Security Awareness Training Switzerland, Vendors, Setup, KPIs
Introduction
Within five years, security awareness training in Switzerland has matured from a one-off annual mandatory e-learning slot to a measurable, continuous behaviour-change programme. The drivers are regulatory (ISO/IEC 27001:2022 Annex A.6.3, FINMA Circular 23/01, DORA Art. 13(6), Art. 21(2)(g) NIS2) and economic: phishing remains, per the IBM Cost of a Data Breach Report 2024, the most common initial vector in incidents involving personal-data exposure. Anyone not running awareness professionally accepts an avoidable residual risk.
This article covers:
- Vendor landscape 2025 (KnowBe4, SoSafe, Hoxhunt, Mimecast, Proofpoint).
- Programme setup: campaign cadence, content, just-in-time training.
- KPIs: why click-rate alone is the wrong KPI.
- Management body reporting and the move to behavioural-security metrics.
- Swiss specifics: multilingualism, cultural tone, data-protection compliance.
Normative anchors are ISO/IEC 27001:2022 Annex A.6.3 (information security awareness, education and training), ISO/IEC 27002:2022 clause 6.3 (more comprehensive), NIST SP 800-50r1 (Building a Cybersecurity and Privacy Awareness and Training Program), FINMA Circular 23/01 para 24 (HR and training requirements), DORA Art. 13(6) and Art. 21(2)(g) NIS2 supplemented by the management-body training duty in Art. 20(2) NIS2.
Vendor landscape 2025
The security-awareness market in DACH consolidated in 2025 around a handful of dominant vendors:
- KnowBe4: global market leader, very broad content library (1,000+ modules), strong phishing-simulation engine, robust reporting. Swiss data residency available since 2023. Price indication: CHF 25-50 per user per year by tier and volume.
- SoSafe: Cologne-based, very strong in the DACH mid-market, localised content (DE/EN/FR/IT, high Swiss market loyalty), behavioural-science approach. GDPR-compliant, EU hosting. Price indication: CHF 30-55 per user.
- Hoxhunt: Finland-based, gamified approach with continuous micro-trainings instead of annual modules, high engagement rates. Focus: measurable behaviour change. Price indication: CHF 35-60 per user.
- Mimecast Awareness Training: strong where Mimecast email security is already deployed (integration). Shorter modules, good phishing simulation. Price indication: CHF 20-40 per user.
- Proofpoint Security Awareness (former Wombat): strong in the enterprise segment, granular reporting, high customisability. Price indication: CHF 30-60 per user.
Further relevant options: G DATA (DE vendor, very SME-friendly), Cofense PhishMe (US, strong anti-phishing reporter), Junglemap NanoLearning (DE, micro-format units). Selection drivers: content quality in the main language(s), data residency and DSG / GDPR compliance, API integration (Microsoft 365, Google Workspace, Okta/Entra for auto-provisioning), reporting depth and phishing-simulation quality.
Programme setup and cadence
A professional awareness programme is not a one-shot e-learning, but a 12-month programme of multiple building blocks:
- Onboarding module (15-20 min): mandatory for new joiners within the first 14 days. Covers phishing basics, password hygiene, data classification, incident reporting.
- Annual refresher (20-30 min): mandatory for all, with current threat themes (e.g. AI-generated phishing, deepfake calls, MFA bombing).
- Monthly micro-modules (3-5 min): theme-specific, often video-based. Examples: USB finds, social media oversharing, traveller security, secure home office.
- Phishing simulations: monthly or bimonthly, with rising difficulty. Lures adapted to current threat landscape and Swiss context (Swiss Post, SBB, Swiss FedEx, taxes).
- Just-in-time training: anyone who clicks a simulation receives an immediate 60-second micro-lesson, not days later.
- Role-specific modules: developers get secure-coding training, finance gets CEO-fraud awareness, HR gets GDPR depth.
- Management body briefing (1× annual, 60 min): mandatory under Art. 20(2) NIS2; recommended even without NIS2 scope.
For a mid-sized Swiss company (200-500 staff) total effort per employee is around 2-3 hours per year, a good trade-off between effectiveness and acceptance.
Click-rate is the wrong KPI
One of the most damaging practices in awareness is to report only on phishing click-rate. Click-rate measures how many employees click a simulated email. It is easy to collect and easy to communicate, but it captures only half of the relevant behaviour.
The far more meaningful dual KPI is:
- Click-rate (lower = better): share of recipients clicking the link. Industry median 2024 for office staff: 5-12% depending on lure quality.
- Report-rate (higher = better): share of recipients reporting the email via a phish-report button. Industry target for mature programmes: 25-40%+.
An organisation with 3% click and 5% report is significantly more vulnerable than one with 8% click and 40% report. In the first case 92% of real phishing emails are reported by no one and can sit undetected for hours. In the second a meaningful share of staff reports real phishing to the SOC, massively accelerating detection and response.
Recommendation: always report click-rate and report-rate together; a phish-report button (Outlook add-in, KnowBe4 PAB, Cofense Reporter, vendor-native Mimecast/Proofpoint tooling) is mandatory.
Extended behavioural metrics
Mature awareness programmes measure further behavioural indicators beyond click and report:
- Time-to-report: how fast is a simulated or real phishing email reported? Target: under 30 minutes median.
- Repeat-clicker rate: share of staff clicking in two or more campaigns. These require targeted 1:1 coaching.
- Credential-submission rate: share of those who submit credentials on the lure page in a simulation. Materially more critical than a mere click.
- Training completion rate: target > 95% within 30 days of assignment.
- Awareness index: composite score from click, report, completion and knowledge-check results. Enables comparison across departments, over time, and industry benchmarks.
- Real incident reporting rate: how many actual incidents per employee per year are reported? Low values are not good news, they usually mean incidents are missed.
Important: all metrics should be aggregated at department or site level, not made public at individual level. A "Wall of Shame" backfires, it suppresses report-rates because staff fear reprisals. Positive reinforcement (recognition of top reporters) works better.
Management body reporting
Awareness reporting to the management body should be quarterly and cover three layers:
- Programme status: training completion rate, number of campaigns run, themes covered.
- Behavioural indicators: click-rate trend, report-rate trend, time-to-report, repeat-clicker share. With 12-month trend lines.
- Risk translation: what do these numbers mean for business risk? Concrete real incidents (anonymised), repelled attacks, new threat themes, planned programme adjustments.
A typical quarterly report runs to 4-6 slides:
- Slide 1: executive summary (3 bullets, 1 KPI tile).
- Slide 2: programme KPIs (completion rate, count of modules/campaigns).
- Slide 3: behavioural KPIs with 12-month trend.
- Slide 4: top 3 findings per threat theme.
- Slide 5: real incidents and lessons learned.
- Slide 6: roadmap for next quarter.
Failing to translate awareness KPIs into business risk leaves the programme in IT-bullet-point mode and loses management attention. Awareness is business protection, not IT hygiene.
Swiss specifics
Swiss companies differ from DACH or global setups in several aspects:
- Multilingualism: content must be available in DE, FR and partly IT, ideally with Swiss-German nuance (no German "Tüte" in DE-CH modules). Vendors such as SoSafe and KnowBe4 deliver explicit CH localisation.
- Data residency: DSG and GDPR require clear accountability for awareness platforms processing personal learning-progress data. Recommendation: EU or CH hosting, processor agreement under Art. 28 GDPR or Art. 9 DSG, SCCs for US vendors with transfer impact assessment.
- Cultural tone: Swiss staff often react sceptically to US cheerleader tone. Sober, technically precise modules work better.
- Phishing lures: Swiss brands (Die Post, SBB, Swisscom, ZKB, UBS, Migros, Coop) feel more realistic than generic US brands; use should be aligned with trademark considerations (disclaimer and selection of brands already abused per BACS / NCSC threat reports).
- Works council: for large Swiss companies, engage staff representation early, phishing simulations can be misread as "employee surveillance."
More on our training offer: IT security workshop for SMEs and data protection workshop for SMEs.
How SIDD supports you
SIDD supports Swiss companies in building and running professional awareness programmes. We start with a maturity assessment (against NIST SP 800-50r1 and ISO/IEC 27002:2022 clause 6.3), select the right platform with you (KnowBe4, SoSafe, Hoxhunt, Mimecast, Proofpoint, vendor-neutral), and design a 12-month programme with onboarding, annual refresher, monthly micro-modules, phishing simulations and role-specific deep dives.
For the management body training under Art. 20(2) NIS2 we deliver 60-90-minute sessions with concrete sector relevance, tailored to board or executive audiences. For ongoing programme steering we take over the awareness mandate in a managed-service model, integrated with our external CISO service. For on-site awareness workshops see IT security workshop for SMEs.
Arrange a non-binding first conversation at /kontakt or request a fixed-price quote for a 12-month awareness programme at /offerte. Typical entry: a 3-month pilot with 2 phishing simulations, an onboarding module and a management body briefing for CHF 12,000-25,000, then roll-out to a full annual setup.
