Security Awareness Training

Training your team lives through — not sits through.

No more videos nobody watches or quizzes that just get clicked through. Employees step into a simulated workplace, face real attacks and make the decisions themselves. The mistakes happen in training, not in your inbox.

100+

interactive exercises

5–15

minutes per exercise

4

course categories

0

installs or headsets needed

Why it works

People remember what they have done themselves

Classic awareness training is watched with the sound off. Hands-on simulations force real decisions — and show the consequences immediately.

Classic video training

  • Passive watching, tabs open in the background
  • Generic slides that have little to do with daily work
  • Multiple-choice quiz at the end — guessed, forgotten
  • The same annual course for everyone

Interactive simulations

  • Employees act inside a realistic desktop and phone
  • Scenarios based on documented real-world breaches
  • Every decision branches the story — including what the attacker does next
  • Short 5–15 minute units that fit between two meetings

NIS2 cybersecurity training

Security awareness training that supports NIS2 compliance

NIS2 Article 21(2)(g) includes basic cyber hygiene and cybersecurity training among risk-management measures. Article 20(2) addresses training for management bodies and encourages regular employee training.

AutoPhish combines phishing simulations, interactive employee security training, automatic follow-up courses and completion reporting. This helps teams practise recognizing phishing, smishing and social engineering while documenting their NIS2 awareness activities.

Cybersecurity training supports one part of NIS2 compliance. Wider obligations depend on your entity, national rules and other security measures.

Learning by doing

A complete simulated workplace

Learners don't read about attacks — they handle them in an environment that looks and feels like their own workday.

Realistic desktop

Mail client, browser, terminal, password manager and more than twenty other applications — all simulated, all interactive.

Simulated smartphone

Calls, text messages and authenticator prompts: vishing, smishing and MFA fatigue are practised where they really happen.

Branching scenarios

Every choice changes the outcome. Wrong decisions show exactly what an attacker would have done next.

Based on real incidents

Each scenario is built on documented attack patterns from real corporate breaches — not on invented textbook examples.

Scored knowledge check

Every exercise ends with a short, scored knowledge check so progress is measurable, not assumed.

Runs in the browser

Interactive 3D without installation, plug-ins or VR headset. Works on any modern browser, ready for your whole workforce.

Training catalog

From phishing basics to deepfakes and the EU AI Act

More than 100 hands-on exercises across four categories — covering today's attacks and tomorrow's compliance requirements.

Security awareness

The fundamentals every employee needs, trained on realistic attacks.

  • Phishing
  • Ransomware
  • Social engineering
  • Vishing
  • Smishing
  • Business email compromise
  • Passwords & MFA

Privacy & compliance

Regulatory knowledge made practical — including a dedicated multi-part EU AI Act course.

  • GDPR
  • EU AI Act
  • AI literacy
  • Data handling
  • Incident reporting

AI & LLM security

New attack surfaces that most awareness programmes do not cover yet.

  • Deepfake whaling
  • Voice cloning
  • Prompt injection
  • OWASP LLM Top 10
  • Safe use of AI tools

Real-world incidents

Replay well-known breaches step by step and learn where they could have been stopped.

  • Breach reconstructions
  • Attacker kill chain
  • Missed warning signs
  • Lessons learned

Available in several languages including English and German. The catalog is updated monthly with new exercises. Basic, Professional and Enterprise include phishing training and micro-training; the full cybersecurity course catalog is available with a Custom plan.

Simulation and training in one closed loop

AutoPhish connects phishing simulations directly to the training catalog — no exports, no manual assignments.

  1. 1

    Simulation reveals the risk

    An employee enters their credentials on a simulated login page — reached via email, SMS or QR code.

  2. 2

    Training is assigned automatically

    Right after the mistake, the learner is enrolled on the training platform and assigned an awareness course — while the lesson still sticks.

  3. 3

    Progress shows up in your reports

    Completion is tracked per employee and reflected in your AutoPhish reports, ready for audits and management.

Flexible deployment

Use it the way your organisation works

Start instantly on the AutoPhish training platform or bring the content into the systems you already use.

AutoPhish training platform

Hosted for you, connected to your simulations, with automatic assignment and completion reporting out of the box.

Your own LMS

Exercises are available as SCORM 1.2 and SCORM 2004 packages and run in any standards-compliant learning management system.

Bring your own training

Already have SCORM content of your own? Upload it and assign it through the same automated workflow.

Custom training modules

Need content tailored to your industry or internal processes? We build bespoke modules on request (additional fees may apply).

Frequently asked questions

Do employees need to install anything or use a VR headset?
No. All exercises run in a normal web browser on desktop hardware. There is nothing to install and no special equipment is required.
How long does a training exercise take?
Most exercises take between 5 and 15 minutes and end with a short scored knowledge check. That makes them easy to fit into a normal workday.
Which topics does the catalog cover?
Phishing, ransomware, social engineering, vishing, smishing, business email compromise, deepfakes, AI prompt injection, GDPR and the EU AI Act, plus reconstructions of real-world incidents. New exercises are added every month.
Can we use the training in our existing LMS?
Yes. The exercises are available as SCORM 1.2 and SCORM 2004 packages. Alternatively, you can use the hosted AutoPhish training platform, which is connected to your simulations.
How is training assigned after a failed simulation?
When an employee falls for an AutoPhish simulation, they are automatically enrolled on the training platform and assigned a course. You configure this per campaign and see completion in your reports.
Which languages are available?
The exercises are available in several languages, including English and German. Contact us if you need a specific language for your workforce.
Can security awareness training help with NIS2 compliance?
Yes. NIS2 includes cyber hygiene and cybersecurity training in Article 21(2)(g). AutoPhish helps deliver phishing awareness training, assign follow-up courses and track completion. Training alone does not fulfill every NIS2 obligation.

Have a question about the training catalog? Get in touch

Turn your riskiest moments into your best lessons

Combine realistic phishing simulations with interactive training your employees actually finish.

Book a demo