Security awareness training

The best firewall does not help if an employee gives the attacker the password or transfers money to the wrong account. The large majority of successful attacks start with people, which makes training the cheapest security measure with the biggest effect. The workshops are run by our ethical hackers, who show real attacks as they see them in tests. We measure the effect with phishing simulations before and after training, so management sees how many clicks less vulnerable the company is.

Training programmes

Workshop for all employees

Click for more info →

Workshop for all employees

Two hours live or remote: spotting fake e-mails, passwords and MFA, safe remote work, what to do when in doubt.

Phishing simulations

Click for more info →

Phishing simulations

Fake messages tailored to your company throughout the year; whoever clicks gets a short explanation straight away instead of a reprimand.

Management training

Click for more info →

Management training

Responsibilities under NIS2, decision-making during an incident and the questions management must ask its IT.

Finance and purchasing

Click for more info →

Finance and purchasing

Fake invoice and supplier bank-account change fraud: how to recognise and verify it.

Developers and IT

Click for more info →

Developers and IT

Secure coding by OWASP, handling secrets and access, what our pen-testers find most often.

Measurement and reporting

Click for more info →

Measurement and reporting

Click rate, suspicious-mail reports and attendance by department; training evidence for ISO 27001 and NIS2.

How the programme runs

  1. 01

    Baseline measurement

    An unannounced phishing simulation shows how many employees click and how many report the suspicious mail.

  2. 02

    Workshops

    By group and role: all employees, management, finance, IT; with examples from your industry.

  3. 03

    Simulations through the year

    Every month or quarter a new simulation with a different scenario; whoever clicks gets a short explanation.

  4. 04

    Report and evidence

    Progress by department, the attendance list and the certificates you need for ISO 27001, NIS2 or your insurer.

Frequently asked questions

How much of the employees' time does it take?

The basic workshop takes two hours, a phishing simulation none, because it is part of normal mail. Whoever clicks spends a minute on the explanation. Less than half a day per employee per year in total.

Do phishing simulations offend employees?

Not if they are set up properly: management announces them in advance as part of the programme, results are anonymous by department and nobody is punished. The goal is the habit of reporting a suspicious message, not a hunt for culprits.

Is training legally required?

For entities under NIS2 and ZInfV-1 yes: they require regular training of employees and management. ISO 27001 requires awareness as a control, and cyber insurers often make it a condition.

In which languages do you run the workshops?

In Slovenian, English and Croatian, live or remote. Materials and simulations are prepared in the language your employees use, including for locations abroad.

What result can we expect?

At companies that run the programme for a year, the click rate on simulations typically falls from around a third to a few percent, while reports of suspicious mail multiply. The baseline measurement shows the exact numbers for your company.

Can the programme be combined with a penetration test?

Yes, and we recommend it: social engineering within a Red team test shows how far an attacker gets through people, and the workshops then address exactly those weak points.

Let's start with a baseline measurement

Tell us the number of employees and departments; within a week we prepare a programme and price.