Security Awareness Training
Role-based training and phishing simulations that reduce human risk and prove it.
Most breaches start with a person: a clicked link, a shared password, an invoice that looked right. Awareness training reduces that risk when it is relevant to the person's role, repeated and measured. We build programmes that people find useful rather than tedious, and we report the trend.
Phishing simulations are run to teach, not to trap, with immediate feedback and coaching rather than blame.
- Content is built from real incidents we have seen, not stock scenarios.
- We measure reporting rate as well as click rate, because reporting is the behaviour that saves you.
- Developer and executive modules are written by people who test systems and brief boards.
- A bank, airline or retailer with thousands of staff across shifts, languages and roles.
- A finance function that approves payments and has been targeted by invoice fraud.
- A group whose annual e-learning is completed and forgotten.
- Phishing click rates are unknown or measured once a year.
- A recent incident began with a credential or an approved payment.
- Developers and executives receive the same module as everyone else.
- Auditors ask for training evidence and the records are incomplete.
What is included.
- 01
Curriculum design
Role-based modules for staff, managers, finance, developers and executives.
- 02
Training delivery
Live sessions, short e-learning and micro-content on a schedule.
- 03
Phishing simulations
Realistic campaigns with graded difficulty and instant learning moments.
- 04
Targeted coaching
Follow-up for high-risk roles and repeat clickers, handled respectfully.
- 05
Measurement
Quarterly scorecard on click rates, report rates and training completion.
Four steps, no surprises.
- 01
Baseline
Initial simulation and survey to measure the starting point.
- 02
Design
Curriculum and simulation calendar by role.
- 03
Run
Training and simulations delivered on schedule with coaching.
- 04
Report
Quarterly scorecard and programme adjustments.
From first meeting to steady state.
- 01Weeks 1 to 3
Baseline
Initial simulation and survey measure the starting point by role and location.
- 02Weeks 4 to 6
Design
Curriculum, simulation calendar and coaching approach agreed with HR and communications.
- 03Month 2 onwards
Run and report
Training, simulations and coaching delivered on schedule with a quarterly scorecard.
- Phishing simulation click rate by role and over time.
- Report rate on simulated and real phishing.
- Training completion by role within the agreed window.
- Size of the repeat-click population after coaching.
- Awareness programme lead
- Security trainer
- Phishing simulation specialist
- Reporting analyst
- Baseline risk report.
- Role-based curriculum.
- Training sessions and e-learning access.
- Phishing simulation results.
- Quarterly scorecard.
Awareness programmes run as an annual retainer sized by headcount, including platform, content and quarterly reporting. A one-off baseline and workshop package is available as a fixed-scope engagement of two to four weeks for organisations that want a measured starting point before committing to a programme.
Red Team & Social Engineering
Objective-based adversary emulation including phishing and physical scenarios, measured against your defences.
CybersecurityCompliance & Governance (ISO 27001, SOC 2, NIS2, GDPR)
Gap assessment, policy writing and audit preparation across the frameworks your customers demand.
IT ConsultingManaged IT & Support
Proactive monitoring, help desk and infrastructure management under a service level you can hold us to.
Security Awareness Training, in plain terms.
KnowBe4 or an equivalent, chosen for your size and language needs. The platform is included in the retainer.
Not when they are framed as practice and followed by coaching. We never publish individual results and we brief managers on tone.
Yes. Secure coding modules built around the issues we find most in penetration tests.
Yes. The programme produces the completion records and evidence that ISO 27001, SOC 2 and NIS2 expect.