ThreatNoir Academy · for organisations

SECURITY AWARENESS THAT PEOPLE ACTUALLY DO, WITH A REGISTER YOU CAN SHOW

Every Wednesday, five real cases from last week in security. Three minutes. Each person's completion is recorded for your organisation, and the training register comes out as CSV or PDF with the regulatory mapping on the cover.

No annual slide deck. No made-up scenarios. The same debrief the public plays at quiz.threatnoir.com, with the record your management body and your auditor ask for.

Already enrolled? Sign in.

Every week

Real incidents from the previous week, reviewed by a human before publication. Judgment questions, a verdict and a short teaching note after each answer.

Recorded per person

Who was eligible, who completed, when, and the score. Administrators see completion. Which answers someone got wrong stays with that person.

Management body

A quarterly executive brief for the people who oversee the company: governance decisions, not technical trivia, recorded separately.

What the register supports

The register documents training activity that supports evidence for the obligations below. Whether that activity is sufficient is a judgement for your organisation and its supervisor. Nothing here certifies compliance.

NIS2 Art. 21(2)(g)
Basic cyber hygiene practices and cybersecurity training, as part of the risk-management measures.
NIS2 Art. 20(2)
Members of management bodies must follow training, and are encouraged to offer similar training to employees.
DORA Art. 13(6)
ICT security awareness programmes and digital operational resilience training for staff and the management body.

How it works

  1. 01You get an organisation and invite people by email. They accept once and play as themselves from then on.
  2. 02Wednesday morning everyone gets one email: the debrief is live. Three minutes, from a laptop or a phone.
  3. 03Tuesday your administrators get last week's completion and what the organisation missed most.
  4. 04Whenever you need it: the training register as CSV or PDF, with a verification id and hash anyone can check.

The line we hold

Administrators see completion, time and score per person, and what the organisation as a whole misses most (once five people have answered). No one in your organisation sees an individual's wrong answers. This is written into the product and into the data-processing agreement.

Data lives in the EU (Supabase, Ireland). Sweden first: pilots with Swedish organisations, in English, priced per seat. Swedish content when there is demand for it.

Ask for a pilot

We reply personally. No newsletter, no drip sequence.

Real incidents. Real lessons. No signup.

A ThreatNoir production