Manager console
See who is competent, who is behind, and what follows from it.
The console that comes with the Platform + manager console + audit plan. Not a reporting tab bolted onto a course platform, but a tool built around the questions a security lead has to answer upwards and outwards.
The views
Five views, one question each.
Overview
Is this under control?
Readiness, activity and the week's movement on one screen. This is the view you open on a Monday morning.
Compliance
Are the duties met?
Coverage one control at a time, grouped by framework: NIS2, ISO 27001, SOC 2, GDPR, PCI DSS, the AI Act, the Cyber Resilience Act and cyber insurance.
People
Who is behind?
The roster with completions, scores and retention. The inactive surface on their own rather than having to be hunted for.
Lessons
What is in the catalogue?
The whole library and what requirement each lesson is mapped to. This is the view an auditor wants to see.
Leaderboards
Who is pulling others along?
Optional, and only within your own organisation. Included because it works, kept separate because it is not a metric anyone reports on.
What it measures
A completion rate tells you who clicked. We measure what is left.
The readiness figure is weighted so retention counts for most. It is a less comfortable number than completion, and it is the only one with anything to do with real risk.
35%
Completion
Did the person take the lesson
25%
Quiz quality
Did they get it right first time
40%
Retention
Was it still there weeks later
Competency matrix
Six competencies by department — as one grid.
Compliance tells you whether a duty is met. This tells you where the competence is thin, which is a different question. Competencies are the rows and departments the columns, so a gap shows up as a place rather than as an average.
- See that finance is strong on fraud and thin on AI literacy — and point the training there rather than at everyone
- The same grid works for onboarding and hiring: what the team is actually missing
- The figures match the report, because they are computed from the same completions
One completion, two purposes
The same lesson that raises a person's competence is filed against the requirement it satisfies. Building competence and collecting audit evidence are not two projects, and nobody has to assemble a folder separately.
Out of the system
Three exports, all one click.
Training log (CSV)
One row per person, lesson and completion date. This is the file an auditor asks for first.
Evidence pack (CSV)
Control by control: which requirement, who covers it and through which lessons. Ready to attach to an audit.
Board report (PDF)
A printable document for the board and the auditor: summary, a management-body section by name, and the evidence appendix.
The management body as its own group
Under NIS2 Article 20 the management body approves and oversees the cybersecurity measures, and its members are required to follow training; your country's NIS2 law sets out how. A percentage does not answer it, so board members are marked as their own group and reported by name, against a management path built for exactly this.
Start for free