Managed Security Services

Security awareness training that changes behaviour.

Annual click-through training satisfies an auditor and changes nothing. SubRosa runs continuous simulation and short, specific teaching against the attacks your people actually receive, and reports the one number that matters: how many of them still click.

Phishing · Passwords · Social engineering · Data handling

Security awareness training, defined

What is security awareness training?

Security awareness training teaches the people in an organization to recognize and respond to the attacks aimed at them: phishing, social engineering, credential theft, unsafe data handling. It exists because most breaches begin with a person rather than a system: attackers target staff precisely because human judgement is easier to exploit than a patched server. Effective programmes are continuous and measured rather than an annual module, and most regulatory frameworks now require documented training as evidence of due diligence.

What we cover

The attacks your people actually get.

Interactive modules and live simulation across the topics that account for most real-world compromise.

Phishing & email security

Recognizing phishing indicators, reporting suspicious messages, and real-world phishing simulations run against your own staff.

Passwords & authentication

Strong credentials, password manager use, multi-factor authentication, and everyday account hygiene.

Social engineering

Pretexting, impersonation, physical tailgating, and the vishing and smishing techniques that bypass email filters entirely.

Data protection & mobile

Data classification, secure file sharing, privacy obligations, and securing mobile and remote working.

How the programme runs

Behaviour change, not an annual tick-box.

Annual training completed in one sitting changes very little. A programme that measurably reduces risk works differently.

  1. 01

    Baseline measurement

    We establish where you actually are with a baseline phishing simulation and a review of prior incidents. Without a baseline you cannot show improvement, and improvement is the only justification for the spend.

  2. 02

    Content matched to your risks

    Training is matched to the threats your staff actually face and the systems they actually use. Generic content aimed at no particular organisation is what makes awareness training feel like an obligation.

  3. 03

    Continuous delivery

    Short modules delivered through the year rather than one long annual session. The evidence on retention is not ambiguous — spaced repetition works and a single sitting does not.

  4. 04

    Simulated phishing

    Regular simulations using pretexts that resemble real attacks, not obvious templates. We exclude the manipulative categories — bereavement, medical, redundancy, payroll — because a simulation that humiliates staff damages reporting culture.

  5. 05

    Measurement that means something

    Reporting rate matters more than click rate. A workforce that clicks occasionally but reports quickly is genuinely safer than one that clicks rarely and stays silent, and the second is what a click-rate-only programme optimises for.

  6. 06

    Reinforcement where it is needed

    Additional support goes to the people and teams who need it, rather than repeating the same material for everyone. Finance and executives face different attacks and warrant different preparation.

Why SubRosa

Taught by the people who run the attacks.

Built from real engagements

Our social engineering team phishes organizations for a living. The training teaches what is currently working against companies like yours, not a generic curriculum.

Measured, not attended

Success is a falling click rate and a rising report rate, tracked per team over time, not a completion percentage.

Audit-ready reporting

Documented training records and evidence of a continuous programme, delivered to you in the form auditors and insurers ask for.

The click rate is the number that matters.

Proof it actually worked.

Every round is measured against a baseline taken before any training runs, then broken down by team so you can see where the risk sits rather than an average that hides it. Completion records and simulation results come to you as a documented trail your auditors and insurers accept.

Measuring the programme
Phishing click rateSimulation rounds
  • Baseline14.2%
    no training yet
  • Round 29.6%
    after phishing module
  • Round 36.1%
    after social engineering
  • Round 43.8%
    current
Illustrative of a typical programmeCompletion tracked too

Common questions

What is security awareness training?
Security awareness training teaches the people in an organization to recognize and respond to the attacks aimed at them: phishing, social engineering, credential theft, and unsafe data handling. It exists because most breaches begin with a person rather than a system, and attackers target staff precisely because human judgement is easier to exploit than a patched server.
How often should security awareness training be run?
Continuously rather than annually. An annual module satisfies an auditor but has largely faded by the time an attack arrives. Effective programmes combine short, regular teaching with ongoing phishing simulation, so behaviour is reinforced and measured throughout the year rather than tested once.
How is the effectiveness of awareness training measured?
By behaviour, not attendance. The meaningful measures are the phishing simulation click rate falling over time and the report rate rising, tracked per team so you can see where risk actually sits. A completion percentage only records that a module was opened.
Does security awareness training satisfy compliance requirements?
Most frameworks and cyber insurers require documented security awareness training as evidence of due diligence, including SOC 2, ISO 27001, HIPAA, and PCI DSS. SubRosa provides completion records and simulation results as a documented trail, so producing that evidence at audit is a matter of handing it over rather than reconstructing it.
Does security awareness training actually work?
Annual training completed in one sitting changes very little, and it is fair to be sceptical of it. What does work is continuous short modules, realistic simulation, and measuring reporting rather than only clicks. If you are buying training to satisfy a control rather than to change behaviour, be honest with yourself about which you are buying — the cheaper option will satisfy the auditor.
What metrics should we track?
Reporting rate above all. A workforce that occasionally clicks but reports quickly is genuinely safer than one that rarely clicks and says nothing, because the second gives your security team no signal. A programme optimised for click rate alone quietly trains people to stay quiet when they do click.
How often should training run?
Short modules through the year rather than one annual session. The evidence on retention is not ambiguous: spaced repetition works, a single long sitting does not. Most compliance frameworks require annual training as a minimum, which is a floor rather than a target.
Do you run phishing simulations, and are they fair?
Yes, using pretexts that resemble real attacks rather than obvious templates. We exclude manipulative categories by default — bereavement, medical circumstances, redundancy fears, payroll problems — and report in aggregate rather than naming individuals. A simulation that humiliates staff damages the reporting culture it was meant to build.

Ready to find out who clicks?

Start with a baseline simulation against your own staff. You will know within a fortnight where the risk actually sits.