Methodology · NIS2 · ISO 27001 · TISAX

How cyber awareness becomes real decision training.

A realistic attack situation, a participant decision, immediate feedback, a knowledge check and documentable completion – in 15 minutes and without an LMS project.

Attack chainDecisionFeedbackKnowledge checkEvidence
01Attack chain

A realistic workplace situation develops across several steps.

02Decision

Participants assess risk and choose an action themselves.

03Feedback

The consequence and a safer alternative become immediately visible.

04Completion

The knowledge check and participation become documentable.

How to interpret the results.

The completion rate compares finished runs with the booked participant quota. It is not a verified count of distinct people. The weighted risk score (HRE) summarises scenario decisions: 100 × the sum of weighted risk values ÷ the sum of weights. Higher scores mean more risky decisions in that exercise. Compare matching exercises, versions, roles and periods; repeat participation and learning effects can change results. Small groups limit interpretation. The score is neither an individual performance assessment nor a prediction of real incidents or losses.

In depth: how decision training works

Learning through application.

Participants do not only read rules. They assess plausible situations, identify risks and make their own decisions. Knowledge is reinforced where it is needed: in day-to-day work.

Attack chains instead of isolated events.

Modern attacks develop through several steps: first contact, trust building, manipulation, decision and response. The missions model such chains in phishing, social engineering, supplier attacks, AI use and data loss.

Immediate feedback.

After each decision, the consequence, risk pattern and safer alternative are explained directly. Feedback connects action and professional context instead of merely showing right or wrong.

Interactive, but not playful for its own sake.

Elements from serious games and experiential learning are used only where they help: understanding context, making a decision, receiving feedback and reflecting on behaviour.

Knowledge checks and evidence are included – but they are not the methodology.

Evidence documents completion. Learning happens earlier through situation, decision and feedback.

Knowledge check

Checks the mission’s key learning objectives and makes understanding traceable.

Participation evidence

Documents topic, completion, time and mission reference for internal records.

Clear boundaries

No certification, audit or legal advice. Audience, frequency, effectiveness review and ISMS integration remain organisational responsibilities.

One methodology, three professional contexts.

The mission stays action-oriented; its classification depends on the management system, risk context and assessment objective.

NIS2

Awareness and cyber hygiene support organisational security measures. Management responsibility remains a separate requirement.

Understand NIS2 awareness

ISO 27001

Training and awareness can be documented in the ISMS. Competence management, effectiveness review and audit remain separate tasks.

Read the ISO 27001 context

TISAX

For automotive suppliers, completion may be one evidence component. Scope, VDA ISA requirements and the specific assessment objective remain decisive.

Professional responsibility and sources.

The content is professionally framed and reviewed by Alexander Graf Schulenburg, Certified ISO/IEC 27001 Lead Auditor.

Practice-oriented review

Typical requirements are translated into concrete actions: identify, assess, decide, report and document.

Recognised orientation

The framing draws on information security, NIS2, ISO/IEC 27001, cyber hygiene, BCM and human risk management.

Train. Decide. Understand. Document.

Paragamix combines action-oriented learning with a clear, documentable completion.