Training your team lives through — not sits through.
No more videos nobody watches or quizzes that just get clicked through. Employees step into a simulated workplace, face real attacks and make the decisions themselves. The mistakes happen in training, not in your inbox.
100+
interactive exercises
5–15
minutes per exercise
4
course categories
0
installs or headsets needed
Why it works
People remember what they have done themselves
Classic awareness training is watched with the sound off. Hands-on simulations force real decisions — and show the consequences immediately.
Classic video training
- Passive watching, tabs open in the background
- Generic slides that have little to do with daily work
- Multiple-choice quiz at the end — guessed, forgotten
- The same annual course for everyone
Interactive simulations
- Employees act inside a realistic desktop and phone
- Scenarios based on documented real-world breaches
- Every decision branches the story — including what the attacker does next
- Short 5–15 minute units that fit between two meetings
NIS2 cybersecurity training
Security awareness training that supports NIS2 compliance
NIS2 Article 21(2)(g) includes basic cyber hygiene and cybersecurity training among risk-management measures. Article 20(2) addresses training for management bodies and encourages regular employee training.
AutoPhish combines phishing simulations, interactive employee security training, automatic follow-up courses and completion reporting. This helps teams practise recognizing phishing, smishing and social engineering while documenting their NIS2 awareness activities.
Cybersecurity training supports one part of NIS2 compliance. Wider obligations depend on your entity, national rules and other security measures.
Learning by doing
A complete simulated workplace
Learners don't read about attacks — they handle them in an environment that looks and feels like their own workday.
Realistic desktop
Mail client, browser, terminal, password manager and more than twenty other applications — all simulated, all interactive.
Simulated smartphone
Calls, text messages and authenticator prompts: vishing, smishing and MFA fatigue are practised where they really happen.
Branching scenarios
Every choice changes the outcome. Wrong decisions show exactly what an attacker would have done next.
Based on real incidents
Each scenario is built on documented attack patterns from real corporate breaches — not on invented textbook examples.
Scored knowledge check
Every exercise ends with a short, scored knowledge check so progress is measurable, not assumed.
Runs in the browser
Interactive 3D without installation, plug-ins or VR headset. Works on any modern browser, ready for your whole workforce.
Training catalog
From phishing basics to deepfakes and the EU AI Act
More than 100 hands-on exercises across four categories — covering today's attacks and tomorrow's compliance requirements.
Security awareness
The fundamentals every employee needs, trained on realistic attacks.
- Phishing
- Ransomware
- Social engineering
- Vishing
- Smishing
- Business email compromise
- Passwords & MFA
Privacy & compliance
Regulatory knowledge made practical — including a dedicated multi-part EU AI Act course.
- GDPR
- EU AI Act
- AI literacy
- Data handling
- Incident reporting
AI & LLM security
New attack surfaces that most awareness programmes do not cover yet.
- Deepfake whaling
- Voice cloning
- Prompt injection
- OWASP LLM Top 10
- Safe use of AI tools
Real-world incidents
Replay well-known breaches step by step and learn where they could have been stopped.
- Breach reconstructions
- Attacker kill chain
- Missed warning signs
- Lessons learned
Available in several languages including English and German. The catalog is updated monthly with new exercises. Basic, Professional and Enterprise include phishing training and micro-training; the full cybersecurity course catalog is available with a Custom plan.
Simulation and training in one closed loop
AutoPhish connects phishing simulations directly to the training catalog — no exports, no manual assignments.
- 1
Simulation reveals the risk
An employee enters their credentials on a simulated login page — reached via email, SMS or QR code.
- 2
Training is assigned automatically
Right after the mistake, the learner is enrolled on the training platform and assigned an awareness course — while the lesson still sticks.
- 3
Progress shows up in your reports
Completion is tracked per employee and reflected in your AutoPhish reports, ready for audits and management.
Flexible deployment
Use it the way your organisation works
Start instantly on the AutoPhish training platform or bring the content into the systems you already use.
AutoPhish training platform
Hosted for you, connected to your simulations, with automatic assignment and completion reporting out of the box.
Your own LMS
Exercises are available as SCORM 1.2 and SCORM 2004 packages and run in any standards-compliant learning management system.
Bring your own training
Already have SCORM content of your own? Upload it and assign it through the same automated workflow.
Custom training modules
Need content tailored to your industry or internal processes? We build bespoke modules on request (additional fees may apply).
Frequently asked questions
Do employees need to install anything or use a VR headset?
How long does a training exercise take?
Which topics does the catalog cover?
Can we use the training in our existing LMS?
How is training assigned after a failed simulation?
Which languages are available?
Can security awareness training help with NIS2 compliance?
Have a question about the training catalog? Get in touch
Turn your riskiest moments into your best lessons
Combine realistic phishing simulations with interactive training your employees actually finish.
Book a demo