Skip to main content

Changelog

What has been added to Varhugi and what has changed, dated by when it went live. A new module is added every month and existing ones are revised when there is reason to.

Only changes customers can see or use are listed here. What is coming next is on the roadmap.

August 2026

  1. Security-officer checklist on the security page, an explicit MFA statement, and a 24-hour breach notification commitment in the DPA.

  2. Per-person risk indicator on the dashboard: low, elevated or high, always with the reasons.

  3. Changelog, roadmap and an explainer of how the risk indicator is scored. Version and last-updated date now shown for every module in the curriculum.

  4. Board memo template and Varhugi's answers to the vendor security questionnaire as a PDF.

  5. See the product before signing up: the full phishing module with its quiz, the dashboard with fictional data and the "Genuine or scam?" self-test, all open without sign-in.

  6. Automatic annual refreshers (opt-in, Pro): a year after a member passed a required module it comes back as a refresher with a 30-day due date, one per person per month.

  7. Architecture and operations section on the security page: components, tenant separation, sessions, audit trail, backups and certifications.

  8. Module 01 (Passwords) updated: quiz question on sharing passwords.

  9. Admins can change member roles and invite department managers directly. A module can now be assigned to one person.

  10. AI use policy template rewritten with a printable document layout.

  11. Public sample of the audit report (PDF) and the NIS2 mapping table, no sign-in needed.

  12. Security improvements to self-signup links and reminder dispatch.

  13. Consistent terminology and phrasing across 26 modules.

  14. Refreshers: send a specific module back to one member after an incident, with a due date and reminders.

  15. Icelandic copy cleaned up across modules, guides and the interface.

  16. Module 03 (Two-factor authentication) updated to 1.2.0: passkeys and what they protect against.

  17. Vendor security page at /oryggi: hosting, access control, safeguards, subprocessors and data handling.

July 2026

  1. New Lite 50 plan and annual billing. The free plan now covers the first three modules.

  2. Guide articles on phishing, two-factor authentication, NIS2 and security awareness, linked to the glossary.

  3. Security review of the whole codebase with fixes shipped: access control, sessions, headers and rate limits tightened.

  4. Entra sign-in: simpler admin consent. The dashboard gains learning coverage, department comparison and CSV export.

  5. All 32 modules rewritten as clean informational texts, version 1.1.0.

  6. Data Processing Agreement, processing records and legal pages published.

June 2026

  1. Module wording refined. Shadow IT is now rendered in Icelandic throughout.

  2. Certificates redesigned: landscape PDF and downloadable PNG.

May 2026

  1. Three new modules: PDF document threats, Frontline staff under pressure, and Digital security in plain language. Passkeys section in module 03. Gender-neutral language across all modules.

  2. Advanced track for sysadmins: Sysadmins under attack, and Supply chains and attacks you don't see at first. Assigned manually, not automatically.

  3. Mobile improvements: reading progress, a bottom action button, and the app can be saved to the home screen.

  4. Invitations staged in a batch and sent immediately or on a schedule.

  5. Members can be marked on leave so stats and reminders skip them. Per-department curricula. Modules grouped into themes. Glossary tooltips inside modules. Roles synced from Entra. Admin sessions end after four hours idle.

  6. Audit log of admin actions, strict Content Security Policy, and rate limiting on sign-in.

  7. Ten new modules on physical security, the workplace and everyday practice. Self-signup links restricted to the company domain. Colleagues from the same Entra tenant join automatically.

  8. Ready-made staff announcements in the dashboard. Public curriculum at /namskra.

  9. Sign-in with Google and Microsoft Entra ID. Departments and department managers. Audit readiness and an at-risk list on the dashboard.

  10. Four new AI safety modules. Glossary of 31 Icelandic cybersecurity terms.

April 2026

  1. NIS2 audit report as PDF for a chosen period. Daily reminders for invitations, due dates and overdue modules.

  2. Ten new modules: AI-written phishing, MFA fatigue, invoice fraud, deepfakes, incident response and more. NIS2 explainer page.

  3. The first three modules (passwords, phishing, two-factor authentication), quizzes and certificates with public verification.

Want to see the modules themselves?

Every module is listed in the curriculum with its version number and the date of its last revision.