve the works council. Group level evaluation removes the hardest point from that conversation.

2

Set up the programme

We configure the first round together, with schedule, techniques and training units.

3

Review the result

After the first round you see the report and decide how to continue. From then on it runs by itself.

A first round is set up within days. The development becomes meaningful from the second round, which is why a programme spans months.

Enterprise infrastructure and security

Certified protection, seamless integration, and full transparency.

Monitoring and audit logs

Live dashboardVisualized spam timeline and mail flow in real time.
End to end audit loggingAudit log and cryptography logging stored tamper proof.
RetentionStandard 90 days retention and export.
SIEM exportSecurity events via pull API to Splunk, Sentinel, QRadar and Elastic.
Mails processed
128.4k
Encrypted
Spam trend

Integration and compatibility

Seamless integration into your existing system landscape.

Compatibility & Clients
Native support for Microsoft Outlook, Apple Mail, iOS, Android, and all common email clients — without additional installations.
OUTLOOKAPPLE MAILMOBILE
Integration & Management
Scheduled sync with Microsoft Entra ID, with a local Active Directory through an outbound agent and with LDAP. Central control from the interface.
ENTRA IDAD/LDAPSAML SSO
Team members
Manage members of your team.
Invite
Search members
NameEmailRoleJoined
M
Maximilian M.
m.mueller@example.com
Owner
P
3.4.2025
S
Sarah K.
s.krause@firm.com
Owner
20.5.2025
T
Timo S.
t.schmidt@mail.de
Contact
2.9.2025

Infrastructure, Performance & Deployment

Highly available architecture for maximum reliability.

Infrastructure and architecture

  • ISO 27001 hostingGeo redundant servers in Germany (the EU and Berlin).
  • Active active clusterFor maximum resilience and load distribution.
the EUBerlin ISO 27001

Performance and reliability

  • SLA guarantee99.9% guaranteed system availability.
  • High performance routingMinimal latency (< 50ms) for email processing.
SLA guarantee
99.9%
Avg. latency
< 50ms

Deployment & Multi-Tenancy

  • ISO 27001 certified hostingHosting in ISO 27001 certified EU data centers (Germany)
  • Flexible service packagesCustom service packages per tenant
CLOUD / SAAS
ON-PREM

Support and documentation

Benefit from a broad range of support services

24/7 ticketing

Guaranteed response times around the clock

Phone support

Personal contact through prioritized phone support

Documentation and FAQs

Comprehensive documentation, step by steps, and FAQs

Frequently asked questions

Does the simulation expose individual employees?

No. Evaluation is designed around groups. Anyone who reacts to a simulation gets an explanation, not a report to their manager.

How often should we simulate?

Effect comes from repetition spread across the year. A programme with several rounds achieves far more than a single campaign.

Does the works council need to be involved?

Usually yes, as soon as behaviour is evaluated. Group level evaluation exists for exactly that reason and makes the agreement easier.

Does it work without MailGuard?

Yes. Awareness can be used on its own. Together with MailGuard the effect is stronger, because technology and people are prepared for the same techniques.

Which plan includes Awareness?

Awareness is part of the largest plan. It can also be booked separately where that fits better.

Related pages

More on training and phishing.

Rehearse the real thing before it happens

We set up the first programme with you and go through the results together after the first round.