Cyber security awareness training for small and medium-sized businesses

Cyber awareness training for SMEs, without an SME-sized budget

AutoPhish runs the whole security awareness programme for you: realistic phishing simulations every month, bite-sized employee training the moment someone falls for one, and the audit evidence NIS2 and ISO 27001 ask for. No consultants, no annual video nobody watches.

  • From 10 to 500 employees
  • Servers in Germany
  • GDPR by default
  • First campaign in 10 minutes

Your awareness programme, on autopilot

What a running AutoPhish programme does every month, without you touching it.

  • Sends AI-written phishing simulations to every employee
  • Delivers a teachable moment the second someone submits credentials
  • Assigns a short training module on the exact tactic that worked
  • Tracks click rate and repeat clickers per team over time
  • Watches your SPF, DKIM and DMARC records for drift
  • Keeps per-user training records ready for an auditor

Trusted by security-conscious teams

edeja software
Post Business Solutions
RansomLeak Security Training
Allegro Vivo
Brevius
Perfect-EDV IT Services

Join teams using AutoPhish to build a human firewall against phishing.

Why SMEs

Attackers don't skip you because you're small

Small and medium-sized enterprises are targeted precisely because they hold real money and real data with a fraction of an enterprise security team. There is rarely a dedicated security officer, the IT lead already has three other jobs, and the awareness budget is a fraction of what the vendors on the analyst quadrants assume you have. So security awareness training gets bought once, delivered as an annual e-learning video, ticked off, and forgotten — until an invoice gets paid to the wrong bank account.

Cyber awareness training for SMEs has to work differently. It has to install itself in minutes rather than quarters, run without a programme manager, teach at the moment someone actually makes a mistake, and produce compliance evidence as a by-product instead of a separate project. That is exactly what AutoPhish is built to do.

Email is still the front door

Phishing, invoice fraud and business email compromise remain the most common way attackers get their first foothold in a small company — because they bypass every technical control by asking a human nicely.

Everyone is an admin somewhere

In a 40-person company the office manager has the bank portal, the assistant has the CRM and the founder approves payments from a phone. Role-based risk assumptions from enterprise programmes simply don't hold.

Nobody has a spare quarter

An awareness programme that needs a kickoff workshop, a content curation phase and a monthly campaign owner will quietly die by month four. It has to run itself or it doesn't run.

Compliance arrived anyway

NIS2, ISO 27001 and customer security questionnaires all ask whether your staff are trained and how you know. "We sent a PDF" is not an answer that survives an audit.

How it works

From signup to your first simulation in about 10 minutes

Four steps, done once. After that the programme runs on a schedule you set and only asks for your attention when something needs deciding.

1

Add your people

Import employees from a CSV, or sync them automatically from Microsoft 365 or Active Directory so joiners and leavers keep themselves up to date. Group by department, location or risk so finance can be tested harder than the workshop floor.

2

Verify your domain

Add the domains you own so AutoPhish can keep checking SPF, DKIM and DMARC for you. Simulations go out from dedicated AutoPhish sending domains, so you don't need a single DNS change before your first campaign.

3

Set the cadence

Choose monthly, quarterly or continuous. AI writes the pretexts for your industry, your language and the time of year — payroll notices in January, delivery scams in December, MFA resets whenever. Delivery is staggered so the whole office doesn't compare notes at 09:05.

4

Let it teach and report

Clicks and credential submissions are recorded. Whoever falls for a simulation lands on a teachable moment naming the red flags they missed and, when you enable it, gets a short training module on that exact tactic. You get click rate by team, repeat-clicker lists and exportable training records.

What's included

A complete security awareness programme in one subscription

Simulation, training, reporting and email-authentication monitoring — not four tools stitched together with a spreadsheet.

AI-generated phishing simulations

Pretexts written for your sector, your language and the current season instead of a shared template library your staff have already seen at their last three employers. Realism is what makes the click rate mean something.

Bite-sized employee training

Short modules assigned automatically to the person who fell for the simulation, covering the tactic that actually worked on them. Minutes, not a mandatory afternoon. Use the built-in course, point at your own training URL, or switch it off per campaign.

Smishing and SMS simulations

The same programme extended to mobile, because the CEO-fraud text message to the finance assistant never lands in a mail gateway at all.

Domain and email security monitoring

Continuous SPF, DKIM and DMARC checks on your real domains, with alerts when records change or look-alike domains appear that someone could spoof you from.

Reporting your board can read

Click rate over time, risk by department, repeat clickers and training completion — in one dashboard, and in an export you can attach to a customer security questionnaire without editing it first.

Automation that survives a busy month

Set the cadence once and campaigns keep going out, keep training people and keep reporting whether or not anyone logs in. The programme's success stops depending on someone remembering it.

Training topics

What your employees actually get trained on

Every module maps to a real attack an SME gets hit with, and is triggered by the simulation that exposed the gap — not delivered as a 40-minute compliance video in January.

Phishing and spear phishing

Spotting spoofed senders, look-alike domains, urgency framing and credential-harvesting login pages that copy your real Microsoft 365 sign-in screen pixel for pixel.

Business email compromise and CEO fraud

Why a payment request from "the managing director" that arrives at 16:50 on a Friday deserves a phone call to a number you already had, not a reply to the email.

Invoice and supplier fraud

The bank-detail change email that costs SMEs more than ransomware does, and the two-person verification habit that stops it.

Passwords, MFA and MFA fatigue

Password managers over reuse, why an approved push notification you didn't trigger is an incident, and what an MFA-fatigue attack feels like from the inside.

Ransomware and malicious attachments

How ransomware gets in through a macro, an archive or a fake invoice PDF, and what the first ten minutes of a response should look like in a company with no SOC.

Smishing, vishing and QR codes

Attacks that arrive by text message, phone call or a printed QR code in the car park, where none of your email filtering applies.

Data protection and GDPR basics

What counts as personal data, why exporting a customer list to a private inbox is a reportable event, and how to handle a data subject request without panicking.

Remote, mobile and travel security

Public Wi-Fi, shoulder surfing, personal devices with company mail and the home-office router nobody has patched since 2019.

Safe use of AI tools

What can and cannot be pasted into a public chatbot, and why AI-written phishing has removed the bad-grammar tell everyone was taught to look for.

Reporting an incident

The most valuable behaviour of all: telling someone quickly, without fear, when you think you clicked. Fast reporting is what turns an incident into a non-event.

Your first year

What a 12-month SME awareness programme looks like

Awareness training is not an event, it's a habit. Here is the rollout most of our SME customers run — and all of it happens on the cadence you set, without a project plan.

  1. Week 1

    Baseline

    Import your people, verify your domains and run a first simulation with no announcement. The click rate you get here is your honest starting point — most SMEs land somewhere between 15% and 35%, and seeing that number is usually what gets the budget approved.

  2. Month 1–3

    Establish the habit

    Monthly simulations across all departments, each with automatic follow-up training for whoever falls for one. Announce the programme internally as a team exercise, not a trap — the goal is a workforce that reports suspicious mail, not one that hides mistakes.

  3. Month 4–8

    Turn up the difficulty

    Move from generic lures to targeted pretexts: supplier bank-detail changes for finance, fake applicant CVs for HR, MFA resets for anyone with admin rights. Add smishing. Repeat clickers get more frequent, shorter interventions instead of one big course.

  4. Month 9–12

    Prove it worked

    Compare click rate and report rate against your baseline, export per-user training records for your ISO 27001 or NIS2 evidence pack, and hand the board a one-page trend instead of an anecdote. Then the cycle starts again — because staff turn over and attacks change.

Compare

Three ways SMEs do awareness training

Most companies end up with one of these. Only one of them changes behaviour and survives an audit at a price an SME can justify.

Time to first campaign

AutoPhish: About 10 minutes, self-serve

Annual e-learning video: One afternoon, once a year

Enterprise awareness suite: Onboarding call, then days of setup

How often staff are tested

AutoPhish: Monthly or continuously, automatically

Annual e-learning video: Never — there is no test

Enterprise awareness suite: Whenever someone finds time to launch a campaign

Training content

AutoPhish: Short module on the tactic that just worked on that person

Annual e-learning video: The same 40 minutes for all 200 employees

Enterprise awareness suite: Large library someone has to curate

Simulation realism

AutoPhish: AI-written per industry, language and season

Annual e-learning video: Not applicable

Enterprise awareness suite: Shared templates staff recognise across employers

Admin effort per month

AutoPhish: None once configured

Annual e-learning video: None, and no result either

Enterprise awareness suite: A named programme owner

Audit evidence

AutoPhish: Per-user records and trend reports, exportable

Annual e-learning video: A completion list with no behavioural data

Enterprise awareness suite: Good, if the programme was actually run

Data residency

AutoPhish: EU only — servers in Germany

Annual e-learning video: Wherever the LMS lives

Enterprise awareness suite: Often US-hosted with transfer clauses

Commitment to start

AutoPhish: Free account with no card; 7-day Pro trial, cancel anytime

Annual e-learning video: Per-seat licence for the year

Enterprise awareness suite: Annual contract with seat minimums

Buyer's guide

What cyber awareness training for SMEs is — and how to choose it

Cyber awareness training is the ongoing practice of teaching employees to recognise and safely handle cyber attacks — above all phishing — and of measuring whether that teaching actually changed what they do. For an SME, the distinction that matters is between awareness training as content and awareness training as a programme. Content is a library of modules someone has to assign, chase and refresh. A programme tests people continuously, teaches at the moment of the mistake, and reports a trend. Content produces completion certificates; a programme produces a falling click rate — and only one of those is a security outcome.

If you are comparing platforms, six things decide whether the programme will still be alive next year. They are worth more attention than the module count on the pricing page.

Does it run without you?

The single strongest predictor of an SME awareness programme surviving twelve months is whether it needs a human to start each round. Look for scheduled, recurring campaigns with automatic target-group updates and automatic training assignment — anything that requires monthly clicking will stop when a quarter gets busy.

How believable are the simulations?

A static template library ages badly. Staff who have seen the same fake parcel notice at two previous employers will pass your test and still fall for a real, well-written attack. Generated pretexts, localised and tied to your sector and calendar, keep the measurement honest — and AI-written attacks are what your people actually face now.

What happens in the ten seconds after a click?

That moment is the entire value of a simulation. A teachable-moment page that names the specific red flags the person missed, followed by a short module on that tactic, changes behaviour in a way a quarterly course cannot. If the platform just logs the click and moves on, you have bought measurement, not training.

Will it produce evidence you can hand over?

Auditors and enterprise customers ask who was trained, on what, when, and what the result was. Per-user, per-campaign records that export cleanly turn awareness training from an assertion into evidence — and answer the security questionnaire that is blocking your next big contract.

Where does employee data live?

Simulation results are employee performance data, which makes them sensitive under GDPR and often a topic for the works council. EU hosting, a signed DPA and the option to anonymise individual results are usually what get an SME programme past legal, HR and staff representatives without a three-month debate.

What does it really cost per employee?

Compare the all-in annual cost per employee, not the headline monthly figure — then add the hours someone has to spend running it. A cheaper platform that consumes two days of your IT lead per quarter is not cheaper. Watch for seat minimums, mandatory onboarding fees and content packs sold separately.

Budget

What should an SME pay for security awareness training?

Per-seat pricing for security awareness training generally lands in the low tens of euros per employee per year, and vendors aimed at larger organisations frequently add onboarding fees, seat minimums and separately licensed content packs on top. For a 50-person company, the difference between a platform priced for SMEs and one priced for enterprises is often larger than the entire rest of the IT security budget.

The number worth comparing is total annual cost per employee including setup, plus the internal hours the programme consumes. A platform that needs a named owner to launch campaigns every month costs you far more than its invoice suggests — and it is the cost that quietly kills SME awareness programmes in month four.

AutoPhish is priced for small and medium-sized businesses: no seat minimums, no onboarding fee, no mandatory annual contract, and phishing simulation, training, smishing and domain monitoring in the same subscription rather than as four line items. Creating an account is free and needs no credit card, and a 7-day Pro trial lets you run a real baseline simulation against your own staff before you commit — cancel before it ends and you are not charged.

See pricing

Compliance

The evidence your auditors and customers ask for

Staff awareness training has quietly become a legal and contractual obligation for European SMEs rather than a nice-to-have. AutoPhish is an Austrian-founded company with servers in Germany, all data is processed inside the EU, and DPAs are signed on request — so the programme that satisfies the requirement doesn't create a new data-transfer problem of its own.

NIS2

Article 20 requires management bodies to take cyber security training and to offer comparable training to staff regularly. Recurring simulations plus per-user records show "regularly" as a fact rather than a claim.

ISO 27001

Clause 7.3 and Annex A control 6.3 require an ongoing awareness programme, not a one-off session. Exportable completion and click-rate history is exactly what an auditor samples.

GDPR

Article 32 expects appropriate organisational measures. Trained staff are one of the cheapest, and results can be anonymised so the programme itself stays proportionate.

Customer questionnaires

Enterprise buyers and insurers increasingly ask whether you run phishing simulations and how often. A one-page export answers it and unblocks the deal.

Works council friendly

Individual results can be anonymised and reported at group level, which is usually what turns a works council objection into an approval.

EU-hosted by default

Servers in Germany, no transatlantic transfer, plain-language privacy policy and a DPA on request.

Cyber awareness training for SMEs: common questions

What small and medium-sized businesses ask us before they start.

Start your awareness programme this week

A 30-minute walkthrough: we set up a live baseline simulation against a test group in your company and show you the reporting an auditor would accept.