Crisis-ready in 30 days
A crisis unit that has met, rehearsed and knows who calls the regulator.
- Duration
- 4 weeks
- Price
- €8,000 to €15,000
- excl. VAT, indicative
AI & Cybersecurity
Deploy AI you can defend, and defend with AI.
Legal

Services
Every employee a strong link, from the boardroom to the build pipeline.
NIS2 makes directors personally accountable for supervising cybersecurity. Most of them have never been told, in their own terms, what that means. Meanwhile the developers shipping your product learned security from a linter, and the person who clicks the link has never seen one that looked like this.
We teach each audience what applies to it. Boards get two hours on their duties, the risk picture and the questions to ask. Developers get hands-on enablement in their own stack. Everyone else gets a programme that is short, regular and measured — with phishing simulations that report a trend rather than a shaming list.
And once a year, the whole company runs a crisis exercise: a realistic scenario, the real decision-makers, a clock. It is the fastest way we know to find out whether the plan works.
Courses for the people who run security, governance, continuity and investigations — one to two days each, on your own cases.
Two days for the people who run security without having been trained for it: risk, controls, incidents, vendors, budgets and how to talk to the board.
A working day on the texts that apply to you — NIS2, DORA, GDPR, ISO 27001 — what each asks for, who owns it, and how one control can answer several.
How to write a continuity plan people will actually follow, how to test it, and what ISO 22301 and DORA expect of the exercise record.
For IT and security staff: how an intrusion looks in the logs, how to preserve evidence, how to contain without destroying it, and when to call for help.
A focused session for directors on what NIS2 and DORA make them personally accountable for, what to ask, and what a good answer sounds like.
Training built on your own codebase and findings, plus a security champion network that gives teams someone to ask before the review rather than after it.
Escape rooms, card games, quizzes, workshops, simulations and phishing campaigns: formats people remember, measured so you can tell.
A team locked in a room with a breach to solve: clues in phishing mails, passwords, badges and a laptop nobody locked. Ninety minutes that people remember for a year.
A card game played in teams over an hour, where every card is a real attack or a real defence. It works because nobody notices they are being trained.
Short, frequent and a little competitive: a quiz your staff take on their phone, scored by team, that tells you which topics have landed and which have not.
Two hours with one team at a time, on the attacks that actually target their job — finance, HR, sales, support — with the real mails we have seen.
A realistic, announced-to-nobody-but-the-sponsor simulation of a phishing-to-ransomware chain, stopped before damage, to see what your people and your tools actually do.
Simulated phishing every month, difficulty rising, reported as a trend by department rather than a list of names, with a thirty-second lesson for anyone who clicks.
The whole year planned: monthly themes, the formats that suit each audience, the phishing curve, the measures, and the report that shows the board the culture is moving.
Role-based training that changes behaviour, including the management body modules NIS2 requires directors to complete, and phishing simulation with coaching rather than blame.
Crisis exercises for the board, multi-team exercises for a company or a sector, and capture-the-flag events for the engineers.
A tabletop or simulation for the crisis unit, with management and communications in the room. NIS2 and DORA both expect this to have happened, and to be documented.
A multi-team exercise designed, run and umpired for you: injects, a control cell, observers with scorecards and a report that names what to fix — for one company or a whole sector.
A capture-the-flag event for your engineers, your students or your sector: challenges written for the level, a platform, a scoreboard and prizes — the fastest way to find and keep talent.
A crisis unit that has met, rehearsed and knows who calls the regulator.
A year-round programme rather than an annual module: short role-based content, phishing simulation with coaching, and reporting that holds up as NIS2 evidence.
A two-hour executive session on NIS2 duties and the risk picture, prepared for your company, is usually where it begins.