Skip to content
The category

Awareness was the starting point. This is where it becomes operational.

Behavioral Defense Engineering is the operational evolution of cybersecurity awareness. Instead of treating awareness as periodic education, it turns what people notice into part of the security stack.

500k+
licensed users worldwide
Cyberdise portfolio overview, September 2026
One-click reporting
straight into your SOC
AI analysis
seconds, not hours
Behavior score
updated continuously
Runs where you say
cloud or your servers
A head of IT security holding a laptop, looking at the viewer
The loop

Every stage feeds the next.

BDE is more than phishing simulation or e-learning: it builds a defense loop around what people actually do. Each stage produces the input the next one needs, and the cycle does not stop.

  1. ReportEmployees flag a suspicious message with one click from the inbox.
  2. AnalyzeAI classifies the signal and scores the behavioral risk behind it.
  3. RespondAutomations and SOC workflows contain the threat at machine speed.
  4. FeedbackThe reporter learns straight away whether the call was right.
  5. PracticeSimulations turn that lesson into a trained reflex.
  6. LMSMicro-training lands exactly where behavior shows a gap.
  7. ChatbotThe Cybersecurity Chatbot answers questions the moment they come up.
Why the shift is needed

The gap is behavior under pressure

Knowing what phishing looks like does not decide what someone does when a convincing message or call arrives in the middle of a busy day.

  • AI makes social engineering faster, more personal and harder to spot.
  • The moment that counts is whether someone pauses, checks, reports or acts.
  • Technical defenses stay essential, and some attacks will still reach people.
A man at his desk pausing before he answers a call shown as coming from the CEO, with icons for pause, check and report beside the phone
The scientific foundation

Measured by what people actually did

With HSLU we compared training, conventional phishing and AI spearphishing, and measured what people actually did. Attitude and behavior turned out to be separate things.

  • Educational vulnerability profiles show what makes an exercise relevant to each person.
  • OSINT reconnaissance adds context from public information, for realistic and privacy-aware personalization.
  • Phishing messages and training are generated from a prompt, with an operator approving before anything sends.
  • Exercises run across several messages and channels, by email, SMS and voice.
  • The AI runs on the model you choose, commercial, private or on your own servers.

Read the study

The study design: a baseline of two phishing exercises and a survey, four groups (control, eLearning, conventional phishing, AI OSINT spearphishing) with N = 539, then a final phishing exercise that measures who visited the site. HSLU study, November 2024 to June 2025
~60%less risky clicking after AI spearphishing exercises, against baseline
539employees in four groups, November 2024 to June 2025

Source: AISP study

Capabilities

One system. Every tool your human defenses need.

Eight capabilities, one platform, one place to operate them.

A course in the Cyberdise LMS: module 1 of Cybersecurity Essentials with theory and game done and the quiz next, a certificate on completion, and SCORM in and out

Training and LMS

A full learning system in the same platform, with SCORM in and out.

A written prompt asking for a two-week smishing wave for field sales in German and French turns into drafted templates and an audience. After an operator approves, it becomes a live campaign running smishing in German and French, micro-training and risk scoring.
Less to operate

Describe what you need. Approve what comes back.

In an awareness program, most of the effort goes into doing the work: building and translating templates, picking audiences, chasing completions, assembling the report. The platform takes that work on, and an operator approves before anything goes out.

  • A campaign described in plain language, with templates, landing pages and audience drafted for you
  • Reminders, escalation to line managers and onboarding schedules that run on their own
  • Stakeholder reports generated from live data, in your layout
  • Nothing sends without an operator's approval
  • Rather not run it yourself? A Cyberdise partner can run the year for you

See the Campaign Automator

Built for those who want full control

Built after AI, not retrofitted for it.

Cyberdise was built from scratch after generative AI existed, which is why the AI sits in the core rather than bolted on as a module. The practical consequence is flexibility: you decide where it runs, what it connects to, and which model answers.

  • Cloud or your own servers: SaaS, your own cloud, or fully on premises as a rootless Docker image
  • Multi Active Directory and Microsoft Entra, with dynamic groups that sync themselves
  • SCORM import and export, so your training content comes in and leaves with you
  • API first, with a central layer for SIEM, SOAR, ticketing and sandbox tools, and a Report-a-Phish Button for Microsoft 365, on-premises Exchange and Gmail
  • Support for leading LLMs and open models, including models on your own servers

See pricing

Two panels: software built before AI has AI bolted on to a legacy core as separate modules; software built after AI has AI in the core, connected to simulations, training and reports in one architecture.
Does Behavioral Defense Engineering replace awareness training?
No. Training stays, and in the HSLU study it was the only intervention that significantly improved attitudes. Behavioral Defense Engineering adds the reporting, response and practice around it.
Where can Cyberdise run?
As SaaS with server locations in Germany and Switzerland, in your own cloud, or on your own servers. If you need SaaS in another region, talk to us. We set up infrastructure in other countries. Self hosting is an add-on for Awareness Plus, Behavioral Defense and MSSP, and the free Community edition is always self-hosted. On your own servers, Cyberdise can run behind a proxy, sends outbound mail over TLS when the receiving server supports it, and lets tenant operators download the service logs.
Does Cyberdise support multitenancy?
Yes, in a structure of three levels: instance, tenant and realm.
Which APIs are available?
Several: a RESTful API for integration and remote control, plus LDAP, Microsoft Entra and Azure, DNS and SMS APIs.
We have nobody to run this. Can Cyberdise run it for us?
Yes, as a managed program. A Cyberdise partner usually delivers it, and Cyberdise can run it directly while you get started. The program is set up for you, exercises and training run through the year, and your designated recipients get a report every month. The platform underneath is the same one described on this page, so you can look in or take over at any time. See Zero effort and the partner program.

See the whole loop running in your own environment.

One of your own scenarios, run from the report to the next exercise.