Security Awareness Training
Your firewall has never once clicked a bad link.
Staff awareness is required from the very first tier of SMB1001, because most incidents start with a person rather than a system. We run the training, simulate the attacks, and keep the completion records that prove it happened.
Why it matters
Required from Bronze, and it does not stop there
SMB1001 asks for cyber security awareness training for all employees from Bronze, the entry tier, and requires the campaign to include an annual review of the policies your staff are responsible for. At the top tier it goes further again, requiring you to actually exercise your incident response plan rather than just file it.
Which is reasonable, because the controls that fail in practice are rarely the technical ones. Invoice fraud, business email compromise and credential phishing all work by asking a person to do something ordinary.
What we do
Training that produces evidence, not just attendance
Ongoing awareness training
- Short, regular modules rather than one long annual session nobody remembers
- Content covering phishing, invoice fraud, passwords, physical security and safe device use
- Tracked completion per employee, with reminders that chase people so you do not have to
Phishing simulation
- Realistic simulated phishing campaigns run against your own staff
- Click and report rates tracked over time, so you can show improvement
- Targeted follow-up training for the people who need it, without naming and shaming
Policy read-and-sign
- Your cyber security policy issued to every employee, with sign-off recorded
- Annual policy review built into the training cycle, as the standard requires
- Records kept in a form you can produce on request
Incident response exercises
- Tabletop exercises that walk your team through a real scenario
- Findings written up so the plan improves rather than just gets tested
- Annual cadence, which is what the upper tiers of the standard ask for
The point
Completion records are the deliverable
Anyone can send staff a video. What certification asks for, and what a customer's assurance questionnaire asks for, is evidence: who was trained, on what, when, and what happened when they were tested. That record is the part we make sure exists, because it is the part that gets requested at the worst possible moment.
Start with a baseline phishing test
Find out how your team actually performs before you spend anything on training.