Security awareness training

The best firewall does not help if an employee gives the attacker the password or transfers money to the wrong account. The large majority of successful attacks start with people, which makes training the cheapest security measure with the biggest effect. The workshops are run by our ethical hackers, who show real attacks as they see them in tests. We measure the effect with phishing simulations before and after training, so management sees how many clicks less vulnerable the company is.

Training programmes

How the programme runs

  1. 01

    Baseline measurement

    An unannounced phishing simulation shows how many employees click and how many report the suspicious mail.

  2. 02

    Workshops

    By group and role: all employees, management, finance, IT; with examples from your industry.

  3. 03

    Simulations through the year

    Every month or quarter a new simulation with a different scenario; whoever clicks gets a short explanation.

  4. 04

    Report and evidence

    Progress by department, the attendance list and the certificates you need for ISO 27001, NIS2 or your insurer.

Frequently asked questions

How much of the employees' time does it take?

The basic workshop takes two hours, a phishing simulation none, because it is part of normal mail. Whoever clicks spends a minute on the explanation. Less than half a day per employee per year in total.

Do phishing simulations offend employees?

Not if they are set up properly: management announces them in advance as part of the programme, results are anonymous by department and nobody is punished. The goal is the habit of reporting a suspicious message, not a hunt for culprits.

Is training legally required?

For entities under NIS2 and ZInfV-1 yes: they require regular training of employees and management. ISO 27001 requires awareness as a control, and cyber insurers often make it a condition.

In which languages do you run the workshops?

In Slovenian, English and Croatian, live or remote. Materials and simulations are prepared in the language your employees use, including for locations abroad.

What result can we expect?

At companies that run the programme for a year, the click rate on simulations typically falls from around a third to a few percent, while reports of suspicious mail multiply. The baseline measurement shows the exact numbers for your company.

Can the programme be combined with a penetration test?

Yes, and we recommend it: social engineering within a Red team test shows how far an attacker gets through people, and the workshops then address exactly those weak points.

Let's start with a baseline measurement

Tell us the number of employees and departments; within a week we prepare a programme and price.