Capability 06
Security Awareness & User Training
The yearly compliance video everyone clicks through by February doesn't change what a tired employee does at 4pm on a Friday. We run an ongoing program instead: short, realistic phishing practice that builds the instinct to stop, check, and report, plus a record of fewer people clicking and more people reporting that you can show an auditor or insurer.
When to engage
Someone on your team clicked something they shouldn't have, or came close, and it rattled you.
Your cyber-insurance renewal asks whether you run regular training and phishing tests, and you can't say yes.
An examiner or auditor asked for proof your staff are trained, and a one-time slideshow won't cut it.
You've run the annual video for years, but you have no idea whether any of it stuck.
How it works
First we run a baseline: a realistic phishing simulation that shows where your team stands, and which roles need the most help. From there it's a steady rhythm, not an annual event: short lessons at the moment someone slips, extra practice for the people attackers target most, like finance and reception, and a no-blame culture so people report a mistake instead of hiding it. Every few months you get a plain report: who's improving, where the risk still sits, and the trend over time.
What you receive
- A baseline phishing simulation that shows where your real risk is, before any training starts.
- Ongoing, realistic phishing practice, with a short lesson at the moment someone clicks, not a lecture months later.
- Role-based training for the people attackers go after most: anyone who moves money, handles records, or answers the phone.
- A one-click way for staff to report a suspicious email, and a culture that thanks them for it.
- New-hire training, so the newest people aren't your biggest gap.
- A plain report you can hand an auditor or insurer: click-rate down, report-rate up, and the trend over time.
Timeframe
A baseline goes out in the first couple of weeks. Awareness is an ongoing program, not a one-time session: behavior shifts over months, and a real reporting culture builds over the first year and beyond.
Ways to work together
Baseline & launch
A few weeks
- Scope
- A phishing baseline, onboarding, and a first training round
- What you get
- A clear read on your risk and a program stood up
- Best for
- A first step, or an insurer or auditor asking
Managed program
Ongoing
- Scope
- Simulations, training, and reporting run for you through the year
- What you get
- A click-rate that falls and a report-rate that climbs, with the trend to show
- Best for
- Most firms that want training to change behavior, not tick a box
Targeted & culture
Ongoing
- Scope
- The managed program, plus role-based tracks and payment-fraud drills for high-risk staff
- What you get
- A reporting reflex built into how your firm works
- Best for
- Firms making security part of the culture, not a yearly chore
Who does the work
Your program is built by people who've defended real organizations and watched smart, careful staff get fooled, not an e-learning vendor reselling the same generic modules. The training lands because it comes from people who've seen these attacks work.