Services / Enablement
Security Awareness & Training
Training your staff remember, and the completion records your auditor requires.
The problem
Once a year everyone clicks through a 40-minute video about a threat landscape that does not resemble their job. Completion looks fine on paper, nobody can tell you what it changed, and the same person keeps approving invoice changes over email.
The method.
Train against the way your company is actually attacked
For a mid-market technology company that means: business email compromise and supplier invoice fraud, MFA fatigue and push-bombing, OAuth consent phishing, and, for the people with production access, credential handling and social engineering aimed at the helpdesk. Generic content about USB drops teaches nothing about the way anyone actually gets in.
Segment by role and by what a person can lose
Engineers with production access, finance with payment authority, support with customer data access, and executives who are the named target of most spear-phishing all need different training. Everyone getting the same module means it is wrong for almost everyone. Role-specific content is also what the standard asks for.
Run phishing simulation as measurement, not as punishment
Simulations calibrated to realistic pretexts, measuring click rate, credential-submission rate and (the metric that matters) report rate. A workforce that reports quickly is a detection capability. A workforce that fears being blamed is a workforce that hides the click, which is the outcome you least want.
Deliver at the moment of use
Short, targeted material at the point of relevance: secure development guidance where engineers already read documentation, payment-fraud verification steps in the finance approval flow, data handling rules where customer data is accessed. Annual modules are forgotten within days; in-context guidance changes behaviour.
Track completion so it is evidence, not admin
Assignment on hire, completion tracked to the individual, and role-specific modules recorded separately. This is a control that gets sampled at every audit, and joiners are the population where it most often fails. Someone hired in November who was never assigned the training is a finding waiting to be found.
Does ISO 27001 require security awareness training?
Yes. ISO 27001 Clause 7.2 and 7.3 require competence and awareness, and Annex A requires information security awareness, education and training appropriate to each person's role. SOC 2 requires the same, and both expect evidence: completion records per individual, including for people who joined mid-year, which is where the control most often fails.
What should security awareness training cover for a technology company?
The attacks that actually reach it: business email compromise and supplier invoice fraud, credential phishing and MFA fatigue, OAuth consent phishing, social engineering of the helpdesk, and secure handling of production credentials and customer data. Content should differ by role: engineers, finance, support and executives face materially different attacks and hold materially different access.
Do phishing simulations actually reduce risk?
They do when the measured outcome is the report rate rather than the click rate. Some proportion of people will always click; what determines the outcome of a real attack is how fast someone reports it, because that starts the response clock. Simulations run to punish clickers reduce reporting, which makes the organisation less safe rather than more.