Skip to content
Concept · Tier 1Programme

Staff Security Awareness Programme

An organisation whose technical controls are reasonable and whose staff are the remaining exposure — clicking links, approving payment changes by email, reusing passwords, sharing accounts to get work done.

The problem

Awareness training is usually an annual slideshow nobody remembers, delivered to satisfy a requirement rather than to change behaviour.

In scope

  • Baseline measurement
  • Role-specific training
  • Phishing simulation
  • Measured improvement
  • A repeatable programme the organisation can run itself afterwards

Out of scope

  • Technical controls — this is the human layer and should be sold alongside Cloud and Application Hardening, not instead of it.
  • Certification of individuals.
  • A one-off session with no measurement, which is what the market usually sells and what does not work.

What this would cover

Grouped by module — open the ones you want to read.

Baseline
  • An initial phishing simulation and a short assessment, before any training, to establish where the organisation actually is
Role-specific training
  • Finance staff on payment-change and invoice fraud, which is where the money actually leaves; reception and administrators on pretexting and impersonation; clinical or records staff on confidentiality and access; management on authority-based attacks aimed at them specifically; everyone on passwords, multi-factor and device basics
Delivery
  • Short, in person or live remote, in the organisation's context with its own systems as examples; not a generic video library
Simulation programme
  • Periodic, varied, increasing in sophistication, with immediate teaching at the moment someone clicks
Reporting incident practice
  • Most organisations train people to spot attacks and never tell them who to call; the reporting path is taught and rehearsed
Measurement
  • Click rate, report rate, and time to report, before and after; report rate is the better metric and is usually ignored
Handover
  • Materials, simulation templates and a cadence the organisation can run without Afivox
Deliverables
  • Baseline report, training delivered by role, simulation results over the programme period, final measurement against baseline, and a self-run programme pack

Data model

  • Not a build. Deliverables are a baseline report, training delivered by role, simulation results over the programme period, a final measurement against baseline, and a self-run programme pack.

Invariants

  • Not applicable — this is a training engagement, not a deployed system. The one structural rule: simulation results are reported in aggregate and never used punitively or by name — see the trade-off.

Offline behavior

Not applicable.

Hard trade-offs

The difficult decisions, stated plainly — not trimmed for length.

Phishing simulation used punitively destroys the thing it measures.

If clicking a simulated phish leads to a reprimand, staff stop reporting real ones — they hide them, and the organisation loses its best early-warning system. The programme must be agreed upfront as non-punitive, results reported in aggregate rather than by name, and the primary metric set as report rate rather than click rate. An organisation that will not commit to that should not run simulations at all.

Awareness decays measurably within months.

A single engagement produces a temporary improvement that management then mistakes for a solved problem. The honest sale is a programme with a cadence, and if the organisation only wants one session, the expected decay should be stated in the final report.

End state

What would be true about their day once this is running.

  • The organisation knows its baseline and its improvement, measured rather than assumed.
  • Staff in each role have been trained on the attacks aimed at their role.
  • People know who to call and have practised calling them.
  • Report rate is up, which matters more than click rate being down.
  • The organisation can run the next round itself.

Let's map how your operation actually runs.

One session. We look at what's breaking, and what we'd build around it — whether or not you hire us afterward.

Start the operations review