Skip to content
../services/security

ARSENAL 03

Cybersecurity training

The most effective firewall is still an employee who spots a trap.

Verizon’s annual data breach investigations report places the human element in the large majority of incidents. We train your teams with simulation campaigns, short workshops and concrete access rules. The approach is measured before and after and, above all, never punitive — otherwise nobody reports anything ever again.

Who it is for

  • Companies whose employees handle external email all day
  • Organisations that have already faced an attempted payment fraud
  • Teams sharing passwords for lack of a better tool
  • Leadership wanting a hard number rather than an impression

What you live with today

  • Passwords circulate by email or on notes stuck to screens
  • Two-factor authentication is enabled on only a few accounts
  • An employee who clicked a suspicious link would rather stay quiet
  • Employee departures are not followed by systematic access removal

What it gets you

Measured

Click rate

A first campaign establishes your real baseline, then each subsequent campaign shows the trend.

Generalised

Two-factor auth

MFA rolled out on the accounts that matter, starting with email and privileged access.

Encouraged

Reporting

A simple channel to flag a doubt, and an explicit guarantee that reporting never leads to a sanction.

What is included

  • Simulated phishing campaigns, adapted to your sector and your tools
  • Short workshops per team, using examples drawn from your own cases
  • A specific module for leadership and finance on payment fraud
  • Rolling out or strengthening MFA and reviewing privileged accounts
  • A reporting procedure and an employee onboarding/offboarding process
  • A before/after report with indicators per team, never per person

How it runs

01

Baseline measurement

2 weeks

An unannounced simulation campaign establishes your starting point. Results are aggregated per team: nobody is named.

02

Training

2 to 4 weeks

Short workshops built from what the campaign revealed rather than from generic content.

03

Hardening access

2 to 4 weeks

MFA, privileged account review, a password manager and an offboarding procedure. Training alone is not enough.

04

Follow-up campaigns

Quarterly

New simulations to verify the effect holds. Without repetition, the gains fade within months.

Indicative timelines for a mid-sized organisation. The number of teams and sites mainly affects the workshop phase.

The questions you are asking

Are employees who fail sanctioned?

No, and we decline engagements built that way. A punitive approach produces exactly one outcome: people hide their mistakes, and you discover the incident much later. Results are aggregated per team and never shared by name.

How often should campaigns be repeated?

A quarterly rhythm works well. Beyond six months without a reminder, click rates rise noticeably in most organisations we follow.

Will MFA slow our teams down?

Marginally, and the trade-off against the risk avoided is quickly made. We favour the least painful methods and start with the most exposed accounts rather than imposing everything everywhere at once.

Our employees are not comfortable with IT. Is that an obstacle?

Quite the opposite — those groups often improve the most. The workshops start from concrete situations, such as an unusual invoice or an email from the boss on a Friday evening, not from technical vocabulary.

Your employees are your widest attack surface.

We start with a measurement campaign: it gives you a real number, without blaming anyone.

The rest of the arsenal