Security training that changes behavior
Most breaches start with a person, not a firewall. We train your workforce to spot attacks, your IT team to defend against them and your leadership to respond when one gets through. It is live, practical and built around your business.
Training programs
Delivered on-site in the DC region or live online. Every class includes attendance records and materials you can keep, which also satisfies the awareness and training requirements in NIST SP 800-171 (3.2.1 to 3.2.3).
Workforce security awareness
For all employees. A 60 to 90 minute live session that teaches people to recognize and report attacks, not just sit through slides.
What we cover
- Phishing, smishing and voice scams, using real examples from current campaigns
- Business email compromise and wire fraud red flags
- Passwords, MFA fatigue attacks and account takeover
- Safe use of AI tools and what never to paste into them
- Physical security, tailgating and lost devices
- How to report, and why reporting fast matters more than being right
CUI handling and insider threat
For defense contractors. Role-based training that prepares your staff for the questions a CMMC assessor will ask them.
What we cover
- What CUI is, how it's marked and where it's allowed to live
- Approved storage, sharing and transmission methods
- Insider threat indicators and reporting obligations
- Incident reporting, including DFARS 72-hour requirements
- Assessment interview preparation for key staff
Hands-on defense training for IT teams
For IT staff and MSP technicians. Practical, lab-based training on hardening and defending the systems you actually run, taught from real security operations experience.
Workshop tracks
- Hardening Microsoft 365 and Entra ID: conditional access, MFA and logging
- Endpoint defense: EDR configuration, application control and patching
- Logging and detection: what to collect, what to alert on, what to ignore
- Incident response first hour: containment, evidence and escalation
- Attacker's view: live demonstration of common attacks and how to stop them
Executive tabletop exercises
For owners and leadership teams. A facilitated ransomware or data breach scenario that tests decisions, communication and your incident response plan.
What you get
- A scenario tailored to your business, contracts and systems
- Live facilitation with injects that escalate the situation
- Decision points on ransom, disclosure, customers and DoD reporting
- After-action report with gaps and recommended fixes
- Evidence for the incident response testing requirement (3.6.3)
Managed phishing campaigns
Simulated phishing that measures real risk and trains people at the moment they click. We design, run and report on every campaign, so your team doesn't have to.
Baseline
An unannounced first campaign measures your true click and report rates.
Design
Lures built around your industry, vendors and the attacks hitting businesses like yours.
Run monthly
Varied difficulty and timing so people can't game it.
Teach at the click
Anyone who clicks gets a short, specific lesson on what they missed.
Report
Monthly trends for leadership: click rate, report rate, repeat clickers and risk by team.
| Program | Includes | Best for |
|---|---|---|
| Baseline assessment | One campaign, results report and a live debrief with leadership | A first look at your real risk |
| Quarterly program | 4 campaigns a year, click-time training, quarterly reports | Meeting annual training requirements |
| Monthly program | 12 campaigns, click-time training, monthly reports and an annual live awareness session | Measurably reducing click rates |
Every campaign is authorized in writing by your leadership before launch.
Training questions
Can training be delivered at our office?
Yes. We deliver on-site across the DC, Maryland and Virginia region, and live online for teams anywhere in the U.S.
Will employees be punished for clicking a simulated phish?
We recommend against it, and our programs are built around teaching, not shaming. People who feel safe reporting mistakes report real attacks faster.
Does this satisfy CMMC awareness and training requirements?
Our programs are designed to meet NIST SP 800-171 requirements 3.2.1 through 3.2.3, and we provide the attendance records and materials an assessor will ask to see.
Can you train our MSP's technicians too?
Yes. Many clients include their MSP in our hands-on defense workshops so everyone is configuring systems to the same standard.
Build a training plan for your team
Tell us your headcount and goals. We'll recommend a program and send a quote.