
PRACTICE 05 — SECURITY TRAINING & AWARENESS
Awareness that changes what people actually do — not an annual e-learning module with a certificate at the end.
THE PROBLEM
Most security training is bought to evidence compliance. So it optimises for the thing it can measure — completion. People click through the module, pass the quiz, collect the certificate, and go back to work exactly as they were. The record says trained. Nothing else has changed.
Meanwhile, most incidents start with an ordinary person making an ordinary mistake — a rushed approval, a plausible email, a password reused because the deadline mattered more. The firm's controls quietly assume that won't happen. Our standing test applies here as everywhere: if your people can't explain a control in a sentence, they'll route around it.
WHAT YOU GET
Plain-English campaigns built around your real incidents and near-misses, not stock scenarios. People pay attention to things that actually happened here.
Finance, engineering, assistants and executives face different attacks — so they get different sessions, each built around the decisions that role actually makes.
Simulations run to coach, with the lesson delivered in the moment someone clicks — never to name and shame. The point is that people get better.
Short, senior and jargon-free — the fluency DORA and NIS2 now expect at the top, including NIS2's training expectations on management itself.
WHERE WE'RE USUALLY CALLED IN
People protect what they understand.
Start a conversation