Security awareness training

Training that stops the risky click.

Every technical control you buy is there to catch the email before a person sees it. Eventually one gets through, and at that point the only thing left is whether somebody recognises it. We run short courses people finish, simulated phishing every month, and extra training for anyone who keeps clicking.

Talk to us 029 2111 1202

13 to 32 mintotal course length, not a wasted afternoon

Monthlysimulated phishing, adjusted to the business

Audit trailedevery completion logged, ready for your insurer

Why bother

Why does security awareness training matter?

Because every other control you pay for is designed to stop the message before a human being reads it, and eventually one gets through anyway. When that happens the entire defence is one person deciding whether something looks right.

The SRA found the same thing when it looked at law firms: three in five identified their own staff’s knowledge and behaviour as the single biggest vulnerability in the business, and one firm in five had never run specific training at all.

That is not a criticism of anybody’s staff. A convincing phishing email at half past four on a Friday will catch people who are good at their jobs and paying attention.

What training changes is not whether somebody can be fooled. It is whether they pause on the one that matters, and whether they tell you afterwards instead of hoping nobody noticed. The second one is worth more than the first, and you only get it if the training makes people feel capable rather than stupid.

What is in it

What does the training actually cover?

Eighteen modules, built into four courses of different depths so you can pick what suits the business. The shortest is under thirteen minutes in total and the longest is a little over half an hour, because a course nobody finishes teaches nobody anything.

The threats people actually meet

Phishing, and everything it turned into.

  • Phishing, and a longer module for the courses that go deeper
  • Phishing websites, and how to spot one
  • AI phishing, which is why the spelling mistakes stopped
  • QR phishing, the one nobody is looking for yet
  • Malvertising
  • Social engineering, the phone call rather than the email

The habits around them

Where the risk actually sits day to day.

  • Passwords, and why the advice changed
  • Handling sensitive information, short and extended versions
  • AI best practice, for the staff already pasting into ChatGPT
  • Insider threat
  • Mobile security, wifi and social media
  • Physical security, and today’s threats as a refresher

Worth knowing

AI phishing, QR phishing and AI best practice are the modules that matter most right now and the ones most training packages have not caught up with yet. If your staff last sat through a course that taught them to look for bad spelling and a dodgy sender address, they have been trained for the threat as it was five years ago.

Our partner providers

  • usecure
  • Cyber Security Awareness

The part that changes behaviour

How does simulated phishing work?

We send your team a realistic phishing email, roughly once a month, and record what happens. Nobody is named and shamed. The point is to find out where the business actually stands rather than where a completion certificate says it does.

Monthly, tuned to the business

Once a month suits most businesses. Some want it more often, some less, and a firm that has just had a scare usually wants it more for a while. It is set to what the business needs rather than to a default nobody chose.

Repeat clickers get more help

Somebody who clicks once has had a bad day. Somebody who clicks every time needs something different, so they get additional training automatically rather than a quiet word from their manager that never happens.

It is a measurement, not a trap

The number that matters is whether the click rate falls over a year, and whether people start reporting the suspicious ones. A team that reports a real phishing email quickly is worth more than a team that has never clicked anything.

Everything is logged

Who was enrolled, who completed what and when, what the simulation results were. It builds up on its own, which matters for the reason in the next section.

The bit people find out too late

Your cyber insurance schedule probably mentions this

Most cyber insurance policies have a schedule. The schedule lists the things you have told the insurer you are doing. Multi-factor authentication on all accounts. Regular patching. Endpoint protection. A documented incident response plan. Security awareness training.

If you have a breach, the first thing the insurer does is check whether you were actually doing those things on the day you got hit.

If you were not, the claim can be refused. Not reduced. Refused. And a lot of small businesses have never read their own schedule, because there are a lot of hats to wear when you are running a business and it went in a drawer the day it arrived.

This is why every completion, every enrolment and every simulation result is logged and kept. Not because reports are interesting, but because “we run security awareness training” is a claim, and the audit trail is the proof. Go and read your schedule. If training is on it, you need to be able to show it.

The insurance is there to catch you when something goes wrong. It only works if the safety net you described is the one you actually built.

Talk to us

Find out where your team actually stands

Tell us how many people you have and whether anyone has run training before. We will tell you which course depth fits, what a first simulated phishing round usually turns up, and what it costs.

How it is bought

Included with support, or on its own

Two ways, and they are both normal. We would rather run training for a business we do not support than watch it not happen at all.

Included on Secure+

If we look after your IT on our Secure+ level, training and simulated phishing are part of it rather than an extra line. Nothing more to buy and nothing to remember to renew.

See what the levels include

Standalone, without a support contract

Plenty of businesses have their own IT arrangement and just want this part run properly by somebody who does it every day. We set it up, run it, and send you the reporting. You do not have to move your IT to us.

Ask about standalone training

We run this on usecure, which is built for exactly this: courses, phishing simulation and the reporting behind both, for businesses of your size rather than for a bank.

Questions

The things people ask first

How long does the training take?

Between about thirteen minutes and half an hour in total, depending which of the four course depths you choose. It is broken into eighteen short modules, most of them a couple of minutes, so people can do it in gaps rather than blocking out an afternoon. Length is the main reason training does not get completed, so it is deliberately short.

How often do you send simulated phishing emails?

Typically once a month, adjusted to what the business wants. Anyone who clicks repeatedly is automatically given additional training rather than left to keep clicking.

Do we get reporting we can show our insurer?

Yes. Enrolments, completions, dates and simulation results are all logged and kept, so if your cyber insurance schedule says you run security awareness training you can evidence it rather than assert it. That matters because an insurer checks the schedule against reality before paying a claim.

Will this embarrass our staff?

Not the way we run it. Nobody is named in front of the team and the simulations are not there to catch people out. Anyone can be caught on the wrong day by something well made. What we are trying to build is a team that pauses on the odd one and tells somebody quickly when they think they have made a mistake, and you do not get that by making people feel foolish.

Does it cover AI, or is it the old phishing course?

It covers AI phishing, QR code phishing and AI best practice for staff who are already using tools like ChatGPT, alongside the traditional material. This matters, because AI is the reason phishing emails stopped having obvious spelling mistakes, and a course that still teaches people to look for bad grammar is training them for an old threat.

Do we have to be an IT support client?

No. Training is included on our Secure+ level if we support you, we run it as its own line for clients on Essential or Secure, and we run it for businesses that have their own IT arrangement entirely.

Next step

Run a first simulation and see

The first round tells you more about where your business actually stands than any policy document will. Tell us how many people you have and we will explain what it involves and what it costs.

IT support and cyber security across Wales and beyond

Based in Cardiff, working across Wales and the West.