Phishing & spear-phishing
Deceptive emails crafted to steal credentials, trigger payments, or install malware — increasingly personalised using AI to mimic real colleagues, customers, or suppliers.
Training & Awareness
Practical training, realistic phishing simulations, and role-specific scenarios. Built around the threats your team is actually being targeted by — not generic compliance modules.
The threat surface
Deceptive emails crafted to steal credentials, trigger payments, or install malware — increasingly personalised using AI to mimic real colleagues, customers, or suppliers.
Manipulation over phone, email, or in person — impersonating IT support, suppliers, or senior management to extract information or trigger an action.
Fraudulent payment instructions sent from spoofed or compromised executive accounts — direct financial loss, often six figures, often unrecoverable.
Most ransomware enters via a phishing attachment or malicious link clicked by an employee — not via a technical exploit.
Password reuse, weak credentials, and fake login pages let attackers into systems without any technical hacking — they walk in through the front door.
Unintentional data exposure through poor data handling, misconfigured sharing settings, or use of personal devices for work data.
Six interlocking programs
The baseline program for all employees: phishing recognition, password hygiene, safe data handling, incident reporting, acceptable use. Short modules in plain language. Satisfies the awareness training requirements of GDPR and ISO 27001.
Realistic simulated phishing attacks measuring click rates, credential submission, and reporting behaviour — followed automatically by targeted micro-training the moment someone clicks.
Finance teams, executives, HR, IT. Each role faces different attack patterns — BEC for finance, deepfake fraud for executives, privilege abuse for IT admins. Targeted training for each.
The training mandated by NIS2, DORA, GDPR, ISO 27001, and PCI DSS — covering data protection obligations, incident reporting, acceptable use, and sector-specific requirements. Documented completion records.
Tailored sessions for senior leadership and the board: governance responsibilities, personal liability under NIS2, cyber risk as business risk. Plain language, no security theatre.
Scenario-based workshops where your leadership team practices responding to a live cyberattack — detection, containment, communication, regulatory notification, recovery.
How phishing simulation works
An unannounced campaign establishes your current click rate and reporting behaviour — the honest starting point everything else gets measured against.
Employees who click see a short, specific explanation of what they missed and why — delivered the moment the lesson is freshest.
Simulations increase in sophistication over time, testing your team against increasingly convincing scenarios drawn from current attacker tradecraft.
Detailed reports showing click rates, reporting rates, and department-level trends across campaigns — quarter on quarter.
All campaign data is exportable as documentation for NIS2, GDPR, ISO 27001, DORA, and PCI DSS audit requirements.
Regulatory training requirements
Outcomes
Measurable decline in phishing click rates — tracked over time, reportable to auditors, comparable across departments.
More employees flagging suspicious activity — the first and most critical step in early detection of real attacks.
Documented completion records, scores, and simulation results ready for NIS2, GDPR, ISO 27001, and DORA audits.
Employees who understand why security matters — not just what the rules are — behave securely by default.
Teams who have practiced through tabletop exercises contain real incidents faster, with significantly lower impact.
Documented active programs are increasingly a factor in cyber-insurance underwriting — influencing premiums and coverage terms.
FAQ