Rows of empty seats in a dark auditorium

PRACTICE 05 — SECURITY TRAINING & AWARENESS

Training your people don't sleep through.

Awareness that changes what people actually do — not an annual e-learning module with a certificate at the end.

THE PROBLEM

Most training is bought to prove it happened.

Most security training is bought to evidence compliance. So it optimises for the thing it can measure — completion. People click through the module, pass the quiz, collect the certificate, and go back to work exactly as they were. The record says trained. Nothing else has changed.

Meanwhile, most incidents start with an ordinary person making an ordinary mistake — a rushed approval, a plausible email, a password reused because the deadline mattered more. The firm's controls quietly assume that won't happen. Our standing test applies here as everywhere: if your people can't explain a control in a sentence, they'll route around it.

A tiered lecture theatre

If the training worked, the helpdesk would know.

WHAT YOU GET

01

Awareness that sticks

Plain-English campaigns built around your real incidents and near-misses, not stock scenarios. People pay attention to things that actually happened here.

02

Role-specific training

Finance, engineering, assistants and executives face different attacks — so they get different sessions, each built around the decisions that role actually makes.

03

Phishing drills that teach

Simulations run to coach, with the lesson delivered in the moment someone clicks — never to name and shame. The point is that people get better.

04

Exec & board sessions

Short, senior and jargon-free — the fluency DORA and NIS2 now expect at the top, including NIS2's training expectations on management itself.

WHERE WE'RE USUALLY CALLED IN

RELATED

People protect what they understand.

Start a conversation