Skip to content
A cybersecurity training class: people at workstations, one reading through a printed exercise.

Services

Training & Awareness

Every employee a strong link, from the boardroom to the build pipeline.

Every employee a strong link, from the boardroom to the build pipeline.

NIS2 makes directors personally accountable for supervising cybersecurity. Most of them have never been told, in their own terms, what that means. Meanwhile the developers shipping your product learned security from a linter, and the person who clicks the link has never seen one that looked like this.

We teach each audience what applies to it. Boards get two hours on their duties, the risk picture and the questions to ask. Developers get hands-on enablement in their own stack. Everyone else gets a programme that is short, regular and measured — with phishing simulations that report a trend rather than a shaming list.

And once a year, the whole company runs a crisis exercise: a realistic scenario, the real decision-makers, a clock. It is the fastest way we know to find out whether the plan works.

Training & Awareness

Training and awareness

Boards, developers and everyone else, taught what applies to them and tested on it.

  • Awareness and trainingTypical duration: Recurring

    Role-based training that changes behaviour, including the management body modules NIS2 requires directors to complete, and phishing simulation with coaching rather than blame.

    You receive

    • Annual awareness plan by population
    • Executive and board modules
    • Phishing simulation campaigns
    • Participation and progress reporting
  • Board and executive trainingTypical duration: 2–4 hours

    A focused session for directors on what NIS2 and DORA make them personally accountable for, what to ask, and what a good answer sounds like.

    You receive

    • Tailored session for the management body
    • Director obligation briefing note
    • Question set for oversight
    • Attendance record for the compliance file
  • Developer security enablementTypical duration: Recurring

    Training built on your own codebase and findings, plus a security champion network that gives teams someone to ask before the review rather than after it.

    You receive

    • Role-based training sessions
    • Security champion programme
    • Secure coding guidelines for your stack
    • Progress measurement
  • Executive and business enablementTypical duration: 4–16 hours

    Working sessions that leave leaders able to judge an AI proposal: what these systems do well, where they fail, and what the regulation asks of them.

    You receive

    • Executive briefing session
    • Business team workshops
    • Use-case identification output
    • Internal communication material
  • Cyber crisis exerciseTypical duration: 3–6 days

    A tabletop or simulation for the crisis unit, with management and communications in the room. NIS2 and DORA both expect this to have happened, and to be documented.

    You receive

    • Tailored scenario and injects
    • Facilitated exercise session
    • Observation report with findings
    • Improvement plan and evidence pack

Continuous awareness

A year-round programme rather than an annual module: short role-based content, phishing simulation with coaching, and reporting that holds up as NIS2 evidence.

What is included

  • Annual plan by population
  • Phishing simulation campaigns
  • Short role-based modules
  • Executive and board sessions
  • Participation evidence for audits
Training

Discuss this service — Continuous awareness

Start with the board

A two-hour executive session on NIS2 duties and the risk picture, prepared for your company, is usually where it begins.