Capability & Resourcing

Security Awareness & Phishing Simulation

Behaviour change, measured — not an annual video nobody watches.

The situation

Awareness programmes fail when they are compliance theatre.

We design campaigns around the behaviours that actually reduce incidents in that specific organisation, run realistic phishing and social engineering simulation with a coaching rather than punitive response, target high-risk roles specifically, and measure reporting rates as the primary metric — because a workforce that reports quickly is worth more than one that never clicks.

What the client receives

Schedule of deliverables

  1. 01Awareness programme design and annual campaign calendar
  2. 02Phishing, smishing and vishing simulation with coaching follow-up
  3. 03Role-targeted modules for finance, HR, developers and executives
  4. 04Executive and high-value-target briefings
  5. 05Behavioural metrics and reporting-rate tracking
  6. 06NIS2 Art. 20(2) and ISO 27001 A.6.3 training evidence

Frameworks and standards

Assessment is carried out against named references, so a conclusion can be traced back to the requirement it was measured against.

  • NIS2 Art. 20(2)
  • ISO/IEC 27001 A.6.3
  • ENISA awareness guidance

Discuss this engagement

Tell us about the behaviours you want changed and the population in scope and we will set out the scope, the method and the reporting format.

Contact us