This is not a compliance tick box. It is a simple program that helps staff spot risky emails, slow down before they click, and feel more comfortable reporting something that looks odd.
Most clients start with a three to six month run and then roll it into their ongoing security care. We can keep it light and practical so staff do not switch off.
The aim is not to flood staff with material. It is to build a steady habit of noticing red flags, asking for help and reporting issues early.
Short sessions or micro modules that cover real attack examples, common tricks and what staff should do if they click on something they regret.
Simple, realistic test emails sent at agreed times so people can practice spotting bad messages in a safe way.
Follow up guidance for anyone who clicks during a test, focused on what to look for next time, not on shaming them.
Periodic summary with results, trends and a few points leaders can discuss at management or board level.
Where possible, we align training to the security tools you already use, such as reporting buttons in Outlook or Microsoft 365 defensive features.
We can support a small group of internal champions so they know how to answer basic staff questions and encourage better habits.
We keep the structure clear so staff know what to expect and leaders can see how the program fits in with other work.
We review your current risk, recent incidents and any past awareness efforts. Together we pick a reasonable starting point and schedule.
We roll out short material and send test emails at the agreed frequency. Staff get simple guidance and managers get light touch updates.
Every few months we review results with you, adjust the difficulty of tests and update examples to match current attack trends.
A few of the things leaders usually ask before they roll this out for their staff.
We are clear that this is a practice environment. The tone is supportive and we avoid gotcha tests. The goal is to build better habits, not to catch people out.
That depends on your size and risk, but a common pattern is one or two test campaigns per month, with a mix of easy and moderate examples.
Yes. If you have real phishing or fraud attempts that are safe to share, we can build those into awareness material so staff see examples from your world, not just generic samples.
No. While many clients are on Microsoft 365, we can support other email platforms as well. The core ideas about spotting risk carry across systems.