TRAINING AND AWARENESS
Back to Blog
THE CONTROL YOU CANNOT WRITE YOUR WAY OUT OF
Every risk assessment we have ever seen arrives at the same place. Somewhere in the top five, phrased one way or another, sits the human factor. Someone clicks the link. Someone approves the invoice. Someone sends the file to the wrong address.
And then something odd happens. The organisation writes a control — employee security awareness — marks it as implemented, attaches a policy document from three years ago, and moves on to the next risk.
This is the gap that governance platforms, ours included, cannot close on their own. A GRC platform is very good at telling you that a risk exists, who owns it, and what you said you would do about it. It cannot make anyone behave differently. It can only record, with admirable precision, that you intended to.
So we have done something about it:
Cyrigo has established a partnership with Moxso, and their security awareness training is available directly through us.
Moxso is a Copenhagen-based company that builds awareness training the way it should have been built all along — as something people actually do, rather than something they endure once a year. The format is micro-learning: Roughly ten minutes a month per employee, delivered through short videos and interactive exercises, with possibilities to combine with phishing simulations well suited for learning.
Three things made us choose them.
The training adapts to the individual. Rather than sending the same annual course to everyone, the platform establishes a baseline through phishing simulation and then adjusts what each employee receives according to their actual risk level and behaviour. The finance team and the warehouse do not need the same training, and neither does the person who reports every suspicious email as opposed to the person who has clicked twice this quarter.
It produces data. Completion rates, phishing click rates, reporting rates, improvement over time. This is the part that matters most to us, and we will come back to it.
It meets the standard we hold ourselves to. Moxso is ISO 27001 certified with European hosting and GDPR compliance. We were not going to recommend a security vendor that could not answer the questions we ask everyone else.
Why this belongs in a risk platform
Here is the part that made this partnership obvious rather than merely sensible.
An awareness control has always been difficult to evidence. You can show an auditor a training policy. You can show them an attendance list. Neither tells you whether the control works, and both are the kind of documentation that satisfies a checkbox while leaving the underlying risk exactly where it was.
Training data changes that. Phishing click rate is not a document — it is a measurement of the control's effectiveness, taken from live behaviour, repeatable month over month. Attach that to the risk it mitigates, and you have something genuinely rare in this field: A control you can prove is working, or prove is not.
That is the whole idea behind Cyrigo. Understand and control your risks, rather than assemble evidence that you thought about them. The human factor has been the hardest place to live up to that, because the tooling to measure it sat outside the governance platform. Now it doesn't have to.
The regulatory part, briefly
Awareness training is not optional, and it is becoming less optional. ISO/IEC 27001 requires information security awareness, education and training. NIS2 requires cyber hygiene practices and cybersecurity training, and puts an explicit obligation on management bodies to undergo training themselves — not merely to fund it for everyone else. The Norwegian Digital Security Act carries the same requirements into Norwegian law.
We mention this last, deliberately. Compliance is the reason many organisations start; it is a poor reason to stop. The organisations that get value from awareness training are the ones that treat the click rate as a number to improve, not a report to file.
Getting started
Moxso training is available now to Cyrigo customers. If you are already using the platform, contact us and we will get you set up. If you are not, this is a good moment to talk about both.

Back to Blog