
Operate
Security awareness
Most awareness programmes are measured on completion and change nothing. These three are measured on whether people report, how fast, and whether the processes that invite fraud get fixed.
The continuous programme is the spine: a twelve-month calendar of short contacts, with report rate and time to report as the headline numbers and a one-page board report every quarter.
Twelve months, delivered in a repeating cycle
Continuous awareness programme
A year-round programme measured on whether people report things, not on whether they completed a module. Built around the incidents your organisation actually has, and reported in numbers a board can act on.
Phishing simulation measures whether the reporting route works, using pretexts your people will actually receive — and explicitly not the ones that humiliate staff and suppress reporting for months afterwards.
Quarterly campaigns, or monthly at higher maturity
Phishing simulation
Realistic campaigns that measure whether people report, with coaching instead of blame — and a firm line on the pretexts we will not use, because a simulation that humiliates staff buys you one number and costs you the reporting culture.
Role-based training handles the populations where the realistic attack is specific: finance, developers, HR, legal, executive assistants and executives, each trained separately on what will actually be used against them.
Half a day to two days per role group
Role-based security training
Separate training for developers, finance, HR, legal and executives — because the realistic attack on each is different, and a single all-staff module is pitched to be relevant to nobody in particular.
All three are delivered in English or French, on site, in Amsterdam or Casablanca, or live online. Accredited certification sits in the training tracks; this is behaviour, and it is measured differently.

Leave with your top three risks documented
Thirty minutes with a senior practitioner. No slideware, no sales engineer.