Security Awareness Training

Most incidents begin with a reasonable person doing a reasonable thing at the wrong moment. We train for that moment — role by role — rather than for the annual compliance tick.

Typical duration
6–12 weeks to launch
Primary audience
Both
You leave with
A workforce that recognises the moment it is being worked — and an audit trail that proves the training happened.

Three phases, start to finish.

  1. 01 Role and risk mapping Which roles can actually cause a loss, and how. A finance approver, a platform engineer and a receptionist are exposed to three different attacks and should not sit through the same slide deck. Roles mapped to the losses they are positioned to cause Existing incidents and near-misses mined for the material that lands hardest Baseline taken from a phishing simulation where one is running
  2. 02 Deliver, role by role Live sessions where discussion is the point, short async modules where it is not. Written in English and French, and refreshed as the lures change. Executive track: fraud authorisation, disclosure decisions, deepfake and voice pretexts Engineering track: secrets handling, dependency risk, secure review, cloud console hygiene Frontline and finance tracks: payment verification, supplier changes, physical access
  3. 03 Evidence and cadence The part that saves you in an audit. Attendance, comprehension and refresh cadence recorded in the shape ISO 27001 and SOC 2 auditors sample. Attendance and comprehension records mapped to Annex A 6.3 and the relevant TSC Onboarding module wired into your joiner process, not run once a year Annual refresh calendar handed over with the content

Train the moment, not the module

Verizon’s Data Breach Investigations Report has found a human element in roughly two-thirds to three-quarters of breaches in every recent edition. That statistic is usually deployed to sell annual training, which is the wrong conclusion to draw from it. The finding is not that staff are careless; it is that attacks are designed to arrive at the exact moment a reasonable action is the wrong one.

So the training is built around moments rather than topics. Not “here is what phishing is”, but “a supplier you have paid for four years has emailed new bank details, the invoice is real, and it is the last day of the month”.

The tracks

  • Executive. Fraud authorisation, disclosure decisions under time pressure, deepfake and voice pretexts, and what a regulator expects you to have decided before an incident rather than during one.
  • Engineering. Secrets handling, dependency and supply-chain risk, secure review habits, cloud console hygiene, and the social engineering aimed specifically at people with production access.
  • Finance and operations. Payment verification, supplier bank-detail changes, invoice fraud and the out-of-band approval that stops all three.
  • Frontline and general staff. Reporting routes, physical access, device handling, and permission to be suspicious of someone senior.

Format

Live role sessions run 45 to 60 minutes, where the discussion is the point and the slides are not. Async modules run 8 to 12 minutes and are built to be finished rather than endured. Onboarding is a single module wired into your joiner process, so a new starter is trained in week one instead of at the next annual cycle. All of it is delivered in English and French.

Evidence your auditor will accept

ISO 27001 Annex A 6.3 requires awareness, education and training appropriate to role, and the Trust Services Criteria expect evidence that it happened. We record attendance, comprehension and refresh cadence in the shape an auditor samples, and hand over the annual calendar with the content — so year two is a scheduled activity rather than a reconstruction the week before fieldwork.

Attacks are not designed to defeat knowledge. They are designed to arrive at the worst possible moment.

Security Awareness Training: the questions we get asked.

Does this satisfy ISO 27001 and SOC 2 training requirements?

Yes. Annex A 6.3 requires awareness, education and training appropriate to role, and the Trust Services Criteria expect evidence that it happened. We record attendance, comprehension and refresh cadence in the form an auditor samples, so the evidence is a query rather than a reconstruction.

Is training available in French?

Yes. Materials and live sessions are delivered in English and French, which matters for organisations with Quebec operations or federal contracts.

How long does a session take?

Live role sessions run 45 to 60 minutes. Async modules are 8 to 12 minutes and are built to be finished, not endured. Onboarding is a single module wired into your joiner process.

Can you train a small team?

Yes. The role mapping is smaller when the company is, but the exposure is not — small organisations are targeted precisely because the finance approver and the IT administrator are often the same person.

Other lines of work

All services

Tell us what triggered the search. We will scope to that.

We reply to every assessment request within one business day.