Skip to main content

Service

Cybersecurity Awareness Training

Practical, role-specific training so staff recognise an attack in progress.

Most awareness training teaches people to look for spelling mistakes and urgent language, which stopped being useful once attackers started proxying the real login page. Training that changes behaviour has to be about what the current attacks actually look like, and has to give people one rule they can follow when they are busy and unsure.

How this works

Current techniques, shown working

Sessions are built around what is being used now rather than what was used a decade ago: adversary-in-the-middle pages that proxy your real identity provider, thread hijacking from a genuinely compromised supplier, and requests that arrive through the channels people trust. Demonstrated live, because a screenshot of a phishing email teaches nothing that a description had not already covered.

Different sessions for different exposure

Finance staff face invoice fraud and payment redirection. Developers face dependency and repository attacks. Executives and their assistants face targeted impersonation. Support staff face social engineering aimed at account recovery. A single all-hands deck serves none of them well, so the content is split by what each group is actually targeted with.

One rule that survives being busy

The habit that defeats the whole modern phishing chain is never authenticating from a link: navigate to the service yourself, from a bookmark. Training is built around making that automatic, because a person under time pressure will not run a checklist but will follow a habit.

Reporting made blameless and fast

The user who clicked is the fastest detection available, and they will only use the report button if using it is easy and carries no punishment. Sessions cover what to do after a mistake, and the organisation is advised on making that path frictionless, because an organisation where people hide errors has traded its best signal for a training statistic.

What we look for

  • Whether staff can distinguish a legitimate authentication prompt from a proxied one, which most cannot without a rule
  • Whether the reporting path is known, quick and free of consequence
  • Which groups are targeted with what, and whether the training they receive matches
  • Whether prior training taught obsolete signals that now produce false confidence

What you get

  • Sessions built for the specific roles in the room
  • Live demonstration of current techniques rather than screenshots
  • One behavioural rule per group, chosen because it survives real conditions
  • Guidance on making the reporting path fast and blameless
  • Materials left with you for onboarding new staff

What this does not include

  • Naming or reporting individuals who fail an exercise
  • A compliance certificate for having run training, though attendance records are provided
  • Simulated phishing, which is a separate engagement and works better alongside this rather than inside it

Questions people ask

How long does a session take?
Long enough to demonstrate the techniques and rehearse the habit, and short enough that people stay. The right shape depends on the group and is agreed with you rather than fixed, since a developer session and an all-staff session are not the same problem.
Does awareness training actually work?
It works for teaching a habit and it fails as a control. Nobody should build a security programme on staff not clicking. The realistic goal is faster reporting and one reliable behaviour, with technical controls carrying the load, and the sessions are honest with attendees about that.
Can this be delivered remotely?
Yes, and the live demonstrations work fine over a call. In-person tends to produce better questions, which is where a lot of the value is.