Book an Appointment
Training & certifications

Strengthen knowledge. Live security. Demonstrate compliance.

With practical training and recognized certifications, we get your team ready for today’s requirements in information security, cyber resilience, and compliance.

Training & certifications

Build competence — anchor security and compliance sustainably

Information security, cyber resilience, and regulatory compliance can only be implemented successfully if the necessary knowledge and awareness are present in the company. Our training & certifications convey practical know-how, raise awareness among employees, and prepare your team specifically for certifications and audits.

Our offering

Our training and certification formats

Click on an area to see contents, target audiences, and focus topics for each training.

VamiAcademy is an AI-driven e-learning platform that helps companies deliver role-based security and compliance training efficiently, individually, and always up to date. Whether for employees, HR, developers, management, or security teams — VamiAcademy delivers tailored learning content on demand and continuously adapts it to new threats, standards, and regulations.

VamiAcademy core strengths

Audience-specific contentFine-grained adaptation by role, department, seniority, location, and language. Content, difficulty, and examples are optimally tailored to each persona — from developers to HR to C-level.
Compliance by designContent is aligned directly with frameworks and regulations (e.g. ISO 27001, NIS2, GDPR, HIPAA) and is automatically kept up to date.
Custom learning paths & rapid course creationAI-generated curricula aligned to business goals that significantly reduce time-to-launch.
Audit-traceable contentEvery lesson and assessment is auditable and linked to policies and controls — instantly usable for external audits.
Multiformat learning for maximum impactCourses in multiple formats — slides, videos, podcasts, quizzes, scenarios, and gamification — boost motivation, completion rates, and knowledge transfer.
Analytics & visibilityReal-time reporting, gap analyses, risk scoring, and management dashboards provide full transparency on learning progress and compliance maturity.

This practical training delivers a structured overview of the Cyber Resilience Act (CRA) and its place in Europe’s cybersecurity and data strategy. Participants gain a clear understanding of the regulatory, organizational, and technical requirements across the entire product lifecycle — from development to market surveillance.

Core training content

CRA regulatory overview & contextObjectives, scope, affected products, and the relationship with NIS2, DORA, and the AI Act.
Roles, responsibilities & dutiesManufacturer, importer, and distributor obligations along the entire product lifecycle.
Hands-on implementation of CRA requirementsImplementation in product development, governance, and supply chain with proven methods, technical controls, and ready-to-use templates.
Secure-by-design & SSDLCIntegration of secure-by-design and secure-by-default into development processes and CI/CD pipelines.
Risk assessment & threat modelingCRA-compliant risk analyses with TARA, attack trees, and realistic threat scenarios.
Vulnerability management, SBOM & open sourceVulnerability management, coordinated vulnerability disclosure, SBOMs, and update/patch obligations.
Supply chain, contracts & liabilitySecurity requirements for suppliers, contractual obligations, liability and sanction risks.
Flexible training structureDesigned as a compact one-day course but flexible in time and content to match your company’s needs.

This practical training delivers a structured overview of the EU AI Act (EU AI regulation) and its impact on companies. Participants gain a clear understanding of regulatory requirements, roles and responsibilities, and the organizational and technical measures needed for compliant and safe use of AI systems.

Core training content

EU AI Act — regulatory overview & timelineObjectives, structure, and scope of the EU AI regulation, and the relevant implementation deadlines.
Risk-based classification of AI systemsCategorization of AI applications by risk class, including prohibited, high-risk, and transparency-obligated AI.
Roles, responsibilities & management dutiesObligations for providers, deployers, and management — including AI literacy duty per Art. 4 EU AI Act.
Operational AI governance in the companyAI inventory, use case identification, risk assessment, and building effective governance structures.
AI risks, security & control mechanismsHandling of bias, hallucinations, model drift, prompt injection, data leakage, and shadow AI.
Documentation, compliance & integrationEvidence and documentation requirements and integration into existing ISMS, compliance, and data protection processes.
Practical templates & guidelinesAI policy, acceptable use policy, contractual employee obligations, and supplier and AI system questionnaires.
Flexible training structureDesigned as a compact one-day course but flexible in time and content to match your company’s needs.

This practical training delivers a structured overview of the NIS2 directive and its implementation under the German NIS2 implementation act (NIS2UmsuCG). Participants gain clarity on scope, obligations, supervision, and reporting requirements, and on management responsibility.

The focus is on the operational implementation of NIS2 based on ISO/IEC 27001, including integration with existing ISMS, BCM, and data protection processes, and management of supply chain and third-party risks.

Core training content

NIS2 — regulatory overview & scopeObjectives, structure, and the entities covered (critical, essential, important).
German NIS2 implementation act & supervisionRole of the NIS2UmsuCG, tasks of BSI and CSIRTs, registration obligations, and the first applicable deadlines.
Obligations, governance & management responsibilityRisk and security management, TOMs, incident reporting, and training and oversight duties of executive management.
Operational implementation with ISO/IEC 27001NIS2 gap analysis, deriving statutory requirements, and integration into existing ISMS, BCM, and data protection processes.
Supply chain, ICT providers & third partiesNIS2 requirements for suppliers, supply-chain risk analysis, and management of ICT service providers.
Documentation, evidence & contractual requirementsEvidence, reporting, and contractual and governance requirements.
Practical templates & guidelinesNIS2 guidelines, security policies, supplier questionnaires, and contract templates.
Flexible training structureDesigned as a compact one-day course but flexible in time and content to match your company’s needs.

The role of the Chief Information Security Officer (CISO) and Information Security Officer (ISO) is gaining importance in companies. Regulatory requirements such as ISO 27001, NIS2, DORA, and TISAX® make clear accountability for information security mandatory. At the same time, customers and partners expect companies to have competent security contacts.

Our CISO & ISO program delivers practical knowledge and enables participants to fill these key roles successfully — with deep expertise, strategic perspective, and legal certainty.

What the program covers

Program contentsISMS build-out, risk management, awareness programs, audit preparation, crisis and incident management, and reporting to top management.
Target audiencesFuture CISOs/ISOs, security officers, IT leadership, and compliance leads from mid-market companies and corporates.
Your benefitsWell-trained leaders who own information security strategically and operationally at the highest level — including audit and supervisory context.

ISO/IEC 27001 is the world-recognized standard for information security management systems (ISMS). But an ISMS is only as strong as the people who live and apply it every day. Our ISO 27001 employee training qualifies your team for the standard’s requirements — practical, accessible, and tailored to your organization.

Certification information

Audience & prerequisitesAll employees with ISMS exposure, owners for risks & controls, and auditors-in-training. No prior knowledge required.
Training contents (TRECCERT example)ISMS fundamentals, ISO 27001:2022 requirements, Annex A controls, risk processes, continuous improvement, and audit practice.
Completion & certificationRecognized certificate (e.g. TRECCERT, PECB) after passing the exam — usable as audit evidence.
Delivery formatsIn-house workshops, virtual live training, or hybrid formats — in German or English.

Most cyber attacks don’t start with a technical vulnerability but with the human factor — through phishing, social engineering, or weak passwords. That’s why a high level of security awareness across the company is essential. With our awareness trainings we sensitize your employees to current threats, deliver practical knowledge, and foster a sustainable security culture.

Information about our awareness trainings

Audiences & formatsShort onboarding formats for new employees, annual mandatory trainings, and role-specific modules for IT, HR, and management.
Awareness KPIs & reportsClick and report rates, knowledge quiz scores, and maturity-based KPIs delivered in dashboards.
Phishing campaigns & analysisRealistic simulation campaigns with per-department analysis, learning paths for clickers, and escalation paths.
Certificates & audit evidencePer-employee participation and pass certificates, packaged for audit.
Interactive learning & training platformsMicro-learnings, videos, quizzes, and gamification — via VamiAcademy or your existing LMS.

Security and compliance knowledge tailored to your business areas. With targeted trainings for IT, HR, procurement, facility, and compliance, you create clarity, security, and accountability.

Not every training fits every role. Business areas have specific risks, tasks, and regulatory obligations. Our audience-specific trainings deliver exactly the content your employees actually need — practical, interactive, and audit-relevant.

Information about our audience-specific trainings

Audiences & contentIT operations, developers, HR, procurement, facility, compliance, marketing & sales — each with their own use cases and obligations (e.g. GDPR, NIS2, ISO 27001).
Formats & deliveryLive workshops, virtual training, in-house sessions, or hybrid — complemented by learning cards and pocket guides.
Evidence & reportingParticipation evidence, knowledge tests, and reporting at employee, team, and area level for audit preparation.

System and network administrators play a key role for information security in the company. Misconfigurations, missing patches, and inadequate access controls are among the most common causes of successful cyber attacks. Our administrator trainings deliver practical know-how to operate IT infrastructures securely, detect attacks early, and minimize risk over the long term.

Information about our admin trainings

Content & focusSystem hardening, secure configurations (CIS benchmarks), patch and vulnerability management, logging & monitoring, identity and access management, EDR/XDR, and cloud security.
Formats & learning environmentHands-on labs, virtual training, and in-house workshops with dedicated lab environments for safe practice.
AudiencesSystem and network administrators, DevOps engineers, cloud owners, security operations teams.
Evidence & audit preparationAudit-ready training records, targeted preparation for ISO 27001, NIS2, and sector-specific audits.

The quality and security of modern applications depend significantly on the development practices in use. Errors in code or insecure architectures can cause serious security gaps — with consequences such as data loss, compliance breaches, or attacks on customer systems. Our developer trainings deliver practical knowledge on secure programming, current threats, and regulatory requirements.

Information about our developer trainings

Content & focusSecure coding (OWASP Top 10, ASVS), threat modeling, secure architectures, SAST/DAST/SCA, secrets handling, secure CI/CD pipelines, AI- & LLM-specific risks.
AudiencesFrontend, backend, mobile, and cloud developers, DevSecOps teams, architects, and technical lead roles.
Formats & deliveryHands-on labs (capture-the-flag, vulnerable apps), live workshops, on-demand modules, and code review sessions on your codebase.
Evidence & regulatory contextAudit evidence with reference to ISO 27001, NIS2, CRA, and the EU AI Act — including targeted preparation for security audits.

Only when all instruments are well tuned to one another will your organization be secure and compliant.

Valeri Milke, CEO — VamiSec GmbH

Protect Your Organization Now!

Contact us for an individual consultation and security solution tailored to your requirements.

Valeri Milke, CEO of VamiSec

"Only when all instruments are well-tuned does your organization become secure and compliant."