Interactive training, simulations and guides for individuals and businesses — simple, practical, without technical jargon.
// Training modules
Where do you start?
🎯
Cybersecurity Quiz
Knowledge test on phishing, passwords, social engineering and network security. See where you stand.
⏱ ~5 min10 questions
📧
Phishing Simulator
Real phishing email scenarios. Can you tell the fake from the real?
⏱ ~7 min10 emails
🔑
Password Guide
How to create and manage strong passwords. Step-by-step, for everyone.
⏱ ~4 minBeginner
🦠
What is Ransomware?
How the most dangerous cyber threat for small businesses works and how to protect yourself.
⏱ ~5 minImportant
🎭
Social Engineering
Attackers don't always hack systems — they hack people. Learn how.
⏱ ~5 minAdvanced
📱
Mobile Security
Your phone knows everything about you. How to protect it from interception and malicious apps.
⏱ ~4 minBeginner
🔐
Password Strength Checker
See live how strong your password is and how to improve it.
⏱ 1 minLive
🔗
URL Analyzer
Enter a URL and see if it has suspicious phishing characteristics.
⏱ 1 minTool
📊
Cyber Risk Assessment
10 questions for businesses — learn your risk level with recommendations.
⏱ 3 minBusiness
⚖️
NIS2 Readiness Checklist
Interactive NIS2 compliance checklist for companies.
⏱ 5 minNIS2
🎭
Scenario Game
Interactive cyber attack scenarios — what do you do in each situation?
⏱ 5 minInteractive
📰
Cyber News
Latest cybersecurity news and threat of the month.
UpdatedNews
40
Quiz Questions
10
Phishing Emails
11
Step-by-step Guides
5
Tools
100%
Free
// Quiz
How well do you know how to protect yourself?
Choose a category or play the full mix with questions from all sections.
🎯
All Categories
Mix of 40 questions from all categories.
40 questions
🎣
Phishing
Spot the scams from real emails.
5 questions
🔑
Passwords & 2FA
Passwords, password managers, authentication.
5 questions
🦠
Malware & Ransomware
Viruses, ransomware, malicious files.
5 questions
🎭
Social Engineering
Manipulation, vishing, pretexting.
5 questions
🌐
Browsing & Social Media
Browser security, social media, online shopping.
5 questions
⚖️
GDPR & Data
Law, rights, business obligations.
5 questions
🏢
Business & SMEs
Corporate security, NIS2, incident response.
5 questions
Question 1
Score: 0/0
// Phishing Simulator
Can you tell the difference?
Read each email and decide: is it phishing or real?
Email 1 of 10 | Score: 0/10
📬 Inbox
correct answers out of 10
// Step-by-step Guides
Practical knowledge for everyone
// Your Badges
Prove what you know!
Earn digital badges by completing quiz categories with a score ≥70%. Download or share your certificate.
Earned: 0 / 9
📜 Completion Certificate
📤 Share on Social — 2 steps
Step 1: Download the PNG image above Step 2: Upload the image + copy the text:
✅ Copied! Upload the image and paste the text.
// Tools
Interactive Security Tools
// News & Updates
Cyber News & Threat of the Month
Curated sources and the most important threat of the month you need to know about.
🔥 THREAT OF THE MONTH
AI-Powered Phishing — The New Danger
In 2025–2026, phishing attacks using AI to create extremely convincing emails have skyrocketed — without spelling mistakes, with your name, employer and context from your social media. The traditional way of identifying phishing is no longer enough.
AI-GeneratedSpear PhishingHigh Risk
How to protect yourself: Always verify the sender through an independent channel (phone). Enable 2FA. Don't click links in emails — go directly to the site.
Ready-made cybersecurity policy template — customisable for any small business
GDPRNIS2FreeEnglish
// Glossary
Cybersecurity Dictionary
All the key terms — simply and clearly explained.
// About
The person behind CyberGnosi
A personal project built to make cybersecurity understandable, practical and accessible to everyone.
GA
Grigorios Avramidis
Founder of CyberGnosiCybersecurity Awareness EducatorMSc Cybersecurity Candidate
I create cybersecurity educational content and interactive learning tools, with a focus on security awareness, GRC and European compliance frameworks (NIS2, ISO 27001).
I am a cybersecurity awareness educator and an MSc Cybersecurity candidate. My work centres on the human side of security: how we think, how attackers exploit our habits, and how small changes in everyday behaviour can prevent the majority of incidents.
CyberGnosi is both my personal project and my portfolio: an awareness platform built from the ground up — content, design and code — to demonstrate, in practice, how interactive learning makes cybersecurity approachable for everyone.
// Mission
Cybersecurity is not only about technology. It is about people, habits and everyday decisions.
CyberGnosi was created to make cybersecurity understandable, practical and accessible through interactive learning — with quizzes, simulations, tools and guides, free of charge and with no registration required.
// Expertise Areas
🧠
Cyber Awareness
Designing educational content and awareness programmes focused on the human factor.
📋
Governance, Risk & Compliance (GRC)
Security policies, governance structures, risk management and compliance frameworks.
🛡️
NIS2
The EU NIS2 Directive and its national transposition: obligations, incident reporting and governance.
📐
ISO 27001
Information Security Management Systems (ISMS), Annex A controls and internal audits.
⚖️
Risk Management
Identifying, assessing and treating information security risks.
// Certifications
📜
ISO/IEC 27001 Internal Auditor
ISMS internal auditing
🎓
Google Cybersecurity Professional Certificate
Security foundations & SOC fundamentals
🌐
Cisco Cybersecurity & Threat Management
Threats, defences & incident handling
🛡️
NIS2 Training
NIS2 Directive & compliance requirements
// Conferences & Workshops
I actively take part in cybersecurity conferences, seminars and workshops — both as an attendee and as a speaker in awareness sessions for schools, public-sector bodies and educational events.
Multi-category interactive quiz with instant educational feedback.
📧
Phishing Simulator
A realistic inbox simulator: separate the phishing emails from the legitimate ones.
🛠️
Security Tools
Password checker, URL analyser, risk assessment and other hands-on tools.
🏅
Badge System
Gamified learning with badges and completion certificates for every module.
✅
NIS2 Checklist
An interactive self-assessment tool for NIS2 readiness.
📖
Learning Modules
Structured step-by-step guides: passwords, ransomware, social engineering, GDPR and more.
// Training & Awareness
Learning Center
Structured cybersecurity learning tracks — from the fundamentals to the threats of the AI era.
// 01 — Cyber Awareness Fundamentals
The foundations of digital self-protection: the habits that prevent the vast majority of incidents.
🔑
Password Security
Strong passwords, password managers, and why length beats complexity.
📲
MFA — Multi-Factor Authentication
Why MFA blocks the vast majority of account-takeover attacks, and how to enable it properly.
🌐
Safe Browsing
HTTPS, suspicious sites, browser extensions and staying safe on public Wi-Fi.
🧹
Digital Hygiene
Updates, backups, app permissions and keeping your devices clean and healthy.
// 02 — Phishing Awareness
The world's number-one attack method. Learn to recognise it before you click.
📧
Email Security
The tell-tale signs of suspicious emails: sender, tone, attachments and links.
💼
Business Email Compromise (BEC)
Fake "CEO" emails requesting urgent transfers — the most expensive scam for organisations.
🎭
Social Engineering
Pretexting, baiting and vishing: how attackers manipulate human psychology.
🔍
URL Inspection
Typosquatting, suspicious domains and short links — analyse a URL before you open it.
Ready to practise?Try the Phishing Simulator with realistic inbox scenarios.
// 03 — AI & Cybersecurity
Artificial intelligence is reshaping the threat landscape — and the defences.
🎬
Deepfakes
Fabricated videos and voice cloning: how they are used in fraud, and how to spot them (inconsistencies, second-channel verification).
💉
Prompt Injection
How malicious instructions hidden inside content can manipulate AI systems — a new category of threat.
⚠️
AI Risks
AI-generated phishing, automated attacks, disinformation and fake profiles at scale.
🔒
Privacy Challenges
What do we share with AI tools? Training data, company secrets in prompts, and responsible use.
// 04 — Awareness Presentations
Live awareness sessions, tailored to each audience.
🏫
Schools
Online safety for students: social media, cyberbullying and personal data — in language they actually understand.
🏛️
Public Sector
Awareness sessions for public-sector staff: phishing, data handling and core obligations.
🎪
Educational Events
Talks and interactive activities at seminars, festivals and digital-literacy events.
🧑💻
Workshops
Hands-on labs with live demos: phishing simulation, password-cracking demos and scenario exercises.
// Learning Outcomes
By completing the Learning Center modules, you will be able to:
✓Recognise phishing emails, suspicious URLs and social-engineering techniques before falling victim to them.
✓Create and manage strong passwords and enable MFA on your critical accounts.
✓Apply core digital-hygiene practices: updates, 3-2-1 backups and app-permission reviews.
✓Understand the new threats of the AI era: deepfakes, prompt injection and AI-generated fraud.
✓Respond correctly to an incident: isolate, report, recover.
// NIS2 Hub
NIS2 Learning Center
Everything you need to know about the NIS2 Directive — explained simply and practically.
// What is NIS2
NIS2 (Network and Information Security Directive 2 — EU Directive 2022/2555) is the European Union's updated cybersecurity framework. It replaces the original 2016 NIS Directive, dramatically expands the sectors it covers, and introduces stricter requirements for risk management, incident reporting and corporate accountability.
Each EU Member State transposes the Directive into national law, with a designated national cybersecurity authority responsible for supervision and enforcement.
EU 2022/2555National transposition18 sectorsFines up to €10M / 2% of turnover
// Who It Affects
NIS2 covers medium and large entities across 18 sectors, divided into two categories with different levels of supervision:
🏛️
Essential Entities
Energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration, space.
Proactive (ex-ante) supervision
🏢
Important Entities
Postal services, waste management, chemicals, food, manufacturing, digital providers (marketplaces, search engines, social platforms), research.
Reactive (ex-post) supervision
// Core Obligations (Article 21)
📊
Risk Management
Policies for risk analysis and information-system security.
🚨
Incident Handling
Procedures to prevent, detect and respond to incidents.
🔄
Business Continuity
Backups, disaster recovery and crisis management.
🔗
Supply Chain Security
Assessing risks from suppliers and service providers.
🔐
Cryptography & MFA
Encryption policies and the use of multi-factor authentication.
🎓
Training & Awareness
Basic cyber hygiene and regular training for staff and management.
// Incident Reporting
For significant incidents, NIS2 sets a strict reporting timeline to the competent authority / CSIRT:
24 hours
Early Warning Initial notification — indicating whether malicious action or cross-border impact is suspected.
72 hours
Incident Notification Updated assessment: severity, impact and indicators of compromise (IoCs).
1 month
Final Report A detailed account: root causes, mitigation measures and cross-border effects.
// Governance Responsibilities
NIS2 brings cybersecurity into the boardroom. Management bodies must:
• Approve the cybersecurity risk-management measures.
• Oversee their implementation.
• Undergo training in cybersecurity matters.
• Be held personally accountable for infringements — responsibility cannot simply be delegated to IT.
// NIS2 Compliance Roadmap
1
Scoping
Determine whether the organisation falls under NIS2 (sector + size) and in which category (Essential / Important).
2
Gap Analysis & Risk Assessment
Inventory assets, assess risks and identify gaps against the Article 21 requirements.
3
Policies & Technical Measures
Security policy, MFA, encryption, backups, supplier security and vulnerability management.
4
Incident Response & Reporting
Incident-response plan and the 24h / 72h / 1-month reporting workflow to the competent authority.
5
Training & Awareness
Training for management and staff — regular awareness sessions and phishing exercises.
6
Continuous Improvement
Periodic risk reassessment, effectiveness reviews and measure updates.
// Interactive Readiness Checklist
0/7
Tick what your organisation already has in place — see how close you are to baseline readiness.
⬜
Asset Inventory
A complete inventory of systems, applications and data.
⬜
Risk Assessment
A documented, prioritised risk assessment.
⬜
Incident Response Plan
A written plan: roles, steps, communication and authority reporting.
⬜
MFA
Multi-factor authentication on all critical accounts.
⬜
Security Awareness Program
Regular training for staff and management.
⬜
Backup Strategy
3-2-1 rule, encrypted backups and regular recovery tests.
⬜
Supplier Security
Supplier security assessments and contractual clauses.
Want a full self-assessment?Try the detailed NIS2 Checklist tool.
// ISO 27001 Hub
ISO 27001 Learning Center
The international standard for information security management — explained simply, step by step.
// What is ISO 27001
ISO/IEC 27001 is the leading international standard for information security management. It defines the requirements for establishing, implementing, maintaining and continually improving an Information Security Management System (ISMS).
Its goal: protecting the Confidentiality, Integrity and Availability of information (the CIA triad) — in a systematic, auditable way.
ISO/IEC 27001:202293 Annex A controlsCertifiable standard
// Core Concepts
🏗️
ISMS
The Information Security Management System: policies, processes, roles and controls operating as one living system — not a binder of documents.
📊
Risk Assessment
The heart of the standard: identify threats and vulnerabilities, estimate likelihood and impact, and choose a treatment (mitigate, accept, transfer, avoid).
🧩
Annex A Controls
93 security controls (2022 edition) across four themes. Controls are selected based on the risk assessment and documented in the Statement of Applicability (SoA).
🔍
Internal Audits
Periodic internal audits verify the ISMS works as designed and surface nonconformities before the external audit does.
🔄
Continuous Improvement
The PDCA cycle (Plan–Do–Check–Act): the ISMS continuously improves through audit findings, incidents and changes in the risk landscape.
// Annex A — The Four Control Themes (2022)
🏛️ Organizational — 37 controls
Policies, roles, supplier management, information classification, threat intelligence.
👥 People — 8 controls
Screening, terms of employment, awareness training, disciplinary process, remote working.
🏢 Physical — 14 controls
Physical access, securing premises and equipment, clear desk, secure media disposal.
The foundational elements every ISMS needs — tick what is already in place.
⬜
Information Security Policy
Approved by management and communicated to everyone.
⬜
Asset Register
A register of information assets with owners and classification.
⬜
Risk Register
A risk register with assessment and treatment plans.
⬜
Supplier Management
Security assessments and contractual terms for suppliers.
⬜
Backup Policy
A documented backup policy with regular recovery tests.
⬜
Awareness Program
A security training programme covering all staff.
⬜
Internal Audit Process
An internal audit programme with documented findings.
Pair it with NIS2:ISO 27001 provides an excellent foundation for NIS2 compliance.
// Blog
CyberGnosi Blog
Articles, guides and analysis on cybersecurity — written plainly, for everyone.
FeaturedNIS2Compliance
NIS2: Europe's new cybersecurity framework — and what it means in practice
The NIS2 Directive reshapes the landscape: 18 sectors, personal accountability for management, strict reporting timelines and fines up to €10 million. A complete, plain-language guide to what applies, who it affects and where to start.
⏱ 12 min read
Compliance
What is NIS2?
The new Directive in plain language: who it affects, what it requires and what the deadlines are.
⏱ 8'
Phishing
10 signs an email is phishing
From the suspicious sender to the "urgent" tone — learn to spot them in seconds.
⏱ 6'
Basics
Password Security Guide
Why "P@ssw0rd1!" isn't safe, what passphrases are, and how a password manager saves you.
⏱ 7'
Basics
Multi-Factor Authentication (MFA)
The single most effective self-protection measure: what it is, which forms exist, and where to enable it first.
⏱ 5'
AI
AI & Cybersecurity
Deepfakes, prompt injection and AI-generated phishing: the threats of the new era and how to stay protected.
⏱ 9'
Standards
ISO 27001 for beginners
ISMS, risk assessment, Annex A: the international information security standard without the jargon.
⏱ 10'
More articles
In-depth pieces and analysis are published regularly — in English on Medium and in Greek on LinkedIn.