Skip to content
Sign inGet started

A tick in a box is not proof they would spot it.

Build the course from your own security policy, put a test at the end that cannot be clicked through, and find out who actually recognises a phishing mail. Next year we test them again, automatically.

Start 30 days freeBook a demo

No credit card needed. Up to 5 users, cancel anytime.

Phishing and passwords · Test result

Test result

Submitted 14 Mar

Not enough points to pass.

Passing score: 24 points

21

of 30

Which of these senders is genuine?

+6 pts

Mark the warning signs in this mail

+8 pts

An unexpected invoice arrives. What now?

Incorrect

Sort these requests: safe or suspicious

+7 pts

What you get

Three things a completion tick cannot tell you

Sitting through it and knowing it are not the same thing.

Your policy, not a stock library

We do not sell you a video about a stranger's company. The course is built from your own password rules, your own incident procedure and the systems your people actually log into.

A test they cannot click through

Set the score they have to reach, give the heavy questions more weight, subtract points for a wrong answer and shuffle the options for everyone. Ask them to point at the warning sign in a screenshot instead of picking A, B or C.

It comes back every year

Set the course to repeat and everyone who is due gets it again. When someone asks for the records you export the overview instead of rebuilding it, and every pass files a dated certificate.

Your first hour

From sign-up to a live test

Not a promise. The three screens you will actually be looking at.

  1. Bring the policy you already have

    Drop in the security policy or the awareness deck that is already circulating and turn it into a course with the block editor. Add the screenshots your own people are getting.

  2. Say who and by when

    Assign by tag rather than by person, mark the course required for that team, and give them a year before it comes round again.

  3. See who guessed

    What comes back is a score against a pass mark, not a tick. You see who passed, who is still working through it, and what each person actually scored.

Before you sign up

The things people ask us first

Do you supply the course content?

No, and that is deliberate. Zunderwork is where your own policy becomes a course. If you have a security policy, an incident procedure or a deck from your last awareness session, you already have the material.

Can I stop people clicking straight through the test?

Set a passing score, give the important questions more weight, subtract points for a wrong answer and shuffle the options. You decide whether a failed test may be retaken, and a course can be set to stay unfinished until the test is passed.

What kind of questions can I ask?

Multiple choice and true or false, but also filling in the blanks, matching pairs, putting steps in the right order, sorting items into groups, and clicking the right spot in a screenshot. That last one is how you find out whether someone actually sees the warning sign.

Can I show that the training happened?

The overview of who completed what can be exported whenever it is asked for. Switch certificates on for the course and every pass files a dated one as well.

Where does our data live?

In the European Union. Zunderwork is built in Rotterdam and hosted entirely within the EU, under the GDPR, and never shipped overseas.

Ready to start?

Find out what your people actually know

Thirty days, your own policy, your own team. Build one course, run one test, and see where you stand.

No credit card needed. Up to 5 users, cancel anytime.