I design training, awareness programmes and simulations for staff, leadership and higher-risk roles. The aim is to help people recognise, avoid and report real risks in their work.
Cybersecurity awareness helps people recognise the digital risks they may encounter at work and know how to respond. It combines training, practice, internal communications and follow-up; it can include phishing simulations.
A session teaches a specific topic. An awareness programme revisits important decisions, provides clear reporting channels and adjusts reinforcement according to the results. Clear processes and technical controls also matter: staff cannot manage every risk on their own.
One session a year, on its own, is unlikely to build a culture. It leaves an attendance record but does not show how people will act months later. It helps to practise decisions tied to each person's work and see what needs reinforcement.
Hence the distinction I keep on every project: running training is an action with a date on it; building a culture is a continuous programme in which training is one piece among several.
Messages arrive imitating clients, suppliers or your own management, and the workforce isn't clear on what to do with them.
It happened and was recorded, but people struggle to apply it when a real situation arises.
Depending on the applicable framework and scope, you may need to plan and document training and awareness as well as deliver them. Read the NIS2 analysis if that framework is relevant to you.
At ACBSEC I can prepare anything from a focused session to a continuous programme. The scope depends on your size, sector, risks, roles, maturity and compliance requirements.
The frame that holds up everything else: objectives, calendar, owners and measurement.
Different content depending on who it is for: finance doesn't need the same session as IT.
Exercises agreed with the organisation to practise decisions and improve reporting, without individual rankings.
Content can start from payment fraud, impersonation, information protection or the use of corporate tools. We first agree which actions to make easier and what support each group needs.
An awareness programme starts with the organisation's real risks, defines the actions it wants to improve and combines training, practice, simulations and follow-up throughout the year. This is ACBSEC's practical approach, not a prescribed standard.
I review incidents, channels, tasks and situations in each area. An initial simulation, authorised by the organisation, can establish a baseline.
I define observable decisions: verifying a payment change, protecting data or reporting a suspicious message.
I prepare objectives, a calendar and content for each role, with leadership involved and examples from your sector.
I spread exercises, campaigns and simulations across the cycle. Each activity offers feedback and a clear way to ask for help.
I compare the baseline with reporting rates, reporting speed and change by group; clicks are only one signal.
I reinforce what remains difficult and adjust content, processes and controls for the next cycle.
Not everyone faces the same decisions. General staff may need ways to recognise and report impersonation; finance and HR, exercises on payments and personal data; IT, development and privileged users, cases involving access and configuration. Leadership and sales teams need examples tied to their responsibilities.
I agree the groups and content with each organisation. A focused session can address a specific risk; a continuous programme lets people practise, review results and reinforce learning.
I want people to recognise risks, know what to check and be able to report quickly. I establish a baseline and review reporting rates, time to report and change by group, alongside participation and learning.
Simulations may also record clicks or other actions, but the assessment does not rest on a single number. The results guide training and process improvements, rather than singling people out.
Reusable material and evidence that works for the board and for an audit alike.
Scope of the serviceI provide the plan, the content, the simulations and the measurement. If you also need a platform to manage courses and certificates, that gets chosen separately and I help you compare them. One commitment I always keep: simulations have a learning objective and their results are read by area and by role, never to single out individuals to their manager.
They can cause resistance if used as a trap or to single someone out. The organisation authorises the exercise and agrees how it is communicated; results are read by area and role, never as an individual ranking. People who need help receive feedback and reinforcement.
There is no universal schedule. It depends on risks, roles and what assessments show. Short activities and reinforcement can be spread across the year, with the calendar reviewed when risks or results change.
Planning, content, participation and results can provide useful evidence when these frameworks apply. Whether it is sufficient depends on the scope and specific requirements of each assessment.
Yes. I prepare sessions for leadership built around decisions and situations they are responsible for, such as payment authorisations, impersonation or crisis management. The format and level of detail are tailored to them.
Yes. An initial simulation and a leadership session can provide a starting point. You can then decide whether an annual programme or a narrower scope makes sense.
Tell me about your roles, risks and objectives. We can define a first session or a continuous programme with practice and follow-up.
I reply personally within 24 working hours · No commitment