Security awareness platform
Security awareness training that holds up in an audit
24 training modules, an exam with a named certificate, controlled phishing simulations and a report your NIS2 auditor can read. No installation, no IT project.
What you get
Three things any training programme has to do
A slide deck once a year changes no behaviour and proves nothing to an auditor. A programme works when it teaches, tests in practice and leaves evidence behind.
Training and exams
Short modules that end with an exam and a PDF certificate. Microlearning and spaced repetition, so the knowledge does not evaporate within a week. See the catalogue of 24 modules.
Phishing simulations
A controlled campaign built on realistic scenarios. Who opened, who clicked, who entered credentials — and immediate remediation training for the people who need it.
Compliance reports
Who completed which training, when and with what score. Processing records, an event log and certificates ready to hand to a NIS2, ISO 27001 or GDPR auditor.
Why it works
Because we know what a real attack looks like
We are not reselling theory from a slide deck. We run live social engineering campaigns and penetration tests — and the scenarios in the platform come from them. We know where the human layer of defence actually breaks, because we watch it break in our own campaigns.
- Scenarios from the field — modelled on campaigns that genuinely got past spam filters.
- Measurement, not impressions — opens, clicks, credentials entered, reports to the SOC.
- Remediation on the spot — whoever clicks is assigned training immediately, not next quarter.
$ campaign --status --anon
10:31:58 #0412 link clicked
10:32:06 #0412 credentials entered
password ...... not stored
trace ......... SHA-256 + 3 chars
HIBP .......... found in 3 breaches
module ........ „Phishing and Social Engineering”
deadline ...... 7 days
10:38:12 #0871 reported to SOC
Compliance
In Poland, security training is now a statutory duty
Poland implemented NIS2 through an amendment to the Act on the National Cybersecurity System (Journal of Laws 2026, item 252), in force since 3 April 2026. Article 8(1)(2)(i) requires „cybersecurity education for the entity's personnel"; Article 8e obliges the management to complete documented training once every calendar year; Article 73a provides for a fine of up to 300% of remuneration — imposed personally on the people running the entity, not on the company.
If your group has a Polish entity in scope, this is the law it answers to.
Pricing
You pay per user. No setup fee
You choose the plan separately from the number of people. The bigger the team, the lower the rate per person. No licence minimum — you pay for as many users as you actually have. Prices in Polish złoty, net.
- Full catalogue of 24 modules
- Exams and certificates
- Phishing simulation and USB Drop
- No payment card
- For a team of any size up to 500 people
- Everything in the trial
- 2 phishing campaigns and 1 USB Drop a month
- 5 custom training modules
- Named PDF certificates
- For a team of any size up to 500 people
- Unlimited phishing and USB campaigns
- Unlimited custom modules and questions
- Training paths per department
- Monthly report for a NIS2 / ISO 27001 audit
- Everything in PROFESSIONAL
- SSO (SAML 2.0) and SCIM
- Dedicated onboarding and account manager
- Data processing agreement and SLA
- Above 500 people always a quote
See the full pricing table
| Number of users | STARTER net / user / month | PROFESSIONAL net / user / month |
|---|---|---|
| up to 10 (14 days, TRIAL) | 0 PLN | 0 PLN |
| 1–10 | 39 PLN | 49 PLN |
| 11–25 | 35 PLN | 44 PLN |
| 26–50 | 29 PLN | 36 PLN |
| 51–100 | 24 PLN | 30 PLN |
| 101–200 | 19 PLN | 24 PLN |
| 201–500 | 15 PLN | 19 PLN |
| 501 and above | individual quote (ENTERPRISE) | |
| ENTERPRISE — SSO/SCIM, SLA, account manager | quote for a team of any size | |
All prices net, in Polish złoty. Paying a year up front is 15% cheaper. No setup fee, no licence minimum, cancel at any point in the billing period.
Services
When training is not enough
Employee awareness is one layer. If you need to know what an attacker would do with your application or your network — we do that by hand, using OWASP ASVS and PTES.
Questions
What people ask us most
What does the KS-CYBER platform cost?
The plan and the number of people are two independent choices, and billing is per user per month. Starter: 39 PLN net for 1–10 people, 35 PLN for 11–25, 29 PLN for 26–50, 24 PLN for 51–100, 19 PLN for 101–200 and 15 PLN for 201–500 users. Professional: 49, 44, 36, 30, 24 and 19 PLN respectively. Enterprise (SSO/SCIM, SLA, account manager) is quoted individually for a team of any size, and above 500 people the quote is always individual. Paying a year up front is 15% cheaper.
Is there a free trial?
Yes — 14 days for up to 10 users, with no payment card and no installation.
How long does onboarding take?
About 15 minutes. The platform runs in the browser as SaaS and needs nothing installed on your side. You create accounts in bulk — by uploading a CSV list or sending email invitations in one batch — and on the Enterprise plan through SSO (SAML 2.0) and SCIM with automatic account provisioning.
Does the platform help meet the Polish NIS2 requirements?
Yes. The Polish Act on the National Cybersecurity System, as in force since 3 April 2026, requires education for personnel (Art. 8(1)(2)(i)), obliges the head of the entity to ensure staff awareness (Art. 8d(4)) and requires documented annual training for management (Art. 8e). The platform delivers the training, verifies knowledge with an exam and generates named certificates and reports that evidence those duties. Details in the summary of provisions.
Are phishing simulations GDPR-compliant?
Yes, provided the ground rules are kept: the legal basis is the controller's legitimate interest, employees must be told in the security policy that simulations are run, and results must be analysed in aggregate — not used to punish individuals. We go through this in a separate article.
How many languages does the platform support?
The interface and the training content are available in 35 languages, so an international organisation runs one programme rather than a separate one in every country.
Insights
Before you buy — check what the law and the numbers say
Is training mandatory?
Articles 8, 8d and 8e of the Polish NIS2 act — quoted in full, plus the 300% fine.
CostsWhat does it really cost?
Classroom versus e-learning — worked through on a 60-person company, hidden costs included.
LawPhishing simulations and GDPR
Legal basis, the duty to inform, and the lines that are not worth crossing.
Data97% of incidents target a person
CERT Polska figures for 2025: 272,941 incidents and a 144.4% year-on-year rise.
The duty is statutory. The evidence has to be yours.
Leave your details — we will send back a quote for your headcount together with scope and timing. If you would rather see the platform from the inside first, the trial starts immediately: 14 days, no installation, no card.