Awareness Training
Short, engaging monthly training and skills assessments, so the person reading a convincing email has seen one before
An hour once a year is gone by Thursday
Most awareness training is one long session, taken once, forgotten immediately. Ours is a few minutes every month, on the things attackers are actually trying, followed by a short skills assessment so you can see what landed.
The point is not to catch anyone out. Your people are the ones being targeted, and they are the ones in a position to stop it.
Awareness Training overview (PDF)Benefits
- Reduced human risk and security incidents
- Improved employee awareness
- Improved cybersecurity behaviors
- Improved regulatory compliance

Features
A few minutes each month for the team, and transparent reporting for you.
- Short monthly training videos, unlimited for each user
- A quick skills assessment after each session
- Custom training content that can be tailored
- Clear reporting on who has completed what
- “Passwordless” login reduces employee frustrations
- Automated scheduling and reminders
- As always, unlimited support
Does this satisfy HIPAA, CMMC, NYSDFS, PCI, or the FTC Safeguards Rule?
Yes, all five. Awareness training is one of the few controls almost every rule names outright, which is part of why it is usually the first thing we put in place.
- HIPAA requires security awareness and training across the whole workforce, with periodic updates rather than a single session.
- CMMC, through NIST SP 800-171, requires role-based training and insider threat awareness. That is why content is assigned by role rather than sent to everybody at once.
- NYSDFS Part 500 requires training at least annually that covers social engineering specifically, including phishing, business email compromise, and AI-assisted attacks such as deepfakes.
- The FTC Safeguards Rule requires awareness training kept current with the risks in your written risk assessment, plus specialist training for anyone carrying security responsibilities.
- PCI DSS 4.0 requires training at hire and at least every twelve months, and since March 2025 that training has to cover phishing and social engineering.
Monthly delivery clears every one of those annual bars with room to spare. And whichever applies to you, the part an assessor asks for is the evidence. We keep the completion records, so when someone wants proof, it is already there.
How much time does it take each month?
A few minutes per person. That is the point of the format: an hour once a year is gone by Thursday, and a business your size cannot afford to lose an afternoon anyway.
Our people have done training before and nothing changed. Why would this?
Because frequency is what builds the instinct, and because we test it. A short skills assessment after each topic shows what actually landed, which means you find out before an attacker does.
Does it satisfy what we are being asked for?
Several rules require workforce training and, more to the point, evidence that it happened. We keep those records, so producing them is a matter of asking rather than reconstructing.
Tell us about your business.
A half-hour conversation about what you're being asked for and where you actually stand. If we can help, you'll have a proposal usually within a day.
Not ready to talk? Check your readiness in five minutes and see where to start.