Skip to content
ISO 27001, SOC 2, the DPDP Act and manual VAPT.
Part of Managed Services7 services in this practice area

Make Security Second Nature

Security Awareness Training

Security awareness works when it fits the job and sticks in the mind. We build training around the real risks your teams face, deliver it in a way people enjoy, and measure whether behaviour actually changes.

See the engagement path, 5 phasesSee the full Managed Services service index

Overview

Awareness training turns your workforce from a soft target into a strong line of defence. We start by understanding the risks and roles across your business, then build a curriculum that speaks to each group in plain language. Delivery is short, practical and human, not a wall of policy. We measure what people learn and how their behaviour shifts, then reinforce the lessons so they last. The result is a team that spots trouble early and knows what to do.

Methodology

How the Engagement Runs

Every phase has a named output, so you always know what is being worked on and what lands on your side of the table.

The Engagement, End to End

5 Phases, 5 Named Handovers

Flow

Flow chart of the Awareness Trainings engagement, 5 phases in order, each one selectable. Phase 1, Needs Assessment. We look at your risks, roles and past incidents to work out what each part of your business actually needs to learn, so nobody sits through irrelevant content. Activities: Review past incidents and near misses for recurring themes; Group staff into audiences by the risks their role carries; Survey existing knowledge and confidence levels; Map training needs to your compliance obligations. Hands over Training Needs Analysis. Phase 2, Content and Curriculum. We build a curriculum in plain language, tailored to roles from the front desk to the finance team to developers, with real examples from your world. Activities: Write role-based modules for finance, developers and executives; Build scenarios from incidents in your own sector; Add secure coding and data handling content where it applies; Review the language with a non-technical reader. Hands over Role-Based Training Curriculum. Phase 3, Delivery. We deliver through short modules, live sessions or workshops, whatever fits your culture, keeping it engaging and easy to fit around real work. Activities: Run live sessions and workshops for priority teams; Publish short modules to your learning platform; Hold a tailored briefing for the executive team; Track attendance and completion across the business. Hands over Delivered Sessions and Completion Record. Phase 4, Measurement. We measure understanding and behaviour, not just completion, so you can see whether the training is actually landing. Activities: Assess knowledge before and after each module; Compare phishing report rates against training completion; Gather feedback on what people found useful; Package the evidence auditors ask for. Hands over Awareness Measurement Report. Phase 5, Reinforcement. We keep the message alive with refreshers, tips and simulations, because awareness fades without repetition. Activities: Schedule refreshers on a calendar the business can keep; Send short reminders tied to current threats; Refresh onboarding content for new joiners; Recognise teams that report threats well. Hands over Reinforcement Plan and Refresher Content. Each phase begins from the artefact the phase before it produced.

Phase 01 Needs Assessment

We look at your risks, roles and past incidents to work out what each part of your business actually needs to learn, so nobody sits through irrelevant content.

What Happens In This Phase

  • Review past incidents and near misses for recurring themes
  • Group staff into audiences by the risks their role carries
  • Survey existing knowledge and confidence levels
  • Map training needs to your compliance obligations

The Handover

Training Needs Analysis

The next phase starts from this.

Read the handover cards on their own and you have the paper trail. Select a phase to see what happens inside it.
  1. 01

    Needs Assessment

    We look at your risks, roles and past incidents to work out what each part of your business actually needs to learn, so nobody sits through irrelevant content.

    OutputTraining Needs Analysis

    Activities

    • Review past incidents and near misses for recurring themes
    • Group staff into audiences by the risks their role carries
    • Survey existing knowledge and confidence levels
    • Map training needs to your compliance obligations
  2. 02

    Content and Curriculum

    We build a curriculum in plain language, tailored to roles from the front desk to the finance team to developers, with real examples from your world.

    OutputRole-Based Training Curriculum

    Activities

    • Write role-based modules for finance, developers and executives
    • Build scenarios from incidents in your own sector
    • Add secure coding and data handling content where it applies
    • Review the language with a non-technical reader
  3. 03

    Delivery

    We deliver through short modules, live sessions or workshops, whatever fits your culture, keeping it engaging and easy to fit around real work.

    OutputDelivered Sessions and Completion Record

    Activities

    • Run live sessions and workshops for priority teams
    • Publish short modules to your learning platform
    • Hold a tailored briefing for the executive team
    • Track attendance and completion across the business
  4. 04

    Measurement

    We measure understanding and behaviour, not just completion, so you can see whether the training is actually landing.

    OutputAwareness Measurement Report

    Activities

    • Assess knowledge before and after each module
    • Compare phishing report rates against training completion
    • Gather feedback on what people found useful
    • Package the evidence auditors ask for
  5. 05

    Reinforcement

    We keep the message alive with refreshers, tips and simulations, because awareness fades without repetition.

    OutputReinforcement Plan and Refresher Content

    Activities

    • Schedule refreshers on a calendar the business can keep
    • Send short reminders tied to current threats
    • Refresh onboarding content for new joiners
    • Recognise teams that report threats well

Specification

What We Run, and What We Measure You Against

The tooling our engineers use on this work, and the published standards the findings and evidence are mapped to.

Scope

What Is Examined, and What it Is Measured Against

Map

Map of the Awareness Trainings scope, running left to right in three stages. Stage one, what we run, 5 tools and techniques: KnowBe4, Learning management systems, Phishing simulation platforms, Custom content production, Interactive workshop toolkits. Stage two, findings from all of it are proven by hand and written up once. Stage three, measured against 4 published standards: NIST SP 800-50, NIST SP 800-16, SANS Security Awareness Maturity Model, ISO 27001 Annex A awareness controls.

What We Run

5 tools

  • KnowBe4
  • Learning management systems
  • Phishing simulation platforms
  • Custom content production
  • Interactive workshop toolkits

Converges On

One Set of Proven Findings

Every issue is reproduced by hand before it is written down, and it is written down once.

Measured Against

4 standards

  • NIST SP 800-50
  • NIST SP 800-16
  • SANSAwareness Maturity Model
  • ISO 27001 Annex A awareness controls
One pass of testing and analysis, one set of findings, then that single set is graded against every standard on the right. You are not paying for the same work once per framework.

Deliverables

What You Receive

  • Role-based training curriculum
  • Delivered modules, sessions or workshops
  • Understanding and behaviour measurement
  • Reinforcement plan and refresher content
  • Programme report for leadership and auditors

Scope This Engagement

Tell us about your environment, your timelines and any audit dates you are working to. We come back with scope, effort and a start date.

Questions

What Clients Ask Us

Something here not covered? Ask Us Directly.

Is this just an annual video everyone clicks through?

No. We build role-based content people find relevant, deliver it in short and engaging formats, and reinforce it through the year so the lessons actually change behaviour.

Can you tailor training to specific teams?

Yes. Finance, developers, executives and front-line staff each face different risks, so we tailor the content and examples to what each group actually deals with.

How do we prove the training worked for an audit?

We measure completion, understanding and behaviour change, and report it in a form auditors accept, so you can evidence your awareness controls with confidence.

Keep Moving Through Managed Services

Service 6 of 7 in this practice area