Capability & Resourcing
Security Awareness & Phishing Simulation
Behaviour change, measured — not an annual video nobody watches.
The situation
What the client receives
Schedule of deliverables
- Awareness programme design and annual campaign calendar
- Phishing, smishing and vishing simulation with coaching follow-up
- Role-targeted modules for finance, HR, developers and executives
- Executive and high-value-target briefings
- Behavioural metrics and reporting-rate tracking
- NIS2 Art. 20(2) and ISO 27001 A.6.3 training evidence
Frameworks and standards
Assessment is carried out against named references, so a conclusion can be traced back to the requirement it was measured against.
- NIS2 Art. 20(2)
- ISO/IEC 27001 A.6.3
- ENISA awareness guidance
Related services
Discuss this engagement
Tell us about the behaviours you want changed and the population in scope and we will set out the scope, the method and the reporting format.