Awareness · Training

Technology stopsmost of it.Your team the rest.

What gets through the filter is well made and lands with a person under time pressure. Security awareness training rehearses that exact moment, repeatedly across the year, with evidence at the end.

Why the annual session changes nothing

Four reasons knowledge alone does not protect.

Once a year is too rare

A session in January has faded by March. Attack patterns change faster than an annual rhythm can follow.

Knowing is not behaving

Almost everyone knows phishing exists. What counts is whether someone pauses at half past five on the thirtieth message of the day.

Without evidence it does not count

An auditor does not ask whether you trained, but with what, when and to what effect. A paper attendance list is thin for that.

Done wrong it damages trust

A simulation that exposes individuals creates resentment instead of attention. After that the topic is burned for years.

A programme, not a campaign

Practise, explain, repeat.

1. Choose the audience

You pick departments, groups or the whole company. Evaluation stays at group level, nobody is listed individually.

2. Simulation spread over time

Test messages go out staggered so they are not recognised as a campaign and announced between colleagues.

3. Training right afterwards

Anyone who reacted receives a short unit on that exact technique. The lesson lands where it came up.

Programme 2026running
1

Choose the audience

Departments or the whole company.

2

Simulation

Staggered over time so it does not stand out as a campaign.

3

Training

Short and specific to the technique that was fallen for.

4

Next round

The report shows the development over time.

One programme

Four steps that repeat.

A programme keeps running for months without anyone chasing it. That is exactly where the development comes from that an audit wants to see.

Set it up once and it keeps running

Audience adjustable per round

Training follows the reaction immediately

The report grows with every round

What the programme delivers

Six points that survive an audit.

Realistic simulations

Messages modelled on techniques in actual use, not obvious test mails nobody takes seriously.

Training at the moment of the mistake

Short units immediately after the reaction, not weeks later in a group session.

Repetition across months

A programme keeps running over a longer period without anyone having to start it again each time.

Reports for the audit

Progress per department and period, exportable for internal review, certification and management.

Group level evaluation

No ranking of individual employees, which makes the agreement with the works council far easier.

Operated in Germany or on your premises

Either from German data centres or entirely inside your own environment.

Programme versus annual session

Same effort, very different effect.

 
With Conbool
Annual mandatory session
Repetition spread across the year
yes
no
Everyday reaction is measurable
yes
no
Training targeted at the observed weakness
yes
generic for everyone
Evidence per period and department
yes
attendance list
Without exposing individuals
yes
depends on the tool

The comparison describes the common practice of an annual mandatory briefing, not a specific competing product.

Frequently asked questions

Does NIS2 really require training?
Yes. German law implements the directive through the BSIG and names training as part of the risk management measures. For management there is an additional obligation that cannot be delegated.
Is a phishing simulation mandatory?
Not explicitly. It is however the instrument that documents best, because it produces measurable figures over time rather than a bare attendance record.
Are individual employees exposed?
No. Evaluation is built around groups. Anyone who reacts gets an explanation, not a report to their manager. That is precisely what makes the works council agreement easier.
Does the works council have to be involved?
Usually yes, as soon as behaviour is evaluated. Limiting evaluation to group level exists for that reason and removes the hardest point from the discussion.
How often should we simulate?
Several times a year, spread out rather than bundled. A programme with multiple rounds achieves far more than one large campaign.
Does it work without the Conbool spam filter?
Yes, Awareness can be used independently. Together with MailGuard the effect is greater, because technical defence and training address the same techniques.

Related solutions

Set up the first round together

We configure the programme with you and go through the results after the first round.