Security awareness training
Help your people spot the email that gets past the filters.
Phishing is still one of the most common ways attackers get in, and insurers and customers now ask how staff are trained. We run realistic phishing simulations and short, relevant training, and connect the results to the technical controls that catch what people miss.
Start with a cyber risk assessment
What is included
- Phishing simulations matched to the attacks your organisation receives, run on a schedule
- Short training modules, assigned automatically to people who click and available to everyone
- Onboarding training for new starters
- A report button in Outlook, so staff can flag suspicious email in one click
- Targeted sessions for higher-risk roles, such as finance, executives and IT administrators
- Monthly reporting on click rates, report rates and completion, for leadership and insurers
Using what you already own
If you have Microsoft Defender for Office 365 Plan 2, through Microsoft 365 E5 or an add-on, Attack Simulation Training is included and we run it for you. If not, we recommend a platform that fits your licences and budget.
People and controls together
Training reduces risk, but people will still click sometimes. Phishing-resistant MFA, Defender for Office 365, Conditional Access and a monitored report button limit the damage when they do. We design both sides together.
How it runs
- Baseline: a first simulation shows where you start.
- Train: modules assigned by role and by result.
- Repeat: simulations on a schedule, varied so people can't learn the pattern.
- Report: trends shared monthly, with the controls that caught what people missed.
Questions buyers ask
Will simulations upset staff?
They are designed to teach. Someone who clicks gets short, immediate training, and results are reported as trends rather than naming individuals to leadership.
How often should we run simulations?
Monthly or every two months works well for most organisations, with training assigned automatically after each one.
Does this help with cyber insurance?
Insurers commonly ask about security awareness training and phishing testing. The monthly report gives you the evidence.
Do we need Microsoft E5?
No. E5 includes Attack Simulation Training, but we can run training on another platform if you don't have it.
Can you train our IT team on security?
Yes. Targeted sessions for administrators cover privileged access, phishing aimed at IT staff and incident procedures.
Start a conversation
Make your people part of your defence.
Tell us how staff are trained today.
Talk to an Engineer