Sensitize employees. Minimize risks. Strengthen security.

Security Awareness

Security awareness helps people make safer decisions at work.

  • 01Reduction of security incidents caused by human error
  • 02Traceable training evidence for relevant requirements and reviews
  • 03Strengthening security awareness and reporting culture
  • 04Sustainable anchoring of information security in the organization
11+Years of experience
120+Employees
540+Projects
ISO 27001certified

Security Awareness

Security Awareness is the foundation of every successful security strategy. Only informed and sensitized employees can identify risks, defend against attacks, and sustainably strengthen information security in the organization.

Our offering includes the analysis, development, and implementation of security awareness programs tailored to your individual requirements. We accompany you from strategy to technical implementation and training of your employees.

2 service modules

What we take on for you

Bookable individually or as an end-to-end programme.

01

Awareness Analysis & Strategy

Analysis of awareness maturity level and development of an individual awareness strategy.

  • Inventory and assessment of awareness level
  • Development of awareness policies and processes
  • Integration into compliance and audit processes
  • Training and awareness measures
02

Training & Simulations

Execution of interactive training, phishing simulations, and awareness campaigns.

  • Interactive training formats for all target groups
  • Phishing simulations and social engineering tests
  • Awareness campaigns and practical workshops
  • Integration into processes, systems, and corporate culture

5 phases

Our Approach

We start with employee groups, existing training, relevant risks and internal reporting routes. These inform the awareness strategy, learning formats and evaluation. For an initial inquiry, useful inputs include employee numbers, languages, locations and any existing learning platform. Scope, responsibilities, evidence needs and effort are agreed around your starting point.

  1. Inventory and maturity assessment

  2. Development of a customized awareness strategy

  3. Selection and integration of suitable training and simulation formats

  4. Training and sensitization of employees

  5. Continuous success monitoring and optimization

Sarah Richter

Your contact

Sarah Richter

Head of Information Security, Cyber Security

10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security

Security Awareness is the key to sustainable information security. Those who sensitize and empower their employees make the organization more resilient, effective, and better positioned for the future.

Our Strengths

  • 01Years of experience in developing and implementing awareness programs
  • 02Technical, psychological, and didactic expertise from a single source
  • 03Practical, interactive training formats for all target groups
  • 04Support with audits, certifications, and regulatory inquiries

Expert Tip

Security Awareness is not a one-time project, but a continuous process. Only through regular training, practical simulations, and an open error culture can sustainable behavioral changes be achieved.

15 QUESTIONS, BRIEFLY ANSWERED

Frequently asked questions about Security Awareness

What does a professional security awareness program encompass and why is it indispensable for organizations?

Security awareness means recognising information risks and acting safely in everyday work. Awareness builds understanding; training develops practical skills, such as reporting a suspicious message or checking recipients before sharing data. A programme connects both with usable procedures, technical safeguards and a culture that supports reporting.

Identification of the most critical threats and vulnerabilities within the organization. Analysis of attack patterns, social engineering, and phishing trends. Assessment of the individual risk profile and derivation of awareness priorities. Integration of lessons learned from incidents and audits. Regular updates to the threat and risk assessment. Program Design & Content: Development of tailored training content for different target groups. Integration of current threats, compliance requirements, and best practices. Use of interactive formats, gamification, and practical examples. Application of learning psychology and didactics to drive lasting behavioral change. Regular review and adaptation of content to address new threats. Automation & Scalability: Use of Learning Management Systems (LMS) and awareness platforms. Automated assignment, delivery, and tracking of training activities. Use of performance monitoring tools for continuous optimization. Reminders for incomplete assignments; personal evaluation only within an agreed legal and organisational framework. Integration with HR and compliance systems for enterprise-wide scalability. Integration & Corporate Culture: Embedding security awareness into processes, systems, and corporate culture. Involvement of managers and multipliers as role models. Promotion of an open error-reporting and incident-reporting culture.

How is an effective security awareness project built and operated?

📝 Project Phases:

• Inventory: Analysis of the current awareness maturity level and identification of weaknesses.
• Goal Definition: Establishing awareness objectives, target groups, and KPIs.
• Awareness Concept Development: Selection of training formats, content, and communication channels.
• Implementation: Rollout of training, simulations, and campaigns.
• Performance Review: Measurement of participation, learning outcomes, and behavioral change.

🔧 Automation & Tools:

• Use of LMS, awareness platforms, and phishing simulation tools.
• Automated assignment, delivery, and tracking of training activities.
• Use of dashboards for real-time monitoring and trend analysis.
• Reminders for incomplete assignments; personal evaluation only within an agreed legal and organisational framework.
• Integration with HR and compliance systems for enterprise-wide scalability.

🛡 ️ Compliance & Auditing:

• Integration of awareness training into compliance and audit processes.
• Use of audit trails and logs for forensic analysis.
• Regular review of awareness processes and practical behaviour exercises; technical penetration tests are a separate scope.
• Traceable learning records as supporting evidence for relevant privacy, standards and industry requirements.
• Training of IT teams on audit and certification processes.

📢 Awareness & Policy:

• Development of awareness guidelines and processes.
• Integration of awareness into onboarding, change, and project management.
• Development of e-learnings, awareness campaigns, and practical workshops.
• Involvement of managers and IT teams in the training process.
• Regular review and adaptation of training content.

💡 Expert Tip:

A successful security awareness project requires structured project management, interdisciplinary collaboration, and continuous improvement. Organizations should rely on open standards, automation, and ongoing optimization.

Measurement and ownership: Agree the baseline, observation period and responsible owners before rollout. Completion rate measures finished assignments against assigned participants; knowledge checks measure learning. Neither proves safe behaviour during a real incident.

For an authorised phishing exercise, define the reporting rate as unique recipients who report the exercise divided by recipients successfully reached. Count repeated reports from one person once. Track clicks, any simulated data-entry event and time to the first report separately. Use consistent observation windows, comparable groups and documented message difficulty. Automated link scanning can distort click counts.

Review the results alongside employee feedback and the security team's handling of reports. More reports may indicate a healthier reporting culture; fewer observed incidents alone do not prove that training prevented losses. Refresh activities when risks, roles, tools or incident lessons change, rather than assuming a universal monthly legal requirement.

Effort depends on audience size and languages, content adaptation, existing platforms, exercise scope, privacy review and ongoing evaluation. These inputs support a meaningful scope and quote; a price without defined coverage does not.

What challenges arise when introducing security awareness and how are they addressed?

⚠ ️ Challenges:

• Acceptance: Employees often perceive awareness activities as a burdensome obligation.
• Integration: Technical and organizational embedding into existing systems and processes.
• Dynamics: Threats and requirements are constantly evolving.
• Measurability: Success and behavioral change are difficult to quantify.
• Resources: Time and budget constraints for training and campaigns.

🛠 ️ Solution Approaches:

• Clear communication and training to convey the added value.
• Automation of awareness processes wherever possible (e.g., through LMS and simulation tools).
• Simple, easy-to-understand awareness models and processes.
• Regular review and adaptation of awareness processes.
• Interdisciplinary teams, pilot projects, and continuous improvement.

🔗 Integration & Corporate Culture:

• Embedding awareness into processes, systems, and corporate culture.
• Involvement of managers and multipliers as role models.
• Promotion of an open error-reporting and incident-reporting culture.
• Integration of awareness into onboarding, change, and project management.
• Regular communication and campaigns to raise awareness.

🛡 ️ Compliance & Auditing:

• Integration of awareness training into compliance and audit processes.
• Use of audit trails and logs for forensic analysis.
• Regular review of awareness processes and practical behaviour exercises; technical penetration tests are a separate scope.
• Traceable learning records as supporting evidence for relevant privacy, standards and industry requirements.
• Training of IT teams on audit and certification processes.

💡 Expert Tip:

Successful awareness projects rely on interdisciplinary teams, pilot projects, and continuous improvement. Organizations should build on open standards, automation, and ongoing optimization.

How does security awareness support compliance with data protection and regulatory requirements?

Security awareness supports evidence of specific learning and awareness activities. A completion certificate, dashboard or automated policy check does not establish compliance with every privacy and security obligation. ISO 27001 is a standard; GDPR is legislation. Their requirements need separate assessment.

DORA: For financial entities within the relevant scope, Article 13(6) requires compulsory ICT-security-awareness and digital-operational-resilience training modules for employees and senior management. Complexity must match their functions; relevant ICT third-party providers are included where appropriate. This does not prescribe a universal monthly training frequency.

NIS2 in Germany: Section 30(2)(7) BSIG covers foundational training and awareness; section 38(3) addresses regular management training. Assess applicability and the exceptions in section 28 first. The DORA financial entities specified in section 28(6)(1) are exempt from, among other provisions, sections 30 and 38. Do not automatically assign both sets of obligations to a bank. These German and EU provisions are not universal rules for every UK organisation.

GDPR: Article 39(1)(b) includes awareness-raising and training within the data protection officer's monitoring tasks. An awareness programme does not replace assessment of individual processing activities or other required safeguards.

Retain the mapped requirements, audiences, learning objectives, approved content versions, participation records, evaluation and agreed improvements. Responsible specialists assess whether this evidence is sufficient for the particular review.

Primary sources: DORA, Article 13; BSIG section 28; BSIG section 30; BSIG section 38; GDPR, Article 39.

How is security awareness training differentiated and implemented for various target groups within an organization?

👩 💼 Target Group-Specific Content:

• Development of training modules for executives, IT staff, specialist departments, and all employees.
• Consideration of industry-specific risks and compliance requirements.
• Use of practical examples and real incidents tailored to each target group.
• Adaptation of language, depth, and complexity to the respective audience.
• Regular review and adaptation of content to address new threats.

🎓 Didactics & Learning Formats:

• Use of e-learnings, classroom training, webinars, and micro-learning.
• Use of gamification, quizzes, and interactive elements to boost motivation.
• Integration of awareness into onboarding, change, and project management.
• Development of awareness campaigns and practical workshops.
• Regular review and adaptation of learning formats.

🛡 ️ Phishing Simulations & Social Engineering:

• Regular conduct of phishing simulations and social engineering tests.
• Analysis of results and derivation of improvement measures.
• Integration of lessons learned from incidents and audits.
• Use of simulation tools for automated execution and evaluation.
• Training of employees on recognizing and responding to attacks.

📈 Performance Measurement & Reporting:

• Measurement of participation, learning outcomes, and behavioral change.
• Use of dashboards for real-time monitoring and trend analysis.
• Generation of compliance and audit reports for management and regulatory authorities.
• Integration with HR and compliance systems for enterprise-wide scalability.
• Regular review and adaptation of performance measurement processes.

💡 Expert Tip:

Differentiated, target group-specific awareness training is the key to lasting behavioral change. Organizations should build on open standards, automation, and continuous improvement.

How are security awareness campaigns and communication measures successfully implemented?

📢 Awareness Campaigns:

• Development of campaigns addressing current threats, compliance topics, and best practices.
• Use of email, intranet, posters, videos, and social media for maximum reach.
• Integration of awareness into onboarding, change, and project management.
• Conducting awareness days, competitions, and practical workshops.
• Regular review and adaptation of the campaign strategy.

🎯 Target Group Outreach & Personalization:

• Adaptation of content, language, and formats to the respective target group.
• Use of practical examples and real incidents tailored to each target group.
• Personalized communication and feedback channels.
• Involvement of managers and multipliers as role models.
• Promotion of an open error-reporting and incident-reporting culture.

🛡 ️ Integration & Corporate Culture:

• Embedding awareness into processes, systems, and corporate culture.
• Development of awareness guidelines and processes.
• Integration of awareness into onboarding, change, and project management.
• Regular communication and campaigns to raise awareness.
• Involvement of managers and IT teams in the training process.

📈 Performance Measurement & Reporting:

• Measurement of participation, learning outcomes, and behavioral change.
• Use of dashboards for real-time monitoring and trend analysis.
• Generation of compliance and audit reports for management and regulatory authorities.
• Integration with HR and compliance systems for enterprise-wide scalability.
• Regular review and adaptation of performance measurement processes.

💡 Expert Tip:

Successful awareness campaigns rely on target group-specific content, continuous communication, and an open error culture. Organizations should build on open standards, automation, and continuous improvement.

How are security awareness measures implemented for international organizations and global teams?

Development of an international awareness strategy that takes into account local laws, cultures, and languages.

Use of multi-language LMS and awareness platforms. Integration of awareness into all global IT and business processes. Use of compliance dashboards for real-time monitoring. Regular review and adaptation of the strategy to reflect new laws and standards. Target Group Outreach & Personalization: Adaptation of content, language, and formats to the respective target group and region. Use of practical examples and real incidents tailored to each target group. Personalized communication and feedback channels. Involvement of managers and multipliers as role models. Promotion of an open error-reporting and incident-reporting culture. Compliance & Auditing: Central records support assessment of applicable requirements; they do not by themselves prove complete compliance. Integration of compliance checks into global IT and awareness platforms. Use of audit trails and logs for forensic analysis. Review of mapped requirements and evidence; technical testing does not replace compliance assessment. Integration of lessons learned from audits and incidents into continuous improvement processes. Performance Measurement & Reporting: Measurement of participation, learning outcomes, and behavioral change across all regions.

How are security awareness measures implemented for executives and specialists?

👨 💼 Executive Training:

• Development of training modules for executives and specialists.
• Consideration of industry-specific risks and compliance requirements.
• Use of practical examples and real incidents tailored to each target group.
• Adaptation of language, depth, and complexity to the respective audience.
• Regular review and adaptation of content to address new threats.

🎓 Didactics & Learning Formats:

• Use of e-learnings, classroom training, webinars, and micro-learning.
• Use of gamification, quizzes, and interactive elements to boost motivation.
• Integration of awareness into onboarding, change, and project management.
• Development of awareness campaigns and practical workshops.
• Regular review and adaptation of learning formats.

🛡 ️ Phishing Simulations & Social Engineering:

• Regular conduct of phishing simulations and social engineering tests.
• Analysis of results and derivation of improvement measures.
• Integration of lessons learned from incidents and audits.
• Use of simulation tools for automated execution and evaluation.
• Training of executives on recognizing and responding to attacks.

📈 Performance Measurement & Reporting:

• Measurement of participation, learning outcomes, and behavioral change.
• Use of dashboards for real-time monitoring and trend analysis.
• Generation of compliance and audit reports for management and regulatory authorities.
• Integration with HR and compliance systems for enterprise-wide scalability.
• Regular review and adaptation of performance measurement processes.

💡 Expert Tip:

Executives and specialists require target group-specific awareness training tailored to their particular responsibilities and requirements. Organizations should build on open standards, automation, and continuous improvement.

How are security awareness measures for phishing, social engineering, and current threats implemented?

Phishing and social-engineering exercises should reflect the audience's actual responsibilities. Agree authorisation, learning objectives, a safe technical setup, evaluation and feedback before starting. Executive impersonation, fake support calls and emerging attack patterns can be suitable topics. Red teaming is a separate scope requiring explicit authorisation.

Editorial exercise example: An apparent supplier emails a change of bank details for an upcoming payment. The desired response is to pause the change and verify it through an independently known contact route. A telephone number or link supplied in the suspicious message is not independent confirmation. Existing approval and dual-control procedures still apply.

Report suspicious messages through the agreed channel to the security team. If someone has already clicked or entered information, they should report that promptly as well, without experimenting further with the link. The responsible team assesses the incident and follows the internal response procedure.

Evaluation: Did the participant pause the payment change, verify it independently and report it? Was the report received and handled? Record scenario version, audience, observation window and follow-up learning. Exercises should not collect real passwords or execute production payment orders. This is an illustrative aid, not a completed customer test or evidence of prevented losses.

How are security awareness measures for data protection and compliance implemented?

Development of training modules on GDPR, ISO 27001, TISAX, and industry-specific requirements. Use of practical examples and real incidents tailored to each target group. Integration of data protection into all awareness and compliance processes. Use of compliance dashboards for real-time monitoring. Regular review and adaptation of content to reflect new laws and standards. Policy Enforcement & Auditing: Teaching privacy rules through specific processing scenarios; technical policy checks provide complementary controls. Integration of compliance checks into all awareness processes. Use of audit trails and logs for forensic analysis. Review of privacy safeguards by responsible specialists; technical testing has a separate scope. Integration of lessons learned from audits and incidents into continuous improvement processes. Performance Measurement & Reporting: Measurement of participation, learning outcomes, and behavioral change. Use of dashboards for real-time monitoring and trend analysis. Generation of compliance and audit reports for management and regulatory authorities. Integration with HR and compliance systems for enterprise-wide scalability. Regular review and adaptation of performance measurement processes. Integration & Corporate Culture: Embedding data protection into processes, systems, and corporate culture. Involvement of managers and multipliers as role models.

Privacy in measurement: Before using a platform or simulation, agree the purpose, lawful basis, necessary data, access rights and retention with the responsible specialists; involve privacy staff and employee representatives where applicable. Do not collect real passwords. Separate aggregate programme evaluation from any necessary individual completion evidence. Public rankings or naming and shaming do not support an open reporting culture.

How are security awareness measures for cloud, mobile, and remote work implemented?

Development of training modules on cloud security, the Shared Responsibility Model, and compliance. Use of practical examples and real incidents tailored to each target group. Integration of cloud awareness into all IT and business processes. Use of compliance dashboards for real-time monitoring. Regular review and adaptation of content to reflect new cloud technologies. Mobile & BYOD Awareness: Development of training modules on mobile security, BYOD, and application security. Use of practical examples and real incidents tailored to each target group. Integration of mobile awareness into all IT and business processes. Use of compliance dashboards for real-time monitoring. Regular review and adaptation of content to reflect new mobile technologies. Remote Work & Home Office: Development of training modules on remote work, home office, and secure working environments. Use of practical examples and real incidents tailored to each target group. Integration of remote awareness into all IT and business processes. Use of compliance dashboards for real-time monitoring. Regular review and adaptation of content to reflect new remote technologies.

How are security awareness measures for incident response and crisis management implemented?

🚨 Incident Response Awareness:

• Development of training modules on incident response, emergency management, and crisis communication.
• Use of practical examples and real incidents tailored to each target group.
• Integration of incident response into all awareness and compliance processes.
• Use of compliance dashboards for real-time monitoring.
• Regular review and adaptation of content to address new threats.

🛡 ️ Policy Enforcement & Auditing:

• Practising reporting routes, responsibilities and escalation using the approved incident-response plan.
• Integration of compliance checks into all awareness processes.
• Use of audit trails and logs for forensic analysis.
• Review of response exercises and incidents; technical attack testing is a separate scope.
• Integration of lessons learned from audits and incidents into continuous improvement processes.

📈 Performance Measurement & Reporting:

• Measurement of participation, learning outcomes, and behavioral change.
• Use of dashboards for real-time monitoring and trend analysis.
• Generation of compliance and audit reports for management and regulatory authorities.
• Integration with HR and compliance systems for enterprise-wide scalability.
• Regular review and adaptation of performance measurement processes.

🔗 Integration & Corporate Culture:

• Embedding incident response into processes, systems, and corporate culture.
• Involvement of managers and multipliers as role models.
• Promotion of an open error-reporting and incident-reporting culture.
• Integration of incident response into onboarding, change, and project management.
• Regular communication and campaigns to raise awareness.

💡 Expert Tip:

Incident response and crisis management awareness are critical to sustainable information security. Organizations should build on open standards, automation, and continuous improvement.

How are security awareness measures implemented for suppliers, partners, and external service providers?

🤝 Third-Party Awareness:

• Development of awareness programs for suppliers, partners, and external service providers.
• Integration of awareness requirements into contracts and SLAs.
• Conduct of training, simulations, and audits for third parties.
• Use of compliance dashboards for real-time monitoring.
• Regular review and adaptation of programs to address new risks.

🔗 Integration & Communication:

• Inclusion of third parties in all relevant awareness and compliance processes.
• Use of multi-language LMS and awareness platforms.
• Personalized communication and feedback channels.
• Involvement of managers and multipliers as role models.
• Promotion of an open error-reporting and incident-reporting culture.

🛡 ️ Compliance & Auditing:

• Central records support assessment of applicable requirements; they do not by themselves prove complete compliance.
• Integration of compliance checks into all third-party processes.
• Use of audit trails and logs for forensic analysis.
• Review of mapped requirements and evidence; technical testing does not replace compliance assessment.
• Integration of lessons learned from audits and incidents into continuous improvement processes.

📈 Performance Measurement & Reporting:

• Measurement of participation, learning outcomes, and behavioral change among third parties.
• Use of dashboards for real-time monitoring and trend analysis.
• Generation of compliance and audit reports for management and regulatory authorities.
• Integration with HR and compliance systems for enterprise-wide scalability.
• Regular review and adaptation of performance measurement processes.

💡 Expert Tip:

Awareness programs for third parties are critical to sustainable information security. Organizations should build on open standards, automation, and continuous improvement.

How are security awareness measures for new technologies and emerging threats implemented?

Development of awareness programs addressing new technologies such as AI, IoT, blockchain, and quantum computing.

Use of threat intelligence and security news for awareness campaigns. Use of simulation tools for automated execution and evaluation. Regular review and adaptation of content to reflect new technologies. Involvement of managers and IT teams in the training process. Integration & Corporate Culture: Embedding future awareness into processes, systems, and corporate culture. Development of awareness guidelines and processes for new technologies. Integration of future awareness into onboarding, change, and project management. Regular communication and campaigns to raise awareness. Promotion of an open error-reporting and incident-reporting culture. Compliance & Auditing: Central records support assessment of applicable requirements; they do not by themselves prove complete compliance. Integration of compliance checks into all future awareness processes. Use of audit trails and logs for forensic analysis. Review of mapped requirements and evidence; technical testing does not replace compliance assessment. Integration of lessons learned from audits and incidents into continuous improvement processes. Performance Measurement & Reporting: Measurement of participation, learning outcomes, and behavioral change related to new technologies.

How are security awareness measures for crisis management and business continuity implemented?

🚨 Crisis Management Awareness:

• Development of training modules on crisis management, emergency management, and business continuity.
• Use of practical examples and real incidents tailored to each target group.
• Integration of crisis management into all awareness and compliance processes.
• Use of compliance dashboards for real-time monitoring.
• Regular review and adaptation of content to address new threats.

🛡 ️ Policy Enforcement & Auditing:

• Practising decisions, deputies and emergency communication using approved crisis plans.
• Integration of compliance checks into all awareness processes.
• Use of audit trails and logs for forensic analysis.
• Reviewing crisis procedures through exercises and debriefs; technical tests do not replace these.
• Integration of lessons learned from audits and incidents into continuous improvement processes.

📈 Performance Measurement & Reporting:

• Measurement of participation, learning outcomes, and behavioral change.
• Use of dashboards for real-time monitoring and trend analysis.
• Generation of compliance and audit reports for management and regulatory authorities.
• Integration with HR and compliance systems for enterprise-wide scalability.
• Regular review and adaptation of performance measurement processes.

🔗 Integration & Corporate Culture:

• Embedding crisis management into processes, systems, and corporate culture.
• Involvement of managers and multipliers as role models.
• Promotion of an open error-reporting and incident-reporting culture.
• Integration of crisis management into onboarding, change, and project management.
• Regular communication and campaigns to raise awareness.

💡 Expert Tip:

Crisis management and business continuity awareness are critical to sustainable information security. Organizations should build on open standards, automation, and continuous improvement.

Certificates, partners and more

ISO 9001 CertifiedISO 27001 CertifiedISO 14001 CertifiedBeyondTrust PartnerBVMW Bundesverband MitgliedMitigant PartnerGoogle PartnerTop 100 InnovatorMicrosoft AzureAmazon Web Services

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

Ready for the next step?

Schedule a strategic consultation with our experts now

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

Your strategic goals and challenges
Desired business outcomes and ROI expectations
Current compliance and risk situation
Stakeholders and decision-makers in the project

Prefer direct contact?

Direct hotline for decision-makers

Strategic inquiries via email

Detailed Project Inquiry

For complex inquiries or if you want to provide specific information in advance