Security Awareness Training · Research-based
Whether people click is decided by the interplay of overconfidence, context-message fit, distraction and stress — not by a knowledge gap. Our science-based security awareness training targets exactly that: comic-based, with audit-ready documentation, as cloud or SCORM 1.2 in your own LMS.
Including blue collar and deskless teams. Completely free to test.
The industry treats every phishing click as a knowledge gap: more mandatory videos, more campaigns, more tests. Research paints a different picture — people rarely click because they don't know better.
“I'd never fall for that.” That very confidence is what makes people vulnerable: those who feel safe stop checking. Our doctoral research on overconfidence in phishing is the core of our didactics.
A phishing email works because it lands in the right work context at the right moment: the invoice in accounting, the parcel notice in logistics. Effective training works with these situations — not with abstract checklists.
Most clicks happen on the side — between two meetings, on a phone. When the brain runs on autopilot, knowledge doesn't help much. That's why we train intuitive recognition through storytelling and repetition.
Under time pressure and heavy workload, the brain takes shortcuts: get it done fast instead of checking closely. That's exactly what attackers target with artificial urgency. Safe behavior has to hold up under stress.
None of these factors acts alone — and none of them stops at phishing: attackers use the same mechanisms in vishing, deepfakes and social engineering. That's why Webguardiola doesn't just close knowledge gaps, but trains the entire human attack surface — calibrating self-assessment, sharpening situational awareness, anchoring intuitive recognition. Built on cognitive psychology and storytelling, on ongoing university research — and, if you choose, measurable in your own organization.
Holistic, not just phishing: interactive modules with comic heroes, games and quizzes — from password security and social engineering to AI risks and shadow IT, complemented by the Security Heroes podcast for learning on the go. Designed so the knowledge actually sticks. New: a dedicated NIS2 training for all employees.
Password security · phishing & social engineering · social media & vishing
Clean desk · mobile working · physical access · AI & shadow IT
Dedicated training on the NIS2 obligations (Art. 20 & 21) — for all employees, from management to blue-collar teams.
Compact 30-minute training on the governing bodies' training obligation (Art. 20(2)) — with documented proof of participation. To the management training →
Not checkbox training. Measurable impact on four levels.
Real behavioral change through storytelling, not compliance videos. Employees intuitively recognize phishing, social engineering and risky situations — and warn each other.
Cloud access via email OTP or SCORM package into your LMS — no IT project, no software rollout needed.
Documented training records, certificates and company reports — ready for ISO 27001, TISAX or NIS2 audits.
Comic stories instead of compliance videos: training employees actually finish — less chasing, fewer reminder emails, more voluntary participation.
Servers in Frankfurt. GDPR compliant.
Data processing agreements with all providers.
Developed based on university research. Cognitive psychology & storytelling.
Login via email code. No password, no account risk.
Most training only protects office teams on laptops. Attackers don't stop there. We protect the entire human attack surface around your company.
Manufacturing, logistics, retail, field service — employees without a company laptop or email are left out by classic training. Ours is 100% mobile, works on personal phones and only needs an email code to log in.
NIS2 also puts supply chain risk into sharper focus. Your suppliers and partners — often SMEs without a security budget — can use the free training directly or receive sponsored access.
It only depends on whether you run your own LMS.
Employees sign up with company email. Login via email code. Zero IT effort.
SCORM 1.2 package for SuccessFactors, Moodle or any LMS. Always up to date.
SCORM package & programs in detail →Office teams via SCORM in the LMS, blue collar & supply chain via cloud access without company email. Both in parallel.
Status quo and change: measure how your organization's security knowledge and self-assessment develop through the training — anonymized, without personal data, based on our doctoral research.
Impact measurement in detail →No option is "better" — all that matters is whether you run your own LMS. The learning content is identical in every case.
NIS2 (Art. 20 & 21) puts cybersecurity training for management and employees into sharper focus. Webguardiola supports companies in meeting these requirements — as cloud training or in your own LMS. With science-based e-learning, documented training records and certificates. For the governing bodies' training obligation (Art. 20(2)) there is a dedicated 30-minute management training. Questions? Contact →
Free forever for individuals. For companies, we set everything up after you've tested it.
Webguardiola cloud platform
Ongoing program · based on team size
How it works: Test the complete training for free. Convinced? Then get in touch — and we set everything up for your company (audit evaluations, NIS2/ISO records, SCORM, podcast files, awareness posters).
You've seen the complete training. In a short call we cover audit evaluations, NIS2 & ISO 27001, SCORM for your own LMS and the podcast files for your network — and set everything up for your company.
A short email is enough. What would you like to discuss?
Or write directly to hello@webguardiola.com
Concise updates on current phishing tactics, awareness practice and new modules. No spam, unsubscribe anytime.