Services

    Security Awareness Training

    People remain the most critical factor in cybersecurity resilience. Our awareness programs build security culture through targeted education, behavioral reinforcement, and measurable outcomes. Within the IPV methodology, this service delivers the PROTECT pillar — hardening the human layer.

    The Human Attack Surface

    Your Employees Are Your First Line of Defence - and the Most Targeted.

    People are involved in over 80% of successful breaches - phishing clicks, credential reuse, social engineering, and unauthorized AI tool use. Technical controls cannot compensate for an uninformed workforce.

    80%+

    of breaches involve the human element (Verizon DBIR 2025)

    higher click rate on AI-crafted phishing vs. traditional lures

    68%

    of employees cannot distinguish AI deepfake voice from real

    12 months

    required for sustained behaviour change with reinforcement-based programmes

    What We Deliver

    Five Programmes. One Security Culture.

    // What We Deliver 01

    Security Foundations Training

    Core security awareness covering phishing recognition, password hygiene, device security, safe remote working, and incident reporting. Annual and ongoing delivery formats. Role-specific tracks for general staff, IT, Finance, and Executive teams. Content aligned to ISO 27001 Annex A.6.3 and NIS2 Article 21 requirements.

    • Pre/post knowledge assessment
    • Module completion tracking
    • Certificate of completion
    • Board-ready compliance evidence report

    What you get

    Your employees demonstrate measurably improved phishing recognition within 90 days. You have compliance-ready evidence for ISO 27001 and NIS2 awareness controls that satisfies auditor requirements - without a last-minute scramble.

    Scope boundary

    Awareness training changes human behaviour - it does not replace technical controls. Phishing simulation tests click rates; it does not test your email gateway, endpoint detection, or credential exposure. Technical security requires a separate PT or CISOaaS engagement.

    NEW
    // What We Deliver 02

    AI Awareness Programme

    Your employees are already using AI tools - ChatGPT, Copilot, Gemini, and dozens of shadow AI applications - regardless of whether IT has approved them. This program addresses AI-specific threats that no traditional security awareness curriculum covers: AI-generated phishing, deepfake fraud, prompt injection risks for developers, and how to use AI tools responsibly without leaking sensitive data.

    • AI threat landscape briefing (all-staff and role-specific)
    • Responsible AI Use Policy - drafted for your organisation
    • Shadow AI discovery workshop
    • Deepfake and voice fraud recognition module
    • Prompt injection awareness for developers and power users
    • AI policy acknowledgement tracking (audit-ready)

    What you get

    Your employees can recognise AI-generated phishing emails, know why they must not input sensitive data into public AI tools, and have a verified protocol for questioning suspected deepfake communications. Your organisation has a documented, distributed, and signed Responsible AI Use Policy.

    Scope boundary

    This program covers human awareness of AI threats and responsible use - it does not technically assess or secure your AI systems. For technical AI security coverage, pair this with the AI Security service or AI Architecture Review.

    // What We Deliver 03

    Phishing Simulation Campaign

    Ongoing simulated phishing campaigns using current attack templates - including AI-crafted lures that match the quality of real adversarial campaigns. Employees who click receive immediate, non-punitive microlearning. Managers receive per-team results dashboards.

    • Monthly simulation campaigns
    • Click-rate trend dashboard
    • Departmental risk heat-map
    • Targeted follow-up modules for high-risk users

    What you get

    A continuous, measured baseline of your human-layer phishing resilience - not a one-time number. Regulators and insurers see documented improvement over time, not a single training completion record. Your highest-risk departments are identified and prioritized for intervention.

    Scope boundary

    Simulations test click behaviour - not credential submission or malware execution (those require a full social engineering red team engagement within IRT-aaS). Phishing simulation complements, but does not replace, technical email security controls.

    // What We Deliver 04

    Executive & Board Cyber Briefing

    A 60-90 minute facilitated session for C-suite and board members covering the current threat landscape, regulatory obligations, and board-level responsibilities in cyber governance. Adapted to your industry, your organization's current posture, and recent high-profile incidents. Satisfies NIS2 Article 20 and DORA board-accountability requirements.

    • Board presentation deck
    • Facilitated discussion
    • Board cyber governance checklist
    • Follow-up Q&A documentation

    What you get

    Your board understands their oversight responsibilities under NIS2 and DORA, can ask the right questions of management, and is equipped to make governance decisions with confidence. The session produces documented evidence of board-level cyber governance awareness.

    Scope boundary

    A briefing and governance session - not a technical red team or stress-test of response procedures. Incident response rehearsal is a separate tabletop or IRT-aaS engagement.

    // What We Deliver 05

    Tabletop Incident Simulation

    A facilitated realistic attack scenario exercise for your incident response team - testing decision-making, escalation procedures, and cross-functional communication under pressure, without the cost of a live incident. Scenarios are tailored to your industry and current threat environment.

    • Bespoke scenario design
    • Facilitated 3-hour session
    • Gap findings and decision-point analysis report
    • Improvement roadmap with ownership

    What you get

    Your team has rehearsed a realistic incident before a real one happens. Decision ownership gaps and communication breakdowns are identified while the stakes are low. Regulators and insurers receive evidence of a tested - not just documented - incident response capability.

    Scope boundary

    A facilitated decision-making exercise, not a technical penetration test. Does not generate technical vulnerability findings. Physical security scenarios and live adversarial simulation are separate IRT-aaS engagements.

    // New for 2026

    Your Employees Are Already Using AI. Is Your Organisation Ready?

    The average knowledge worker uses 3-5 AI tools weekly. Most use public AI services - ChatGPT, Copilot, Claude — that have never been reviewed by your IT or security team. This creates three compounding risks your existing security awareness program almost certainly does not address:

    • Data leakage. Sensitive client data, source code, and financial information pasted into public AI prompts is processed outside your control and may be retained in training datasets or audit logs.
    • AI-generated attacks. Phishing emails written with GPT-4 achieve 3× the click rate of traditionally crafted lures. Your employees are being targeted with attacks their existing training did not prepare them for.
    • Deepfake fraud. AI-generated audio and video are being used in executive impersonation attacks. Employees receiving calls from a convincing facsimile of your CEO have no verification framework without specific training.

    "Phishing emails written by GPT-4 achieve 3× the click rate of traditionally crafted phishing. Your employees need to be trained on AI-era threats - not 2019 security awareness content."

    - IPV Security AI Security Practice, 2026

    AI Awareness Program - what's covered

    • AI threat landscape briefing (all-staff and role-specific tracks)
    • Responsible AI Use Policy - drafted for your organization, not a downloaded template
    • Shadow AI discovery workshop - what tools are actually in use across the organization
    • Deepfake recognition module - video and audio examples with verification protocols
    • Prompt injection awareness for developers and power users
    • AI policy distribution and signed acknowledgement tracking (audit-ready)
    • Quarterly AI threat landscape update as the attack surface evolves

    The IPV Methodology - how everything we do is delivered

    GOVERN Strategic leadership & program ownership
    ASSESS Continuous risk visibility
    PROTECT Controls implementation & hardening
    COMPLY Audit-ready at all times
    RESPOND Incident readiness & fast recovery
    See how the methodology works →
    // Scope Clarity

    What This Program Does Not Include

    Awareness programs change human behaviour - they do not replace technical controls. Here is where the scope ends and what to use instead.

    Technical security testing

    Phishing simulation measures click rates; it is not a penetration test of your email gateway, endpoint detection, or credential exposure. Technical testing requires a separate PT engagement.

    Full ISMS documentation

    We produce an AI Use Policy and security awareness policy as program deliverables. A comprehensive information security policy suite (ISMS documentation) for ISO 27001 certification is covered under the CISOaaS or Compliance service.

    LMS platform provisioning

    We deliver training content and manage campaigns via agreed platforms. Provisioning, licensing, or configuring a Learning Management System (Moodle, TalentLMS, etc.) is not included unless separately scoped.

    Guaranteed certification

    Awareness training satisfies the human-element controls required by ISO 27001 Annex A.6.3 and NIS2 Article 21. It is one component of a certification program - achieving certification requires the broader program delivered under the Compliance service.

    Related Guides

    Want to go deeper before we talk? Start with our in-depth guides:

    Security Awareness Program Guide Incident Response: The First 72 Hours

    Ready to build a security culture?

    Most organizations start with Security Foundations training - then expand. Let's look together at what's right for you.