Your own policies, turned into a habit
Your security policy is a PDF nobody opens. Make it a daily habit.
Upload it once. Synekys extracts every obligation, writes the questions, throws out the ones that do not hold up, waits for your CISO to approve, then asks them in each employee’s own language.
CISO APPROVES BEFORE ANYTHING SHIPS · EU-HOSTED
The human gate
The pipeline writes the draft. Your CISO decides what ships.
Questions are not generated and shipped. An orchestrated run of specialised agents drafts each one against a specific clause, then a chain of checks and counter-tests removes most of what it produced. Only the survivors reach a person, with the citation still attached.
- Written against the source, not the topic. Every question carries the clause it came from, with page and section, for the rest of its life.
- Checked before anyone reads it. Automated validators test structure, ambiguity, difficulty balance and duplication. Failures are rewritten or dropped, not patched over.
- Counter-tested on simulated employees. Drafts are answered by generated profiles at different roles and seniorities. What everyone gets right teaches nothing; what nobody gets right is broken. Both go back.
- Approved or rejected by a person, with a reason. Both are logged, both feed the pipeline, and the review log is part of your audit evidence rather than a side channel.
- Approval freezes the live version. A later re-import surfaces the drift for review instead of silently overwriting what your people are answering.
You need to reach an internal application from a hotel Wi-Fi. According to the policy, what do you do first?
Connect directly, the application requires a password anywayOpen the company VPN, then reach the application through itAsk a colleague to forward you the data by email§4.2 requires all access to internal applications from an untrusted network to pass through the corporate VPN, without exception for short sessions.
Draft against the clause, validate, counter-test, discard, review, approve, translate, deliver. The approved version is frozen; re-importing the policy surfaces the drift for review instead of overwriting what is live.
One question, five languages
Approved once. Marta still reads it in Spanish.
Nobody is asked to do compliance in their second language, which is exactly where awareness training usually loses people.
Three quarters of the drafts never reach a human. What survives is approved once, then read by everyone in their own language.
Vous devez accéder à une application interne depuis le Wi-Fi d’un hôtel. Que faites-vous en premier ?
You need to reach an internal application from a hotel Wi-Fi. What do you do first?
Devi accedere a un’applicazione interna dal Wi-Fi di un hotel. Cosa fai per prima cosa?
Sie müssen aus dem Hotel-WLAN auf eine interne Anwendung zugreifen. Was tun Sie zuerst?
Necesitas acceder a una aplicación interna desde el wifi de un hotel. ¿Qué haces primero?
It counts the same way
Your policies become a framework of their own
Internal policy questions are mapped clause by clause, exactly like DORA articles or ISO controls. They appear in the same coverage meter, the same Human Risk Score, and the same audit export.
- Coverage is reported per clause, so you can prove §4.2 was actually trained.
- Answers land in the same evidence export: one CSV, by user, by clause, by date.
- A revised policy re-imports as a new version; approved content stays frozen until you review the drift.
| Source | Scope | Mapped |
|---|---|---|
| DORA | Art. 5–16 | ✓ article-level |
| NIS2 | Art. 21 (a–j) | ✓ measure-level |
| ISO 27001:2022 | Annex A | ✓ control-level |
| Information security policy | §1–§9 · 38 pp. | ✓ clause-level |
| Remote work policy | §1–§4 · 11 pp. | ✓ clause-level |
| Supplier security annex | §2 · 6 pp. | ✓ clause-level |
Premium
Send one PDF. Get back a question bank.
Your CISO’s only job is to approve, regenerate or cut.
CISO APPROVES BEFORE ANYTHING SHIPS · EU-HOSTED