CYBER
SECURITY
TRAINING
Your firewall won't stop a staff member who clicks a phishing link. Human error drives 95% of security incidents. Our security awareness training programme turns your team from the biggest risk into the last line of defence.
What's included in
our training programme
Phishing Simulation
Regular simulated phishing campaigns targeting your staff. Those who click receive immediate in-context micro-training.
Security Awareness eLearning
Short, engaging training modules covering phishing, password hygiene, social engineering, remote working, and data handling.
Spear Phishing Campaigns
Advanced targeted simulations mimicking real supplier or executive impersonation — for higher-risk roles.
Reporting & Risk Scores
Per-user and per-department risk scores, click rates, training completion rates, and trend data over time.
New Joiner Training
Automated security awareness training assigned to new starters during onboarding — ensuring day-one security hygiene.
Compliance Reporting
Training records and completion certificates for ISO 27001, Cyber Essentials, and regulatory compliance evidence.
Security training
questions answered
Q.Why is security awareness training important?
Over 90% of successful cyber attacks involve human error — a staff member clicking a phishing link, using a weak password, or sharing credentials. Technical controls can filter threats, but they cannot block everything. Security awareness training reduces the human risk factor, which is the single largest attack vector for SMEs.
Q.How often should phishing simulations be run?
Monthly is optimal — frequent enough to keep staff alert without creating fatigue. We recommend starting with a baseline test, then running monthly campaigns with varied templates. We provide a 12-month campaign calendar as part of onboarding.
Q.What happens when a staff member fails a phishing simulation?
They receive immediate, in-context micro-training explaining why the email was suspicious and what they should have done. This just-in-time training is far more effective than annual lectures. Serial clickers are flagged in reporting for targeted follow-up.
Q.Is cyber security awareness training required for Cyber Essentials?
Cyber Essentials does not specifically require training, but it does require you to have controls that prevent malware and phishing attacks. NCSC strongly recommends training as a complementary measure. For ISO 27001, staff security training is a mandatory control.
Q.Can training be customised to our industry?
Yes. We use industry-specific phishing templates — for example, fake invoice emails for finance teams, fake contract updates for legal firms, or GDPR breach notifications for healthcare. Relevant scenarios produce higher engagement and better learning outcomes.
