ISMS awareness
What your ISMS is for, how it works and what it means for each person.
Cybersecurity & compliance
People follow rules they understand. Our training connects information security to your real policies, systems, risks and responsibilities — so employees know not only what to do, but why.
We combine fundamentals with content tailored to your environment. Typical modules:
What your ISMS is for, how it works and what it means for each person.
What employees, managers, process owners and system owners are responsible for.
Recognizing manipulation — by email, phone, messenger or QR code.
Passwords, password managers, multi-factor authentication and why they matter.
Classification, sharing and storing sensitive information in your systems.
What to report, how, to whom — and why reporting early is always right.
Secure work from home, on the road and on mobile devices.
Which AI tools are allowed, what information may be entered and why.
Policies, systems, risks, incidents and the audiences involved.
Examples from your tools and processes instead of generic scenarios.
Workshops on site or remote, sessions for specific roles, material for onboarding.
Participation and competence records that fit your ISMS.
Regular updates based on new risks, incidents and changes.
Compliance works better when people understand why it exists
Training is part of knowledge transfer. The goal is not a completion rate, but people who make better security decisions in their daily work.
Security awareness training helps employees recognize and handle information security risks in their daily work — for example phishing, handling sensitive data, secure authentication and reporting incidents. ISO/IEC 27001 and NIS2 both expect organizations to build awareness and competence.
Our focus is training connected to your real environment. If phishing simulations make sense for you, we help you choose an appropriate approach or tool and integrate the results into your awareness program.
Yes. We deliver training in German and English, on site or remotely.
Build a working ISMS and prepare for ISO/IEC 27001 certification — together with your team and on top of the tools you already use.
Ongoing support for an existing ISMS: risks, controls, evidence, audits and reviews that keep happening — not just before the audit.
Develop a clear incident response plan with your team: roles, escalation, communication, reporting and lessons learned.
How to implement ISO 27001 step by step: scope, gap analysis, risk assessment, SoA, measures, internal audit and certification — realistically explained.
What an information security management system (ISMS) is, what it consists of, how it relates to ISO/IEC 27001 — and why it is more than a set of documents.
Fake official letters with manipulated QR codes target young adults in Germany. How quishing works, how to recognize fakes and what to do if you suspect fraud.
Tell us about your teams, tools and goals — we will suggest a format.