Skip to content
A cybersecurity training class: people at workstations, one reading through a printed exercise.

Services

Training & Awareness

Every employee a strong link, from the boardroom to the build pipeline.

Every employee a strong link, from the boardroom to the build pipeline.

NIS2 makes directors personally accountable for supervising cybersecurity. Most of them have never been told, in their own terms, what that means. Meanwhile the developers shipping your product learned security from a linter, and the person who clicks the link has never seen one that looked like this.

We teach each audience what applies to it. Boards get two hours on their duties, the risk picture and the questions to ask. Developers get hands-on enablement in their own stack. Everyone else gets a programme that is short, regular and measured — with phishing simulations that report a trend rather than a shaming list.

And once a year, the whole company runs a crisis exercise: a realistic scenario, the real decision-makers, a clock. It is the fastest way we know to find out whether the plan works.

Training & Awareness

Training

Courses for the people who run security, governance, continuity and investigations — one to two days each, on your own cases.

  • Security management trainingTypical duration: 2–3 days

    Two days for the people who run security without having been trained for it: risk, controls, incidents, vendors, budgets and how to talk to the board.

    You receive

    • Two-day course with your own cases
    • Course material and templates
    • Certificate of completion
  • Governance, risk and compliance trainingTypical duration: 1–2 days

    A working day on the texts that apply to you — NIS2, DORA, GDPR, ISO 27001 — what each asks for, who owns it, and how one control can answer several.

    You receive

    • One-day course per audience
    • Obligation map for your company
    • Quiz and attendance record
  • Business continuity and resilience trainingTypical duration: 1–2 days

    How to write a continuity plan people will actually follow, how to test it, and what ISO 22301 and DORA expect of the exercise record.

    You receive

    • One-day course with a live tabletop
    • Plan and exercise templates
    • Attendance record
  • Cybersecurity and investigation trainingTypical duration: 2–3 days

    For IT and security staff: how an intrusion looks in the logs, how to preserve evidence, how to contain without destroying it, and when to call for help.

    You receive

    • Two-day hands-on course on a lab estate
    • Evidence-handling checklist
    • Certificate of completion
  • Board and executive trainingTypical duration: 2–4 hours

    A focused session for directors on what NIS2 and DORA make them personally accountable for, what to ask, and what a good answer sounds like.

    You receive

    • Tailored session for the management body
    • Director obligation briefing note
    • Question set for oversight
    • Attendance record for the compliance file
  • Developer security enablementTypical duration: Recurring

    Training built on your own codebase and findings, plus a security champion network that gives teams someone to ask before the review rather than after it.

    You receive

    • Role-based training sessions
    • Security champion programme
    • Secure coding guidelines for your stack
    • Progress measurement

Awareness

Escape rooms, card games, quizzes, workshops, simulations and phishing campaigns: formats people remember, measured so you can tell.

  • Cyber escape roomTypical duration: 2–4 hours

    A team locked in a room with a breach to solve: clues in phishing mails, passwords, badges and a laptop nobody locked. Ninety minutes that people remember for a year.

    You receive

    • Facilitated session for up to twelve
    • Scenario adapted to your company
    • Debrief with the lessons made explicit
  • Cyber card gameTypical duration: 1–2 hours

    A card game played in teams over an hour, where every card is a real attack or a real defence. It works because nobody notices they are being trained.

    You receive

    • Game sets for your teams
    • Facilitator guide
    • Session debrief
  • Security quizTypical duration: 1–2 hours

    Short, frequent and a little competitive: a quiz your staff take on their phone, scored by team, that tells you which topics have landed and which have not.

    You receive

    • Question bank tuned to your rules
    • Team leaderboard
    • Topic-level comprehension figures
  • Awareness workshopsTypical duration: 2–3 hours

    Two hours with one team at a time, on the attacks that actually target their job — finance, HR, sales, support — with the real mails we have seen.

    You receive

    • Workshop per team, on their own cases
    • Team-specific rules card
    • Attendance and feedback record
  • Attack simulationTypical duration: 3–6 days

    A realistic, announced-to-nobody-but-the-sponsor simulation of a phishing-to-ransomware chain, stopped before damage, to see what your people and your tools actually do.

    You receive

    • Scenario and kill-switch agreed with the sponsor
    • Timeline of what was detected and when
    • Findings for people, process and tooling
  • Phishing campaignsTypical duration: Recurring

    Simulated phishing every month, difficulty rising, reported as a trend by department rather than a list of names, with a thirty-second lesson for anyone who clicks.

    You receive

    • Monthly campaigns on a rising curve
    • Trend report by department
    • Just-in-time lesson on click
  • Awareness programmeTypical duration: Recurring

    The whole year planned: monthly themes, the formats that suit each audience, the phishing curve, the measures, and the report that shows the board the culture is moving.

    You receive

    • Twelve-month programme calendar
    • Content and campaigns delivered monthly
    • Quarterly culture report
  • Awareness and trainingTypical duration: Recurring

    Role-based training that changes behaviour, including the management body modules NIS2 requires directors to complete, and phishing simulation with coaching rather than blame.

    You receive

    • Annual awareness plan by population
    • Executive and board modules
    • Phishing simulation campaigns
    • Participation and progress reporting

Cyber exercises and competitions

Crisis exercises for the board, multi-team exercises for a company or a sector, and capture-the-flag events for the engineers.

  • Cyber crisis exerciseTypical duration: 3–6 days

    A tabletop or simulation for the crisis unit, with management and communications in the room. NIS2 and DORA both expect this to have happened, and to be documented.

    You receive

    • Tailored scenario and injects
    • Facilitated exercise session
    • Observation report with findings
    • Improvement plan and evidence pack
  • Cyber exercise design and managementTypical duration: 3–6 weeks

    A multi-team exercise designed, run and umpired for you: injects, a control cell, observers with scorecards and a report that names what to fix — for one company or a whole sector.

    You receive

    • Exercise design with injects and objectives
    • Facilitation and control cell on the day
    • After-action report with improvement plan
  • CTF competition organisationTypical duration: 4–8 weeks

    A capture-the-flag event for your engineers, your students or your sector: challenges written for the level, a platform, a scoreboard and prizes — the fastest way to find and keep talent.

    You receive

    • Challenge set written for the audience
    • Platform, scoring and event day run
    • Results and talent report

Continuous awareness

A year-round programme rather than an annual module: short role-based content, phishing simulation with coaching, and reporting that holds up as NIS2 evidence.

What is included

  • Annual plan by population
  • Phishing simulation campaigns
  • Short role-based modules
  • Executive and board sessions
  • Participation evidence for audits
Training

Discuss this service — Continuous awareness

Start with the board

A two-hour executive session on NIS2 duties and the risk picture, prepared for your company, is usually where it begins.