Complete training · free to test
NIS2 · ISO 27001 · SCORM · EU-Hosting

Security Awareness Training · Research-based

Everyone knows what phishing is. People still click.

The approach

Whether people click is decided by the interplay of overconfidence, context-message fit, distraction and stress — not by a knowledge gap. Our science-based security awareness training targets exactly that: comic-based, with audit-ready documentation, as cloud or SCORM 1.2 in your own LMS.

Reaches everyone

Including blue collar and deskless teams. Completely free to test.

Test complete training → Talk business →
GDPR compliant
Supports NIS2 training duties
Research-based · SCORM 1.2
Audit-ready for NIS2DORAISO 27001DSGVOSCORM 1.2
I · The science behind it

Why most awareness programs fail to change behavior.

The industry treats every phishing click as a knowledge gap: more mandatory videos, more campaigns, more tests. Research paints a different picture — people rarely click because they don't know better.

Overconfidence Bias

“I'd never fall for that.” That very confidence is what makes people vulnerable: those who feel safe stop checking. Our doctoral research on overconfidence in phishing is the core of our didactics.

Doctoral researchSelf-assessment

Context-Message-Fit

A phishing email works because it lands in the right work context at the right moment: the invoice in accounting, the parcel notice in logistics. Effective training works with these situations — not with abstract checklists.

Real scenariosContext over checklists

Distraction & Autopilot

Most clicks happen on the side — between two meetings, on a phone. When the brain runs on autopilot, knowledge doesn't help much. That's why we train intuitive recognition through storytelling and repetition.

Intuitive recognitionStorytelling

Workload & Stress

Under time pressure and heavy workload, the brain takes shortcuts: get it done fast instead of checking closely. That's exactly what attackers target with artificial urgency. Safe behavior has to hold up under stress.

Time pressureSpotting urgency

None of these factors acts alone — and none of them stops at phishing: attackers use the same mechanisms in vishing, deepfakes and social engineering. That's why Webguardiola doesn't just close knowledge gaps, but trains the entire human attack surface — calibrating self-assessment, sharpening situational awareness, anchoring intuitive recognition. Built on cognitive psychology and storytelling, on ongoing university research — and, if you choose, measurable in your own organization.

II · Training content

7 modules. Certificate. Documented training proof.

Holistic, not just phishing: interactive modules with comic heroes, games and quizzes — from password security and social engineering to AI risks and shadow IT, complemented by the Security Heroes podcast for learning on the go. Designed so the knowledge actually sticks. New: a dedicated NIS2 training for all employees.

Screenshot from Part 1 of the Webguardiola training: fundamentals modules on password security, phishing and social engineering
Part 1 — Fundamentals

Password security · phishing & social engineering · social media & vishing

Screenshot from Part 2 of the Webguardiola training: advanced modules on clean desk, mobile working and shadow IT
Part 2 — Advanced

Clean desk · mobile working · physical access · AI & shadow IT

Preview of the NIS2 training for all employees
New · NIS2 Training

Dedicated training on the NIS2 obligations (Art. 20 & 21) — for all employees, from management to blue-collar teams.

Preview of the compact NIS2 training for management and governing bodies
New · NIS2 for Leadership

Compact 30-minute training on the governing bodies' training obligation (Art. 20(2)) — with documented proof of participation. To the management training →

Test complete training →
III · Outcomes, not features

What actually changes for your company

Not checkbox training. Measurable impact on four levels.

Less human risk

Real behavioral change through storytelling, not compliance videos. Employees intuitively recognize phishing, social engineering and risky situations — and warn each other.

Less effort for HR & IT

Cloud access via email OTP or SCORM package into your LMS — no IT project, no software rollout needed.

Better audit documentation

Documented training records, certificates and company reports — ready for ISO 27001, TISAX or NIS2 audits.

Engagement, not obligation

Comic stories instead of compliance videos: training employees actually finish — less chasing, fewer reminder emails, more voluntary participation.

EU/EEA Hosting

Servers in Frankfurt. GDPR compliant.

DPA available

Data processing agreements with all providers.

Research-based

Developed based on university research. Cognitive psychology & storytelling.

Passwordless

Login via email code. No password, no account risk.

IV · Our difference

Security doesn't end at the desk.

Most training only protects office teams on laptops. Attackers don't stop there. We protect the entire human attack surface around your company.

Blue Collar & Deskless Workers

Manufacturing, logistics, retail, field service — employees without a company laptop or email are left out by classic training. Ours is 100% mobile, works on personal phones and only needs an email code to log in.

Fully responsiveNo company laptop needed

Supply Chain & Partner SMEs

NIS2 also puts supply chain risk into sharper focus. Your suppliers and partners — often SMEs without a security budget — can use the free training directly or receive sponsored access.

Supply chain awarenessFree for partners
For Companies

Cloud or your own LMS — your choice

It only depends on whether you run your own LMS.

Without your own LMS

Use Cloud

Employees sign up with company email. Login via email code. Zero IT effort.

With your own LMS

Integrate into your LMS

SCORM 1.2 package for SuccessFactors, Moodle or any LMS. Always up to date.

SCORM package & programs in detail →
Both in parallel

Combine hybrid

Office teams via SCORM in the LMS, blue collar & supply chain via cloud access without company email. Both in parallel.

Optional with the SCORM package

Impact measurement

Status quo and change: measure how your organization's security knowledge and self-assessment develop through the training — anonymized, without personal data, based on our doctoral research.

Impact measurement in detail →

No option is "better" — all that matters is whether you run your own LMS. The learning content is identical in every case.

The right answer for every decision-maker

HR & People

Easy rollout, high acceptance

  • Comic format instead of compliance videos — employees actually engage
  • No training room needed — everyone learns at their own pace
  • Certificates and training records generated automatically
IT & Security

Secure content, zero IT effort

  • SCORM 1.2 or cloud — you keep control of your data
  • SCORM package — no software rollout, no new platform
  • Passwordless access — no account management needed
Compliance & Audit

Documented proof, ready-made reporting

  • Documented training proof as PDF (NIS2 context)
  • Company report with vulnerability analysis per topic area
  • Industry comparison for management reporting

NIS2: Awareness & training obligations in focus

NIS2 (Art. 20 & 21) puts cybersecurity training for management and employees into sharper focus. Webguardiola supports companies in meeting these requirements — as cloud training or in your own LMS. With science-based e-learning, documented training records and certificates. For the governing bodies' training obligation (Art. 20(2)) there is a dedicated 30-minute management training. Questions? Contact →

Plans

Free to test — scale to your whole team.

Free forever for individuals. For companies, we set everything up after you've tested it.

Community · Individuals
Free forever

Webguardiola cloud platform

  • Part 1 + Part 2 training (DE + EN)
  • NIS2 training for all employees
  • All games & quizzes
  • Personal certificate
  • Security Heroes Podcast
  • Ideal for self-paced learning
Start free →

Learn more about the free security awareness training →

Business · Companies
Custom

Ongoing program · based on team size

  • Part 1 + Part 2 with certificates for all employees
  • NIS2 training (Art. 20 & 21) with documented proof
  • Dedicated company access & audit evaluations
  • Regular reports & tracking
  • Always latest modules & updates
  • Documented training records (NIS2, ISO 27001)
  • SCORM package for your LMS · mp3/mp4 podcasts for your network
  • Printable comic-style awareness posters
Request quote →

How it works: Test the complete training for free. Convinced? Then get in touch — and we set everything up for your company (audit evaluations, NIS2/ISO records, SCORM, podcast files, awareness posters).

FAQ

Frequently Asked Questions

No. We don't run phishing campaigns ourselves — nobody is covertly tested by us, and we process no employee data for this. For companies planning their own campaign, we provide advisory support on concept, design and evaluation: our research on overconfidence bias shows what makes a test trigger learning instead of distrust. This knowledge is also available as a dedicated e-learning for security professionals: running phishing campaigns the right way.
The didactics are based on university research in cognitive psychology and storytelling. We only introduce methods that have demonstrably proven themselves.
No. Without an LMS you use our cloud platform; with an LMS you receive the modules as SCORM 1.2. Neither option is better — it depends solely on your setup.
Practically none. Cloud access works via email code — no software rollout, no account management. For SCORM integration, simply upload the package to your LMS. Done.
Yes. Every employee receives a certificate. The Business package delivers ongoing, documented training records for NIS2, ISO 27001 or TISAX audits.
Yes. EU hosting in Frankfurt, DPA with all providers, passwordless access via email OTP. No sharing for third-party purposes — processing only with necessary data processors.
You receive a SCORM 1.2 package as ZIP. Upload it to your LMS (SuccessFactors, Moodle, Cornerstone, …) — content stays current via our CDN infrastructure.
We believe cybersecurity shouldn't be a luxury. The free training makes society safer. Companies that want an ongoing program with regular reports, audit records and new modules get in touch for the Business solution.
Yes, in the Business package. Logo, colors and company-specific scenarios are available.
Tested the training? Let's talk.

Ready to protect your team?

You've seen the complete training. In a short call we cover audit evaluations, NIS2 & ISO 27001, SCORM for your own LMS and the podcast files for your network — and set everything up for your company.

Get in touch

A short email is enough. What would you like to discuss?

  • Security awareness training for all employees
  • NIS2 training for all employees
  • NIS2 training for management & governing bodies
  • Audit evaluations
  • NIS2 / ISO 27001
  • SCORM for your own LMS
  • mp3/mp4 podcasts for your network
Inquiry by email →

Or write directly to hello@webguardiola.com

Security Awareness · Newsletter

Understand threats before they reach your team.

Concise updates on current phishing tactics, awareness practice and new modules. No spam, unsubscribe anytime.