Security awareness training · 50–250 staffQuarterly phishing campaigns
Your people are the targetMake them the defenceProve it to your auditor
Video-and-quiz training in 12–20 minute sittings, a quarterly Knowledge Benchmark, real phishing campaigns, and a company-wide Awareness Score your board can read at a glance — all on a bespoke platform we built ourselves, with new content every month as attackers change their tactics. Set up your team in about ten minutes.
30 days · up to 5 team members · no card required
Written by experts who have worked on blue teams — modelled on live attacks
Illustration: an inbox with a fake browser-update email. Revealing the attacker's view exposes the lookalike sender domain, the manufactured five o'clock deadline, and a download link on a domain that is not Chrome's.
Every company gets tested
The only question is whether it happens in a drill, or for real.
Try one yourself
Would your team click this?
This is modelled on a real lure — the fake browser update chain known as SocGholish, which the team behind this training fights in the wild. There are three tells. Click them in the email. Once you subscribe, a campaign like this one lands in your team's inboxes every quarter — safely, and measured.
-
Tell one — look at who it is really from The sender's domain. The display name says IT Helpdesk, but acme-it-support.net is not your company. Lookalike domains are the oldest tell there is.
-
Tell two — notice how it makes you feel The deadline. "Suspended at 5pm today" is manufactured pressure. The attacker needs you to act before you think.
-
Tell three — check where the button goes The download link. Chrome updates itself, silently. A browser update arriving by email from a third-party domain is how SocGholish spreads.
0 of 3 tells found ·
That is the whole product in one email. Your team meets module 9 before the real one arrives — and you get the score that proves it. Then, every quarter, a campaign like this one tests them for real.
Start free trialHello,
Our monitoring has flagged your browser as out of date and vulnerable. All staff must install the security update below.
Thank you,
IT Helpdesk
Every element above is a pattern from module 9, Malware & Fake Updates. Nothing on this page can be clicked into trouble.
Section 02Who wrote this
Every module in this library is an attack we have watched land — the vishing call, the fake update, the invoice that nearly got paid. We wrote the training we wish every target had done the week before.
Written by the people who fight these attacks
The authors have spent their careers on blue teams, defending live environments against these exact campaigns today. All 39 topics are written in-house — not licensed stock content — and each one is modelled on threat-actor behaviour they actually encounter, from AI vishing calls to SocGholish fake-update chains to business email compromise.
That is why the modules read like your inbox instead of a textbook, and why the curriculum moves when the attacks move. And the platform they run on is theirs as well — a bespoke LMS built around this curriculum and nothing else.
- Every topic written and maintained in-house
- A bespoke platform, built and run in-house
- Scenarios modelled on live attacks, not theory
- Updated as threat actors change tactics
Section 03Why now
The attacks that work are aimed at people
Not at your firewall. At the person in finance who gets a convincing invoice, and the new starter who gets an urgent message from "the CEO".
People are the way in
Business email compromise, QR codes, fake browser updates and MFA bombing all work on a person, not a port. Training is the control for that.
NIS2 names training as a minimum measure
Article 21(2)(g) lists cyber hygiene practices and cybersecurity training among ten required measures for in-scope entities. Irish transposition is coming.
Auditors want evidence, not intentions
ISO 27001 control 6.3 and insurance proposal forms ask the same question: who was trained, on what, when, and did it work. A record answers it.
Section 04How it works
Set up your team in about ten minutes
Three steps, no implementation project — then the platform quietly carries it from there.
| User | Role | Joined |
|---|---|---|
| ABAoife Byrne | Manager | Today |
| SOSeán O'Brien | Member | Today |
| PMPriya Murphy | Member | Today |
| TKTomasz Kowalski | Member | Today |
| NWNiamh Walsh | Member | Today |
Two-factor authentication is part of setup, not an upsell. It takes about a minute and it is on for everyone.
Section 05CurriculumUpdated monthly
Threats your staff will recognise
Eleven modules, each sized for one 12–20 minute sitting — a coffee break, not an afternoon. Every topic is a video lesson followed by a quiz. Select a module to see what it covers.
New content every month, at no extra cost. Attackers change their tactics and techniques; the training changes with them, so what your staff practise is what is actually arriving in inboxes.
The phishing lures employees meet most often.
- Zoom Meeting Invites
- OneNote Malware
- Microsoft Planner
- Docusign
Quizzes allow three attempts and record the best. 147 questions across the programme. Every module and topic
Section 06The platform
Built for this, and only this
CyberAwareHub does not run on a rented learning platform. It is a bespoke LMS — conceived, designed and built by us, and polished to perfection. Every screen, every score and every certificate comes from the same hands that wrote the curriculum.
That is worth more than it sounds. When you own the whole stack, the Awareness Score is not a plugin's guess — it is computed from the same records as everything else you see. The audit log can be written before the action it records. The certificate can never disagree with the dashboard, because they are the same code. Nothing here is licensed, white-labelled or bolted together.
The tour below walks through it, page by page.
100%
built in-house, end to end
- One codebase — training, benchmark, reports and audit trail
- No rented LMS, no licensed content, no plugins
- Refined release after release, around one job
Section 07The loop
Train · Test · Measure · Prove
Every report is generated from the same numbers as the dashboard, so what you present can never disagree with what you saw.
The phishing lures employees meet most often.
- Zoom Meeting Invites
- OneNote Malware
- Microsoft Planner
- Docusign
Section 08Evidence for your auditor
Mapped to NIS2 and ISO 27001
Mapped — not "certified". No body certifies awareness-training content, so we publish the mapping instead.
Completion records, quiz scores and certificates are the evidence an auditor asks for under control 6.3. For NIS2 in-scope entities, training is one of ten named minimum measures — we address that one, and we say so precisely.
Section 09Security, briefly
Built to be careful with your data
Two-factor authentication
Authenticator app, enforceable across your whole organisation.
Encrypted in transit and at rest
Card details go straight to Stripe and never touch our systems.
Self-service GDPR export and delete
Users can download everything we hold and delete their account, in Settings.
Audit log, written first
Records are written before the action, so the record of a deletion outlives the deletion.
Hosted in the UK today under the UK adequacy decision, moving to EU hosting. Sub-processors published, with 30 days' notice before changes.
Section 10Pricing
Simple per-employee pricing
One plan with everything in it. From per employee per month, falling to as your team grows. Minimum 20. Cancel any time.
per employee per month at scale · from for small teams · minimum 20 employees · cancel any time · new content every month
Payments handled by Stripe · Cancel anytime · Seat changes prorated
Starter band · or per employee a year, two months free
What's included, for every employee
- All 11 modules and 39 topics, video and quiz
- New content every month, at no extra cost
- Company dashboard, Awareness Score and quarterly Knowledge Benchmark
- Quarterly phishing campaigns, scheduled for you
- Per-course and whole-programme certificates
- Executive PDF report and per-employee compliance export
- Team management with CSV import and an audit log
- Two-factor authentication, enforceable org-wide
Payments handled by Stripe · Cancel any time · Seat changes prorated
Need a formal quote, bespoke content or a results review with us? Talk to us
Each rate applies only to the employees in its own range — like tax bands, so nobody pays more for growing. At 200 employees you pay 49 × + 100 × + 51 × , so a month.
Section 11The trial, exactly
What the free trial includes
We would rather you read the limits here than discover them after you have added your team.
| Feature | Free trial | Subscription |
|---|---|---|
| Team size | You + 5 people | Your whole team |
| Course library | Modules 1–4 (12 topics) | All 11 modules (39 topics) |
| Duration | 30 days | Ongoing |
| Awareness Score and Knowledge Benchmark | Yes | Yes |
| Company dashboard and audit log | Yes | Yes |
| Phishing campaigns | Sample data only | Real, every quarter |
| Certificates and executive report | — | Yes |
| Card required | No | At checkout, via Stripe |
No card, and nothing is created until you confirm
An abandoned signup leaves no trace. If you let the trial lapse, your data is kept for 90 days and then permanently deleted, with a warning email first.
Upgrade in place and everything carries over: your people, their progress, your settings.
Section 12Questions buyers ask
Straight answers
The questions a security-conscious buyer actually asks, answered without hedging — including the ones where the answer is no.
How long does setup take, honestly?
About ten minutes for the manager. You fill in a short form, click the confirmation link we email you, sign in, and set up an authenticator app — two-factor authentication is part of the product, not an extra. A three-step onboarding then walks you through adding your team, by CSV or one at a time; everyone receives their login by email. Nothing is created until you click the confirmation link, so an abandoned signup leaves no trace.
What exactly is in the free trial?
Thirty days, you plus up to five team members, no card. The trial includes modules 1–4 — twelve topics — so you can judge the content and the dashboard with real people. The full library, certificates and the executive report unlock when you subscribe, and quarterly phishing campaigns run for real; the trial shows clearly labelled sample data instead. If you subscribe, your workspace upgrades in place and everything carries over.
What happens when the trial ends, and to our data?
Nothing is charged, because we never took a card. Your workspace stays readable, your data is kept for 90 days after expiry and then permanently deleted, and we email a warning before that happens. Subscribe at any point in between and you continue where you left off.
How is the Awareness Score calculated?
It is one 0–100 number for the whole organisation, averaged across people who have completed at least one Knowledge Benchmark. Each person's score blends their latest benchmark result, course completion and quiz pass rate, and their behaviour in quarterly phishing campaigns — which carries the largest weight because it is the closest thing to real life. Anyone with an outstanding urgent module is marked down until they finish it. The exact weights are shown in the app next to the score, and the executive report is generated from the same code, so the PDF can never disagree with the dashboard.
Does this make us NIS2 or ISO 27001 compliant?
No, and be wary of anyone who says otherwise. NIS2 Article 21(2) lists ten minimum measures; we address part of one, point (g), "basic cyber hygiene practices and cybersecurity training". ISO 27001:2022 has ninety-three controls; we give you evidence for one, control 6.3. There is no body that certifies awareness-training content, so we publish a mapping of every module to those clauses instead, and we will send it to you or your auditor on request. Ireland has not yet transposed NIS2 — it is coming, not in force today.
Where is our data hosted, and who else touches it?
Our servers are currently in the United Kingdom, which the EU recognises as adequate; we are moving to EU hosting. Email is sent through a provider that processes in the United States under approved safeguards, and card details go straight to Stripe and never reach us. We publish the full sub-processor list with locations and give you 30 days' notice before it changes. We process your people's data only on your instructions under an Article 28 Data Processing Agreement, and you can export or delete it yourself at any time.
Can staff sign in with Microsoft or Google?
Not today — there is no single sign-on. Staff sign in with email and a password of at least twelve characters, and you can require an authenticator app for the whole organisation. Second-factor secrets are encrypted and codes are stored only as hashes. If single sign-on is a hard requirement for you, tell us; that is exactly the kind of signal that sets our roadmap.
How does pricing work for, say, 100 people?
One plan with everything in it, priced per employee in graduated bands, like tax bands: your first 49 employees are a month each, employees 50 to 149 are , 150 to 499 are , and 500 and up are . So 100 people pay 49 × + 51 × , which is a month, or a year with two months free. Minimum twenty employees, change your seat count any time with prorated billing, cancel any time.
What do the phishing campaigns actually measure?
Whether people click, download or submit credentials when a realistic lure arrives. A campaign runs each quarter, and its funnel shows sent, delivered, opened, clicked, downloaded and submitted, per campaign and per person. That behaviour feeds the Awareness Score more heavily than any quiz. We do not currently measure whether staff report a suspicious email.
Start with five people and thirty days
30 days · up to 5 team members · no card required
Start free trialAlready decided? Buy now · Questions? Talk to us