
Operate
Continuous awareness programme
A year-round programme measured on whether people report things, not on whether they completed a module. Built around the incidents your organisation actually has, and reported in numbers a board can act on.
Duration
Twelve months, delivered in a repeating cycle
Built on
ISO/IEC 27001 Annex A · NIS2 / Cyberbeveiligingswet · GDPR
Indicative price
On request
Who this is for
CISO
Has a completion rate of ninety-six per cent and no idea whether anyone would report a real one.
HR or L&D
Owns the annual module and knows it changes nothing.
Compliance officer
Needs evidence of awareness training for an auditor or an insurer.
CEO of a smaller firm
Is the person an attacker will impersonate.
Completion is not a security metric
Annual awareness training exists almost everywhere and almost nowhere does anyone claim it works. The reason is that it is measured on the wrong thing. A completion rate tells you people clicked through a module in November. It tells you nothing about whether the finance assistant will pause over a payment instruction in March, which is the only behaviour anyone actually cares about.
The metric that matters is the report rate, and its twin, the time to report. An organisation where people forward a suspicious email within four minutes is in a completely different position from one where the same email sits unmentioned for two days — regardless of how many people clicked. Reporting is the control. Everything else in an awareness programme is in service of it.
That reframing changes the design. A programme built to raise reporting has to make reporting easy, fast and socially safe, which means one obvious route, an acknowledgement every time, and no consequence for being wrong. An organisation that treats a false alarm as a waste of time trains its staff to stay quiet, and then wonders why the real one was not flagged.
It also has to be continuous, because attention decays within weeks. Twelve short contacts across a year outperform one long session, and they allow the content to follow what is actually happening — a wave of invoice fraud in your sector, a new tool being rolled out, the fortnight after a reorganisation when nobody is sure who approves what.
And it has to be specific to your organisation. The generic module talks about a Nigerian prince; your actual exposure is a supplier bank detail change, a fake message from a partner during a deal, or an AI-generated voice note from someone senior asking for something urgent. Those are the scenarios that belong in the programme.
How we do it
- 01
Baseline
2–3 weeks
Current report rate and time to report, an unannounced simulation to establish a starting point, and a review of the real incidents and near misses you have had. The baseline is the whole point: without it there is no way to show the programme worked.
- 02
Programme design
1–2 weeks
A twelve-month calendar of short contacts, pitched by role, built around the threats your sector actually sees. Designed so that no single month demands more than twenty minutes from anyone.
- 03
Reporting route
1 week
One obvious way to report, an automatic acknowledgement, and a stated position that nobody is penalised for a false alarm. Where the route is hard to find or slow to respond, fix that before running any campaign.
- 04
Delivery
ongoing
Short contacts, in English or French, mixing simulation, micro-content and live sessions for the roles that carry the most exposure.
- 05
Measurement
quarterly
Report rate, time to report, and repeat-susceptibility by department — with the click rate present but explicitly not the headline.
- 06
Board reporting
quarterly
One page: what changed, where the exposure sits now, and what we are doing next quarter. Written for people who do not want a dashboard.
Named artefacts
What you receive
- Baseline report rate and time to report, measured before anything else
- Twelve-month awareness calendar, by role
- Reporting route designed, tested and acknowledged automatically
- Scenario library built from your sector and your own incident history
- Quarterly measurement by department, with trends
- Quarterly one-page board report
- Evidence pack for auditors, insurers and client questionnaires
- Annual review and the following year's plan
What we need from you
- A stated position from leadership that reporting is never penalised. Without it, the numbers you get are the numbers people think you want.
- Your real incident and near-miss history. The most effective scenarios are always the ones that already nearly worked.
- Twenty minutes per person per month. That is the whole ask, and protecting it is the difference between a programme and a mailing list.
- Acceptance that the first report rate will look bad. It is a starting point, not a verdict.
What changes
- 01You know your report rate and time to report, and both improve measurably.
- 02Reporting is easy, fast and safe, so people use it.
- 03Scenarios reflect your actual exposure rather than a generic catalogue.
- 04The board gets one page a quarter that says something.
- 05You hold evidence that satisfies an auditor, an insurer and a client questionnaire.
What it costs
On request
All prices exclude VAT.
Questions
Is completion tracking included?
Yes, because auditors ask for it and it is easy to produce. It is not the measure of success and we will not present it as one. Report rate and time to report are the numbers on the front page.
Will you name people who fail?
No. Naming individuals suppresses reporting, which costs you the only control that matters. We report by department and by pattern, and where one team is consistently exposed we look at their workflow rather than their character.
Can this satisfy ISO 27001 or NIS2 awareness requirements?
Yes, and it produces better evidence than an annual module, because you can show a programme, a measurement and a trend rather than a completion certificate. Both frameworks expect awareness to be ongoing and evidenced, which is exactly what this is.
What about AI-generated attacks?
They are in the scenario library, because voice cloning and convincing written impersonation have moved the realistic threat well past bad spelling. The defensive behaviour barely changes — verify through a second channel — but the training has to reflect what people will actually receive.
What does it cost?
On request. Priced on headcount and on how much live delivery the programme includes. Quoted annually so it can be budgeted once.

Leave with your top three risks documented
Thirty minutes with a senior practitioner. No slideware, no sales engineer.