Everything in the program, and when it happens.

Awareness lapses in the gaps. Every component below exists to close one of them, on a cadence you can point at during an audit.

The five components

Annual security awareness training

A full curriculum covering current threat vectors, password hygiene, credential security, and safe use of AI tools at work. Every employee completes it once a year, so the baseline never goes stale.

Quarterly phishing simulations

Controlled, realistic phishing and social engineering campaigns four times a year. Each round measures who clicks, who reports, and how fast — and feeds directly into the next round of training.

New hire onboarding training

Cybersecurity orientation built into account provisioning. Every incoming employee finishes the fundamentals before their first login, rather than waiting for the next scheduled training cycle.

Monthly tips and compliance reporting

A short, actionable tip lands every month to keep security top of mind between formal trainings. At year end it rolls up into a compliance report and certificate suitable for a cyber insurance audit.

Executive summaries and Secure Score reviews

Plain-language updates for ownership: dark web monitoring findings and Microsoft Secure Score posture, reviewed monthly with a fuller executive summary each quarter.

Phishing simulations

A click becomes a lesson, not a silent failure.

Every simulated link leads to a training page instead of a real credential form. No data is collected and nothing on the account is affected — but the moment gets used.

What we teach them to check

A sender domain that does not quite match the real one
Urgency, deadlines, or threats pushing you to act fast
Requests to verify, confirm, or update sensitive information
Generic greetings instead of your actual name
Link text that does not match where the link actually leads

Six pretexts, rotated through the year

Each quarterly campaign draws from a set of six pretexts across the difficulty range: an executive gift-card request, an HR payroll direct-deposit redirect, a vendor invoice redirect, a VPN credential harvest, a vishing call during onboarding, and a holiday shipping scam.

The mix is what determines whether a simulation measures baseline awareness or catches your most careful employees. Rotating it is the point — a repeated pretext measures memory, not judgement.

See one of these in action first.

Ninety seconds, no signup — the same simulation we run inside real businesses.

Request a proposal

Tell us your headcount and we will match a tier to it.