Phishing · social engineering · basic mission

Phishing training as concrete workplace decisions.

The mission The New Customer trains employees to assess suspicious emails, links, attachments, QR codes, MFA requests and unusual customer contacts safely.

MissionThe New Customer

Basic training with phishing, MFA, customer data and reporting paths.

EvidenceKnowledge check

Check completion and document participation internally or for audit requests.

TemplatePolicy included

Information security policy as a directly usable working template.

PrivacyLean start

Code-based start without classic participant accounts or storing personal data.

What the phishing training covers.

The focus is not fear of misclicks, but reliable daily decisions: stop, verify, report internally and avoid follow-up mistakes.

  • Check senders, links, attachments, QR codes and login pages
  • Recognise urgency, authority, confidentiality and unusual payment or data requests
  • Use MFA requests, number matching and password managers safely
  • Protect customer, contract, personal and access data from social engineering
  • Report suspicious messages and misclicks through internal channels

Typical phishing situations in daily work.

Effective awareness helps employees recognise patterns and know the next safe action.

Email, link and QR code

Fake senders, lookalike websites, QR codes and attachments are assessed together with context and urgency.

Login and MFA

Suspicious reset pages, authenticator prompts and number matching are stopped before credentials or codes are shared.

Customer, invoice, sharing

Unusual customer contacts, cloud shares, payment data and alleged urgent orders are clarified internally instead of informally confirmed.

Matching missions for phishing.

Depending on the goal, phishing can be trained as part of the basic training or as a more focused click and data sharing mission.

The New Customer

Basic training: phishing, MFA, customer data, remote work, AI use and internal reporting paths in one broad awareness mission.

One Click Too Many

Phishing and data sharing: designed for situations where a link, share or wrong access decision can lead to unintended disclosure.

Phishing simulation or phishing training?

A simulation measures whether employees react to a staged attack. Training explains why a message is risky and which action is safe. Paragamix.Cyber uses interactive decisions with feedback, a knowledge check and participation evidence.

Included documentation.

The package includes an information security policy as a directly usable template for internal rules on email, access, reporting paths and safe work.

  • Participation evidence for internal records, customer requests and external audit requests
  • Knowledge check as mission completion
  • Policy template as a practical aid, not legal advice, certification or individual audit confirmation

Frequently asked questions about phishing training.

Concrete answers for information security, HR and management.

What is phishing training for employees?

Phishing training helps employees recognise suspicious emails, links, attachments, QR codes and social engineering situations, verify them and report them internally.

What is the difference between phishing simulation and phishing training?

A simulation usually tests behaviour with a staged attack. Training explains decisions, warning signs and reporting paths. Paragamix.Cyber uses interactive missions so employees can classify situations and react safely.

What should employees do after clicking a suspicious link?

Employees should stop interacting, avoid entering further data, report the incident internally and follow the defined reporting path. Fast reporting without blame is the priority.

Which phishing types should employees know?

Important examples include email phishing, smishing, QR phishing, fake login pages, malicious attachments, business email compromise and CEO fraud. The key outcome is not terminology, but safe action in daily work.

How often should phishing awareness be repeated?

Repetition is useful when threats, processes, tools or reporting paths change. Many organizations use short recurring impulses instead of rare large training events.

Can the training be documented for ISO 27001 or NIS2?

The participation evidence documents completion and the knowledge check. It can be used for internal records, customer requests and external audit requests, but does not replace legal advice, certification or individual audit confirmation.

Train phishing as a mission.

The New Customer covers phishing within the basic training. One Click Too Many is designed as a focused mission for click, sharing and data leakage situations.