Security awareness · Built for NIS2

It only takes one.

One click opens the company. AwareOne trains every employee to catch it — five minutes a month, no accounts to create, and reporting your auditor will accept.

Hosted in the EU GDPR by design Your sender domain Localised content
 Inbox — Tuesday, 09:41
PayrollFebruary payslip is now available08:04
Jana K.Re: warehouse handover — notes attached08:22
FacilitiesLift maintenance, floors 3–5, Thursday08:47
Tomáš B.Q1 supplier list for review09:15
IT Helpdesk Action required: your password expires in 2 hours 09:41 from: helpdesk@it-support-verify.eu
CanteenThis week's menu09:44
Lookalike domain Artificial urgency Link ≠ display text
Six ordinary emails. One simulated attack. AwareOne teaches the difference — in the inbox, where it happens.
5 min
per employee, per month. Short enough that people actually finish it.
12+1
microlearning modules — a full annual curriculum, plus a final check.
0
passwords stored. Simulations record the click, never the credential.
6,000+
organisations newly in scope in Czechia alone under the NIS2 transposition — up from roughly 450.
How it works

Three steps. No IT project.

You send a list of employees. We do the rest. There is nothing to install, no SSO to configure, and no accounts for your people to forget.

STEP 01

Upload your people

A CSV or a sync is enough. Split by department, site or country — each group can run its own schedule and language.

STEP 02

Lessons land in the inbox

Each employee gets a personal link. One tap opens the lesson — no password, no app. Between lessons, simulated phishing and smishing test what stuck.

STEP 03

Export the evidence

Completion, click rates and reporting rates per team, per campaign, per period. Pull the report yourself, whenever the auditor asks.

Platform

What you get

Access

No logins, no friction

Every employee gets a tokenised personal link. Nothing to remember, nothing for the helpdesk to reset — which is why completion rates hold up.

Curriculum

A year of microlearning

Phishing, passwords and MFA, data handling, mobile and remote work, social engineering, AI risks — one topic a month, then a closing assessment.

Simulations

Phishing and smishing

Realistic campaigns sent from your own domain. We log the click and the submit event; the credential itself never reaches us.

Reporting

Evidence on demand

Self-service exports, timestamped and structured for an audit file — not a screenshot someone assembled the night before.

Architecture

Multi-tenant from day one

Built for groups, resellers and MSPs. Strict tenant isolation, separate branding and separate reporting per company.

Localisation

Speaks their language

Content adapted per market, not machine-translated. A phishing lure only works as training if it reads like a real local email.

NIS2 · ZoKB 264/2025

Training is not optional any more.

NIS2 puts cyber hygiene training in the law: management bodies must be trained, and must offer comparable training to their employees on a regular basis. Regulators will ask what you ran, who completed it, and when.

Member States shall ensure that the members of the management bodies of essential and important entities follow training, and shall encourage those entities to offer similar training to their employees on a regular basis. NIS2 Directive (EU) 2022/2555, Article 20(2)

Awareness report — Q1

generated 04/2026
DepartmentCompletedClickedReported
Finance96%4%71%
Operations91%11%58%
Sales88%14%49%
Management100%2%83%
Sample data Export PDF · CSV

Show us your riskiest inbox.

A 20-minute demo: we run a live simulated campaign against a test group and walk you through the report your auditor would see.