ANOMAL service

Security awareness training: turning click risk into reporting behaviour

Security awareness training is a measurable behavioural process, beyond a mandatory e-learning module. The target is not a zero click rate but a reporting rate for suspicious mail in the 40 to 50 percent target band before the SOC escalates. ANOMAL combines short role-specific modules, realistic phishing simulations and a reporting interface in Microsoft 365 so awareness becomes a detection source. The 'Regular security awareness training with phishing simulations' requirement of most Swiss cyber insurers is documented in the process.

All

Why awareness is the cheapest control layer

Most successful attacks on Swiss SMEs still start with email: phishing, business email compromise, MFA fatigue. Technical filters catch the majority but never everything. Whoever clicks is a stepping stone; whoever reports is a detection source. A good awareness programme moves exactly that ratio.

Insurers require it, not just us

Regular security awareness training with phishing simulations is a common cyber-insurance requirement in the Swiss market. Without evidence, insurers apply surcharges or sub-limits, see [Cyber insurance](/en/soc/soc-and-cyber-insurance-switzerland).

Programme structure

  1. Annual baseline training for all employees: mandatory module with a knowledge test, completion documented per person.
  2. Department modules supplement the baseline training. Finance and HR cover BEC and invoice fraud; IT covers MFA fatigue and console access; executives cover whaling and deepfake voice. We provide custom content to meet customer requirements.
  3. Knowledge test per module: results support assessment of each employee and guide follow-up training.
  4. Onboarding gate: completing the initial training is a prerequisite for system access. We reconcile status against the customer's HR onboarding process.
  5. Quarterly phishing campaigns over the contract term, with gradually rising difficulty and DE plus EN variants for Swiss mixed-language workforces.
  6. Report button in Outlook and Teams: one click sends the message to the SOC, the user gets immediate feedback (real / simulated / suspicious).
  7. Quarterly report to the CISO: training status, test results, phishing results (click rate, data entry, report rate) and risk-score trend; evidence for insurer and regulator.
  8. Operations: ANOMAL plans, coordinates, delivers and manages the programme on an ongoing basis.

The programme runs on an awareness platform, and the choice of platform is not part of the positioning. Examples are KnowBe4, Proofpoint Security Awareness, SoSafe, Hoxhunt or Microsoft Attack Simulation Training. We take over an existing platform; if none exists, we recommend one based on languages, seat count and Microsoft 365 integration.

Scope and pricing logic

The managed service covers programme design, modules, campaigns, reporting and steering. The per-seat platform licence is not part of the managed fee; it is listed separately and transparently. Because seat count, languages, module scope and term differ per environment, there is no list price: every customer receives a dedicated quote.

Phishing simulation as part of the programme

The simulations in this programme send controlled but realistic mails and measure two values: who clicks, and who reports. Both are evaluated by role and business unit. Only the reporting rate via the report button turns the simulation into a detection exercise.

  1. Baseline: one unannounced wave at medium difficulty, click and report rate per business unit as the starting point.
  2. Role segments: finance and HR receive BEC and invoice lures, IT gets MFA fatigue and console access, executives get whaling and deepfake-voice pre-warnings.
  3. Cadence: a wave every four to six weeks, difficulty rising in steps, DE and EN variants.
  4. Immediate feedback: whoever clicks sees a short explainer with the concrete signals in the lure.
Swiss context matters

Generic EN templates lose value fast. Effective campaigns use QR-invoice, eBill, SwissID prompts, ISO-20022 phrasing, cantonal and health-insurer context, plus DE and EN variants for mixed workforces.

Metrics that matter

MetricWhy it mattersRealistic target band
Simulation click rateCoarse indicator, drops fast and then plateaus; not meaningful in isolation.Under 5 percent after twelve months of programme.
Report-button reporting rateThe actual detection value for the SOC.40 to 50 percent for well-crafted simulations.
Time to first reportDetermines how fast the SOC stops a real wave.Under 15 minutes after send-out.
Repeat-clicker shareShows whether the programme reaches risk groups.Under 2 percent of the workforce.
Source note

The under-5-percent click rate matches the published 12-month industry benchmark (KnowBe4 Phishing by Industry Benchmarking Report 2025: 4.1 percent global, 5.0 percent Europe). Report rate, time to first report and repeat-clicker share are ANOMAL target bands from live programmes, not published market data.

The report button connects awareness and SOC operations. The SOC treats reported emails as detection signals and incorporates them into the MTTD chain. See MTTD and MTTR in a SOC.

How this compares to plain e-learning or phishing-simulation only

ApproachWhat it deliversWhere it falls short
Mandatory once-a-year e-learningCompliance tick for audits.Behaviour does not measurably change.
Phishing simulation without trainingClick rate becomes visible.Without feedback and reporting interface no detection uplift.
Awareness programme with report buttonBehaviour measurable and steerable, SOC gains a detection source.Does not replace technical filters (email sandboxing remains mandatory).

Awareness contributes to the detection stack and cannot replace it. See SOC as a Service Switzerland for the framework and its interaction with SOC operations.

Frequently asked questions

Do we announce campaigns?

The baseline is not announced, otherwise it is not a baseline. Afterwards management communicates transparently that there is an ongoing programme, without leaking dates or lures.

What happens to those who click?

A short explainer page with the concrete signals in the lure, no sanctions. Repeat clickers get an additional short module, no naming and shaming in open reports.

How often do phishing campaigns run?

A wave every four to six weeks across the entire contract term, with varying difficulty and themes. We can agree additional ad-hoc campaigns in the scope, for example after a real incident.

Is the platform licence included in the price?

The managed fee excludes the platform licence and covers programme design, modules, campaigns, reporting and steering. We list the per-seat licence separately so you can see the service and licence costs. Both appear in the same quote.

Which languages are standard?

Training content is available in every language our training platform offers.

Who owns the onboarding gate?

The customer's HR onboarding process requires employees to complete the initial training before gaining system access. We provide assignment, reminders and completion status; you enforce the rule in your access process.

Does this programme satisfy the insurance requirement?

Yes, provided you document frequency, role coverage and reporting. The quarterly report supports this documentation. On request, we share it directly with the broker or insurer.

What happens to simulation results and personal data?

Management receives analytics aggregated by business unit, with no individual-level results. We store personal data about who clicked or reported in accordance with revFADP (revised Federal Act on Data Protection). We use it only for follow-up training and delete it after a defined retention period.

Continue reading in this cluster
Penetration testing Switzerland: find attack surfaces before attackers do
A penetration test is a targeted attack simulation against defined systems, carried out by Swiss testers using a documented methodology. The test produces an auditable report with prioritised findings and recommendations that fit your environment. The report provides evidence for regulators and insurers. ANOMAL tests web, cloud, Active Directory, APIs and internal networks.
Red team assessment: detection and response under realistic load
A red team assessment is a goal-based, multi-week attack simulation against the entire detection and response chain, not against a narrow scope. The output is not a vulnerability list but an evidence-backed statement about what SOC, EDR, identity and cloud controls stop together. ANOMAL runs red team engagements using MITRE ATT&CK with a methodology based on TIBER-EU. For systemically important institutions, FINMA considers red-teaming exercises a required part of cyber exercises (supervisory notice 03/2024) and names frameworks such as TIBER-EU and CBEST.
SOC and cyber insurance: what Swiss insurers require
Cyber insurers in Switzerland and the EU increasingly require applicants to evidence security controls. MFA, EDR, segregated backups, a documented incident response plan and a patch process appear on nearly every proposal form. Missing 24/7 detection via a managed SOC or MDR is rarely a formal exclusion. It is a strong premium driver and, in many policies, the only realistic way to meet short policy notification deadlines.
SOC as a Service in Switzerland: The Complete Guide
SOC as a Service is an externally operated Security Operations Center that monitors your environment around the clock, detects attacks and triggers the response. According to Mandiant M-Trends 2026, attackers went undetected for a median of 14 days in 2025. With a SOC that detects and assesses around the clock, typical detection time becomes much shorter.