# Security Awareness Training Switzerland, Vendors, Setup, KPIs

> Security awareness training in Switzerland: providers, programme design, meaningful metrics beyond the click rate and reporting to management.

- Source: https://www.sidd.swiss/en/insights/security-awareness-training-switzerland/
- Language: en
- Published: 2026-05-24
- Last updated: 2026-05-24
- Author: Marc Grob
- Publisher: SIDD Institute for Data Protection and Data Security, a brand of Priverion GmbH, Zugerstrasse 32, 6340 Baar (ZG), Switzerland

## Introduction

Within five years, security awareness training in Switzerland has matured from a one-off annual mandatory e-learning slot to a measurable, continuous behaviour-change programme. The drivers are regulatory (ISO/IEC 27001:2022 Annex A.6.3, FINMA Circular 23/01, DORA Art. 13(6), Art. 21(2)(g) NIS2) and economic: phishing remains, per the IBM Cost of a Data Breach Report 2024, the most common initial vector in incidents involving personal-data exposure. Anyone not running awareness professionally accepts an avoidable residual risk.

**This article covers:**

- Vendor landscape 2025 (KnowBe4, SoSafe, Hoxhunt, Mimecast, Proofpoint).
- Programme setup: campaign cadence, content, just-in-time training.
- KPIs: why click-rate alone is the wrong KPI.
- Management body reporting and the move to behavioural-security metrics.
- Swiss specifics: multilingualism, cultural tone, data-protection compliance.

Normative anchors are ISO/IEC 27001:2022 Annex A.6.3 (information security awareness, education and training), ISO/IEC 27002:2022 clause 6.3 (more comprehensive), NIST SP 800-50r1 (Building a Cybersecurity and Privacy Awareness and Training Program), FINMA Circular 23/01 para 24 (HR and training requirements), DORA Art. 13(6) and Art. 21(2)(g) NIS2 supplemented by the management-body training duty in Art. 20(2) NIS2.

## Vendor landscape 2025

The security-awareness market in DACH consolidated in 2025 around a handful of dominant vendors:

- **KnowBe4:** global market leader, very broad content library (1,000+ modules), strong phishing-simulation engine, robust reporting. Swiss data residency available since 2023. Price indication: CHF 25-50 per user per year by tier and volume.
- **SoSafe:** Cologne-based, very strong in the DACH mid-market, localised content (DE/EN/FR/IT, high Swiss market loyalty), behavioural-science approach. GDPR-compliant, EU hosting. Price indication: CHF 30-55 per user.
- **Hoxhunt:** Finland-based, gamified approach with continuous micro-trainings instead of annual modules, high engagement rates. Focus: measurable behaviour change. Price indication: CHF 35-60 per user.
- **Mimecast Awareness Training:** strong where Mimecast email security is already deployed (integration). Shorter modules, good phishing simulation. Price indication: CHF 20-40 per user.
- **Proofpoint Security Awareness (former Wombat):** strong in the enterprise segment, granular reporting, high customisability. Price indication: CHF 30-60 per user.

Further relevant options: G DATA (DE vendor, very SME-friendly), Cofense PhishMe (US, strong anti-phishing reporter), Junglemap NanoLearning (DE, micro-format units). Selection drivers: content quality in the main language(s), data residency and DSG / GDPR compliance, API integration (Microsoft 365, Google Workspace, Okta/Entra for auto-provisioning), reporting depth and phishing-simulation quality.

## Programme setup and cadence

A professional awareness programme is not a one-shot e-learning, but a 12-month programme of multiple building blocks:

- **Onboarding module (15-20 min):** mandatory for new joiners within the first 14 days. Covers phishing basics, password hygiene, data classification, incident reporting.
- **Annual refresher (20-30 min):** mandatory for all, with current threat themes (e.g. AI-generated phishing, deepfake calls, MFA bombing).
- **Monthly micro-modules (3-5 min):** theme-specific, often video-based. Examples: USB finds, social media oversharing, traveller security, secure home office.
- **Phishing simulations:** monthly or bimonthly, with rising difficulty. Lures adapted to current threat landscape and Swiss context (Swiss Post, SBB, Swiss FedEx, taxes).
- **Just-in-time training:** anyone who clicks a simulation receives an immediate 60-second micro-lesson, not days later.
- **Role-specific modules:** developers get secure-coding training, finance gets CEO-fraud awareness, HR gets GDPR depth.
- **Management body briefing (1× annual, 60 min):** mandatory under Art. 20(2) NIS2; recommended even without NIS2 scope.

For a mid-sized Swiss company (200-500 staff) total effort per employee is around 2-3 hours per year, a good trade-off between effectiveness and acceptance.

## Click-rate is the wrong KPI

One of the most damaging practices in awareness is to report only on phishing click-rate. Click-rate measures how many employees click a simulated email. It is easy to collect and easy to communicate, but it captures only half of the relevant behaviour.

The far more meaningful dual KPI is:

- **Click-rate (lower = better):** share of recipients clicking the link. Industry median 2024 for office staff: 5-12% depending on lure quality.
- **Report-rate (higher = better):** share of recipients reporting the email via a phish-report button. Industry target for mature programmes: 25-40%+.

An organisation with 3% click and 5% report is significantly more vulnerable than one with 8% click and 40% report. In the first case 92% of real phishing emails are reported by no one and can sit undetected for hours. In the second a meaningful share of staff reports real phishing to the SOC, massively accelerating detection and response.

Recommendation: always report click-rate and report-rate together; a phish-report button (Outlook add-in, KnowBe4 PAB, Cofense Reporter, vendor-native Mimecast/Proofpoint tooling) is mandatory.

## Extended behavioural metrics

Mature awareness programmes measure further behavioural indicators beyond click and report:

- **Time-to-report:** how fast is a simulated or real phishing email reported? Target: under 30 minutes median.
- **Repeat-clicker rate:** share of staff clicking in two or more campaigns. These require targeted 1:1 coaching.
- **Credential-submission rate:** share of those who submit credentials on the lure page in a simulation. Materially more critical than a mere click.
- **Training completion rate:** target > 95% within 30 days of assignment.
- **Awareness index:** composite score from click, report, completion and knowledge-check results. Enables comparison across departments, over time, and industry benchmarks.
- **Real incident reporting rate:** how many actual incidents per employee per year are reported? Low values are not good news, they usually mean incidents are missed.

Important: all metrics should be aggregated at department or site level, not made public at individual level. A "Wall of Shame" backfires, it suppresses report-rates because staff fear reprisals. Positive reinforcement (recognition of top reporters) works better.

## Management body reporting

Awareness reporting to the management body should be quarterly and cover three layers:

1. **Programme status:** training completion rate, number of campaigns run, themes covered.
2. **Behavioural indicators:** click-rate trend, report-rate trend, time-to-report, repeat-clicker share. With 12-month trend lines.
3. **Risk translation:** what do these numbers mean for business risk? Concrete real incidents (anonymised), repelled attacks, new threat themes, planned programme adjustments.

A typical quarterly report runs to 4-6 slides:

- Slide 1: executive summary (3 bullets, 1 KPI tile).
- Slide 2: programme KPIs (completion rate, count of modules/campaigns).
- Slide 3: behavioural KPIs with 12-month trend.
- Slide 4: top 3 findings per threat theme.
- Slide 5: real incidents and lessons learned.
- Slide 6: roadmap for next quarter.

Failing to translate awareness KPIs into business risk leaves the programme in IT-bullet-point mode and loses management attention. Awareness is business protection, not IT hygiene.

## Swiss specifics

Swiss companies differ from DACH or global setups in several aspects:

- **Multilingualism:** content must be available in DE, FR and partly IT, ideally with Swiss-German nuance (no German "Tüte" in DE-CH modules). Vendors such as SoSafe and KnowBe4 deliver explicit CH localisation.
- **Data residency:** DSG and GDPR require clear accountability for awareness platforms processing personal learning-progress data. Recommendation: EU or CH hosting, processor agreement under Art. 28 GDPR or Art. 9 DSG, SCCs for US vendors with transfer impact assessment.
- **Cultural tone:** Swiss staff often react sceptically to US cheerleader tone. Sober, technically precise modules work better.
- **Phishing lures:** Swiss brands (Die Post, SBB, Swisscom, ZKB, UBS, Migros, Coop) feel more realistic than generic US brands; use should be aligned with trademark considerations (disclaimer and selection of brands already abused per BACS / NCSC threat reports).
- **Works council:** for large Swiss companies, engage staff representation early, phishing simulations can be misread as "employee surveillance."

More on our training offer: [IT security workshop for SMEs](https://www.sidd.swiss/en/services/it-security-workshop-sme) and [data protection workshop for SMEs](https://www.sidd.swiss/en/services/data-protection-workshop-sme).

## How SIDD supports you

SIDD supports Swiss companies in building and running professional awareness programmes. We start with a maturity assessment (against NIST SP 800-50r1 and ISO/IEC 27002:2022 clause 6.3), select the right platform with you (KnowBe4, SoSafe, Hoxhunt, Mimecast, Proofpoint, vendor-neutral), and design a 12-month programme with onboarding, annual refresher, monthly micro-modules, phishing simulations and role-specific deep dives.

For the management body training under Art. 20(2) NIS2 we deliver 60-90-minute sessions with concrete sector relevance, tailored to board or executive audiences. For ongoing programme steering we take over the awareness mandate in a managed-service model, integrated with our [external CISO service](https://www.sidd.swiss/en/services/vciso). For on-site awareness workshops see [IT security workshop for SMEs](https://www.sidd.swiss/en/services/it-security-workshop-sme).

Arrange a non-binding first conversation at [/kontakt](https://www.sidd.swiss/en/contact) or request a fixed-price quote for a 12-month awareness programme at [/offerte](https://www.sidd.swiss/en/quote). Typical entry: a 3-month pilot with 2 phishing simulations, an onboarding module and a management body briefing for CHF 12,000-25,000, then roll-out to a full annual setup.

---

This document is the Markdown rendition of the page linked above. Please cite the HTML URL.
