Mon–Sat 10:00–18:00 London · UK
Remote & on-site ☎ 0207 096 0936
← Services
London · IT Services

Security Awareness Training

Short, practical training that teaches your staff to recognise the scams aimed at them — with simulated phishing that coaches rather than catches people out.

Response within 4 hours On-site & remote No long contracts Windows & Mac

The technical controls are working. The remaining way in is a person.

Filtering, patching, endpoint protection and multi-factor authentication stop most of what arrives at a small business, and they stop it so quietly that nobody notices. What gets through is the message built for a human rather than a machine: an invoice that matches a real project, an email from a supplier saying their bank details have changed, a prompt on someone’s phone at 11pm that they approve just to make it stop.

No product fixes that. Security awareness training works on the people — regularly, in short bursts, using the scams your staff are genuinely likely to meet.

It sits alongside the rest of our security work rather than duplicating it. Cyber security is the technical layer: the controls, the monitoring, the response. Penetration testing probes your systems for exploitable weaknesses. Cyber Essentials certification proves a baseline of controls to clients and insurers. This service covers the one thing none of those reach — judgement at the moment somebody is being manipulated.

What the training consists of

  • Short, regular sessions — ten to fifteen minutes, delivered online, built around current tactics rather than a fixed annual syllabus
  • Simulated phishing that coaches — realistic test emails followed immediately by an explanation of the tells, with no blame attached to a click
  • Role-specific attention — extra depth for finance, payroll, accounts and anyone who can move money, change a bank record or approve a supplier
  • The scams UK small firms actually meet — invoice and mandate fraud, CEO fraud, fake supplier bank-change emails, MFA fatigue prompts, QR codes in printed letters and car parks, and callback scams where the “bank” or “IT department” phones you
  • A reporting route people will use — a single obvious way to flag something, and a response that thanks the reporter
  • New-starter onboarding — the essentials covered in week one, not at the next quarterly session
  • Progress reporting — reporting rates, time-to-first-report and repeat-click trends, in plain language for whoever owns risk

Reporting culture matters more than click rate

The most damaging minute in a breach is the one where somebody realises they made a mistake and decides to say nothing. Attackers rely on that silence. Our sessions are explicit that “I clicked it” gets a thank-you, because a compromised mailbox reported in five minutes is a contained incident, while the same mailbox reported the next morning is often a fraudulent payment. Managers get the same message, since one sarcastic comment about a colleague’s mistake undoes a year of training.

Who benefits most

Small and mid-sized businesses across Streatham, South London, Croydon and Surrey where staff handle money, personal data or client instructions by email. Accountancy and bookkeeping practices, law firms handling completion funds, estate and lettings agents moving deposits, recruitment agencies paying contractors, charities with a small finance team, and construction firms paying subcontractors are all targeted precisely because a payment redirect is worth trying. It suits hybrid and home-based teams too, where the quick check with a colleague across the desk isn’t available and a convincing email gets less scrutiny.

How we run it

  1. Baseline — a first simulated phishing campaign and a short review of your current habits, so improvement can be measured against something real
  2. Set the ground rules — we agree with you that results are used for coaching, not discipline, and tell staff that in advance
  3. Roll out the sessions — short modules on a regular rhythm, with the topics weighted towards the risks your business actually carries
  4. Targeted follow-up — extra practice for finance and payment-approval roles, plus a documented verification step for any bank-detail change
  5. Report and adjust — we review the trend with you and change the emphasis as the tactics move

What this heads off

  • Invoice redirection — a genuine invoice paid to a criminal’s account after a convincing bank-change email; our guide to invoice fraud and business email compromise covers the pattern in detail
  • Compromised mailboxes — credentials handed over on a fake login page, then used to watch your email traffic for weeks
  • CEO fraud — an urgent, discreet payment request that arrives while the director is provably in a meeting
  • MFA fatigue — repeated approval prompts worn down until someone taps accept
  • Late reporting — mistakes hidden for hours because staff expected to be blamed
  • Unrecognised phishing — the everyday attempts staff should be able to name, which we cover further in our guide on spotting and stopping phishing emails

An honest word on limits: training reduces risk, it does not remove it. A determined, well-researched attack will fool a trained person on a bad day, which is why this only works on top of multi-factor authentication, patched devices and tested backups. What it changes is the odds, and how fast you find out. If your technical controls are in reasonable shape and your people are the untested part, get in touch and we’ll start with a baseline.

Frequently asked questions

Isn't one training session a year enough?

It ticks a box and changes very little. People forget most of a two-hour slog within a month, and the scams move faster than that. Ten or fifteen minutes every few weeks, tied to something currently doing the rounds, sticks far better — and it fits into a working day without anyone resenting it.

Do the simulated phishing emails get staff into trouble?

They shouldn't, and we set them up so they don't. Anyone who clicks lands on a short explanation of what the giveaway was, not a report to their manager. Simulations that are used to name and shame teach one lesson only — hide your mistakes — which is the opposite of what you need. The measure that matters is how many people report the thing, not how many fell for it.

What should we actually be measuring?

Direction of travel, not a perfect score. Useful signals are the reporting rate, how quickly the first report arrives after a simulation lands, whether repeat clickers reduce over time, and whether finance staff verify payment changes by phone. Chasing a 0% click rate encourages easy tests and tells you nothing; a hard test with a fast report is a healthier result.

How do new starters get covered?

We fold it into onboarding rather than waiting for the next scheduled session. A new joiner gets the basics in their first week — how your business handles payment requests, how to report something suspicious, why the MFA prompt matters — before they've had time to learn bad habits from anyone else.

What clients say

Trusted by London businesses.

“Honest and transparent — they could have charged me more, but instead showed me a simple fix. Trustworthy people.”
— Small business client, London
“One of the most ethical companies I’ve ever dealt with. A genuine pleasure to work with — highly recommended.”
— Managed IT client
“The service was flawless — no bad surprises, everything just worked. Highly recommended.”
— Business client, London
“Thank you very much for your assistance. A pleasure as always.”
— General manager, accommodation business, Chelsea SW3

Feedback from clients of our team, including our sister company PC Macgicians, who deliver much of our engineering work. Names withheld at their request.

Free · no obligation

Need help with Security Awareness Training?

Tell us what you need and we'll come back with a clear, no-obligation plan and price.