Research-backed, no employee profiling

Security and AI skills training that people finish.

CyberCoach teaches phishing judgment, role-based AI skills and secure coding through short conversations in Microsoft Teams, Slack or the browser. No surprise emails, no individual risk scores, no blame — because the peer-reviewed evidence says those don't work.

  • Microsoft Teams
  • Slack
  • Any browser
  • Anonymous by default
  • No GDPR profiling
  • 14 languages
CyberCoach running a conversational phishing challenge inside a Microsoft Teams chat in dark mode
No individual scoringPsychologically safe practice
EU AI Act readyMeet Article 4 Requirements

Trusted by security teams worldwide

City of Helsinki MavenBlue Stockholmsregionens Försäkring Virta iLOQ Finnlines Finnfund Finnish National Opera and Ballet PlaytestCloud Suomen Ekonomit
What makes CyberCoach different

Three things no other awareness platform does this way

Most vendors sell the same deceptive email test engine with a different dashboard. CyberCoach replaces it with practice, and adds two skill areas that really make a difference.

01

Psychologically safe phishing practice

Employees practise against realistic social-engineering scenarios in a conversation and explain their reasoning in their own words. Nobody is tricked, nobody is caught, and no per-person failure record is created.

  • Announced practice instead of surprise deception
  • Only successful completion is recorded — never how someone answered
  • Covers all channels (including SMS, Teams, WhatsApp, LinkedIn, QR and voice), not just email
Read the research
02

Role-based AI skills, not just AI risk

Compliance training tells people what not to do. CyberCoach also teaches them to work well with AI: writing better prompts, checking generated output, and knowing what may never be pasted into a model.

  • Separate paths for developers, finance, HR, legal, sales and leadership
  • Hands-on prompting and output-validation challenges
  • Covers the EU AI Act Article 4 literacy duty, mandatory since February 2025
Explore AI training
03

Secure coding at two levels of seniority

Interactive secure development training in the same chat as everything else. Secure Coding Practices covers recognizing the common vulnerability classes. Applied Secure Coding takes the same topics to senior level, for engineers who have to judge whether a design is genuinely production-ready.

  • Multi-layer scenarios with several interacting trust boundaries
  • Partial controls and trade-offs that need judgment, not rule recall
  • Design secure architectures and critique remediations that leave residual risk
  • Evidence of completion for ISO/IEC 27001 and SOC 2 audits
For developers
The evidence

Why we stopped tricking employees

Separate peer-reviewed studies covering over 30,000 employees have now tested deceptive phishing simulation in real organizations. The results are why CyberCoach is built the way it is.

31,798+
employees studied. Not only does phishing simulation not seem to produce behavior change, those sent to a training page after failing went on to click more phishing emails, not fewer.
Lain et al. (2022, 2024), Rozema & Davis (2026)
0
measurable benefit from mandatory retraining after repeat failures
Lain et al. — ACM CCS 2024, 4,554 employees
50,000+ €
indirect additional costs of person hours required to legally evaluate and procure a phishing simulation platform by a European enterprise
Brünken, Buckmann, Hielscher & Sasse — USENIX Security 2023
How it works

A conversation, not a training page

STEP 01

It's already in their chat

Pinned to the Teams or Slack sidebar and sitting in their inbox — one click, no separate login. We only notify people when a mandatory training deadline is close, never to interrupt real work.

STEP 02

They work through a real scenario

Answering in their own words and reasoning out loud instead of clicking through slides. Guessing does not get you far.

STEP 03

Feedback lands immediately

Personal, in context, while the scenario is still live in their head.

STEP 04

You get compliance evidence

Completions are recorded for your audit. How someone answered never is. Runs on pseudonymous Microsoft or Slack IDs.

AI skills training

Your people already use AI. Teach them to use it well.

AI training is not only about avoiding risk — it is about the productivity you lose when people prompt badly and trust output blindly. CyberCoach coaches both sides: precise prompting and critical review, tailored to what each role actually does.

  • Write prompts that get usable answers first time
  • Spot hallucinated, biased or unusable output
  • Know what may never be pasted into a public model
  • Meet the EU AI Act Article 4 AI-literacy obligation
A CyberCoach AI skills challenge teaching LLM basics inside a chat window
Customers

What security teams tell us

Good luck guessing your way through these. Even I failed a CyberCoach Skill Test.

Anonymous CISODeep tech company

CyberCoach creates ongoing learning moments in a way that fits our culture of continuous learning. The AI-enhanced interactions especially help things stick.

Security teamCity of Helsinki, Urban Environment Division

The integration with Microsoft Teams was very quick and straightforward. Making it safe to make mistakes and ask questions at any time has had several positive effects.

Stockholmsregionens Försäkring ABInsurance, Sweden
FAQ

Questions security and privacy teams ask

Do you run phishing tests?
Yes, but not by deceiving people. Employees practise against realistic social-engineering scenarios inside Teams, Slack or the browser and test their judgment safely. Peer-reviewed research from ETH Zurich found that the traditional method — surprise emails and a training page on failure — does not produce lasting improvement and can make behaviour worse.
Is phishing simulation legal under GDPR?
Simulated phishing with per-employee tracking is profiling under Article 4(4) GDPR, and for most European employers the only realistic legal basis is legitimate interest — which requires the processing to actually be necessary. CyberCoach avoids the question entirely: there are no individual risk scores, learning is anonymous, and only successful completion is recorded. Read the full legal analysis.
How is CyberCoach different from a normal security awareness platform?
Three ways. Phishing skills are built through announced, psychologically safe practice rather than deception and scoring. AI training covers practical role-based skills, not only risk and compliance. And secure coding for technical roles is part of the same platform, in the same chat, rather than a separate developer tool.
Does CyberCoach cover the EU AI Act?
Yes. The Article 4 AI-literacy obligation has applied since February 2025 and was not deferred by the Digital Omnibus on AI. CyberCoach delivers role-based AI literacy training and records completions as evidence. See what the AI Act actually requires.
What languages do you support?
English, Spanish, Portuguese (Brazil), Portuguese (Portugal), French, Dutch, German, Swedish, Finnish, Danish, Norwegian, Polish, Estonian and Russian. More are in progress — tell us what you need.
Can we create our own content?
Yes, and it is quick. You can build your own training with AI assistance and adapt our existing content to your own policies and instructions.
How long does it take to roll out?
CyberCoach installs as a native Teams or Slack app, so there is no new system for employees to log into and no separate account provisioning. Customers typically describe setup as quick and straightforward, and Advanced and Complete plans include a hosted kick-off for employees.

See it in your own Teams or Slack

Start a free trial in minutes, or take 15–30 minutes with us to walk through the platform and check it against your training and compliance requirements.

No credit card needed.