Hornetsecurity Security Awareness Service
– Frequently Asked Questions (FAQ)

Operational effort is very low. After initial onboarding, the Security Awareness Service runs largely automated:

  • Users are automatically synchronized
  • Trainings and simulations are self-managed
  • Evaluations are centrally available

No manual training management required.

No. Participation can be strategically managed, for example:

  • all employees
  • only specific business units
  • Executives or IT
  • Phased implementation

Selection is determined individually as part of the onboarding process.

No. The simulations are designed to be:

  • realistic but not disruptive
  • do not impact production systems
  • are clearly identified as a training measure

Through onboarding, necessary protection mechanisms (e.g., whitelisting) are seamlessly aligned.

The goal is learning, not sanctioning.

Employees receive:

  • Immediate Feedback
  • Relevant Training Content
  • Understandable Guidance for Secure Response

The focus is on sustainable awareness, not control.

Yes,ceterion supports the implementation of intermunicipal cooperation models (IKZ) within Hornetsecurity's Security Awareness Service.

This service is particularly well-suited for cross-institutional collaboration scenarios because:

  • centralized control and administration are possible
  • separate analyses can be performed for each municipality or organizational unit
  • Data protection requirements must also be taken into account when multiple partners are involved
  • Economies of scale arise in operations, organization, and implementation

ceterion can help you with:

  • the conceptual design of the IKZ model
  • the technical and organizational separation of participants and evaluations
  • the vote on data protection, employee participation, and role models
  • the structured rollout for multiple municipalities

This way, multiple municipalities can benefit together—with clearly defined responsibilities and transparent management.

The Security Awareness Service is particularly well-suited for:

  • Municipalities and cities
  • Public administrations and government agencies
  • Municipal enterprises and public organizations
  • Mid-sized Companies
  • Organizations using Microsoft 365 / Exchange

The service is scalable and adapts flexibly to organizations of all sizes—from small government agencies to larger organizations, medium-sized businesses, and municipal associations.

Yes. As part of Hornetsecurity's Security Awareness Service, a company certificate (Company Certificatethat reflects your organization’s current level of security awareness based on the Employee Security Index (ESI®).

The certificate is based on:

  • the results of the awareness training sessions
  • the phishing simulations
  • the aggregate safety behavior of employees

The company certificate:

  • is requested from Hornetsecurity
  • is updated annually to reflect progress in security levels
  • serves as documentation for internal and external purposes

Typical applications include:

  • Information from senior management, the executive board, or governing bodies
  • Internal communication and employee motivation
  • Documentation of preventive measures
  • providing support during discussions with cyber insurers, auditors, or partners

The corporate certificate makes the level of security awareness transparent, traceable, and verifiable.

Note:
The company certificate does not constitute ISO or formal security certification, but rather documents your organization’s awareness status based on the ESI®.

Yes. In the User Panel of Hornetsecurity’s Security Awareness Service, employees can download a personal certificate for completed e-training courses in the “Achievements” module.

The certificate:

  • confirms successful participation in the respective e-training sessions
  • is available for download directly in the User Panel
  • can be used for internal records, personal documentation, or motivation

User certificates help ensure that training is well-received, reinforce employees' sense of personal responsibility, and foster a sustainable safety culture.

Note:
User certificates document the training completed by individual employees and are independent of the company certificate based on the ESI®.

Yes. The Security Awareness Service offers a special data protection mode that is particularly well-suited for local governments and public institutions.

Optionally, you can:

  • individual click or behavioral data is anonymized
  • Analyses are performed exclusively at the group level

Data protection and employee participation requirements are taken into account during the onboarding process.

The engine simulates realistic, customized spear-phishing attacks of varying difficulty levels —so that employees can familiarize themselves with even the most sophisticated attacks.

Level 1 – Mass phishing
Level 2 – Spear phishing from the CEO
Level 3 – Includes specific company information
Level 4 – Includes job title + colleagues and supervisors
Level 5 – Includes spoofed domains
Level 6 – Includes email thread history
Level 7 – Includes customization based on individual inbox content

(Level 6 & 7 phishing scenarios planned for future expansion.
Prerequisite: Spam and Malware Protection or 365 Total Protection)

Auto Training Mode
The training content is automatically rolled out to users and groups based on their needs.

Single User & Productivity Booster
: Users with additional learning needs receive more intensive training, while those who are already at a good proficiency level receive less.

Automatic onboarding of new users
(requires LDAP/AD sync)

Manual Training Mode
You have the option to manually roll out training modules to groups and users.

Gamification involves incorporating game-like elements into learning and training content. The goal is to increase employees’ attention and willingness to learn—for example, through quizzes, progress indicators, or small successes. This helps ensure that safety-related content is better understood and retained over the long term.

As a general rule:

  • Microsoft 365 / Exchange Online or On-Premises Exchange
  • Internet access
  • Optional: Active Directory or Entra ID for automatic synchronization

The exact details will be reviewed on an individual basis during the onboarding process.

Hornetsecurity's Security Awareness Service can be seamlessly integrated into existing email environments.

Among others, the following are supported:

  • Microsoft 365 / Exchange Online
  • On-Premises Exchange

respectively:

  • with or without Hornetsecurity Total Protection
  • regardless of whether Hornetsecurity is used as an email relay

As part of the initial onboarding process, ceterion ensures that:

  • simulated phishing emails are reliably delivered
  • existing security measures (e.g., Microsoft Defender, firewalls, email gateways) are properly taken into account
  • the necessary whitelist and security settings have been properly configured

This will not affect ongoing email operations.

Depending on the environment and coordination, this typically takes 2–4 weeks until the system goes live. The timeline will be agreed upon transparently in advance.

Yes. We offer you the opportunity to try out Hornetsecurity’s Security Awareness Service in advance—with no obligation and at no risk.

These include:

  • a no-obligation initial consultation
  • a live demo of the Security Awareness Service
  • Optional: a 30-day trial in your organization

This gives you a realistic idea of the software’s features, usability, and added value before you make a decision— ideal for local governments, public institutions, and businesses that need a solid basis for decision-making.

The fixed-price onboarding includes, among other things:

  • Technical Setup and Integration
  • User Setup & Structuring
  • Data Protection Configuration
  • Custom Baseline Configurations
  • Start & Testing of Simulations and Trainings
  • Admin Briefing

A clearly defined scope of services – without hidden additional costs.

ceterion is your single point of contact and supports you throughout the entire service lifecycle:

  • during implementation and initial setup
  • during operation
  • for adjustments, additions, and questions

The Security Awareness Service is operated by the manufacturer Hornetsecurity (hosted by Hornetsecurity). This ensures professional, scalable, and secure operation of the platform.

Hornetsecurity, a German IT security company headquartered in Hanover, develops and operates its solutions with a focus on the European market.

This means you have a dedicated point of contact —for both technical and organizational matters—while also benefiting from the established platform provided by Hornetsecurity.

Hornetsecurity is a German provider that is actively committed to verified security, data protection, and digital sovereignty in Europe:

  • BSI Certification (BSZ): Hornetsecurity's Email Protection has been security-certified by the BSI and tested with no exploitable vulnerabilities found.
  • Cybersecurity made in Europe: Hornetsecurity holds the ECSO label for European cybersecurity companies with trustworthy values.
  • European Champions Alliance: Hornetsecurity is a member of the ECA and is committed to strengthening European technology and digital sovereignty.
  • eco – Association of the German Internet Industry: Hornetsecurity is an eco member and supports Germany as a business location, including through the Certified Senders Alliance.

Didn’t find the answer to your question in the FAQ section? Feel free to contact us!
Or simply book a no-obligation “Meet an Expert” appointment! We’d be happy to provide you with personalized advice.