Cybersecurity Training
Learning Management SystemCybersecurity TrainingPhishing SimulationEnterprise SaaS

They Asked Us To Build An LMS.
We Ended Up Building A Platform That Proves Training Actually Works.

And completing a course doesn't necessarily make someone more security-aware.

GoPhishColossyan

5

Core modules

2

Integrations

RBAC

Four-level roles

Analytics Dashboard
Analytics Dashboard
Training Overview
Training Overview
Phishing Campaigns
Phishing Campaigns
User Management
User Management
Interactive Lesson
Interactive Lesson
Campaign Details
Campaign Details

Project Snapshot

Industry
Cybersecurity Training
Platform
Enterprise Learning Management System
Focus
Automated Security Awareness & Behavioral Validation
Integrations
GoPhish · Colossyan
Core Modules
Course ManagementUser ManagementSecurity TrainingAnalyticsRole Management

The brief

At first, it sounded like a standard Learning Management System.

Create courses. Manage users. Track progress. Generate reports.

But after understanding the client's business, we realized they weren't selling courses.

They were selling safer employees.

And completing a course doesn't necessarily make someone more security-aware.

The platform had to answer one question: Did the training actually change behavior?

Watching Videos Isn't The Same As Learning

Most LMS platforms stop at completion certificates.

Someone watches a few videos. Clicks "Complete." Receives a certificate. Everyone assumes the training worked.

But cybersecurity doesn't work that way.

People only learn if they recognize threats when they encounter them in the real world.

That completely changed how we designed the platform.

Instead of measuring course completion, we built a system that measures behavioral change.

Engineering Note

We built a full course management system with lesson delivery, progress tracking, completion monitoring, and automated lifecycle management to support enterprise-scale learning.

Course Dashboard & Learning Progress
Course Dashboard & Learning Progress
Training overview with enrolled learners, progress states, and completion rates across cybersecurity modules.

Instead of measuring course completion, we built a system that measures behavioral change.

The Real Test Starts After The Course Ends

Phishing Campaign Dashboard
Phishing Campaign Dashboard
Campaign management with attack simulations, launch scheduling, and status tracking for engineering and department-wide tests.

This became the most interesting part of the project.

As soon as a training program finishes, the system automatically prepares a phishing simulation.

Employees receive a realistic phishing email without knowing it's a test.

Their actions become measurable outcomes. Did they ignore it? Report it? Or click the malicious link?

Now administrators know whether the training actually worked instead of simply assuming it did.

What would normally require weeks of manual coordination happens automatically in the background. The platform schedules campaigns, launches them, and associates results with the completed training lifecycle.

Behind The Scenes

Integrated GoPhish, automated campaign scheduling with cron jobs, synchronized user groups, and built rollback mechanisms to keep both systems in sync.

Training Hundreds Of Employees Shouldn't Mean Managing Hundreds Of Accounts

Large organizations don't onboard users one at a time.

They work with departments. Teams. Business units. Different managers. Different responsibilities.

So instead of creating a flat user list, we designed a hierarchical permission system.

Administrators oversee the entire platform. Contributors manage organizations. Group leaders manage their own teams. Subscribers simply focus on learning.

Every person sees only the information relevant to their role, making the platform significantly easier to manage as organizations grow.

Engineering Note

Designed a four-level RBAC system with dedicated dashboards, scoped permissions, protected routes, and role-aware APIs.

User Management & Role Dashboard
User Management & Role Dashboard
Phishing Campaigns
Phishing Campaigns

Subscription management with partners, organizations, groups, and employees across a four-level role hierarchy.

Courses Should Run Themselves

Course lifecycle automation

Launch
Enroll
Train
Expire
Simulate
Course Scheduling & Automation
Course Scheduling & Automation
Training Overview
Training Overview

Campaign details with launch dates, time zones, group assignments, and automated lifecycle tracking.

Engineering Note

Built scheduled automation services that activate courses, expire content, sequence training, and trigger follow-up simulations without manual intervention.

Another problem appeared during discovery.

Training coordinators were manually launching courses, closing enrollments, and scheduling follow-up activities.

The work was repetitive. And mistakes were common.

So we automated the course lifecycle.

Courses automatically become available on launch dates. They expire when training windows end. Follow-up phishing simulations are scheduled automatically.

Administrators spend their time improving training instead of managing calendars.

Great Content Deserves Great Delivery

The client already used Colossyan to produce interactive training videos.

Rather than forcing content creators to upload files into another system, we integrated directly with their existing workflow.

Training creators simply paste a Colossyan lesson link. The platform embeds the lesson automatically.

Employees enjoy a seamless learning experience without ever leaving the LMS.

Sometimes the best integration isn't adding another feature. It's removing unnecessary work.

Engineering Note

Replaced the previous H5P upload flow with embedded Colossyan lessons using secure iframe integration and responsive rendering across devices.

Embedded Interactive Lesson
Embedded Interactive Lesson
Lesson player with Colossyan embed, progress tracking, and navigation across multi-lesson cybersecurity modules.

Measuring Progress Is Only Half The Story

Enterprise customers needed more than completion percentages.

They wanted visibility. Which departments are improving? Which teams repeatedly fail phishing tests? Which managers need additional coaching?

The platform combines learning progress, campaign performance, and behavioral results into one reporting system, allowing organizations to continuously improve their security awareness programs instead of treating training as a yearly checkbox.

Behind The Scenes

Built centralized reporting backed by React Query, real-time progress tracking, campaign analytics, and organization-wide learning insights.

Analytics & Reporting Dashboard
Analytics & Reporting Dashboard
Admin dashboard with license usage, enrollment rates, completion trends, and engagement metrics across organizations.

The Outcome

Outcome 1

Organizations create courses.

Outcome 2

Employees complete interactive learning.

Outcome 3

The platform automatically validates that learning through real phishing simulations.

Outcome 4

Managers receive meaningful insights.

Outcome 5

Administrators oversee the entire training lifecycle from one place.

What started as another Learning Management System became a complete cybersecurity training ecosystem.

Instead of measuring who finished a course, the platform measures whether the training actually made employees safer.

Explore The Demo

Experience the platform from the perspective of administrators, managers, and learners, and see how training, automation, phishing simulations, and analytics work together inside one connected cybersecurity learning platform.