Phishy
Cyber Command
Editorial

Security awareness resources that read like operator guidance.

Practical guides on phishing simulations, NIS2 compliance, and building a security culture that actually works.

Articles
3
Coverage
Practice + compliance
Audience
Security teams
Tone
Calm and precise

Why this exists

The blog should support commercial trust, not inflate it. Every article should help a buyer understand how the product thinks about training, reporting, and risk.

Best Practices2025-11-12· 8 min read

Phishing Simulation Best Practices for SMBs in 2025

How to run effective phishing tests without shaming employees — practical guide for organisations with 10–500 people.

Read article →
Compliance2025-12-03· 10 min read

How NIS2 Changes Your Security Awareness Training Requirements

NIS2 mandates regular security training for all staff. Here's exactly what you need to document and prove to auditors.

Read article →
Research2026-01-08· 7 min read

Why "Gotcha" Phishing Training Backfires (And What Works Instead)

Public shame after clicking a phishing link increases anxiety without reducing risk. The research is clear — here’s a better approach.

Read article →