All posts

Your People Are Your Strongest Defense

guideawareness trainingphishing

Bayloz campaign poster for Security Awareness Training: a cluster of surveillance cameras with eyes on them.

Every organization that has had an incident can name the moment a person was involved. Someone clicked, someone approved a payment, someone let a contractor in behind them.

The usual response is to treat the person as the failure. It is the wrong response, and it is expensive, because the next person to notice something odd now has a very good reason to say nothing.

Why the annual module does not work

The standard approach is a slide deck once a year, a short quiz, and a completion percentage for the audit.

It fails for a simple reason. Recognizing a phishing email is a skill, not a fact, and skills do not transfer from a slide. Worse, the examples used are almost always obvious: the misspelled bank, the foreign prince. Nobody in your organization is going to fall for those. They are going to fall for an email that references a real project, arrives on a Thursday afternoon during a real deadline, and appears to come from someone they report to.

Realistic pressure is the part the module leaves out, and it is the only part that matters.

What actually changes behavior

  • Recent, real examples. Techniques from the last few months, not a generic deck. Attackers iterate constantly, and training that lags by a year teaches last year's tells.
  • Your context. Your tools, your suppliers, your invoice process, your approval chain. Generic training produces generic vigilance.
  • Practice, not description. People need to look at something ambiguous and decide, then find out whether they were right. There is a live example of exactly this on our awareness section, where you find the five red flags in a phishing email yourself.
  • A route to report that costs nothing. One obvious channel, no form, no blame, and a thank you for every report including the false alarms. A team that reports ten harmless emails to catch one real one is working correctly.
  • Repetition in small doses. Fifteen minutes a quarter beats three hours a year, every time.

What we cover

Phishing and its more targeted relatives, business email compromise and invoice fraud, voice and message-based social engineering including the AI-assisted versions now in common use, credential hygiene and multi-factor authentication that actually resists interception, physical and in-person pretexting, and what to do in the first ten minutes after someone realizes they clicked.

That last part gets skipped almost everywhere, and it is the highest-value fifteen minutes of the session. The difference between an incident and a non-event is usually how fast somebody speaks up.

How we run it

Sessions are live, in small groups, and built around your organization rather than a stock curriculum. We can run a simulated phishing campaign first, so the training addresses what your team actually does rather than what we assume.

On simulations, one condition. They are a diagnostic, not a trap. We do not publish names, we do not use them for performance management, and we do not run the cruel ones, the fake bonus or the fake redundancy notice. Those produce a great click rate for a report and a workforce that will never trust a security message again.

Measure the right number

Click rate is the number everyone reports, and on its own it is close to meaningless.

The number that predicts how an incident goes is the report rate, and specifically how fast the first report arrives. An organization where somebody flags a suspicious email within four minutes survives things that flatten an organization where nobody says anything for two days.

Train your team. Tell us your size and what your team actually handles, and we will put together a session that fits.