Use case

Security awareness that lands between two training sessions

An annual e-learning module is a compliance record, not a behaviour change. What changes behaviour is a short, well-timed reminder on the screen — the same screen where the phishing email is about to arrive.

The problem

Why awareness fades three weeks after the training

Security teams rarely lack content. They lack a channel that people actually see.

📉

Retention drops fast

Knowledge from a one-off session decays within weeks. Without reinforcement, the click rate on a simulated phishing campaign creeps back up to where it started.

📧

Security emails are the least read of all

Asking people to read a long email about not trusting emails is a structural problem. The message competes with the very inbox it is warning about.

📁

Auditors want evidence, not intentions

ISO 27001, NIS 2 and cyber insurance questionnaires all ask how awareness is delivered and how you know it reached people. "We sent a newsletter" is a thin answer.

How it works

Short, repeated, targeted — and recorded

The format does the work: a few seconds of attention, often, beats an hour of attention once.

1

One idea per message

A single rule, one screen: how to spot a spoofed sender, why the password manager exists, what to do with an unexpected attachment. Short enough to be read standing up.

2

Reach the population that matters

Finance and executive assistants face different attacks from the workshop floor. Target by Active Directory group so each message is relevant to whoever receives it.

3

Turn the campaign into evidence

Every dispatch keeps the recipient list, the display timestamp per workstation and the acknowledgements. That is an awareness log an auditor can actually read.

On screen

A phishing reminder on the desktop

Small, branded, dismissed in two seconds — and logged.

Before you click
Three invoice-themed phishing attempts were blocked this morning. Check the sender's full address before opening any attachment, even from a familiar name. In doubt: forward to security@, do not open.
Ready to send

A year of awareness, already written

Twelve short messages beat one long module.

Monthly phishing reminder
A rotating pop-up with one recognition tip. Two minutes to prepare, thirty seconds to read, logged for the audit trail.
After a simulated campaign
Send the debrief to the people who clicked, and only to them — targeted by directory group, without naming anyone publicly.
New rule going live
Password policy, MFA rollout, USB restriction: a pop-up with mandatory acknowledgement the week it takes effect.
Live threat
A ticker across the fleet when a specific campaign is circulating right now. Minutes matter and the ticker does not stop anyone working.
FAQ

Frequently asked questions

Can we prove an employee read a security notice?

Yes. With the mandatory acknowledgement the close button stays disabled until the box is ticked, and the acknowledgement is timestamped per workstation. That record is what audits and insurers ask for.

Does it integrate with our phishing simulation platform?

Nuntivo is the delivery channel, not the simulator. In practice teams run the simulation in their existing tool and use Nuntivo for the reminders before and the debrief after, targeted at the right directory groups.

Will people find monthly pop-ups intrusive?

That is a matter of format and frequency, and both are yours to set. Most teams use a ticker for routine reminders and reserve the pop-up window for rules that genuinely change what people must do.

See Nuntivo on your own screens

15-day free trial, no credit card. 10 PCs included.