04Live · Interactive
Nobody ever changed
their behaviour for a slideshow.
Annual compliance training is something people click through while doing something else. These are live sessions where your team watches real attacks succeed in front of them — then learns exactly what would have stopped it.
- Phishing & email security
- Passwords, MFA & authentication
- Data protection (GDPR, POPIA)
- Social engineering & incident response
//The argument
Your staff are not the weakest link. They are the largest attack surface.
The framing matters. Calling people the weakest link tells them they are the problem, which makes them hide mistakes — and a hidden mistake is how a contained incident becomes a breach.
Your people are also the only control that can notice something is wrong and say so. That is worth investing in properly, and it does not happen through a module with a quiz at the end.
The goal is a team that reports fast and feels safe doing it.
01Modules
Six modules. Take all of them or the two that matter.
Sessions are typically 60–90 minutes each and can be combined into a half-day. Content is tailored before delivery, not read from a deck.
Phishing & email security
How modern phishing actually looks, including the approaches that survive contact with a security-aware team.
- Live demonstration of a credential harvest
- Business email compromise patterns
- Verifying an unexpected request properly
Passwords & authentication
Why password rules produced predictable passwords, and what actually helps — demonstrated by cracking some.
- Live password cracking demonstration
- Password managers in practice
- MFA, and which factors resist phishing
Data protection & privacy
Handling sensitive information under GDPR and POPIA without turning every task into a compliance exercise.
- Classifying data sensibly
- Secure sharing that people will actually use
- Recognising a reportable incident
Remote work & BYOD
Working securely outside the office, including the risks that are genuinely overstated and the ones that are not.
- Public networks and VPN reality check
- Personal devices touching company data
- Physical security and shoulder surfing
Social engineering defence
The psychology attackers exploit — authority, urgency, reciprocity — and how to build a pause into your processes.
- Pretexting, vishing and smishing
- Tailgating and physical access
- Making verification socially acceptable
Incident reporting
What to do in the first ten minutes, and why speed of reporting matters far more than avoiding embarrassment.
- Recognising an incident in progress
- Who to tell and how fast
- Containment steps anyone can take
02The approach
Why this sticks when compliance training does not.
Demonstrated, not described
Attacks are performed live in front of the room. Watching a password fall in nine seconds changes behaviour in a way a bullet point never has.
Genuinely interactive
Live virtual sessions with real questions and real answers. People ask about the suspicious message they received last week, and we work through it together.
Built around your risk
Content is shaped by your industry, your tooling and — where a simulation has run — the specific things your people fell for.
03Format
Practicalities.
- Delivery
- Live over video conference. Remote delivery means your distributed team all get the same session, and questions come from everyone rather than the loudest person in the room.
- Length
- 60–90 minutes per module. Long enough to demonstrate properly, short enough that people are still paying attention at the end.
- Group size
- Works well up to around 40. Beyond that the interactive element degrades and it becomes a lecture — which defeats the purpose.
- Audience
- Sessions are pitched separately for general staff, technical teams and executives. Executives face different attacks and deserve a different session.
- Measurement
- Where a phishing programme runs alongside, we track whether reporting rates actually improve. Feeling more secure is not the same as being more secure.
Most effective in combination. Training on its own raises awareness for a few weeks. Training paired with an ongoing simulation programme is what actually shifts behaviour, because the lesson keeps arriving at the moment it is needed.
→Next step
Give your team something worth their attention.
Tell us who needs training and what you are most worried about, and we will propose a session plan — including telling you if you only need one module rather than six.
daniel@theosec.com · +27 63 484 1051