# Security awareness training

> Your people make the right call.

Security awareness training turns your weakest control into the one that catches what the filters miss.

**Key points**

- Sessions built on what a real test just showed
- Short practical sessions, not a slide deck
- Repeat testing, so you can watch the number move

## We work with your people, not around them

### Built on what a real test showed

Each session follows a live campaign against your own staff, so the hour goes on what actually went wrong here instead of on general advice.

### Sessions people sit through willingly

Short, practical and built on what the simulation just showed, rather than an annual hour nobody remembers.

### A number that moves

The click rate is measured, retested and reported, so the effect is visible instead of assumed.

## What your people are actually taught

- **The session itself** — Short and practical, run for the teams it applies to and in the tools they already use, rather than an annual hour that everybody sits through and nobody remembers.
- **Spotting the tell** — What actually gives a message away: the domain that is almost right, the tone that is almost theirs, the request that is almost normal. Taught on real examples rather than stock screenshots.
- **Physical and everyday habits** — Being followed through a door, a device left unlocked, a memory stick that turned up in reception. The parts nobody thinks of as security until afterwards.
- **Passwords and second factors** — Reuse, the manager nobody adopted, and the approval prompt that arrives when you did not ask for one — the last of which is now the way most accounts are lost.
- **Reporting** — What to do in the minute after realising, and how to do it without expecting to be blamed. Nobody stops every attempt; the difference is whether you hear about it in ten minutes or in ten days.
- **Managers and their teams** — What a manager does with a result, and how to ask about a click without teaching the next person to keep quiet about theirs.

## How it runs

1. **Measure** — A first simulation establishes where you actually are. Nobody is named or blamed.
2. **Teach** — Sessions aimed at what went wrong, for the people it went wrong for.
3. **Retest** — Quarterly, so improvement is demonstrated rather than claimed.

## What you get

**A number you can put in front of the board — and watch move** — Click rate and report rate, taken at the start and again every quarter, broken down by team rather than by person. Named individuals never appear: a programme that punishes people teaches them to hide the click, which costs you the ten minutes that actually matter.

---

Canonical: https://centio.bg/uslugi/security-awareness-training