A reported wrong click costs less than a hidden one
Training on phishing, sign-ins and Microsoft 365. Short sessions, repeated over time, with exercises on real messages from your own mailbox.
Book an intro call“I think I just clicked on something I shouldn’t have.” Whether that sentence gets said decides how bad the damage is. Usually it doesn’t. The invoice in the attachment looked like every other one, and so did the Microsoft sign-in window; anyone who feels embarrassed would rather sit tight. Two hours later the assistant’s mailbox is sending invoices with altered bank details to half your customer base.
We teach in units that fit into an hour, working with what your people have in front of them every day: sender addresses, sign-in windows, sharing links in OneDrive and SharePoint. Part of the programme is a commitment from management that a reported click will not be held against anyone. Then we come back. The scams change, and what had sunk in by spring has faded by autumn.
What is included.
Phishing with real messages
In the training room we show real messages from your own mailboxes, redacted where needed, and work through the sender, the link underneath and the attachment. After that, participants judge ten examples themselves.
Sign-in and passwords
Setting up a password manager, breaking the habit of reusing passwords, registering a second factor on the work phone, and understanding why a push notification in the middle of the night is not a slip: it should be denied and reported.
Microsoft 365 in daily work
Teams, OneDrive and SharePoint usually arrive without any instruction. We go through who actually gets access from a sharing link, where deleted files end up and what an external guest sees in a Teams channel.
A reporting route instead of a hunt for someone to blame
Every session ends with the question of who to call once the click has happened. We set the route together, print it on a card and put it next to every phone.
Refreshers in the calendar
One date a year isn't enough. We schedule short refreshers, pick up the tactics of recent months and add cases from your own company if you want that.
No catch rates
We are happy to send simulated phishing messages, but we do not hand management a list of names of who clicked. Anyone who fears ending up on such a list stops reporting. The evaluation covers the department, not the individual.
How we work.
A look at the mailboxes
Beforehand we work out with you which attempted attacks arrived over the past six months, which programs are genuinely in use and who handles invoices and bank details. Those people are trained first.
Scope and dates
You receive a proposal: which groups, which topics, which sessions. We place the dates where your operation can absorb them, and if in doubt run the same session three times for three groups rather than once for everyone.
Training on site
We come to you or join remotely. The work happens on examples, not slides: participants open their own mailbox, check real messages and set up the second factor on their own device.
Refreshers and new joiners
It doesn't stop at one date. New colleagues get the basic session within their first few weeks, everyone else a short refresher as soon as the tactics change. If incidents are reported to you, they feed into the next session.
Common questions.
My people say they know all this already. Is training still worth it?
Usually yes, and it shows within the first twenty minutes. Almost everyone knows the basic rules. The question of whether the Microsoft sign-in page in that browser window is genuine trips up experienced users as well, because the fake now looks identical. We start where the knowledge runs out, not at the basics.
How do I explain to my shareholder that training achieves anything? I can't measure it.
You can't measure it directly, and any percentage figure on this is an estimate. What you can point to are reports: suspicious messages that nobody used to forward now reach your IT. You can count that figure from the first session onwards. It is no proof of damage avoided, but it shows that people are paying attention.
We run shifts. I can't pull thirty people off the production line at the same time.
Then we won't pull them out at the same time. We run the same session several times, in groups of eight to twelve people, and place the dates around the shift change. At sites without a meeting room we have run training in the canteen. What matters more than the room is that the group stays small enough for questions to be asked.
Can you send us simulated phishing messages so we can see who falls for them?
Sending them, yes. Naming names, no. Simulations are a good way to practise, as long as they don't end up as a test. Once a list of names sits with management, reporting drops off sharply, and you lose the one thing that helps when it counts. What you get from us is the evaluation per department and the topics that follow from it for the next session.
Someone here already clicked and said nothing about it for two days. How do we deal with that?
Two days of silence is the norm, not the exception. The way the first reported case is handled decides every case that follows: issue a formal warning, and the next person will think twice about saying anything at all. We prepare the statement you use to make the position clear internally, and we build the reporting route so that it costs two clicks rather than a phone call to three different places.
Let's talk about the first wrong click
Which programs are in use, who approves invoices, whether there has ever been an incident. From those answers we put together a proposal with groups, topics and dates that you can review at your own pace.
Book an intro call