empowsec Mobile App: Security Training in Your Pocket

Security awareness training has traditionally been a desktop activity: open a browser, log in to the training portal, complete a course, close the tab. That pattern works for employees at a fixed workstation, but a significant share of the modern workforce is mobile - field technicians, sales teams, traveling executives, frontline staff who rarely sit at a desk for extended periods. Requiring these employees to complete training only at a computer means training happens less often, gets deferred, and earns a reputation as something that happens to you rather than something that benefits you. The empowsec mobile app changes this by putting the full training experience - assignments, quizzes, certificates, phishing debriefs, and a one-tap phishing report button - directly on the phone employees already carry.
This article covers what the empowsec mobile app offers, how it keeps employees engaged through push notifications, how sign-in works with the same security controls as the web portal, and how it fits into the broader security awareness program.
Complete Training Assignments on the Go
The core function of the mobile app is training. Employees can view all their assigned courses and modules, see which are in progress and which are due, and work through lessons at their own pace on their phone. The same interactive content that runs in the web portal - quizzes, knowledge checks, scenario-based exercises - is accessible from the app, so mobile users are not getting a stripped-down version of the training. They complete the same material and earn the same credit.
Progress is tracked the same way it is on the web. A learner who starts a module on their phone and finishes it on their desktop sees consistent progress across both. The app shows completion status clearly, so employees know exactly where they stand relative to their due dates without having to dig into a settings menu or wait for a reminder email.
For organizations with a mobile or distributed workforce, this parity between web and mobile is important. Training completion rates improve when the training can be done during a commute, a waiting period, or a short break rather than requiring a dedicated block of desk time. Lower friction means higher participation, and higher participation means the security awareness program reaches everyone it is supposed to reach.
Push Notifications for Due and Overdue Training
One of the most effective features of a mobile app for compliance-driven tasks is push notifications. When training is assigned, the employee gets notified. When a due date is approaching, they get a reminder. When something becomes overdue, the push notification provides a direct nudge to act - one that appears on the lock screen rather than in an inbox that may not be checked until later in the day.
This matters for training compliance. Email reminders are effective but can be missed, filtered, or deprioritized among dozens of other messages. A push notification from a mobile app sits at a different level of visibility - it is harder to ignore without actively dismissing it, and dismissing it still creates awareness that action is needed. For employees who receive push notifications on their phone throughout the day for other work applications, a training reminder arriving through the same channel feels like a natural part of the work environment rather than a separate system interrupting them.
Managers and administrators benefit from the knock-on effect: when push notifications improve completion rates among employees, escalation events and overdue flags become rarer. The mobile app's notification capability reduces the operational overhead of chasing down incomplete assignments, freeing up the time that would otherwise go into manual follow-up.
Phishing Debriefs and Certificates on Mobile
Training completion is not the only thing employees need to access. After a phishing simulation, employees receive a debrief that explains the red flags they should have spotted. Being able to read that debrief on a phone - in the moment they receive it, wherever they are - means the learning happens at the point of maximum engagement rather than waiting until they are next at their desk. The mobile app surfaces phishing debriefs alongside training assignments so they are equally easy to find and read.
Completion certificates are also accessible in the app. When an employee finishes a course and receives a certificate showing their name, course, score, and completion date, they can view it directly from their phone. For employees who want to share a certificate with a manager or keep a personal record of their training achievements, mobile access to certificates makes this straightforward. The certificates available in the mobile app are the same ones that can be downloaded as PDFs from the web portal and verified through the public verification link.
Report Phishing from Your Phone
The empowsec mobile app includes a phishing reporting feature so employees can report suspicious emails directly from their phone. This is particularly relevant for employees who access work email through a mobile client rather than through a desktop mail application. Without a mobile reporting option, an employee who spots something suspicious in their mobile inbox faces a friction barrier: they might note it mentally but not report it until they are at their desk - if they remember at all. A report button accessible directly on the phone removes that barrier.
Reporting a phishing simulation through the mobile app earns the same positive risk credit as reporting through the web portal or the Outlook add-in: 5 points credited toward the employee's risk score. Reporting real phishing is worth 8 points. The credit recognizes and reinforces the correct behavior regardless of which channel the employee uses to report. This consistency is important for building the habit: employees learn that the action has value, and the channel they happen to be using does not change that.
Secure Sign-In: Password, 2FA, and SSO
The mobile app uses the same authentication controls as the web portal, which matters for organizations that have invested in centralizing identity management. Employees can sign in with their empowsec password, and if two-factor authentication (TOTP) is enabled on their account, they complete the second factor in the app the same way they would on the web. The 6-digit TOTP code from their authenticator app provides the same account protection on mobile as on desktop - a stolen password alone cannot access the account.
For organizations using single sign-on (SSO) through SAML, OIDC, or OAuth providers, the mobile app supports SSO sign-in as well. Employees who access other work applications through their organization's identity provider can use the same flow to access empowsec on mobile. This keeps the sign-in experience consistent with what employees already know, reducing support tickets and making adoption smoother.
The app also supports switching between accounts and companies. Employees who belong to multiple organizations - for example, contractors or consultants with access to several client environments - can switch between contexts without signing out and back in. This flexibility is especially relevant for reseller environments where the same individual may support multiple client companies.
Fitting the Mobile App Into Your Awareness Program
The mobile app is not a separate product from the empowsec web platform - it is a companion that extends the same program to a different context. Training assignments, risk scores, phishing simulation results, certificates, and debriefs are all shared between web and mobile. An administrator who assigns a course from the web console will see the employee's mobile completion reflected in the same dashboards and reports.
From an adoption perspective, communicating the mobile app to employees during onboarding helps set the expectation that security awareness is an ongoing, accessible activity rather than an annual event on a desktop. When employees know they can complete a 12-minute module during a commute and receive their push notifications alongside their other work apps, the training program becomes part of the rhythm of work rather than an interruption to it.
What This Means for Your Team
- Full training access on mobile means employees complete assigned courses and quizzes on their phone with the same content and credit as the web portal.
- Push notifications for due and overdue training increase completion rates by surfacing reminders directly on employees' lock screens.
- Phishing debriefs and certificates are accessible in the app so learning and achievement records are available wherever employees are.
- One-tap phishing reporting from the mobile app earns the same positive risk credit as the desktop or Outlook add-in, reinforcing the reporting habit regardless of device.
- Password, 2FA, and SSO sign-in keep mobile access under the same security controls as the web portal.
- Multi-account switching supports employees who operate across multiple organizations or client environments.


