Proposal: Cyberact
Security and AI training with audit evidence
The need
- If we are in scope of our country's NIS2 law, staff cybersecurity training is one of the required risk-management measures (NIS2 Art. 21(2)(g)), and the members of the management body must follow training (Art. 20).
- If our people use AI, Article 4 of the AI Act requires us to take measures that support their AI literacy.
- Phishing was the leading intrusion vector in about 60% of the cases ENISA observed across the EU in 2024–2025, and employees' frequent use of AI tools tripled in a year, with unapproved tools now the third most common way data leaks by accident.
Why not the annual course
In a study of 19,500 employees, completing the annual mandatory training had no significant relationship with falling for phishing. We need training that people engage with, that is retained, and that leaves a dated record.
The proposal
Platform + manager console + audit for 12 months: €1,068 excl. VAT, for unlimited users. The subscription renews automatically until you cancel it. For a new customer it starts with a 14-day free trial, and the first charge is made when the trial ends.
What we get
- 249 lessons of about two minutes each, in English and Finnish (no other languages).
- Retention measured, not just completion.
- Management reported by name against the NIS2 management duty (Art. 20) and AI Act Art. 4.
- A dated training log, an evidence pack and a board report.
- AI paths that also teach productive, safe use of AI.
A sample board report: cyberact.io/report
Effort
Invite by pasted list or CSV on day one; the first report after a week. No integration project.
Risks and limits
- No phishing simulation: training is one layer, alongside multi-factor authentication and patching.
- The report evidences training, not the adequacy of our risk management in other respects.
Decision asked
Approve €1,068 a year for Cyberact Platform + manager console + audit.
Sources
- NIS2 Directive (EU) 2022/2555, Articles 20 and 21: https://eur-lex.europa.eu/eli/dir/2022/2555/oj
- ENISA Threat Landscape 2025, 1 October 2025: https://www.enisa.europa.eu/news/etl-2025-eu-consistently-targeted-by-diverse-yet-convergent-threat-groups
- UC San Diego, 17 September 2025: https://today.ucsd.edu/story/cybersecurity-training-programs-dont-prevent-employees-from-falling-for-phishing-scams
- Verizon DBIR 2026, 19 May 2026: https://www.verizon.com/about/news/breach-industry-wide-dbir-finds
cyberact.io · prices and terms at cyberact.io/pricing