Cybersecurity

Cybersecurity awareness training

Most attacks still need a person to click, open or approve something. We run security awareness training that fits your organization: short lessons, realistic phishing simulations and role-based sessions, with reporting that shows whether behaviour is actually changing.

Who this service is for

A good fit if

  • Staff have fallen for phishing or invoice fraud attempts, or nearly did.
  • Your cyber insurer, clients or regulator expect regular security training.
  • Training today is a once-a-year video that nobody remembers.
  • You handle personal, health or financial information and want staff to treat it carefully.
  • You want finance, executives and IT administrators to get training that matches their specific risks.

Another approach may suit you better if

  • You want a one-off lecture with no follow-up. Behaviour changes with repetition, not a single session.
  • You intend to use simulation results to discipline staff. We design programs around learning and reporting, and we will advise against punitive use.

What this service is

Security awareness training teaches staff to recognize common attacks, such as phishing, fake invoices, impersonated executives and malicious attachments, and to report them quickly. It also covers everyday habits: strong passwords and MFA, careful handling of personal information, safe remote work, and what to do after a mistake.

We deliver it as a program, not an event. Short lessons, regular phishing simulations and a few live sessions for high-risk roles work better than a single annual course. New staff receive a short onboarding module in their first weeks, before they have learned which messages look normal.

Why training matters now

Security specialists are hard to hire and many organizations do not have one. Upskilling the people you already have is one of the most practical ways to close that gap. Every staff member who pauses before clicking, checks a payment request by phone, or reports a strange email becomes part of your defence.

Training also supports your other obligations. PIPEDA expects organizations to protect personal information with appropriate safeguards, which include making staff aware of the importance of confidentiality. Cyber insurers and many client contracts now ask whether staff are trained regularly.

What staff learn

  • How to spot phishing, including messages that look like they come from colleagues, suppliers or Microsoft.
  • How invoice and payment fraud works, and why banking changes must be verified by phone using a known number.
  • Why MFA prompts they did not expect should be refused and reported.
  • How to handle personal and confidential information, including in email, shared drives and on paper.
  • Safe habits for remote and hybrid work, public Wi-Fi and personal devices.
  • What to do after a mistake: report it immediately, without fear of blame.

Role-based sessions

Some roles face targeted attacks and need more than the standard lessons:

  • Finance and accounts payable: invoice fraud, supplier impersonation and payment verification.
  • Executives and assistants: impersonation, urgent requests and gift card scams.
  • IT administrators: privileged access, MFA fatigue attacks and helpdesk social engineering.
  • Staff handling health or client records: privacy obligations and safe sharing.

Measuring whether it works

Completion rates alone say little about behaviour. We track a few measures that do:

  • Reporting rate: how many staff report a simulated phish. A rising reporting rate is the clearest sign the program is working.
  • Click rate over time: whether fewer people click, especially on harder scenarios.
  • Repeat clicks: people who need extra, private support.
  • Time to first report: how quickly someone raises the alarm, which matters most in a real attack.

Results are shared with leadership as trends by team, and individual results are handled with the discretion agreed at the start.

How it connects to the rest of your security

Training works best alongside technical controls. Email security blocks many attacks before they reach inboxes, and EDR catches what gets through. Training covers the gap in between. For a broader view, see our cybersecurity services.

What is included

The exact list is agreed in writing for each project. These are the usual deliverables and the usual boundaries.

Typical deliverables

  • A baseline phishing simulation and a short knowledge survey.
  • A training plan covering onboarding, regular short lessons and annual refreshers.
  • A training platform selected and configured, or your existing platform set up properly.
  • Phishing simulations at an agreed frequency, with realistic but fair scenarios.
  • Role-based sessions for finance (payment and invoice fraud), leaders (impersonation) and administrators (privileged access).
  • A simple, well-publicized way for staff to report suspicious messages.
  • Short written guidance on your policies, such as passwords, MFA, data handling and remote work.
  • Progress reports showing completion rates, reporting rates and repeat clicks.

Not included unless agreed separately

  • Training platform licences, billed separately or bought directly by you.
  • HR decisions or disciplinary processes.
  • Legal training on your privacy obligations, which should come from legal counsel.
  • Custom video production, unless agreed.

What we will need from you

Most delays in this kind of work come from access and decisions, not from the technical build. Knowing these early keeps the project predictable.

  • A current staff list with departments and roles.
  • Approval from leadership and HR for the simulation program before it starts.
  • Help from your email administrator to allow simulations through filters.
  • A named contact who receives reports and helps set priorities.
Delivery

How the work is delivered

Each stage ends with something you can review before the next one starts.

  1. Baseline

    Run a first phishing simulation and a short survey, and review past incidents and near misses.

    Output: Baseline results and priority topics.

  2. Plan

    Agree topics, frequency, roles and how results will be shared, with leadership and HR involved.

    Output: Training plan and communication to staff.

  3. Launch

    Configure the platform, enrol staff, publish the reporting button or address, and start the first lessons.

    Output: Live program and staff guidance.

  4. Simulate and teach

    Run regular simulations, give immediate short lessons when someone clicks, and hold role-based sessions.

    Output: Simulation results and session records.

  5. Review

    Report progress, adjust topics to new threats and your results, and brief leadership.

    Output: Progress reports and an updated plan.

Testing and handover

  • Simulations are approved in advance and never impersonate sensitive topics such as layoffs or medical results.
  • Every simulation click leads to a short, respectful lesson, not public blame.
  • Staff know exactly how to report a suspicious message, and reports are acknowledged.
  • Results are reported by team and trend, protecting individual privacy where agreed.
  • Training records are kept, so you can show insurers, clients or auditors what was delivered.

What affects the cost

We do not publish package prices. Each estimate is based on an agreed scope, in Canadian dollars, with taxes shown separately. These are the things that move the number most:

  • The number of staff enrolled.
  • The training platform and licence tier.
  • The number of role-based and live sessions.
  • Language needs, for example English and French content.
  • Reporting and record-keeping requirements.

Questions buyers usually ask

How often should we run phishing simulations?

Monthly or quarterly works for most organizations. More frequent, lower-stakes simulations tend to build habits better than one large test a year. We agree the frequency with you.

Can training be delivered in French?

Where staff need French-language material, we choose platform content that is available in French and confirm it before rollout.

Do we need a separate training platform?

Not always. Some Microsoft 365 plans include attack simulation training, and dedicated platforms offer larger content libraries. We compare what you have with what you need.

Will staff feel tricked?

Not if the program is introduced openly and handled respectfully. We tell staff simulations will happen, focus on reporting rather than blame, and share results at team level.

Does training satisfy our insurer or regulator?

It often forms part of what they expect, and we keep records you can show them. Whether it meets a specific requirement depends on the wording of your policy or rule, which you should confirm.

Would your team spot a convincing scam?

Tell us how many people you have and what training exists today. We will reply to arrange a conversation about a program that fits.