Security Awareness TrainingCompletion is not evidence of learning.

So NOUSEC assigns training from what each employee actually did, proves server-side that it was really watched, and reports which module reduced phishing clicks. Not who ticked a box.

IEEE S&P 2025 · 19,500 employees
GDPR ready · EU data residency (Frankfurt) · No endpoint agents
TRAINING MODULEVIDEOtab hidden — not countingUnique-second watch coverage0%12%26%38%50%62%78%90%18%94%90%Mark as complete18% watched · not counted.Completed · 94% coverage · certificate issued.Coverage computed server-side · accrual pauses when the tab is hidden
TRAINING MODULEVIDEOUnique-second coverage94%90%Completed · 94% coveragecertificate issued

What is AI-adaptive security awareness training?

AI-adaptive security awareness training is training that is assigned by measured behavior rather than by the calendar. Each employee is continuously tested across the channels attackers actually use; every outcome updates their Human Risk Score; and the score — not a compliance date — decides what training they receive next, how hard their next simulation is, and whether they need any training at all.

How behavior-triggered training works

How NOUSEC training works

One workforce. A different program for every person in it.

Nobody is assigned a course because the calendar said so. Every simulation outcome writes to that employee's Human Risk Score and decides what happens next — a branching scenario, a 90-second micro-lesson, or nothing at all if they already handled it. Then the platform re-tests to confirm the behavior actually changed.

M. AydınFinance
Human Risk Score7144
Simulation
Deepfake voice call
Cloned CFO, native language
Outcome
Credentials entered
Failed in 34 seconds
Adaptive response
Branching scenario
Wire-fraud decision tree · 4 min
Verification
Re-test, day 9
Reported before acting
J. OkaforEngineering
Human Risk Score3831
Simulation
QR code lure
Poisoned parking notice
Outcome
Ignored, not reported
Threat left running
Adaptive response
Micro-lesson
Quishing + reporting habit · 90 sec
Verification
Re-test, day 21
Reported in 41 seconds
L. FischerExec office
Human Risk Score2219
Simulation
Callback (TOAD)
Fake invoice, hostile call center
Outcome
Reported in 26 seconds
Passed cleanly
Adaptive response
No training assigned
Difficulty raised instead
Verification
Re-test, day 14
Harder lure · reported

Notice the third lane. An employee who reports the attack correctly is not sent a course — the platform raises their difficulty instead. Training time is a budget, and spending it on people who already passed is how programs lose the room.

Source: NOUSEC platform behavior. Employee names, scores and timings are illustrative examples of the adaptive logic, not customer data.
Admin surface

What the CISO sees

Five tabs. Two of the views answer the question every awareness programme has failed to answer: which module actually reduced clicking.

OverviewPeopleContentCampaignsInsights

Per-module effectiveness

Pearson correlation between completing a module and real phishing-simulation click rate. Displayed only once n ≥ 10 — below that the platform shows nothing rather than a number it cannot stand behind.

ModuleSampleCorrelation to click rate
Business Email Compromisen ≥ 10−0.84
Vishingn ≥ 10−0.71
Deepfake Voicen ≥ 10−0.66
Credential Harvestingn ≥ 10−0.58
Spear Phishingn ≥ 10−0.52
MFA Fatiguen < 10Not shown
Malicious Attachmentsn < 10Not shown
Password Hygienen < 10Not shown

Figures illustrative. Correlations resolve per tenant from live simulation data.

Honesty threshold. Rows below the sample floor stay blank on purpose. The empty cell is the feature.

The correlation quadrant

Phishing click rate against training engagement, by department, with drill-down.

CRITICALRESISTANTDORMANTCHAMPIONPhishing click rateTraining engagementOne bubble per department · select to drill down
CriticalLow engagement, high click rate: the untrained and the exposed.
ResistantHigh engagement, high click rate: they complete the training and click anyway.
DormantLow engagement, low click rate: not yet tested enough to know.
ChampionHigh engagement, low click rate: the behaviour the programme is for.

Resistant is the quadrant every completion-rate report hides.

Champions leaderboard

People view · ranked by risk, not activity

Recognition is derived from the risk score and weighted toward reporting: champion score = (100 − risk score) × 0.6 + reporting weight, with reporting capped so it lifts but never dominates.

EmployeeChampion scoreRisk scoreReports
1Employee 141.64412
2Employee 239.2383
3Employee 337.4405
Rank 1 has the worse risk score. Raising their hand twelve times outranks a safer colleague who reported three. That inversion is deliberate — the board rewards reporting, not merely not-clicking. Figures illustrative; names resolve from the directory.
Individual detail
ReporterSpotlessStreak KeeperFirst ResponderFast Learner
Engagement streak · consecutive weeks
Streak Keeper unlocks at 4+ weeks
Recognition is public. Remediation is private: a failed simulation sends a private lesson, and the admin-side counterpart list is named Training Avoiders — never a wall of shame.

Custom export

Section-selectable and branded.

PDFPPTCSV

Certificates

Each one has a public verification page, so a certificate can be checked by anyone holding it.

Audit log

Exportable to your SIEM.

CSVNDJSONJSON
Completion integrity

Completion integrity, measured server-side

So NOUSEC does not record it as evidence. Every completion is classified by time on content against the module's expected duration, and video completion is a measured quantity, not a click.

Four ways to spend an assigned minute

Time on content ÷ expected duration
Skipped
< 30%
Fast Clicker
30 – 70%
Engaged
70 – 130%
Deep Engaged
> 130%
0%
30%
70%
130%
100% · expected duration
≥90%unique-second coverage

Video completion requires ninety percent of the video's unique seconds to have been watched, computed server-side. Accrual pauses when the tab is hidden or the video is paused.

~0%for scrub-and-idle

Drag to the end and walk away and coverage stays near zero: no completion, no certificate. A failed run leaves the enrollment in progress.

403forged completion request

The completion record is issued by the server, not asked for by the client. Passive video shows no invented score — the certificate carries the completion date and the actual duration, nothing else.

The compliance scorecard reports both rates

A raw completion rate, and an audit-adjusted rate that discounts completions showing no evidence of real engagement. Auditors see the gap between them, which is the number that actually means something.

Completion rate (raw)
Audit-adjusted rate
The gap is the point. Actual rates resolve per tenant.
Content

What employees actually receive

Fourteen formats across three delivery paths, and five things inside them that are built differently from the rest of the category.

SCORMtracked in the LMS
Cinematic VideoMicro VideoAnimated ExplainerCartoonInteractiveGameSlide DeckQuiz
PDFdistributable
NewsletterInfographicPosterPolicy
Video / Webinarlive & on demand
Live WebinarPodcast

Forensic feedback

Every wrong answer names the observable signal that gives the attack away. Specificity is the entire lesson.

Answer marked wrong
NOUSEC
Domain “microsft-team.com” is misspelled — real Microsoft uses microsoft.com
TYPICAL
Be careful of suspicious links

An escape room, not a points system

Async, single-player, in the browser. No scheduled session, no facilitator, no points standing in for a game.

1
3 variants
2
3 variants
3
3 variants
4
3 variants
22 min
Mission mode
28 min
Practice mode

Deepfake voice detection

Real-versus-synthetic audio pairs in a banking context, with a forensic debrief on every clip.

One of these is synthetic. At the hardest level you cannot reliably tell by ear — that is the lesson.
The defence taught is process, not perception: verify through a known, pre-verified number.

15policy templates

White-labelled to the customer's organisation and paired to a training module. Acknowledgement re-gates on version change while the acknowledgement history is preserved.

Acknowledgedv1.2 · history kept
New version publishedv1.3
Acknowledgement re-gatedAt-Risk

Localised, not translated

Character names, company names and cultural context change per language — not just the strings. Arabic runs right-to-left, and every language ships its own SCORM package and subtitles.

TurkishEnglishSpanishFrenchGermanPortugueseArabicChineseJapaneseItalianDutchDanishSwedishNorwegianFinnishPolishCzechSlovakHungarianRomanianBulgarianGreekUkrainianRussianHebrewHindiIndonesianVietnameseThaiKorean
9 shipped21 available on request — built to the same four-gate localisation process

A language that only exists on a pricing page is not a language.

The same learner, across languages
TR
Lale
EN
Sarah
ES
Carmen
FR
Camille
DE
Anna
PT
Beatriz
AR
ليلى
ZH
小芳
JA
由美

The learner is renamed, not subtitled. Company names and scenario context change with them.

The evidence

Why annual security awareness training fails

We built the platform this way because the published research is unambiguous about the alternative. Three findings decided the design.

no effect

Annual training did not reduce phishing failure

A randomized trial across 19,500+ employees over eight months found no significant relationship between recently completing mandated annual training and failing a phishing simulation. Embedded post-failure training moved click likelihood by about 2 percentage points.

Ho et al., IEEE Symposium on Security & Privacy, 2025
6 months

The gain is gone before the next course is due

Re-tested at intervals, employees were still significantly better at spotting phishing four months after a course (d′ 1.60, p = .034). By month six the improvement was no longer statistically significant (d′ 1.46, p = .123). A twelve-month cycle leaves roughly half the year uncovered.

Reinheimer et al., USENIX SOUPS 2020
33.2% → 4.2%

Continuous measurement is what moves the number

Across 42 million simulations at 64,000 organizations, the average share of employees who fail a phishing test fell from 33.2% at baseline to 20.1% after 90 days and 4.2% at twelve months of continuous testing and training.

KnowBe4 Phishing by Industry Benchmarking Report, 2026

All three figures are industry research, not NOUSEC results. We have no customer outcome data to publish yet, and we would rather say so than imply otherwise.

Read the full research →

Conventional security awareness training vs. NOUSEC

The difference is not content quality. It is what decides who gets trained, when, and how anyone knows it worked.

Comparison of conventional security awareness training and the NOUSEC adaptive model
 Conventional awareness trainingNOUSEC
What triggers trainingThe compliance calendarThe employee's own last measured failure
CadenceOne annual course, sometimes quarterlyContinuous — rolling waves all year, no dead months
Channels testedEmail, occasionally SMS8 channels: email, SMS, voice, deepfake, WhatsApp, QR, USB, callback
Lesson length20–45 minute modules60–240 second micro-lessons and branching scenarios
If the employee already passesSame course as everyone elseNo course. Difficulty is raised instead.
ContentFixed library, translatedAI-generated per campaign in the employee's native language
Headline metricCompletion rateHuman Risk Score movement and time-to-report
What the board sees“98% of staff completed training”Risk trend per department, with a published scoring methodology
Data residencyVaries by vendorEU (Frankfurt), GDPR native

Audit evidence for NIS2, DORA, ISO 27001 and PCI DSS

Audit evidence

Four frameworks ask for the same thing. None of them ask for a certificate.

Every major regime that mandates security awareness training asks for capability, delivered on a cadence, evidenced per person. What auditors accept as evidence is a record of behavior over time — which is precisely what a once-a-year completion report cannot produce.

NIS2 Directive
Art. 20(2) · Art. 21(2)(g)
What it requires
Members of management bodies must follow cybersecurity training, and entities must implement basic cyber hygiene practices and cybersecurity training as a risk-management measure.
How NOUSEC evidences it
A separate executive track — deepfake voice, CEO fraud and invoice redirection scenarios aimed at the management body — with per-person completion and behavioral evidence exportable per entity.
DORA
Reg. (EU) 2022/2554, Art. 13(6)
What it requires
Financial entities must run ICT security awareness programs and digital operational resilience training as compulsory modules for all staff and senior management, at a complexity commensurate with each role.
How NOUSEC evidences it
Difficulty and content are weighted by role and current Human Risk Score, so complexity scales with function automatically rather than by manual group assignment.
ISO/IEC 27001:2022
Annex A, control 6.3
What it requires
Personnel and relevant interested parties should receive appropriate awareness, education and training, plus regular updates relevant to their job function.
How NOUSEC evidences it
Continuous delivery rather than an annual event, with a per-employee audit record of every simulation, lesson, outcome and score change.
PCI DSS v4.0
Req. 12.6.3 · 12.6.3.1
What it requires
Security awareness training on hire and at least every 12 months, explicitly covering phishing and related attacks and social engineering.
How NOUSEC evidences it
Day-one baseline assessment on hire, then continuous testing across all eight social engineering channels — well inside the twelve-month floor.
Source: Summarized from the cited instruments for orientation only — this is not legal advice. Consult the official texts: NIS2 (Directive (EU) 2022/2555), DORA (Regulation (EU) 2022/2554), ISO/IEC 27001:2022, PCI DSS v4.0.

Security awareness training FAQ

What is AI-adaptive security awareness training?

AI-adaptive security awareness training is training assigned by measured behavior rather than by the calendar. Each employee is continuously tested across the channels attackers actually use; every outcome updates their Human Risk Score; and the score — not a compliance date — decides what training they receive next, how hard their next simulation is, and whether they need any training at all.

Does security awareness training actually reduce phishing?

Not in the form most organizations run it. A 2025 randomized trial of more than 19,500 employees found no significant relationship between recently completing annual mandated training and failing a phishing simulation. What does move the number is continuous testing paired with training: across 42 million simulations, average phish-prone rates fell from 33.2% to 20.1% within 90 days and to 4.2% at twelve months. The decisive variable is frequency and measurement, not course quality.

How does NOUSEC measure unique-second watch coverage?

Video completion requires 90% of the video's unique seconds to have been watched, computed server-side rather than claimed by the browser. Accrual pauses when the tab is hidden or the video is paused, so scrubbing to the end and walking away leaves coverage near zero — no completion and no certificate. A forged completion request returns 403.

What is an audit-adjusted completion rate?

The compliance scorecard reports two numbers: a raw completion rate, and an audit-adjusted rate that discounts completions showing no evidence of real engagement. Auditors see the gap between them, which is the figure that actually reflects whether people learned anything. Completions are classified by time on content against each module's expected duration — Skipped under 30%, Fast Clicker 30–70%, Engaged 70–130%, Deep Engaged above 130%.

Which compliance frameworks does security awareness training satisfy?

NIS2 requires management bodies to follow cybersecurity training (Article 20(2)) and lists cyber hygiene and training among mandatory risk-management measures (Article 21(2)(g)). DORA requires ICT security awareness programs as compulsory modules for all staff and senior management (Article 13(6)). ISO/IEC 27001:2022 covers it under Annex A control 6.3. PCI DSS v4.0 requires training on hire and at least every 12 months, explicitly including phishing and social engineering (Requirements 12.6.3 and 12.6.3.1).

Is NOUSEC GDPR compliant, and where is our data held?

NOUSEC is GDPR native with EU data residency in Frankfurt. No endpoint agents and no software installation are required. Training content is delivered in employees' own languages — nine shipped today, with twenty-one more built to the same four-gate localisation process on request.

See the training assign itself.

In 20 minutes we will fail a simulation on purpose and show you exactly what the platform does next.

Book a demo