Security Awareness Training Switzerland, Vendors, Setup, KPIs

6 min readLast updated By Marc Grob

Introduction

Within five years, security awareness training in Switzerland has matured from a one-off annual mandatory e-learning slot to a measurable, continuous behaviour-change programme. The drivers are regulatory (ISO/IEC 27001:2022 Annex A.6.3, FINMA Circular 23/01, DORA Art. 13(6), Art. 21(2)(g) NIS2) and economic: phishing remains, per the IBM Cost of a Data Breach Report 2024, the most common initial vector in incidents involving personal-data exposure. Anyone not running awareness professionally accepts an avoidable residual risk.

This article covers:

  • Vendor landscape 2025 (KnowBe4, SoSafe, Hoxhunt, Mimecast, Proofpoint).
  • Programme setup: campaign cadence, content, just-in-time training.
  • KPIs: why click-rate alone is the wrong KPI.
  • Management body reporting and the move to behavioural-security metrics.
  • Swiss specifics: multilingualism, cultural tone, data-protection compliance.

Normative anchors are ISO/IEC 27001:2022 Annex A.6.3 (information security awareness, education and training), ISO/IEC 27002:2022 clause 6.3 (more comprehensive), NIST SP 800-50r1 (Building a Cybersecurity and Privacy Awareness and Training Program), FINMA Circular 23/01 para 24 (HR and training requirements), DORA Art. 13(6) and Art. 21(2)(g) NIS2 supplemented by the management-body training duty in Art. 20(2) NIS2.

Vendor landscape 2025

The security-awareness market in DACH consolidated in 2025 around a handful of dominant vendors:

  • KnowBe4: global market leader, very broad content library (1,000+ modules), strong phishing-simulation engine, robust reporting. Swiss data residency available since 2023. Price indication: CHF 25-50 per user per year by tier and volume.
  • SoSafe: Cologne-based, very strong in the DACH mid-market, localised content (DE/EN/FR/IT, high Swiss market loyalty), behavioural-science approach. GDPR-compliant, EU hosting. Price indication: CHF 30-55 per user.
  • Hoxhunt: Finland-based, gamified approach with continuous micro-trainings instead of annual modules, high engagement rates. Focus: measurable behaviour change. Price indication: CHF 35-60 per user.
  • Mimecast Awareness Training: strong where Mimecast email security is already deployed (integration). Shorter modules, good phishing simulation. Price indication: CHF 20-40 per user.
  • Proofpoint Security Awareness (former Wombat): strong in the enterprise segment, granular reporting, high customisability. Price indication: CHF 30-60 per user.

Further relevant options: G DATA (DE vendor, very SME-friendly), Cofense PhishMe (US, strong anti-phishing reporter), Junglemap NanoLearning (DE, micro-format units). Selection drivers: content quality in the main language(s), data residency and DSG / GDPR compliance, API integration (Microsoft 365, Google Workspace, Okta/Entra for auto-provisioning), reporting depth and phishing-simulation quality.

Programme setup and cadence

A professional awareness programme is not a one-shot e-learning, but a 12-month programme of multiple building blocks:

  • Onboarding module (15-20 min): mandatory for new joiners within the first 14 days. Covers phishing basics, password hygiene, data classification, incident reporting.
  • Annual refresher (20-30 min): mandatory for all, with current threat themes (e.g. AI-generated phishing, deepfake calls, MFA bombing).
  • Monthly micro-modules (3-5 min): theme-specific, often video-based. Examples: USB finds, social media oversharing, traveller security, secure home office.
  • Phishing simulations: monthly or bimonthly, with rising difficulty. Lures adapted to current threat landscape and Swiss context (Swiss Post, SBB, Swiss FedEx, taxes).
  • Just-in-time training: anyone who clicks a simulation receives an immediate 60-second micro-lesson, not days later.
  • Role-specific modules: developers get secure-coding training, finance gets CEO-fraud awareness, HR gets GDPR depth.
  • Management body briefing (1× annual, 60 min): mandatory under Art. 20(2) NIS2; recommended even without NIS2 scope.

For a mid-sized Swiss company (200-500 staff) total effort per employee is around 2-3 hours per year, a good trade-off between effectiveness and acceptance.

Click-rate is the wrong KPI

One of the most damaging practices in awareness is to report only on phishing click-rate. Click-rate measures how many employees click a simulated email. It is easy to collect and easy to communicate, but it captures only half of the relevant behaviour.

The far more meaningful dual KPI is:

  • Click-rate (lower = better): share of recipients clicking the link. Industry median 2024 for office staff: 5-12% depending on lure quality.
  • Report-rate (higher = better): share of recipients reporting the email via a phish-report button. Industry target for mature programmes: 25-40%+.

An organisation with 3% click and 5% report is significantly more vulnerable than one with 8% click and 40% report. In the first case 92% of real phishing emails are reported by no one and can sit undetected for hours. In the second a meaningful share of staff reports real phishing to the SOC, massively accelerating detection and response.

Recommendation: always report click-rate and report-rate together; a phish-report button (Outlook add-in, KnowBe4 PAB, Cofense Reporter, vendor-native Mimecast/Proofpoint tooling) is mandatory.

Extended behavioural metrics

Mature awareness programmes measure further behavioural indicators beyond click and report:

  • Time-to-report: how fast is a simulated or real phishing email reported? Target: under 30 minutes median.
  • Repeat-clicker rate: share of staff clicking in two or more campaigns. These require targeted 1:1 coaching.
  • Credential-submission rate: share of those who submit credentials on the lure page in a simulation. Materially more critical than a mere click.
  • Training completion rate: target > 95% within 30 days of assignment.
  • Awareness index: composite score from click, report, completion and knowledge-check results. Enables comparison across departments, over time, and industry benchmarks.
  • Real incident reporting rate: how many actual incidents per employee per year are reported? Low values are not good news, they usually mean incidents are missed.

Important: all metrics should be aggregated at department or site level, not made public at individual level. A "Wall of Shame" backfires, it suppresses report-rates because staff fear reprisals. Positive reinforcement (recognition of top reporters) works better.

Management body reporting

Awareness reporting to the management body should be quarterly and cover three layers:

  1. Programme status: training completion rate, number of campaigns run, themes covered.
  2. Behavioural indicators: click-rate trend, report-rate trend, time-to-report, repeat-clicker share. With 12-month trend lines.
  3. Risk translation: what do these numbers mean for business risk? Concrete real incidents (anonymised), repelled attacks, new threat themes, planned programme adjustments.

A typical quarterly report runs to 4-6 slides:

  • Slide 1: executive summary (3 bullets, 1 KPI tile).
  • Slide 2: programme KPIs (completion rate, count of modules/campaigns).
  • Slide 3: behavioural KPIs with 12-month trend.
  • Slide 4: top 3 findings per threat theme.
  • Slide 5: real incidents and lessons learned.
  • Slide 6: roadmap for next quarter.

Failing to translate awareness KPIs into business risk leaves the programme in IT-bullet-point mode and loses management attention. Awareness is business protection, not IT hygiene.

Swiss specifics

Swiss companies differ from DACH or global setups in several aspects:

  • Multilingualism: content must be available in DE, FR and partly IT, ideally with Swiss-German nuance (no German "Tüte" in DE-CH modules). Vendors such as SoSafe and KnowBe4 deliver explicit CH localisation.
  • Data residency: DSG and GDPR require clear accountability for awareness platforms processing personal learning-progress data. Recommendation: EU or CH hosting, processor agreement under Art. 28 GDPR or Art. 9 DSG, SCCs for US vendors with transfer impact assessment.
  • Cultural tone: Swiss staff often react sceptically to US cheerleader tone. Sober, technically precise modules work better.
  • Phishing lures: Swiss brands (Die Post, SBB, Swisscom, ZKB, UBS, Migros, Coop) feel more realistic than generic US brands; use should be aligned with trademark considerations (disclaimer and selection of brands already abused per BACS / NCSC threat reports).
  • Works council: for large Swiss companies, engage staff representation early, phishing simulations can be misread as "employee surveillance."

More on our training offer: IT security workshop for SMEs and data protection workshop for SMEs.

How SIDD supports you

SIDD supports Swiss companies in building and running professional awareness programmes. We start with a maturity assessment (against NIST SP 800-50r1 and ISO/IEC 27002:2022 clause 6.3), select the right platform with you (KnowBe4, SoSafe, Hoxhunt, Mimecast, Proofpoint, vendor-neutral), and design a 12-month programme with onboarding, annual refresher, monthly micro-modules, phishing simulations and role-specific deep dives.

For the management body training under Art. 20(2) NIS2 we deliver 60-90-minute sessions with concrete sector relevance, tailored to board or executive audiences. For ongoing programme steering we take over the awareness mandate in a managed-service model, integrated with our external CISO service. For on-site awareness workshops see IT security workshop for SMEs.

Arrange a non-binding first conversation at /kontakt or request a fixed-price quote for a 12-month awareness programme at /offerte. Typical entry: a 3-month pilot with 2 phishing simulations, an onboarding module and a management body briefing for CHF 12,000-25,000, then roll-out to a full annual setup.

Need help putting this into practice? SIDD operates the matching service.
See service →

Security Awareness Training Switzerland, Vendors, Setup, KPIs

INSIGHT

InfoSec
24 May 2026
Marc Grob
Security awareness training in Switzerland: providers, programme design, meaningful metrics beyond the click rate and reporting to management.

Subscribe to our newsletter for free here

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.