Security awareness training · 50–250 staffQuarterly phishing campaigns

Your people are the targetMake them the defenceProve it to your auditor

Video-and-quiz training in 12–20 minute sittings, a quarterly Knowledge Benchmark, real phishing campaigns, and a company-wide Awareness Score your board can read at a glance — all on a bespoke platform we built ourselves, with new content every month as attackers change their tactics. Set up your team in about ten minutes.

30 days · up to 5 team members · no card required

Written by experts who have worked on blue teams — modelled on live attacks

Illustration: an inbox with a fake browser-update email. Revealing the attacker's view exposes the lookalike sender domain, the manufactured five o'clock deadline, and a download link on a domain that is not Chrome's.

11modules
39topics
147quiz questions
12–20minutes per module
a year, Knowledge Benchmark
4phishing campaigns a year
[CUSTOMER_LOGO]

Every company gets tested

The only question is whether it happens in a drill, or for real.

Try one yourself

Would your team click this?

This is modelled on a real lure — the fake browser update chain known as SocGholish, which the team behind this training fights in the wild. There are three tells. Click them in the email. Once you subscribe, a campaign like this one lands in your team's inboxes every quarter — safely, and measured.

  1. Tell one — look at who it is really from The sender's domain. The display name says IT Helpdesk, but acme-it-support.net is not your company. Lookalike domains are the oldest tell there is.
  2. Tell two — notice how it makes you feel The deadline. "Suspended at 5pm today" is manufactured pressure. The attacker needs you to act before you think.
  3. Tell three — check where the button goes The download link. Chrome updates itself, silently. A browser update arriving by email from a third-party domain is how SocGholish spreads.

0 of 3 tells found ·

mail.acme.ie — Inbox
FromIT Helpdesk <>
Toyou@acme.ie
SubjectAction required: mandatory browser security update

Hello,

Our monitoring has flagged your browser as out of date and vulnerable. All staff must install the security update below.

Thank you,
IT Helpdesk

Every element above is a pattern from module 9, Malware & Fake Updates. Nothing on this page can be clicked into trouble.

Section 02Who wrote this

Every module in this library is an attack we have watched land — the vishing call, the fake update, the invoice that nearly got paid. We wrote the training we wish every target had done the week before.
The CyberAwareHub authors Blue-team practitioners

Written by the people who fight these attacks

The authors have spent their careers on blue teams, defending live environments against these exact campaigns today. All 39 topics are written in-house — not licensed stock content — and each one is modelled on threat-actor behaviour they actually encounter, from AI vishing calls to SocGholish fake-update chains to business email compromise.

That is why the modules read like your inbox instead of a textbook, and why the curriculum moves when the attacks move. And the platform they run on is theirs as well — a bespoke LMS built around this curriculum and nothing else.

  • Every topic written and maintained in-house
  • A bespoke platform, built and run in-house
  • Scenarios modelled on live attacks, not theory
  • Updated as threat actors change tactics

Section 03Why now

The attacks that work are aimed at people

Not at your firewall. At the person in finance who gets a convincing invoice, and the new starter who gets an urgent message from "the CEO".

People are the way in

Business email compromise, QR codes, fake browser updates and MFA bombing all work on a person, not a port. Training is the control for that.

NIS2 names training as a minimum measure

Article 21(2)(g) lists cyber hygiene practices and cybersecurity training among ten required measures for in-scope entities. Irish transposition is coming.

Auditors want evidence, not intentions

ISO 27001 control 6.3 and insurance proposal forms ask the same question: who was trained, on what, when, and did it work. A record answers it.

Section 04How it works

Set up your team in about ten minutes

Three steps, no implementation project — then the platform quietly carries it from there.

app1.cyberawarehub.com/sign-up
Start your free trial
30 days · up to 5 team members · no card required
Company nameAcme Ltd
Work emailaoife@acme.ie
Password••••••••••••
I agree to the Terms & Conditions and Privacy Policy
Create trial account
Check your inbox. Nothing is created until you click the link.

Two-factor authentication is part of setup, not an upsell. It takes about a minute and it is on for everyone.

Section 05CurriculumUpdated monthly

Threats your staff will recognise

Eleven modules, each sized for one 12–20 minute sitting — a coffee break, not an afternoon. Every topic is a video lesson followed by a quiz. Select a module to see what it covers.

New content every month, at no extra cost. Attackers change their tactics and techniques; the training changes with them, so what your staff practise is what is actually arriving in inboxes.

app1.cyberawarehub.com/courses/common-phishing-scenariosExample · Acme Ltd
Table of Contents Common Phishing Scenarios Module 6 of 11

The phishing lures employees meet most often.

2/4 completed
  1. Zoom Meeting Invites
  2. OneNote Malware
  3. Microsoft Planner
  4. Docusign
Knowledge check after every topic15 questions in this module · 3 attempts · 70% to pass
Certificate on completionPer module, and for the whole programme

Quizzes allow three attempts and record the best. 147 questions across the programme. Every module and topic

Section 06The platform

Built for this, and only this

CyberAwareHub does not run on a rented learning platform. It is a bespoke LMS — conceived, designed and built by us, and polished to perfection. Every screen, every score and every certificate comes from the same hands that wrote the curriculum.

That is worth more than it sounds. When you own the whole stack, the Awareness Score is not a plugin's guess — it is computed from the same records as everything else you see. The audit log can be written before the action it records. The certificate can never disagree with the dashboard, because they are the same code. Nothing here is licensed, white-labelled or bolted together.

The tour below walks through it, page by page.

100%

built in-house, end to end

  • One codebase — training, benchmark, reports and audit trail
  • No rented LMS, no licensed content, no plugins
  • Refined release after release, around one job

Section 07The loop

Train · Test · Measure · Prove

Every report is generated from the same numbers as the dashboard, so what you present can never disagree with what you saw.

app1.cyberawarehub.comExample · Acme Ltd
Table of Contents Common Phishing Scenarios Module 6 of 11

The phishing lures employees meet most often.

2/4 completed
  1. Zoom Meeting Invites
  2. OneNote Malware
  3. Microsoft Planner
  4. Docusign
Knowledge check after every topic15 questions in this module · 3 attempts · 70% to pass
Certificate on completionPer module, and for the whole programme

Section 08Evidence for your auditor

Mapped to NIS2 and ISO 27001

Mapped — not "certified". No body certifies awareness-training content, so we publish the mapping instead.

Completion records, quiz scores and certificates are the evidence an auditor asks for under control 6.3. For NIS2 in-scope entities, training is one of ten named minimum measures — we address that one, and we say so precisely.

Request the full mapping

NIS2 Art. 21(2)(g)Cyber hygiene and training ISO 27001:2022 A.6.3Awareness, education, training GDPR Art. 32(4)Staff act only on instructions Completion recordsBenchmark scores, certificates Compliance exportOne row per employee, CSV Module 5Protecting Data

Section 09Security, briefly

Built to be careful with your data

Two-factor authentication

Authenticator app, enforceable across your whole organisation.

Encrypted in transit and at rest

Card details go straight to Stripe and never touch our systems.

Self-service GDPR export and delete

Users can download everything we hold and delete their account, in Settings.

Audit log, written first

Records are written before the action, so the record of a deletion outlives the deletion.

Hosted in the UK today under the UK adequacy decision, moving to EU hosting. Sub-processors published, with 30 days' notice before changes.

Read our security page

Section 10Pricing

Simple per-employee pricing

One plan with everything in it. From per employee per month, falling to as your team grows. Minimum 20. Cancel any time.

From

per employee per month at scale · from for small teams · minimum 20 employees · cancel any time · new content every month

Payments handled by Stripe · Cancel anytime · Seat changes prorated

Your price
per employee / month

Starter band · or per employee a year, two months free

Minimum 20
Your total / month

What's included, for every employee

  • All 11 modules and 39 topics, video and quiz
  • New content every month, at no extra cost
  • Company dashboard, Awareness Score and quarterly Knowledge Benchmark
  • Quarterly phishing campaigns, scheduled for you
  • Per-course and whole-programme certificates
  • Executive PDF report and per-employee compliance export
  • Team management with CSV import and an audit log
  • Two-factor authentication, enforceable org-wide
Start free trial Buy now — /month for 40 employees

Payments handled by Stripe · Cancel any time · Seat changes prorated

Need a formal quote, bespoke content or a results review with us? Talk to us

Starter1 – 49
Professional50 – 149
Enterprise150 – 499
Scale500 and up

Each rate applies only to the employees in its own range — like tax bands, so nobody pays more for growing. At 200 employees you pay 49 × + 100 × + 51 × , so a month.

Section 11The trial, exactly

What the free trial includes

We would rather you read the limits here than discover them after you have added your team.

FeatureFree trialSubscription
Team sizeYou + 5 peopleYour whole team
Course libraryModules 1–4 (12 topics)All 11 modules (39 topics)
Duration30 daysOngoing
Awareness Score and Knowledge BenchmarkYesYes
Company dashboard and audit logYesYes
Phishing campaignsSample data onlyReal, every quarter
Certificates and executive reportYes
Card requiredNoAt checkout, via Stripe

No card, and nothing is created until you confirm

An abandoned signup leaves no trace. If you let the trial lapse, your data is kept for 90 days and then permanently deleted, with a warning email first.

Upgrade in place and everything carries over: your people, their progress, your settings.

Start free trial

Section 12Questions buyers ask

Straight answers

The questions a security-conscious buyer actually asks, answered without hedging — including the ones where the answer is no.

Ask one we missed

How long does setup take, honestly?

About ten minutes for the manager. You fill in a short form, click the confirmation link we email you, sign in, and set up an authenticator app — two-factor authentication is part of the product, not an extra. A three-step onboarding then walks you through adding your team, by CSV or one at a time; everyone receives their login by email. Nothing is created until you click the confirmation link, so an abandoned signup leaves no trace.

What exactly is in the free trial?

Thirty days, you plus up to five team members, no card. The trial includes modules 1–4 — twelve topics — so you can judge the content and the dashboard with real people. The full library, certificates and the executive report unlock when you subscribe, and quarterly phishing campaigns run for real; the trial shows clearly labelled sample data instead. If you subscribe, your workspace upgrades in place and everything carries over.

What happens when the trial ends, and to our data?

Nothing is charged, because we never took a card. Your workspace stays readable, your data is kept for 90 days after expiry and then permanently deleted, and we email a warning before that happens. Subscribe at any point in between and you continue where you left off.

How is the Awareness Score calculated?

It is one 0–100 number for the whole organisation, averaged across people who have completed at least one Knowledge Benchmark. Each person's score blends their latest benchmark result, course completion and quiz pass rate, and their behaviour in quarterly phishing campaigns — which carries the largest weight because it is the closest thing to real life. Anyone with an outstanding urgent module is marked down until they finish it. The exact weights are shown in the app next to the score, and the executive report is generated from the same code, so the PDF can never disagree with the dashboard.

Does this make us NIS2 or ISO 27001 compliant?

No, and be wary of anyone who says otherwise. NIS2 Article 21(2) lists ten minimum measures; we address part of one, point (g), "basic cyber hygiene practices and cybersecurity training". ISO 27001:2022 has ninety-three controls; we give you evidence for one, control 6.3. There is no body that certifies awareness-training content, so we publish a mapping of every module to those clauses instead, and we will send it to you or your auditor on request. Ireland has not yet transposed NIS2 — it is coming, not in force today.

Where is our data hosted, and who else touches it?

Our servers are currently in the United Kingdom, which the EU recognises as adequate; we are moving to EU hosting. Email is sent through a provider that processes in the United States under approved safeguards, and card details go straight to Stripe and never reach us. We publish the full sub-processor list with locations and give you 30 days' notice before it changes. We process your people's data only on your instructions under an Article 28 Data Processing Agreement, and you can export or delete it yourself at any time.

Can staff sign in with Microsoft or Google?

Not today — there is no single sign-on. Staff sign in with email and a password of at least twelve characters, and you can require an authenticator app for the whole organisation. Second-factor secrets are encrypted and codes are stored only as hashes. If single sign-on is a hard requirement for you, tell us; that is exactly the kind of signal that sets our roadmap.

How does pricing work for, say, 100 people?

One plan with everything in it, priced per employee in graduated bands, like tax bands: your first 49 employees are a month each, employees 50 to 149 are , 150 to 499 are , and 500 and up are . So 100 people pay 49 × + 51 × , which is a month, or a year with two months free. Minimum twenty employees, change your seat count any time with prorated billing, cancel any time.

What do the phishing campaigns actually measure?

Whether people click, download or submit credentials when a realistic lure arrives. A campaign runs each quarter, and its funnel shows sent, delivered, opened, clicked, downloaded and submitted, per campaign and per person. That behaviour feeds the Awareness Score more heavily than any quiz. We do not currently measure whether staff report a suspicious email.

Start with five people and thirty days

30 days · up to 5 team members · no card required

Start free trial

Already decided? Buy now · Questions? Talk to us