A role-based programme that runs itself
Engineering, sales, finance, ops, executives, each on the content that fits them, delivered in the tools they already use, refreshed on a calendar your team owns.
Short, role-based modules delivered where the team already works. Phishing simulations calibrated to your risk. Evidence rituals every audit asks for. Built so awareness becomes a working control, not an annual video everyone clicks through.
SOC 2, ISO 27001, NIS2, DORA, GDPR, all of them expect role-based training, onboarding coverage and an annual refresher with a dated record per employee. A 12-month-old PDF and an attendance list does not satisfy a serious examiner.
An employee clicked, credentials moved, finance almost lost money. The board wants a response that is not "we'll send a reminder email". The response is a recalibrated programme with the targeted module that addresses what actually happened.
The team groans through 45-minute videos that have nothing to do with their job. Engagement is the lowest in the company. The training is satisfying a checkbox but is not changing behaviour.
The new owner has inherited a folder of slides and a paid platform nobody logs into. They need a programme that runs itself, produces evidence on demand, and can be shown to the board without flinching.
We build the programme with the people who will run it once we are gone, your HR partner, your IT lead, your security owner if you have one.
What is in place, what evidence exists, what the audit framework actually requires, and what your team will and will not engage with. A short report with the gap to a defensible programme and the path to close it.
One module per role group, calibrated to the threats that role actually faces. Engineering gets dependency hygiene and credential management, sales gets BEC and impersonation, finance gets payment-fraud playbooks. Delivered through your existing tools, no new login.
A simulated phishing programme calibrated to the realistic threat. An onboarding flow that hits every new joiner from day one. A response track so a real click triggers a coaching conversation, not a public shaming.
The reports your auditor opens at the start of fieldwork, packaged. The dashboards your board reviews quarterly. The runbook that lets the named owner continue without us. We exit when the programme is operating, not when the content is uploaded.
Engineering, sales, finance, ops, executives, each on the content that fits them, delivered in the tools they already use, refreshed on a calendar your team owns.
Reporting rate, not click rate, as the headline. A calibration loop that gets harder as the team gets better. The first real attack lands in a team prepared to flag it.
Attendance records, completion dates, campaign outcomes, all in a format SOC 2, ISO, NIS2, DORA and GDPR examiners accept. No "let me put a deck together" before each audit.
Employees know what a phish looks like, where to report it, and what happens if they miss one. The programme contributes to security posture, not just to the audit file.
"Awareness training fails for the same reason most controls fail, it is built for the audit, not for the people who would have to use it on a Tuesday. Build it for Tuesday and the audit becomes a snapshot of a working programme, not a panic before the examiner arrives."
Purple Dragon Cybersecurity
Yes, for two reasons that are not "we should". First, every framework that touches you (SOC 2, ISO 27001, NIS2, DORA, GDPR) requires it and the auditor will ask for the evidence. Second, phishing and account takeover are still the most common ways your company gets compromised, and the people in front of the inbox are the control. The version of awareness training employees hate, generic videos forced through once a year, satisfies neither.
Short, role-based modules delivered through tools your team already uses (Slack, email, the wiki). Engineering gets a different module than sales gets a different module than finance. Onboarding is covered from day one, refreshers run quarterly, and one targeted module follows each notable incident in the industry. We avoid the 45-minute video format.
Yes, calibrated to your risk profile and reviewed before the campaign runs. The goal is realistic exposure that produces a teachable moment, not gotcha numbers in a dashboard. Click rates are reported, but the metric that matters is reporting rate, the proportion of employees who flag the message, because that is the working control.
Each module produces an attendance record, each phishing campaign produces a participation and outcome report, each onboarding completion produces a dated record per employee. Together these are the artifacts auditors examine for SOC 2 CC2, ISO 27001 A.6.3, NIS2 Article 21(2)(g) and the equivalent clauses. Same programme, multiple audits.
We are platform-agnostic. If you already have one and it is paid for, we build the programme inside it. If you do not, we recommend what fits your size and stack, often a smaller platform that produces equivalent evidence at a fraction of the cost.
A working session on what your team currently sees, what evidence you have, and what a programme they would actually engage with looks like.
Tell us what you're trying to ship, what's stalled, or which buyer security review is up next. We work with companies across the EU, EEA and US, and we reply within one business day.