Cybersecurity — Awareness
Security awareness training and phishing simulation for New York businesses
Training does not make people unphishable — it makes them faster to report. We run short recurring training and honest simulations, measure what actually changes outcomes, and skip the scare tactics.
What training can and cannot do
Start with the honest version: some phishing emails will always be opened. People are busy, attackers are competent, and one distracted afternoon defeats a year of vigilance. Awareness training is not a force field — it is the layer that shortens the time between a click and a report, and a fast report is what turns a compromise into a contained event instead of a quarter-long investigation.
That is why this service sits behind email security and MFA in our security practice, never in front of them. Controls reduce what people face and what a mistake costs; training adds depth. Any vendor selling awareness as your primary defense is selling the cheapest product with the largest claims.
And what we refuse: humiliation-based programs. Public click walls, entrapment lures built from bonus announcements or layoff rumors, discipline for failing a simulation. Programs like that teach exactly one lesson — hide your mistakes — and a hidden click is the most expensive kind. The employee who reports in two minutes beats the one who never clicks but stays silent when they finally do.
What’s included
Baseline simulation
A fair, unannounced campaign to measure where you actually start — click rate, report rate, and time-to-report.
Short recurring training
Minutes per month, not an annual seminar. Retention follows cadence, and the threat examples stay current.
Role-specific tracks
Payment approvers and finance drill BEC and wire fraud; admins drill consent phishing and MFA-fatigue prompts; everyone else gets the essentials without the padding.
Report-button rollout
One-click reporting in Outlook, routed to people who triage it — reporting only sticks when something visibly happens.
Honest measurement
Report rate and time-to-report tracked over time; repeat clickers coached privately rather than posted publicly.
Compliance evidence
Completion records, content coverage, and simulation results packaged for auditors, insurers, and questionnaires.
How a program runs
Baseline
Measure before training: a realistic simulation, difficulty calibrated to what your firm actually receives — no trick lures designed to inflate the before picture.
Train
Short modules on a cadence, mapped to the attacks that matter for each role. Nobody learns from a 90-minute annual video, and we do not pretend otherwise.
Simulate
Ongoing campaigns of varied difficulty. The goal is practice at recognizing and reporting, not a monthly gotcha.
Measure
Report rate and time-to-report, trended. Click rate is recorded but not worshiped — it is the noisiest number in the program.
Adjust
Themes and difficulty follow the data and the current threat picture; roles that handle money or credentials get the most attention.
Evidence
Records accumulate into the artifact your regulator, FTC Safeguards program, or insurer asks for at renewal.
Measured honestly
Click rate — the industry’s favorite metric — is the weakest one available. It swings with lure difficulty, so a vendor can manufacture improvement by sending easier tests, and a low click rate says nothing about whether the one click that matters gets reported. We track it, but we do not steer by it.
The numbers that predict incident outcomes are report rate and time-to-report: how many people raised a hand, and how fast. A phish reported in minutes gives containment a head start measured in hours of prevented damage. That is the behavior the entire program exists to build, so it is the behavior we measure and reward.
Good fit if
NYDFS or the FTC Safeguards Rule requires training you cannot evidence
Your insurer’s questionnaire asks about awareness programs
Payment approvals move through email
Last year’s training was one long video and a quiz
Nobody knows where to report a suspicious email
Common questions
Do phishing simulations actually work?
The research on click-rate improvement is genuinely mixed, and we will not pretend otherwise. What holds up is narrower and more useful: practiced reporting builds a reporting habit, and simulations are the only safe way to practice. Treat simulation as a fire drill — nobody claims drills fireproof the building, but everyone knows where the exits are.
Will employees be disciplined for clicking?
Not on our recommendation, and we will argue against it if proposed. Repeat clickers get quieter, more specific coaching. The program’s entire value depends on people reporting instantly — including reporting their own click — and nobody reports their way into a disciplinary file.
How often should training run?
Short and recurring beats long and annual — monthly-scale touchpoints hold attention where a yearly seminar evaporates by February. As for obligations: NYDFS expects at least annual training that addresses social engineering, the FTC Safeguards Rule requires awareness training among its nine elements, and HIPAA expects a training program for workforce members. We treat those as floors, not targets.
Does this satisfy our compliance training requirement?
It produces the substance and the evidence: current content covering social engineering, completion records per person, and simulation results over time. Mapping that evidence to NYDFS, HIPAA, or the Safeguards Rule is part of the service; the certification itself remains yours.
Can training replace email security or MFA?
No, and the ordering matters. Email controls reduce what reaches people; MFA caps what a stolen password buys; training shortens the time to containment when both are beaten. A budget that funds training instead of controls — rather than after them — is upside down.
Build the reporting habit.
A baseline campaign shows where your firm actually stands — measured fairly, reported privately.