Technology stopsmost of it.Your team the rest.
What gets through the filter is well made and lands with a person under time pressure. Security awareness training rehearses that exact moment, repeatedly across the year, with evidence at the end.
Why the annual session changes nothing
Four reasons knowledge alone does not protect.
Once a year is too rare
A session in January has faded by March. Attack patterns change faster than an annual rhythm can follow.
Knowing is not behaving
Almost everyone knows phishing exists. What counts is whether someone pauses at half past five on the thirtieth message of the day.
Without evidence it does not count
An auditor does not ask whether you trained, but with what, when and to what effect. A paper attendance list is thin for that.
Done wrong it damages trust
A simulation that exposes individuals creates resentment instead of attention. After that the topic is burned for years.
A programme, not a campaign
Practise, explain, repeat.
1. Choose the audience
You pick departments, groups or the whole company. Evaluation stays at group level, nobody is listed individually.
2. Simulation spread over time
Test messages go out staggered so they are not recognised as a campaign and announced between colleagues.
3. Training right afterwards
Anyone who reacted receives a short unit on that exact technique. The lesson lands where it came up.
Choose the audience
Departments or the whole company.
Simulation
Staggered over time so it does not stand out as a campaign.
Training
Short and specific to the technique that was fallen for.
Next round
The report shows the development over time.
Four steps that repeat.
A programme keeps running for months without anyone chasing it. That is exactly where the development comes from that an audit wants to see.
Set it up once and it keeps running
Audience adjustable per round
Training follows the reaction immediately
The report grows with every round
What the programme delivers
Six points that survive an audit.
Realistic simulations
Messages modelled on techniques in actual use, not obvious test mails nobody takes seriously.
Training at the moment of the mistake
Short units immediately after the reaction, not weeks later in a group session.
Repetition across months
A programme keeps running over a longer period without anyone having to start it again each time.
Reports for the audit
Progress per department and period, exportable for internal review, certification and management.
Group level evaluation
No ranking of individual employees, which makes the agreement with the works council far easier.
Operated in Germany or on your premises
Either from German data centres or entirely inside your own environment.
Programme versus annual session
Same effort, very different effect.
With Conbool | Annual mandatory session | |
|---|---|---|
| Repetition spread across the year | yes | no |
| Everyday reaction is measurable | yes | no |
| Training targeted at the observed weakness | yes | generic for everyone |
| Evidence per period and department | yes | attendance list |
| Without exposing individuals | yes | depends on the tool |
The comparison describes the common practice of an annual mandatory briefing, not a specific competing product.
Frequently asked questions
Does NIS2 really require training?
Is a phishing simulation mandatory?
Are individual employees exposed?
Does the works council have to be involved?
How often should we simulate?
Does it work without the Conbool spam filter?
Related solutions
NIS2 im Überblick
Richtlinie, Umsetzungsgesetz und BSIG: wer betroffen ist und was gilt.
Phishing-Simulation
Den Ernstfall üben, ohne Einzelne vorzuführen.
NIS2-Schulungspflicht
Was Paragraf 30 und Paragraf 38 BSIG konkret verlangen.
Phishing-Schutz
Die technische Abwehr, bevor eine Nachricht den Menschen erreicht.
NIS-2 E-Mail-Sicherheit
Alle E-Mail-Anforderungen nach Paragraf 30 BSIG im Überblick.
Set up the first round together
We configure the programme with you and go through the results after the first round.