602-725-2818Licensed, insured & bondedSchedule a Consultation
Call 602-725-2818Consultation

Cyber Services

Security Awareness Training

Workforce training that reduces the phishing and social-engineering exposure which opens most incidents.

SDVOSBCertified
9FNE2CAGE Code
24 / 7 / 365SOC Monitoring
In-HouseForensic Capability

The control that fails is almost always a person

Organizations spend heavily on technical controls and then get breached through an email nobody should have clicked. That is not a failure of intelligence; it is a failure of preparation. People who have seen a convincing phish in a training environment behave differently when they meet one at 4:55pm on a Friday.

Training is built around your actual exposure — the roles that handle payments, the staff who receive external mail, the executives who are worth impersonating. It is delivered to your people, and it can be delivered to outside agencies and corporate teams as well.

What is included

Phishing Awareness

Recognition and reporting of phishing, spear-phishing and business email compromise attempts.

Social Engineering

Pretexting, vishing and in-person approaches, including the techniques used against front-desk staff.

Role-Based Content

Finance, executive, HR and front-of-house staff trained against the approaches that actually target them.

Delivery Options

Group, on-site or agency delivery, with curricula tailored to your policy and post orders.

Why most awareness training does not work

Annual compliance training exists to be completed, not to change behaviour. Everyone knows this — the staff clicking through it at 4pm on the last day of the quarter know it, and so does the person who bought it. It satisfies an audit line and it moves almost nothing.

Three things make the difference between a completion rate and an actual change in risk.

Frequency over duration. A short, specific intervention every few weeks beats a long session once a year, because the behaviour you are trying to influence happens every day and memory decays in weeks.

Relevance over generality. Training built around your actual threats, your actual systems and your actual processes. A finance team needs payment verification discipline; a clinical team needs device and record handling; an executive assistant needs to recognise a fraudulent instruction that mimics their principal’s writing style. Generic content teaches everyone the average lesson, which is nobody’s lesson.

Reporting culture over blame. The single most valuable behaviour is not “never click”. People will click — the attacks are good, and the person who clicked is usually the one who was busiest, not the one who was careless. The behaviour that saves you is that they tell somebody within minutes. An organisation that shames people for clicking is buying silence, and silence is what turns a contained incident into a breach.

What we actually teach, because the threats have moved

Phishing, and its expensive relative. Recognition of credential harvesting and malicious attachments, but with more time on business email compromise — the invoice that changed bank details, the vendor payment instruction that came from a compromised real account, the executive request that arrives at exactly the moment the executive is known to be travelling. That category costs mid-sized organisations more than ransomware does, and it usually involves no malware at all.

Multi-factor fatigue and approval attacks. Staff are now targeted with repeated push notifications until somebody approves one to make it stop. Training covers why an unexpected prompt is an incident to report rather than a nuisance to dismiss.

Voice and video pretexting. Synthetic audio and video are now cheap and convincing enough that hearing a familiar voice is no longer verification. The control is procedural — verify instructions out of band, through a channel and a number you already had — and it has to be taught as a rule rather than as a judgement call, because the whole point of the attack is that it does not feel like one.

Payment verification. The single highest-value process control in most organisations, taught to the people who actually execute it: any change to payment details is verified by callback to a number held on file beforehand, never a number in the email.

Physical and social. Tailgating, unescorted visitors, unattended screens, devices and documents, and the pretext phone call to the helpdesk — which is how a great many account takeovers actually begin.

Data handling and reporting. Where information may go, what shadow IT costs, and precisely how to report something at 6pm on a Friday.

Simulation, done in a way that does not backfire

Phishing simulation is useful and easy to run badly. Done well it is calibrated — starting realistic rather than trivially obvious, increasing in sophistication over time, and varied so that people learn recognition rather than pattern.

Done badly it is a trap designed to produce a high failure rate for a slide in a board pack. Simulations that impersonate a bonus announcement, a redundancy notice, a bereavement or a payroll error do generate impressive click rates and they also generate a workforce that distrusts internal communications and stops reporting anything. We will decline to run those.

The metric we care about is not click rate. It is report rate and time to report. A workforce with a 15% click rate and a two-minute median report time is far safer than one at 5% that never says anything. Reporting is what gives a monitoring team the chance to act, which is where the value connects to monitoring and response.

Results are used for training, not for discipline. Individual results are handled with care; repeated high-risk behaviour is a coaching conversation rather than a public one. The moment simulation becomes punitive, reporting stops.

Programme structure and compliance

A working programme usually looks like: a baseline assessment and simulation to establish where you actually are; a role-based onboarding module; short monthly or six-weekly modules on current threats; periodic simulation with immediate, non-punitive teaching at the moment of the click; targeted deeper sessions for finance, IT, executives and their assistants; and quarterly reporting on report rate, time to report and the trend.

Where training is a compliance requirement — HIPAA, PCI DSS, CMMC, SOC 2, or an insurer’s conditions — completion records, content and dates are maintained as evidence. Meeting the requirement and changing the behaviour are different objectives, and a programme should do both rather than pretending they are the same thing.

Tabletop exercises for leadership sit alongside this and are frequently the highest-value session of all: the first time an executive team makes a payment decision, a notification decision and a communications decision should not be during a real incident.

How it is priced, and where it connects

Quoted per user per year for the ongoing programme, with a floor for small organisations, driven by headcount, module frequency, whether simulation is included and how much content is customised to your environment. Live sessions, executive briefings and tabletop facilitation are quoted separately.

Content is informed by what we see elsewhere in the practice: the phishing pretexts that actually landed during a penetration test, the routes used in real cyber investigations, and the failure patterns from ransomware engagements. Training built from stock content teaches last year’s attack.

Frequently asked questions

How often should training run?

Short and frequent beats long and annual — monthly or six-weekly modules of a few minutes each. The behaviour you are influencing happens daily and memory decays in weeks, so an annual session is measuring compliance rather than changing risk.

Should we discipline people who fail simulations?

No, and it is actively counterproductive. Punishment buys silence, and silence turns a contained incident into a breach. Use results for coaching. The metric that matters is how quickly people report, not how few people click.

Will you run a simulation about our bonus scheme?

No. Pretexts involving pay, redundancy, bereavement or payroll errors produce impressive click rates and a workforce that stops trusting internal communications. That trade is never worth it, and we will say so rather than deliver it.

Our staff have done training and still get caught. Why?

Usually because the training was generic, annual and abstract, while the attacks are specific, current and well-crafted. Role-based content built from real cases, delivered frequently, with a teaching moment at the point of the click, is a different intervention entirely.

What about deepfake voice and video?

Treat it as procedural rather than perceptual. Nobody can reliably detect a good synthetic voice under time pressure, so the control is verification out of band through a channel and number held beforehand — taught as an absolute rule, because the attack works precisely by not feeling like one.

Does this satisfy our compliance requirement?

Completion records, content and dates are maintained as evidence for HIPAA, PCI DSS, CMMC, SOC 2 or insurer conditions. We will be clear about which requirement the programme evidences and which obligations remain yours — satisfying an auditor and changing behaviour are related but not the same job.

Who this is for

  • Corporate teams
  • Small business
  • Law firms
  • Healthcare
  • Financial services
  • Government contractors
  • Outside agencies

Scope your requirement

Tell us headcount, the roles most exposed, and whether you have had an incident already. Training built after a real incident lands very differently, and we will use it if you are willing.