Security awareness training
Tailored training that gives your colleagues the one thing no control can: the reflex to stop and check. Built around your sector, your size and the risks you actually carry.
Request awareness sessionWhat security awareness training is
Security awareness training is a programme that changes how your people handle the moments an attacker is counting on: a message that arrives at exactly the right time, a caller who knows just enough, a password that has been reused once too often. It is built around your organisation rather than taken off a shelf, and it runs on a rhythm instead of once a year.
A firewall has never once clicked a link. The people who keep your business running are asked to, dozens of times a week, by messages built to look exactly like the ones they are waiting for.
What a programme covers
Six subjects, taught with your own tools and your own scenarios rather than stock examples from a slide deck.
Phishing
What a convincing message looks like now that they are written well, arrive on the right day and refer to a project your colleague is genuinely working on, and what to do in the ten seconds after clicking.
Social engineering
The phone call from the supplier, the visitor who follows someone through the door, the urgent request from a director who is conveniently unreachable. Pressure and authority are the tools; recognising them is the training.
Passwords and access
Why reuse is the risk rather than complexity, how a password manager changes the habit, and what multi-factor authentication does and does not protect against.
Working safely, day to day
Public networks, personal devices, the AI tool nobody registered, and what leaves the building in a shared link or an attachment sent to the wrong autocomplete.
When something goes wrong
How to recognise an incident, who to tell within the hour, and why reporting quickly matters more than not having made the mistake. Blame is what keeps incidents hidden.
Speaking up in time
What counts as suspicious, who to tell, and why saying something an hour after a mistake is worth far more than saying nothing at all.
How a programme runs
A loop, not a course. One session teaches; a rhythm changes what people do.
Measure
We start with where you actually stand, using a simulation and a short survey, so the training answers your situation and you have something to compare against later.
Train
Live sessions, on site or remote, in groups small enough that people ask the questions they would otherwise be embarrassed to ask.
Simulate
Realistic phishing sent to your own people, in your own house style, and used to teach at the moment of clicking rather than to catch anyone out.
Adjust
You get the results per department and per scenario, we agree what needs more attention, and the loop starts again where the risk actually is.
Where AssistSec makes the difference
Awareness is a habit, not a module. That is the whole difference between a programme that changes what people do and one that produces an attendance list.
| Aspect | Traditional training | |
|---|---|---|
| Approach | Cut to your sector, your size and the risks you actually carry | One course, the same for every organisation |
| Rhythm | A loop that repeats and builds on the round before | An annual module to be ticked off |
| Realism | Simulations in your own house style, on the tools your people use | Generic examples nobody recognises |
| Reporting | Per group, measured against your own starting point | A completion percentage |
| Delivery | Live sessions led by the people who run the attacks for a living | A recorded video and a quiz |
| Privacy | Agreed in advance, and never a list of names | Individual scores, passed upward |
Frequently asked questions
Is the training on site or online?
Either, and often both: a live session on site for the discussion, and shorter remote sessions for the people who could not be there or who joined later. What we avoid is a video everybody clicks through in silence.
In which language do you train?
Dutch or English, and we will say plainly if a mixed group is better served by one over the other. The material follows the language of the session.
May you send our staff phishing without telling them?
A simulation only works unannounced, but it is never a secret operation: it is agreed with you in advance, and where a works council or a data protection officer has a say, that conversation happens before anything is sent. Results are reported per group rather than per person. The point is to teach, not to build a list of names.
How long does a programme take?
A first session is usually half a day. Real change comes from repetition, so a programme normally runs across a year with a small number of moments in it. We put the shape in writing before we start.
How do you show it worked?
By comparing the same measurements over time: how many people click, how many report, and how quickly. Reporting speed is the number that matters most, and the one that moves first.
Interested in a pentest?
Discover how AI-backed pentesting gives your organization faster and more thorough insight into vulnerabilities.
Contact us
