Service
Phishing awareness training for your staff
No technical control stops an employee replying to a message from a domain that merely looks like yours. This service is a measured simulation campaign, then a short session with no jargon: the three checks to make before approving a transfer or typing a password. The point is vigilance, not blame.
Duration · Three to four weeks, of which an hour and a half is your team's time
Who it is for
- A team that handles transfers, supplier invoices or bank details: accounts, directors, executive assistants.
- A company that has already set up domain authentication and wants to cover what the technical controls let through: cousin domains and misleading display names.
- An organisation whose insurer or customer asks for evidence of awareness training.
Who it is not for
- An organisation looking for an e-learning platform with quarterly modules and a dashboard. This is not that format.
- A management team wanting to identify “who clicked” and act on it individually. Results are aggregated, and that condition is not negotiable.
The format
- 01
The scoping
Half an hour with the directors to agree the scope, the scenarios plausible for your trade, and the rules: what will be measured, what will be reported, and what will not.
- 02
The simulation campaign
Two to four messages, spread out, written for your context rather than taken from a catalogue. A false change of bank details from a supplier you really have, an urgent request in a director's name, a notification from a tool you actually use.
- 03
The session
Forty-five minutes, no jargon, in person or remote. It shows the campaign's messages, what gave each of them away, and the three checks that would have stopped all of them.
- 04
The report
Aggregate figures for the directors, never named, and a written rule for approving changes of bank details, ready to adopt.
The three checks
This is the heart of the session, and the only content people still have six months later. It fits on a sticky note.
- The address, not the name. The display name is free text: it can say anything at all, including your own address. What counts is what comes after the
@, read character by character. - A change of bank details is confirmed by phone. On the number you already hold, never the one in the message. Two minutes, and it stops almost every case.
- Urgency and confidentiality are the signal. A message asking you to hurry and to tell nobody is asking for exactly the two things that would prevent you checking it.
What the campaign does not do
- No individual results are reported to management. The figures are aggregated, and that is a condition of the engagement, not an option.
- No scenario plays on a bonus, a dismissal, a bereavement or health. Those levers work, and they damage trust: the click rate they gain is not worth what it costs.
- Nothing an employee types into a simulated form is kept. That there was a submission is recorded; what was typed is not.
- Nobody is named during the session. The examples shown are the messages, not the reactions.
What you get
- 01A campaign of two to four scenarios, written for your context.
- 02A forty-five minute session, in person or remote.
- 03An aggregate report for management, with no names in it.
- 04A written rule for approving changes of bank details, ready to adopt.
- 05A one-page aide-memoire for the exposed roles.
FeesFees depend on how many people and how many sites. They take a few minutes to discuss on the phone.
Common questions
The work itself, explained in full and free
Fifteen minutes on the phone is enough to establish whether your domain is exposed, and the call commits you to nothing.