For whoever answers for security
Staff training that survives the audit, and sticks.
NIS2 lists cybersecurity training among the measures an organisation in its scope must take, and requires the members of the management body to be trained too; each EU country brings this in through its own national law. The AI Act asks every organisation that uses AI to support its people's AI literacy. Cyberact covers both in about two minutes a day and leaves one dated record of every completion, for staff and management alike, that you can show the board and an auditor.
Price on a 12-month subscription, excl. VAT. No per-seat fees. Renews automatically until you cancel. 14 days free on a 12-month subscription – card required, no charge until the trial ends.
- Flat price, unlimited users
- 14 days free on a 12-month subscription – card required, no charge until the trial ends
- No sales call: price and terms are public
- Data hosted in the EU, in Germany
The starting point
The annual course leaves little behind, in people's heads or in the record.
Phishing is still the main way in
Across the EU, phishing was the leading intrusion vector in about 60% of the cases ENISA observed from July 2024 to June 2025. By early 2025, AI-supported phishing reportedly made up more than 80% of social-engineering activity worldwide.
Completed is not the same as learned
In a study of 19,500 hospital staff over eight months, whether someone had recently completed the annual mandatory training had no significant relationship with whether they fell for phishing. Three in four spent a minute or less on the training material.
Source: UC San Diego, 17 September 2025
AI is already in use, approved or not
Frequent use of AI tools at work rose from 15% to 45% of employees in one year, and using AI tools the employer has not approved is now the third most common way data leaks without anyone meaning it to.
Source: Verizon DBIR 2026, 19 May 2026
What you will be asked
Three questions a dated record answers and a percentage doesn't.
- 01
Is staff cybersecurity training in place?
NIS2 Article 21(2)(g) names basic cyber hygiene practices and cybersecurity training among the risk-management measures an entity in scope must take, and your country's NIS2 law transposes it. ISO 27001, SOC 2 and PCI DSS ask for evidence of training too, whether or not NIS2 applies to you.
- 02
Has the management body been trained?
Under NIS2 Article 20, the management body approves the risk-management measures and oversees them, and its members are required to follow training. National laws word it in their own way, but the question is always about named people, not an average.
- 03
What have you done for AI literacy?
Article 4 of the AI Act requires providers and deployers of AI systems to take measures that support their staff's AI literacy. It has no size threshold, sets no required level and carries no fine of its own, but you will want to be able to show what was done.
NIS2 requires each country to set maximum fines of at least €10,000,000 or 2% of worldwide annual turnover for essential entities, and at least €7,000,000 or 1.4% for important entities, whichever is higher. Your national law sets the exact ceiling and names the authority.
Source: NIS2 Directive (EU) 2022/2555, Article 34
Not sure NIS2 applies to you? Check in three questionsHow Cyberact handles it
Training that gets finished, and leaves a trace.
Done, because it fits in the day
A lesson and its questions take about two minutes and need no scheduling. The daily quiz brings a point back just before it would be forgotten. The lessons are in English and Finnish only, and read aloud.
Measures what stuck
40% of the readiness figure is retention: whether people still answer correctly weeks later, when the same question comes back. It is a less comfortable number than a completion rate, and a more honest one.
Management as its own group, by name
Mark management as its own department, and the management summary shows each member against the NIS2 management duty (Article 20) and AI Act Article 4, with dated completions. The management path has 41 lessons on what the law asks of management personally.
The record is a by-product
A completion is written the moment a lesson ends and cannot be created or moved afterwards. The training log (CSV), the evidence pack (CSV) and the board report (PDF) come straight out of the console.
See the gap by department
The department matrix shows requirements and competencies for each department, so training goes where competence is thin rather than to everyone.
What Cyberact doesn't do
There is no phishing simulation, so we don't promise a lower click rate. Training is one layer: use passkeys or multi-factor authentication as well, and keep edge devices patched. The report evidences training; it doesn't say your risk management is adequate in other respects.
Check it yourself
No customer logos yet. Everything else you can check before you buy.
A sample report
The board report on invented data, computed exactly as the real console computes it: the management body by name, the department matrix and how every figure is made.
Open the sample reportThe regulation map
Every lesson is tied to the requirement it supports, across eight frameworks: NIS2, ISO 27001, SOC 2, GDPR, the AI Act, the Cyber Resilience Act, PCI DSS and cyber insurance.
See the manager consoleThe method and its limits
How readiness is computed (completion 35%, quiz quality 25%, retention 40%), what counts as up to date (80% of a requirement's lessons) and what the report does not prove.
See how it measuresA public price and a checked comparison
The price, the terms, and a dated comparison with Hoxhunt, Guardey and KnowBe4, including the rows where they are ahead of us.
See pricingGuides checked against the law
What NIS2, the AI Act and the Cyber Resilience Act ask of staff and management across the EU, with the sources.
Read the guidesWe are new. Our first customers shape what we build next, and with their permission their logo goes up here.
Cost
One price for the whole organisation. Per person, it falls as you grow.
Platform + manager console + audit is €1,068 a year, excl. VAT, whether you are 20 people or 500. No per-seat fee and no setup fee. The larger cost is people's time, about two minutes a lesson: any training takes time, and here it is spread so that it sticks.
Per person, a year
- 20 people
- €53.40
- 50 people
- €21.36
- 200 people
- €5.34
Break-even, not a forecast
At €1,068 a year, the programme has paid for itself if it prevents a single €10,000 invoice fraud in nine years. The €10,000 is an example: put in your own figure.
The first report within a week
- Day 1
Paste the email addresses as a list, or upload a CSV. Everyone gets an invitation and signs in with a one-time code: there are no passwords.
- Day 1
Mark management as its own department, and they get their own summary.
- Week 1
The console fills in: who started, where competence is thin, who needs a reminder. Reminders go out from the console.
- End of week 1
Print the first board report. From then on the record builds itself.
Team competence
For your CEO, the same thing the other way round
The lessons that count towards Article 4 of the AI Act also teach people to use AI where it pays off, and to keep company data out of the wrong tools. In controlled studies, AI aimed at the right tasks made work clearly faster; aimed at the wrong ones, it made results worse.
See the business viewThe questions a security lead asks
What does it cost at our size?
€1,068 a year for everyone, excl. VAT: at 50 people, about €21 a person a year. There is no per-seat fee, so the price doesn't rise when you hire.
We already have training. Why change?
Keep it if it shows retention person by person and management's training by name. If it doesn't, ask what it proves: in the largest study so far, completing the annual training had no significant relationship with falling for phishing.
Will people actually do it?
A lesson and its questions take about two minutes and need no scheduling. You report retention, so if people don't do it you see it at once, and reminders go out from the console.
Will an auditor accept it?
The record is dated, cannot be created or moved afterwards, and every percentage can be recomputed from the CSV. The report states what it proves and what it doesn't. An auditor accepts evidence rather than a vendor's name, so judge the evidence.
Is there phishing simulation?
No, and we say so up front. If simulation is what you need, Hoxhunt and KnowBe4 have it. Cyberact covers the training duty, management's training, AI literacy and the evidence, at a flat price.
Can we leave?
Yes. Your main admin can cancel the subscription any time from the billing page. Access continues to the end of the paid period, and the next one isn't charged. You can export the training log and the evidence pack as CSV whenever you like.
What does rollout take?
Paste the addresses and mark management. No single sign-on, directory or learning-platform project is needed: people sign in with a one-time code sent by email.
We are not in NIS2's scope.
Article 4 of the AI Act still applies if your people use AI at work, and ISO 27001, SOC 2 and PCI DSS ask for evidence of training anyway.
We are not in Finland. Does it fit our country's law?
Yes. The lessons are mapped to the EU texts themselves: the NIS2 Directive's articles, which every country's NIS2 law implements, and the AI Act, the Cyber Resilience Act and GDPR, which apply directly in every member state. Your own national law may add detail, so check it, but the training duties and the evidence are the same.
Is it in our language?
Cyberact is in English and Finnish only; no other EU language is offered. If your people work in English, it fits. If they need their own language, it doesn't yet.
Where is our data?
In the EU: the service is hosted in a data centre in Germany.
How do prices and VAT work?
Prices are in euros and exclude VAT for businesses. VAT is handled at checkout, which calculates the final tax.
Is the content made with AI?
Yes. The lesson texts, questions, narration, images and videos are produced wholly or partly with AI, and the narration voices are synthetic. AI can make mistakes, and laws and threats change over time, so some details may be out of date. The content is training, not legal advice: check what a law requires of you against the official sources. The terms of use set this out.
A year you can take back within two weeks.
As a new customer, you get a 14-day free trial on a 12-month subscription, and nothing is charged if you cancel during it on the billing page. The subscription renews automatically, and you can cancel any time. The training log is yours as a CSV.
Price on a 12-month subscription, excl. VAT. No per-seat fees. Renews automatically until you cancel. 14 days free on a 12-month subscription – card required, no charge until the trial ends.