Training & Awareness

Cybersecurity training for employees — from your weakest link to your first line of defence.

Practical training, realistic phishing simulations, and role-specific scenarios. Built around the threats your team is actually being targeted by — not generic compliance modules.

№ 01

The threat surface

The threats your team faces every day.

01

Phishing & spear-phishing

Deceptive emails crafted to steal credentials, trigger payments, or install malware — increasingly personalised using AI to mimic real colleagues, customers, or suppliers.

02

Social engineering

Manipulation over phone, email, or in person — impersonating IT support, suppliers, or senior management to extract information or trigger an action.

03

Business email compromise

Fraudulent payment instructions sent from spoofed or compromised executive accounts — direct financial loss, often six figures, often unrecoverable.

04

Ransomware delivery

Most ransomware enters via a phishing attachment or malicious link clicked by an employee — not via a technical exploit.

05

Credential theft

Password reuse, weak credentials, and fake login pages let attackers into systems without any technical hacking — they walk in through the front door.

06

Insider risk

Unintentional data exposure through poor data handling, misconfigured sharing settings, or use of personal devices for work data.

№ 02

Six interlocking programs

Every program built around your team.

Foundation — security awareness essentials

The baseline program for all employees: phishing recognition, password hygiene, safe data handling, incident reporting, acceptable use. Short modules in plain language. Satisfies the awareness training requirements of GDPR and ISO 27001.

Simulation — phishing campaigns

Realistic simulated phishing attacks measuring click rates, credential submission, and reporting behaviour — followed automatically by targeted micro-training the moment someone clicks.

Role-based — high-risk role training

Finance teams, executives, HR, IT. Each role faces different attack patterns — BEC for finance, deepfake fraud for executives, privilege abuse for IT admins. Targeted training for each.

Regulatory — compliance-mapped training

The training mandated by NIS2, DORA, GDPR, ISO 27001, and PCI DSS — covering data protection obligations, incident reporting, acceptable use, and sector-specific requirements. Documented completion records.

Leadership — executive & board briefings

Tailored sessions for senior leadership and the board: governance responsibilities, personal liability under NIS2, cyber risk as business risk. Plain language, no security theatre.

Incident — tabletop exercises

Scenario-based workshops where your leadership team practices responding to a live cyberattack — detection, containment, communication, regulatory notification, recovery.

№ 03

How phishing simulation works

Real consequences, safe environment.

  1. i.

    Baseline

    An unannounced campaign establishes your current click rate and reporting behaviour — the honest starting point everything else gets measured against.

  2. ii.

    Targeted micro-training

    Employees who click see a short, specific explanation of what they missed and why — delivered the moment the lesson is freshest.

  3. iii.

    Progressive campaigns

    Simulations increase in sophistication over time, testing your team against increasingly convincing scenarios drawn from current attacker tradecraft.

  4. iv.

    Reporting & benchmarking

    Detailed reports showing click rates, reporting rates, and department-level trends across campaigns — quarter on quarter.

  5. v.

    Audit evidence

    All campaign data is exportable as documentation for NIS2, GDPR, ISO 27001, DORA, and PCI DSS audit requirements.

№ 04

Regulatory training requirements

Training is now a requirement, not a best practice.

RegulationTraining requirementStatus
NIS2Cybersecurity awareness for all staff. Dedicated governance training for management. Documented records required.Mandatory · EU
DORAICT security awareness training for staff in ICT functions; operational resilience training for third-party risk roles.Mandatory · Financial
EU GDPRData protection awareness for any staff handling personal data — data subject rights, breach notification, lawful processing.Mandatory · EU
ISO 27001Clauses 7.2 and 7.3 require documented competency programs and awareness training for everyone working under your organisation's control.Certification
PCI DSSRequirement 12.6 mandates a formal awareness program: annual training plus signed acknowledgement of the security policy.Mandatory · Payments
№ 05

Outcomes

Measurable results — not completion certificates.

01.

Reduced click rates

Measurable decline in phishing click rates — tracked over time, reportable to auditors, comparable across departments.

02.

Increased reporting

More employees flagging suspicious activity — the first and most critical step in early detection of real attacks.

03.

Audit evidence

Documented completion records, scores, and simulation results ready for NIS2, GDPR, ISO 27001, and DORA audits.

04.

Stronger culture

Employees who understand why security matters — not just what the rules are — behave securely by default.

05.

Faster incident response

Teams who have practiced through tabletop exercises contain real incidents faster, with significantly lower impact.

06.

Lower insurance risk

Documented active programs are increasingly a factor in cyber-insurance underwriting — influencing premiums and coverage terms.

№ 06

FAQ

Common questions.

How often should training be delivered?
Annual training is the regulatory minimum — and rarely sufficient on its own. Awareness degrades fast without reinforcement. We recommend a continuous rhythm: a foundation module annually, monthly phishing simulations, and quarterly awareness communications on current threats. That cadence keeps security top of mind without creating training fatigue.
How long do training sessions take? Will it disrupt operations?
Designed around lean SMB teams. Foundation modules are 10–15 minutes, completable at each employee's own pace. Phishing simulations run in the background with no disruption. Role-specific workshops are typically 60–90 minutes; executive briefings and tabletop exercises 2–3 hours. Everything is remote-first, on-demand, and scheduled around your operational peaks.
What evidence do we receive for audits and regulators?
A full audit trail: individual completion records with timestamps, assessment scores, phishing simulation results by employee and department, attendance records for workshops, and program summary reports. Formats compatible with ISO 27001 documentation requirements; produced on request for NIS2, GDPR, DORA, and PCI DSS audits. Plus a signed certificate of program delivery for your compliance file.
Is phishing simulation ethical? Will employees feel tricked?
Phishing simulation is a mainstream practice used by the vast majority of organisations with mature security programs. We recommend communicating to your team in advance that simulations will run during the year, without revealing specific timings — this is transparent, reduces resentment, and produces better outcomes because people stay vigilant rather than feeling blindsided. The response to a click is always educational, never punitive.
Can training be customised for our industry?
Yes — and it's one of the most important factors in whether the training actually works. Generic content covering abstract threats produces limited behaviour change. We tailor scenarios, examples, and simulations to your sector — a financial services firm faces different attacks to a manufacturer or healthcare provider. We use current threat intelligence to make sure your team is practicing against the attacks that are actually targeting organisations like yours right now.
Can training be delivered in French?
Yes. We deliver natively in English and French, ensuring language is never a barrier. For multilingual teams we recommend each employee receives training in their primary working language — both for effectiveness and to satisfy the comprehension requirements of GDPR and NIS2. Coverage spans France & DOM, Belgium, Luxembourg, Switzerland, and the broader EU.
Do you cover AI literacy under Article 4 of the EU AI Act?
Yes — Article 4 of the EU AI Act now requires deployers and providers of AI systems to ensure their staff have a sufficient level of AI literacy, proportionate to the risk and context of use. We deliver Article 4 literacy programmes as part of our AI Governance & Security service, using the same Training & Awareness pipeline. Modules cover EU AI Act basics, your AI acceptable-use policy, the OWASP LLM Top 10 risks in business contexts, and your organisation's AI policy. Completion is tracked for audit evidence — the same way ISO 27001 and NIS2 evidence is captured here.
How is the engagement priced?
An annual program fee covering foundation training rollout, twelve months of phishing simulations, quarterly awareness communications, and full audit-evidence reporting. Scoped to your team size and industry threat model. Add-ons — executive briefings, tabletop exercises, role-specific workshops — are priced separately and can be bundled. All numbers fixed and shared in the proposal after the consultation. No surprise bills, no hourly tracking.