All offerings

Capability 06

Security Awareness & User Training

The yearly compliance video everyone clicks through by February doesn't change what a tired employee does at 4pm on a Friday. We run an ongoing program instead: short, realistic phishing practice that builds the instinct to stop, check, and report, plus a record of fewer people clicking and more people reporting that you can show an auditor or insurer.

When to engage

  • Someone on your team clicked something they shouldn't have, or came close, and it rattled you.

  • Your cyber-insurance renewal asks whether you run regular training and phishing tests, and you can't say yes.

  • An examiner or auditor asked for proof your staff are trained, and a one-time slideshow won't cut it.

  • You've run the annual video for years, but you have no idea whether any of it stuck.

How it works

First we run a baseline: a realistic phishing simulation that shows where your team stands, and which roles need the most help. From there it's a steady rhythm, not an annual event: short lessons at the moment someone slips, extra practice for the people attackers target most, like finance and reception, and a no-blame culture so people report a mistake instead of hiding it. Every few months you get a plain report: who's improving, where the risk still sits, and the trend over time.

What you receive

  • A baseline phishing simulation that shows where your real risk is, before any training starts.
  • Ongoing, realistic phishing practice, with a short lesson at the moment someone clicks, not a lecture months later.
  • Role-based training for the people attackers go after most: anyone who moves money, handles records, or answers the phone.
  • A one-click way for staff to report a suspicious email, and a culture that thanks them for it.
  • New-hire training, so the newest people aren't your biggest gap.
  • A plain report you can hand an auditor or insurer: click-rate down, report-rate up, and the trend over time.

Timeframe

A baseline goes out in the first couple of weeks. Awareness is an ongoing program, not a one-time session: behavior shifts over months, and a real reporting culture builds over the first year and beyond.

Ways to work together

Baseline & launch

A few weeks

Scope
A phishing baseline, onboarding, and a first training round
What you get
A clear read on your risk and a program stood up
Best for
A first step, or an insurer or auditor asking
Recommended

Managed program

Ongoing

Scope
Simulations, training, and reporting run for you through the year
What you get
A click-rate that falls and a report-rate that climbs, with the trend to show
Best for
Most firms that want training to change behavior, not tick a box

Targeted & culture

Ongoing

Scope
The managed program, plus role-based tracks and payment-fraud drills for high-risk staff
What you get
A reporting reflex built into how your firm works
Best for
Firms making security part of the culture, not a yearly chore

Who does the work

Your program is built by people who've defended real organizations and watched smart, careful staff get fooled, not an e-learning vendor reselling the same generic modules. The training lands because it comes from people who've seen these attacks work.

Fewer people clicking, more people reporting, and the trend to prove it.