Your own policies, turned into a habit

Your security policy is a PDF nobody opens. Make it a daily habit.

Upload it once. Synekys extracts every obligation, writes the questions, throws out the ones that do not hold up, waits for your CISO to approve, then asks them in each employee’s own language.

CISO APPROVES BEFORE ANYTHING SHIPS · EU-HOSTED

app.synekys.io / policies / import
Information_Security_Policy_v4.pdf38 pages · 1.4 MB · uploaded by S. BianchiQueued
01Extract obligationsClauses parsed, deduplicated, cited back to the page
02Draft questionsWorkplace situations, four difficulty levels, role-aware
03Filters and counter-testsAutomated validators, then testing on simulated profiles
04CISO reviewHuman gate: nothing ships without approval
05TranslateFrom your document’s language into everyone else’s
06Deliver in Slack and TeamsMixed into the same daily rotation as the rest

The human gate

The pipeline writes the draft. Your CISO decides what ships.

Questions are not generated and shipped. An orchestrated run of specialised agents drafts each one against a specific clause, then a chain of checks and counter-tests removes most of what it produced. Only the survivors reach a person, with the citation still attached.

  • Written against the source, not the topic. Every question carries the clause it came from, with page and section, for the rest of its life.
  • Checked before anyone reads it. Automated validators test structure, ambiguity, difficulty balance and duplication. Failures are rewritten or dropped, not patched over.
  • Counter-tested on simulated employees. Drafts are answered by generated profiles at different roles and seniorities. What everyone gets right teaches nothing; what nobody gets right is broken. Both go back.
  • Approved or rejected by a person, with a reason. Both are logged, both feed the pipeline, and the review log is part of your audit evidence rather than a side channel.
  • Approval freezes the live version. A later re-import surfaces the drift for review instead of silently overwriting what your people are answering.
app.synekys.io / policies / review3 awaiting review
Internal · Information security policy§4.2 Remote access · p. 12Difficulty 2

You need to reach an internal application from a hotel Wi-Fi. According to the policy, what do you do first?

Connect directly, the application requires a password anywayOpen the company VPN, then reach the application through itAsk a colleague to forward you the data by email

§4.2 requires all access to internal applications from an untrusted network to pass through the corporate VPN, without exception for short sessions.

✓ cited to §4.2✓ single defensible answer✓ no duplicate in bank✓ 62% on simulated profiles
ApproveRejectRegenerate
Approved by S. Bianchi (CISO) · queued for translation
Nothing publishes itself.
Draft against the clause, validate, counter-test, discard, review, approve, translate, deliver. The approved version is frozen; re-importing the policy surfaces the drift for review instead of overwriting what is live.

One question, five languages

Approved once. Marta still reads it in Spanish.

Nobody is asked to do compliance in their second language, which is exactly where awareness training usually loses people.

One policy, one runwhat reaches your people
Drafted from 24 obligations0
Passed the automated validators0
Survived counter-testing0
Reached your CISO0
Approved and frozen0
Delivered, in five languages0

Three quarters of the drafts never reach a human. What survives is approved once, then read by everyone in their own language.

Français · document language
Marie · Finance · Paris

Vous devez accéder à une application interne depuis le Wi-Fi d’un hôtel. Que faites-vous en premier ?

Vous vous connectez directementVous ouvrez le VPN de l’entreprise, puis l’application
Politique SI · §4.2 · validé le 14 mars
English
Jonas · IT · Frankfurt

You need to reach an internal application from a hotel Wi-Fi. What do you do first?

Connect directlyOpen the company VPN, then the application
IS policy · §4.2 · meaning verified
Italiano
Sofia · Compliance · Milano

Devi accedere a un’applicazione interna dal Wi-Fi di un hotel. Cosa fai per prima cosa?

Ti colleghi direttamenteApri la VPN aziendale, poi l’applicazione
Policy SI · §4.2 · significato verificato
Deutsch
Tomáš · Operations · Wien

Sie müssen aus dem Hotel-WLAN auf eine interne Anwendung zugreifen. Was tun Sie zuerst?

Direkt verbindenDas Firmen-VPN öffnen, dann die Anwendung
IS-Richtlinie · §4.2 · Bedeutung geprüft
Español
Marta · RR. HH. · Madrid

Necesitas acceder a una aplicación interna desde el wifi de un hotel. ¿Qué haces primero?

Te conectas directamenteAbres la VPN de la empresa y luego la aplicación
Política SI · §4.2 · significado verificado
Meaning is what gets checkedEvery translation is verified against the approved source: the same obligation, the same defensible answer, the same trap in the wrong options. A version that shifts the meaning is sent back, not published.
The right answer cannot driftOptions travel as a structure rather than as loose text, so the correct one stays correct in every language, and the clause citation travels with it into the audit export.
Review each language, if you want toAny language can be held in the same review queue as the source and released only once someone signs it off. Off by default, on for the languages your regulator actually reads.

It counts the same way

Your policies become a framework of their own

Internal policy questions are mapped clause by clause, exactly like DORA articles or ISO controls. They appear in the same coverage meter, the same Human Risk Score, and the same audit export.

  • Coverage is reported per clause, so you can prove §4.2 was actually trained.
  • Answers land in the same evidence export: one CSV, by user, by clause, by date.
  • A revised policy re-imports as a new version; approved content stays frozen until you review the drift.
SourceScopeMapped
DORAArt. 5–16✓ article-level
NIS2Art. 21 (a–j)✓ measure-level
ISO 27001:2022Annex A✓ control-level
Information security policy§1–§9 · 38 pp.✓ clause-level
Remote work policy§1–§4 · 11 pp.✓ clause-level
Supplier security annex§2 · 6 pp.✓ clause-level

Premium

Send one PDF. Get back a question bank.

Your CISO’s only job is to approve, regenerate or cut.

CISO APPROVES BEFORE ANYTHING SHIPS · EU-HOSTED