Connect your Security Awareness
Training is a named obligation in most frameworks — including NIS2's management-body duty — and the evidence is completion data. TruSecure's awareness connector pulls training records and phishing-simulation results directly.
What the connector pulls
| Source system | What TruSecure pulls | Feeds governance |
|---|---|---|
| Training completion | Course, person, completion date, score | Board Reporting · NIS2 Art. 20(2) training evidence |
| Phishing simulations | Delivery, open, click, report rates over time | Risk Management · human-risk trend |
| Assignment coverage | Population in scope vs trained, by role | Evidence Automation · coverage controls |
| Attestations | Policy acknowledgements, signed acceptances | Audit Trail · acceptance records |
Evidence produced from Security Awareness data
One control test pulled from live Security Awareness state — not a manual export, not a screenshot, but a verified query result with provenance:
- Control tested
- All staff completed annual security training
- Awareness source
- KnowBe4 · 412 person population
- Test
- re-perform · completion export vs HR population
- Sample
- 358/412 completed · 87.0%, campaign closes 30 Sep
- Result
- in progress · 54 outstanding, reminders automated
- Evidence
- KnowBe4 API query · timestamped 2026-08-22T09:44:57Z
- Export
- sealed · sha256:1d8c...7b3e
Setup and scope model
- Read-only, scoped permission
Connector requires read-only access to training records and simulation results. No write permissions, no ability to mark completions or enroll users.
- Data filtered by entity
Populations scoped to the entity context — group-wide campaigns credit each entity's own staff only.
- Continuous sync
Coverage recomputes as people complete; board reporting shows the live percentage, not last quarter's export.
Commercial packaging
Security Awareness connectors are part of the paid TruSecure Fabric subscription. The connector itself, the continuous sync, the evidence provenance tracking, and the mapping to NIS2, DORA, ISO 27001, SOC 2 and other frameworks are all included — no per-connector fees, no usage tiers. Pricing is scoped in the conversation, not a price list.
How integration works
A demo with your actual Security Awareness environment shown in preview mode — your data pulling into governance, feeding controls and evidence. Then a Resilience Sprint that configures the connector for production, scopes the entity context, and validates the first evidence pull. No self-serve checkout, no per-connector pricing.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.