Training, phishing simulation and policy acknowledgement run where your risks, measures and audits already live. Every completion becomes audit evidence, and the training and reporting rates feed the metrics register. Five languages, reconciliation against your HR system, hosted in Germany.
Book a free demoAwareness rarely fails on the training video and almost always on the evidence: who completed what and when, who is still missing, and how do you show it in an audit? The module answers that from maintained data rather than from spreadsheets exported out of a separate system.
The register is the denominator behind every metric. A file import reconciles the workforce in full: new people are created, missing people are marked as leavers, and their records are retained. Every run is calculated as a preview first and only written after confirmation, matched preferably on the personnel number, otherwise on the email address. Repeated runs never apply twice.
A wizard builds company-specific training from a reviewed core. You supply the context, meaning assets, risks and the tools in use, and the AI tailors sections and test questions to it. Every draft passes a review before release. Language variants then follow in German, English, Spanish, Turkish and Chinese, with the correct answers identical across all of them.
Simulated campaigns run through a connected phishing environment. What is measured is not only who clicked but who reported: the report button produces a reporting rate, the metric that actually shows maturity. Anyone who clicks receives follow-up training immediately rather than next quarter.
Policies are pushed out for confirmation and signed off per person. Expected against confirmed acknowledgements produce a rate that answers the audit question of whether a policy merely exists or is actually known.
The export bundles training completions per person, certificates, policy acknowledgements and phishing results into one file. That addresses ISO 27001 A.6.3 and the training obligation in NIS-2 Article 20, without anyone assembling screenshots from a separate system before the audit.
Training coverage, phishing report rate and acknowledgement rate appear as tiles in the overview, with a jump to the people still outstanding. A daily run writes the training rate and phishing report rate into the platform metrics register; the acknowledgement rate appears in the overview but is not written to the register. Awareness therefore appears in the same management report as risks and measures.
The training content is not the difference. The cores come from freely available material published by European and American authorities, which anyone can use. The difference is where the results end up.
Two requirements drive this topic in regulated organisations, and the same evidence serves both.
Three situations where the training list turns into an audit question.
Need evidence in an audit, not intent. The evidence pack delivers completions, certificates, acknowledgements and phishing results in one go, and the rates are already in the management report.
Run training, phishing and newsletters across the year and need to find stragglers without reconciling lists. The overview shows open assignments per person, and the import keeps the workforce current.
Workforces do not all speak one language. Five languages, evaluation per plant and a register that tracks joiners and leavers make the difference between a group-level rate and one that means something per site.
The awareness module shares its data layer, permission model and audit trail with the ISMS (ISO 27001), BCM (ISO 22301), assessment and TPRM modules. That is where the cross-connections come from: training rates feed the metrics register, the security process for awareness draws its coverage from real data, and the evidence sits in the same audit record as risks and measures.
See the platform overview