Make Security Second Nature
Security Awareness Training
Security awareness works when it fits the job and sticks in the mind. We build training around the real risks your teams face, deliver it in a way people enjoy, and measure whether behaviour actually changes.
See the engagement path, 5 phasesSee the full Managed Services service index
Overview
Awareness training turns your workforce from a soft target into a strong line of defence. We start by understanding the risks and roles across your business, then build a curriculum that speaks to each group in plain language. Delivery is short, practical and human, not a wall of policy. We measure what people learn and how their behaviour shifts, then reinforce the lessons so they last. The result is a team that spots trouble early and knows what to do.
Methodology
How the Engagement Runs
Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.
5 Phases, 5 Named Handovers
Flow
Flow chart of the Awareness Trainings engagement, 5 phases in order, each one selectable. Phase 1, Needs Assessment. We look at your risks, roles and past incidents to work out what each part of your business actually needs to learn, so nobody sits through irrelevant content. Activities: Review past incidents and near misses for recurring themes; Group staff into audiences by the risks their role carries; Survey existing knowledge and confidence levels; Map training needs to your compliance obligations. Hands over Training Needs Analysis. Phase 2, Content and Curriculum. We build a curriculum in plain language, tailored to roles from the front desk to the finance team to developers, with real examples from your world. Activities: Write role-based modules for finance, developers and executives; Build scenarios from incidents in your own sector; Add secure coding and data handling content where it applies; Review the language with a non-technical reader. Hands over Role-Based Training Curriculum. Phase 3, Delivery. We deliver through short modules, live sessions or workshops, whatever fits your culture, keeping it engaging and easy to fit around real work. Activities: Run live sessions and workshops for priority teams; Publish short modules to your learning platform; Hold a tailored briefing for the executive team; Track attendance and completion across the business. Hands over Delivered Sessions and Completion Record. Phase 4, Measurement. We measure understanding and behaviour, not just completion, so you can see whether the training is actually landing. Activities: Assess knowledge before and after each module; Compare phishing report rates against training completion; Gather feedback on what people found useful; Package the evidence auditors ask for. Hands over Awareness Measurement Report. Phase 5, Reinforcement. We keep the message alive with refreshers, tips and simulations, because awareness fades without repetition. Activities: Schedule refreshers on a calendar the business can keep; Send short reminders tied to current threats; Refresh onboarding content for new joiners; Recognise teams that report threats well. Hands over Reinforcement Plan and Refresher Content. Each phase begins from the artefact the phase before it produced.
Phase 01 Needs Assessment
We look at your risks, roles and past incidents to work out what each part of your business actually needs to learn, so nobody sits through irrelevant content.
What Happens In This Phase
- Review past incidents and near misses for recurring themes
- Group staff into audiences by the risks their role carries
- Survey existing knowledge and confidence levels
- Map training needs to your compliance obligations
The Handover
Training Needs Analysis
The next phase starts from this.
Phase 01 Needs Assessment
We look at your risks, roles and past incidents to work out what each part of your business actually needs to learn, so nobody sits through irrelevant content.
What Happens In This Phase
- Review past incidents and near misses for recurring themes
- Group staff into audiences by the risks their role carries
- Survey existing knowledge and confidence levels
- Map training needs to your compliance obligations
The Handover
Training Needs Analysis
The next phase starts from this.
- 01
Needs Assessment
We look at your risks, roles and past incidents to work out what each part of your business actually needs to learn, so nobody sits through irrelevant content.
OutputTraining Needs AnalysisActivities
- Review past incidents and near misses for recurring themes
- Group staff into audiences by the risks their role carries
- Survey existing knowledge and confidence levels
- Map training needs to your compliance obligations
- 02
Content and Curriculum
We build a curriculum in plain language, tailored to roles from the front desk to the finance team to developers, with real examples from your world.
OutputRole-Based Training CurriculumActivities
- Write role-based modules for finance, developers and executives
- Build scenarios from incidents in your own sector
- Add secure coding and data handling content where it applies
- Review the language with a non-technical reader
- 03
Delivery
We deliver through short modules, live sessions or workshops, whatever fits your culture, keeping it engaging and easy to fit around real work.
OutputDelivered Sessions and Completion RecordActivities
- Run live sessions and workshops for priority teams
- Publish short modules to your learning platform
- Hold a tailored briefing for the executive team
- Track attendance and completion across the business
- 04
Measurement
We measure understanding and behaviour, not just completion, so you can see whether the training is actually landing.
OutputAwareness Measurement ReportActivities
- Assess knowledge before and after each module
- Compare phishing report rates against training completion
- Gather feedback on what people found useful
- Package the evidence auditors ask for
- 05
Reinforcement
We keep the message alive with refreshers, tips and simulations, because awareness fades without repetition.
OutputReinforcement Plan and Refresher ContentActivities
- Schedule refreshers on a calendar the business can keep
- Send short reminders tied to current threats
- Refresh onboarding content for new joiners
- Recognise teams that report threats well
Specification
What We Run, and What We Measure You Against
The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.
What Is Examined, and What it Is Measured Against
Map
Map of the Awareness Trainings scope, running left to right in three stages. Stage one, what we run, 5 tools and techniques: KnowBe4, Learning management systems, Phishing simulation platforms, Custom content production, Interactive workshop toolkits. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 4 published standards: NIST SP 800-50, NIST SP 800-16, SANS Security Awareness Maturity Model, ISO 27001 Annex A awareness controls.
What We Run
5 tools
- KnowBe4
- Learning management systems
- Phishing simulation platforms
- Custom content production
- Interactive workshop toolkits
Converges On
One Set of Proven Findings
Every issue is reproduced by hand before it is written down, and it is written down once.
Measured Against
4 standards
- NIST SP 800-50
- NIST SP 800-16
- SANSAwareness Maturity Model
- ISO 27001 Annex A awareness controls
Deliverables
What You Receive
- Role-based training curriculum
- Delivered modules, sessions or workshops
- Understanding and behaviour measurement
- Reinforcement plan and refresher content
- Programme report for leadership and auditors
Scope This Engagement
Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.
What format does the training take, and how long does each part run?
Delivery is a mix rather than one long course. Short modules go to your learning platform for people to take around their work, live sessions and workshops run for the teams carrying the most risk, and the executive team gets its own briefing pitched at decisions rather than mechanics. The mix, the running order and the length of each element are agreed during the needs assessment, because a support shift and a development team cannot absorb the same format. What we will not do is ship one long annual video for the whole company to click through, which records completion and teaches nothing. Two limits are worth naming up front: publishing modules assumes you have a learning platform we can load content into, and live sessions need protected calendar time from the teams involved. Where neither is available, delivery reduces to workshops on the dates you can actually hold.
Who should attend, and does everyone sit through the same material?
Staff are grouped into audiences by the risk their role carries, and each audience gets content built for it. During the needs assessment we sort people by what they can cause or prevent: finance approves payments and changes bank details, developers write and deploy code, executives are the targets of the most researched lures, and front-line staff handle customer data and inbound contact. Each group gets modules written for its own work, with scenarios drawn from incidents in your sector rather than a generic library. New joiners matter as much as anyone, so onboarding content is refreshed as part of the reinforcement phase instead of being left to drift. You supply the headcount, the team structure and someone who can say which roles touch sensitive data; we do not read that out of your HR system. Audiences carrying less risk get a shorter path, not a longer one.
How is the content kept relevant to Indian teams and to current lures?
Relevance comes from your own incident history and your own regulatory obligations. The needs assessment reads your past incidents and near misses for recurring themes, and the curriculum is built from scenarios in your sector rather than imported examples that mean little to an Indian finance or support team. Training needs are mapped to the compliance obligations you actually carry, which for most Indian organisations now includes the DPDP Act, so the data handling content reflects duties your staff really have rather than a foreign statute. Language is reviewed with a non-technical reader before release. The reinforcement phase then sends short reminders tied to threats current at the time, so the material does not quietly age into last year's lures. Our offices are in Kanpur and Greater Noida West, so sessions run in your working hours. What we cannot do is refresh content for a change you have not told us about.
How do you measure whether the training was retained, not just completed?
Retention is measured on three levels, and completion is the weakest of them. Knowledge is assessed before and after each module, so the report shows movement rather than a bare score with nothing to compare it against. Behaviour is read from your phishing reporting data, comparing report rates against who completed which module, which is the closest honest proxy for whether a lesson survived contact with a real inbox. Feedback is collected on what people found useful, because content that everyone passes and nobody rates is usually content that was too easy. Those three go into the Awareness Measurement Report, packaged in the form auditors ask for, so the same evidence serves your training obligation and your audit. The limit is data: behaviour measurement needs simulation or reporting figures to sit beside completion records. Without them we can show understanding, but not behaviour change.
How does this pair with your phishing simulations?
The two measure each other. Awareness training supplies the teaching, and phishing simulations supply the evidence that it took. Simulations produce click and report rates by team, and the measurement phase of this engagement sets those rates against training completion, which is what turns a completion percentage into a statement about behaviour. It works in the other direction too: when a simulation shows one audience falling for a particular pretext, that pretext becomes curriculum content and a refresher for that group rather than a general reminder to everybody. Phishing Simulations is a separate service in the same practice area, with its own scope and its own fixed price, so either can run alone. Training by itself still measures understanding, and simulations by themselves still show behaviour. A 30 to 45 minute scoping call covers both, and the written scope comes back with a timeline and a price.
Keep Moving Through Managed Services
Service 8 of 9 in this practice area
Practice Area
More in Managed Services
- Red Team AssessmentGoal-based adversary simulation across people, process and technology
- SOC as a ServiceA 24/7 security operations centre run by our analysts
- Attack Surface ManagementRecurring discovery of what you expose to the internet, and what is wrong with it
- Dark Web MonitoringAnalyst-validated monitoring for leaked credentials, documents and brand abuse
- vCISOSenior security leadership on demand, without a full-time hire
- vDPOA data protection officer as a service for the DPDP Act and beyond
- Phishing SimulationsSafe, realistic phishing tests that build lasting instincts
- Digital and Cyber ForensicsSound investigation and evidence when something has gone wrong