Resources
In-depth articles, practical guides and templates on security awareness, phishing and behavior.
How to organise your support as a partner
ArticleWho handles support and service delivery depends on your sales model. From reseller (sales only) to white-label (sales, marketing, advice and support), and how…
How to avoid the pitfalls of white-label
ArticleYou cannot sell white-label awareness without mastering the platform and the subject yourself. The biggest pitfalls and how to avoid them, from ownership to…
What the shrinking time-to-exploit means for your organisation
ArticleThe time-to-exploit is shrinking from a year to just over a day, and possibly to hours. What that means for your IT, your organisation and your security…
How to get past the gatekeeper
ArticleGatekeeper objections are not solved with your full pitch but by getting to the right person, briefly and confidently. What to say to the six most common…
How to easily book a meeting
ArticleObjections when booking a meeting are handled by asking questions: an objection about the product is your opening, an objection about the meeting itself you…
Why white-label security awareness delivers more than you think
ArticleSecurity awareness white-label feels like a lot of work, but it gives you your own brand, the highest margin and the strongest customer loyalty. What it really…
How to sell security awareness to your customers
ArticleSelling security awareness is a consultative conversation, not a feature pitch. Follow six steps: understand the need first, present to it, and close apart…
How to become a security awareness reseller
ArticleWant to become a security awareness reseller? Compare the three sales models (reseller, managed service and white-label) and choose what fits your margin,…
What to do with a privacy request from a customer or colleague
ArticleSomeone asks what data you hold on them, or wants it deleted. What are data subjects' rights under the GDPR, and what do you, as an employee, do when such a…
Recognising personal data in your daily work
ArticlePrivacy starts with recognition. Once you know which data is personal data, you handle it more carefully by default. A practical guide for your daily work.
What is the GDPR and what does it mean for you?
ArticleThe GDPR is not a distant law for lawyers; it shapes how you handle data every day. What the GDPR asks of you in your daily work, in plain language.
Acceptable use policy (AUP): what it should cover
ArticlePractical guidance on acceptable use policy aup for organizations that want to improve secure behavior structurally.
Accidental data sharing: how to prevent it
ArticlePractical guidance on accidental data sharing for organizations that want to improve secure behavior structurally.
AI governance and awareness in one program
ArticlePractical guidance on AI governance awareness for organizations that want to improve secure behavior structurally.
API security awareness for end users
ArticlePractical guidance on api security awareness for end users for organizations that want to improve secure behavior structurally.
How to collect audit evidence for awareness
ArticlePractical guidance on audit evidence awareness for organizations that want to improve secure behavior structurally.
Awareness for HR and onboarding
ArticlePractical guidance on awareness for HR and onboarding for organizations that want to improve secure behavior structurally.
Behavior change in security awareness
ArticlePractical guidance on behavior change in security awareness for organizations that want to improve secure behavior structurally.
Board reporting and awareness in the public sector
ArticlePractical guidance on board reporting public sector awareness for organizations that want to improve secure behavior structurally.
Board reporting for awareness without noise
ArticlePractical guidance on board reporting awareness for organizations that want to improve secure behavior structurally.
Connecting breach reporting and awareness
ArticlePractical guidance on breach reporting awareness for organizations that want to improve secure behavior structurally.
How to build a security culture
ArticlePractical guidance on security culture for organizations that want to improve secure behavior structurally.
Business email compromise explained
ArticlePractical guidance on business email compromise for organizations that want to improve secure behavior structurally.
How to choose security awareness content
ArticlePractical guidance on choose security awareness content for organizations that want to improve secure behavior structurally.
Clean desk policy explained
ArticlePractical guidance on clean desk policy for organizations that want to improve secure behavior structurally.
Cloud security basics for end users
ArticlePractical guidance on cloud security basics for end users for organizations that want to improve secure behavior structurally.
Common data breach scenarios in organizations
ArticlePractical guidance on common data breach scenarios for organizations that want to improve secure behavior structurally.
What are the most common security mistakes employees make?
ArticlePractical guidance on common security mistakes employees make for organizations that want to improve secure behavior structurally.
Which compliance requirements mandate security awareness training?
ArticlePractical guidance on compliance requirements security awareness training for organizations that want to improve secure behavior structurally.
What happens when employees skip security training?
ArticlePractical guidance on consequences employees skipping security training for organizations that want to improve secure behavior structurally.
Data protection and privacy: GDPR essentials for employees
ArticlePractical guidance on data protection and privacy gdpr for organizations that want to improve secure behavior structurally.
Device security basics
ArticlePractical guidance on device security basics for organizations that want to improve secure behavior structurally.
What is the difference between security training and compliance training?
ArticlePractical guidance on difference security training and compliance training for organizations that want to improve secure behavior structurally.
DORA for financial institutions, what awareness means
ArticlePractical guidance on dora awareness for organizations that want to improve secure behavior structurally.
Email security and social engineering: what employees need to know
ArticlePractical guidance on email security and social engineering for organizations that want to improve secure behavior structurally.
Employee incident response explained
ArticlePractical guidance on employee incident response for organizations that want to improve secure behavior structurally.
How do I get employees to actually take security training?
ArticlePractical guidance on getting employees to take security training for organizations that want to improve secure behavior structurally.
Healthcare information security awareness across European member states
ArticlePractical guidance on healthcare information security awareness europe for organizations that want to improve secure behavior structurally.
How long should security training take?
ArticlePractical guidance on how long security training for organizations that want to improve secure behavior structurally.
How much does security awareness elearning cost?
ArticlePractical guidance on how much does security awareness elearning cost for organizations that want to improve secure behavior structurally.
How often should employees take security training?
ArticlePractical guidance on how often security training for organizations that want to improve secure behavior structurally.
How do phishing simulations work in training?
ArticlePractical guidance on how phishing simulations work for organizations that want to improve secure behavior structurally.
How to build a security awareness program
ArticlePractical guidance on build a security awareness program for organizations that want to improve secure behavior structurally.
How to choose a security awareness platform
ArticlePractical guidance on choose a security awareness platform for organizations that want to improve secure behavior structurally.
How to engage employees in security awareness
ArticlePractical guidance on how to engage employees in security awareness for organizations that want to improve secure behavior structurally.
How to measure security awareness
ArticlePractical guidance on how to measure security awareness for organizations that want to improve secure behavior structurally.
How to spot CEO fraud and prevent it
ArticlePractical guidance on how to spot CEO fraud for organizations that want to improve secure behavior structurally.
Incident reporting without blame
ArticlePractical guidance on incident reporting without blame for organizations that want to improve secure behavior structurally.
Recognizing insider risk signals early
ArticlePractical guidance on insider risk signals for organizations that want to improve secure behavior structurally.
ISO 27001 awareness requirements explained
ArticlePractical guidance on ISO 27001 awareness requirements for organizations that want to improve secure behavior structurally.
Why a leadership video after phishing creates more impact
ArticlePractical guidance on leadership video phishing simulation for organizations that want to improve secure behavior structurally.
Localizing security awareness content
ArticlePractical guidance on localizing security awareness content for organizations that want to improve secure behavior structurally.
Lost devices and reporting duties
ArticlePractical guidance on lost devices reporting for organizations that want to improve secure behavior structurally.
How do I make security training engaging?
ArticlePractical guidance on making security training engaging for organizations that want to improve secure behavior structurally.
Microlearning for employees with limited time
ArticlePractical guidance on microlearning for employees for organizations that want to improve secure behavior structurally.
NIS2 awareness for healthcare organizations
ArticlePractical guidance on NIS2 awareness healthcare for organizations that want to improve secure behavior structurally.
NIS2 board training obligation across European member states
ArticlePractical guidance on nis2 board training obligation europe for organizations that want to improve secure behavior structurally.
NIS2 roles and responsibilities around awareness
ArticlePractical guidance on NIS2 roles awareness for organizations that want to improve secure behavior structurally.
NIS2 transposition across European member states
ArticlePractical guidance on nis2 transposition europe for organizations that want to improve secure behavior structurally.
Password management best practices
ArticlePractical guidance on password management best practices for organizations that want to improve secure behavior structurally.
Safe payment verification procedures
ArticlePractical guidance on payment verification procedures for organizations that want to improve secure behavior structurally.
Phishing and account abuse in education
ArticlePractical guidance on phishing education for organizations that want to improve secure behavior structurally.
Phishing follow-up in the public sector
ArticlePractical guidance on phishing follow-up public sector for organizations that want to improve secure behavior structurally.
Phishing KPIs that actually matter
ArticlePractical guidance on phishing KPIs for organizations that want to improve secure behavior structurally.
Phishing red flags employees should know
ArticlePractical guidance on phishing red flags for organizations that want to improve secure behavior structurally.
Phishing risks in healthcare: what you should and should not measure
ArticlePractical guidance on phishing risks healthcare for organizations that want to improve secure behavior structurally.
Physical security awareness in the workplace
ArticlePractical guidance on physical security awareness for organizations that want to improve secure behavior structurally.
QR phishing and physical social engineering
ArticlePractical guidance on qr phishing for organizations that want to improve secure behavior structurally.
Ransomware and employee behavior
ArticlePractical guidance on ransomware employee behavior for organizations that want to improve secure behavior structurally.
Incident lessons from remote work
ArticlePractical guidance on remote work incident lessons for organizations that want to improve secure behavior structurally.
How to choose between SCORM and a standalone awareness platform
ArticlePractical guidance on scorm vs standalone awareness platform for organizations that want to improve secure behavior structurally.
How to secure the mobile workplace
ArticlePractical guidance on secure the mobile workplace for organizations that want to improve secure behavior structurally.
Security awareness and customer trust
ArticlePractical guidance on security awareness customer trust for organizations that want to improve secure behavior structurally.
A communication plan for security awareness
ArticlePractical guidance on security awareness communication plan for organizations that want to improve secure behavior structurally.
Security awareness elearning vs standalone training
ArticleComparison for organizations choosing between a structural elearning approach and standalone awareness sessions.
Security awareness for government and municipalities
ArticlePractical guidance on security awareness government for organizations that want to improve secure behavior structurally.
Security awareness for IT service providers and resellers
ArticlePractical guidance on security awareness IT service providers for organizations that want to improve secure behavior structurally.
Security awareness in education
ArticlePractical guidance on security awareness education for organizations that want to improve secure behavior structurally.
Security awareness in healthcare
ArticlePractical guidance on security awareness healthcare for organizations that want to improve secure behavior structurally.
Why security awareness lands faster in private life
ArticlePractical guidance on security awareness private life for organizations that want to improve secure behavior structurally.
Security awareness KPIs for CISOs
ArticlePractical guidance on security awareness KPIs for organizations that want to improve secure behavior structurally.
Getting management buy-in for security awareness
ArticlePractical guidance on security awareness management buy-in for organizations that want to improve secure behavior structurally.
Security awareness onboarding for teachers and staff
ArticlePractical guidance on security awareness onboarding education for organizations that want to improve secure behavior structurally.
Security awareness roadmap for 12 months
ArticlePractical guidance on security awareness roadmap for organizations that want to improve secure behavior structurally.
Security awareness vendor selection: the right questions
ArticlePractical guidance on security awareness vendor selection for organizations that want to improve secure behavior structurally.
Which security topics matter most for executives and boards?
ArticlePractical guidance on security topics for executives and boards for organizations that want to improve secure behavior structurally.
Shadow IT risks for awareness and governance
ArticlePractical guidance on shadow IT risks for organizations that want to improve secure behavior structurally.
Should security training be mandatory?
ArticlePractical guidance on should security training be mandatory for organizations that want to improve secure behavior structurally.
Why small behavior interventions often have bigger impact
ArticlePractical guidance on behavior interventions security awareness for organizations that want to improve secure behavior structurally.
Smishing and vishing risks are growing
ArticlePractical guidance on smishing and vishing for organizations that want to improve secure behavior structurally.
Spear phishing examples from real organizations
ArticlePractical guidance on spear phishing examples for organizations that want to improve secure behavior structurally.
Which topics should a security training cover?
ArticlePractical guidance on topics security training employees for organizations that want to improve secure behavior structurally.
How do I track which employees have completed training?
ArticlePractical guidance on tracking security training completion for organizations that want to improve secure behavior structurally.
Vendor fraud by email explained
ArticlePractical guidance on vendor fraud for organizations that want to improve secure behavior structurally.
What is NIS2 awareness?
ArticlePractical guidance on what is NIS2 awareness for organizations that want to improve secure behavior structurally.
What is phishing?
ArticlePractical guidance on what is phishing for organizations that want to improve secure behavior structurally.
What is security awareness?
ArticlePractical guidance on what is security awareness for organizations that want to improve secure behavior structurally.
What is security awareness elearning?
ArticleDefinition and practical guidance for teams that want to understand when elearning fits within an awareness approach.
Why awareness programs fail
ArticlePractical guidance on why awareness programs fail for organizations that want to improve secure behavior structurally.
Why employees click on phishing
ArticlePractical guidance on why employees click on phishing for organizations that want to improve secure behavior structurally.
Why phishing simulations work
ArticlePractical guidance on why phishing simulations work for organizations that want to improve secure behavior structurally.
How to write a security awareness policy
ArticlePractical guidance on security awareness policy for organizations that want to improve secure behavior structurally.
Why security awareness collapses during busy periods
ArticleAwareness does not collapse because of busyness, but because of plans that pretend the busyness does not exist. How to plan smarter, not do more.
Awareness programmes fail without a risk analysis
ArticleIf you train on everything, nobody learns what really matters. Why role-based segmentation, built on a risk analysis, makes awareness shorter, sharper and more…
The pitfall of the baseline survey in awareness
ArticleA baseline nobody dares to discuss is not a measurement but a reckoning. Why a baseline survey only works when it feels safe, and how to turn it into a…
Cyber charlatans: beware of fear sellers in awareness
ArticleWhoever sells awareness with fear sells not safety but dependence. How to recognise fear sellers and why real awareness builds competence, not panic.
Employees are more digitally skilled than you think
ArticleNever underestimate your employees' digital skill, at most underestimate how poorly we sometimes explain things. Treat people as professionals and your weakest…
External sender warning in Exchange: how effective is the banner?
ArticleAn external-sender banner interrupts autopilot, but its effect fades through habituation and a false sense of safety. How to weigh and design it, and what…
When gamification works in awareness
ArticlePractical guidance on gamification in awareness for organizations that want to improve secure behavior structurally.
Awareness does not work without management involvement
ArticleWithout visible leadership, every awareness programme stays non-committal. Why top-down example sets the tone, what visible leadership looks like, and how to…
How to recognize MFA fatigue attacks
ArticlePractical guidance on MFA fatigue attacks for organizations that want to improve secure behavior structurally.
NIS2 awareness checklist for organizations
ArticlePractical guidance on NIS2 awareness checklist for organizations that want to improve secure behavior structurally.
Safe Links in Exchange (Safe URLs): why URL rewriting is false security
ArticleSafe Links (Safe URLs) in Exchange rewrites links for time-of-click scanning, but it hides the real destination and breeds false security. Read the dilemmas…
Security awareness in onboarding new employees
ArticleThe most underrated awareness opportunity is onboarding. Why the first weeks set the tone, why a simple welcome video beats a glossy e-learning, and how it…
Security awareness stays 'an IT thing'
ArticleSecurity feels technical until you show it happens in your own pocket every day. Why recognition, not technology, drives behaviour change, and how to make…
Security awareness ROI: what does it actually deliver?
ArticlePractical guidance on security awareness ROI for organizations that want to improve secure behavior structurally.
Supplier security awareness in the supply chain
ArticlePractical guidance on supplier security awareness for organizations that want to improve secure behavior structurally.
When a VPN for employees does and doesn't help
ArticlePractical guidance on vpn for employees for organizations that want to improve secure behavior structurally.
When gamification in awareness backfires
ArticleGamification only motivates when the game is about safety, not about points. Why the score can crowd out safe behaviour, and how to use game elements well.
When phishing simulations backfire
ArticleA phishing simulation that humiliates does not train alertness but distrust of the employer. Why simulations should teach, not catch, and why the report rate…
Why employees do not report security incidents
ArticleAn employee who does not report is not a risk but a symptom of a culture that punishes. Why reporting must be easy and safe, and how to build a reporting…
Why security awareness often fails
ArticleWhen fewer than 1% of staff take part, it is rarely the training content. Awareness is change management: meaning, leadership and rhythm decide whether it…
The Canvas/Instructure breach: supplier risk and cloud dependency in education
ArticleIn May 2026 an attack on the Canvas learning platform (Instructure) hit hundreds of millions of users worldwide, including seven Dutch universities. The…
The ChipSoft attack: what a supplier hack means for your awareness programme
ArticleIn April 2026 a ransomware attack hit ChipSoft, the supplier of the electronic patient record used by around 70% of Dutch hospitals. The lesson: you are only…
Epe municipality: why a national ID number and an ID copy are gold for criminals
ArticleIn the hack on the Dutch municipality of Epe (March 2026), data on nearly all residents was stolen, including national ID numbers and copies of identity…
Marks & Spencer and Scattered Spider: the help desk as front door
ArticleIn 2025 the group Scattered Spider crippled Marks & Spencer — not through an exploit, but by calling the IT help desk and asking for a password reset. The…
The Odido breach: how one phone call to customer service exposed 6 million people
ArticleIn February 2026, attackers combined a phishing email with a fake IT phone call to break into Dutch telecom provider Odido. The awareness lesson: customer…
Implementing multi-factor authentication in your organisation
GuideMulti-factor authentication is one of the most effective measures against account takeover. This is how to roll it out step by step, without too much friction…
The six legal bases for processing personal data
ArticleYou cannot just process personal data: you need a legal basis. The six legal bases of the GDPR explained, with practical examples.
Recognising personal data: what counts and what doesn't?
ArticleNames and addresses are not the only personal data. Learn to recognise what falls under the GDPR, including less obvious examples like IP addresses and licence…
Special category data: extra protection, extra rules
ArticleHealth, religion and biometrics are special category data. Which categories exist, why they get extra protection, and how to handle them in practice.
What is the GDPR? The basics in plain language
ArticleThe GDPR in plain language: what the law is, who it applies to, and which principles shape your daily work with personal data.
Data classification and the need-to-know principle
ArticleNot all data needs the same protection. How classification and the need-to-know principle help share the right data with the right people.
Data minimisation in practice: collect only what you need
ArticleThe less data you have, the less can leak. Data minimisation explained, with practical examples for forms, email and storage.
Securely destroying data: paper, drives and cloud data
ArticleDeleting is not the same as destroying, and not all data may simply be thrown away. How to make paper, drives and cloud data truly unreadable, and how legal…
CIA triad versus the GDPR: integrity and confidentiality, twice
ArticleInformation security uses the CIA triad; the GDPR names integrity and confidentiality as a principle. The same words, a different scope. The difference…
Data subject rights: access, rectification and erasure
ArticlePeople have rights over their own data. Which rights the GDPR grants, what a request means for you, and how to handle it correctly.
Privacy by design and by default: privacy from the start
ArticlePrivacy is not arranged afterwards, but from the start. What privacy by design and by default mean, and how to apply them in projects and daily choices.
Recognising and preventing identity theft
ArticleIn identity theft, someone uses your data to impersonate you. How it works, how to recognise it, and what to do if it happens to you.
Privacy implications of AI-driven platforms
ArticleAI platforms often process large amounts of personal data. What privacy risks this brings, what the GDPR and the AI Act require, and which agreements employees…
ISO/IEC 27002:2022 updated: what does it mean for your security awareness programme?
ArticleISO/IEC 27002:2022 makes awareness more explicit: demonstrable, role-based and repeated. What changed, and how to set up your programme without turning it into…
Government baseline security in Europe: meeting the awareness requirement step by step
ArticleMost European governments work to a national baseline for information security, and all of them require demonstrable awareness. This is how public bodies meet…
Use mobile data or secure Wi-Fi while travelling
ArticleFree public Wi-Fi is convenient but risky for work email and sensitive accounts. Why mobile data is almost always safer, how to recognise public networks, and…
Medical personal data is highly sought after: why healthcare is a target
ArticleMedical data is often worth more than credit card data on the black market. Why healthcare is a favourite target, which legislation applies, and how employees…
Book a short demo or ask a question. We respond quickly.