Security awareness training that changes behaviour.
Annual click-through training satisfies an auditor and changes nothing. SubRosa runs continuous simulation and short, specific teaching against the attacks your people actually receive, and reports the one number that matters: how many of them still click.
Phishing · Passwords · Social engineering · Data handling
What is security awareness training?
Security awareness training teaches the people in an organization to recognize and respond to the attacks aimed at them: phishing, social engineering, credential theft, unsafe data handling. It exists because most breaches begin with a person rather than a system: attackers target staff precisely because human judgement is easier to exploit than a patched server. Effective programmes are continuous and measured rather than an annual module, and most regulatory frameworks now require documented training as evidence of due diligence.
The attacks your people actually get.
Interactive modules and live simulation across the topics that account for most real-world compromise.
Phishing & email security
Recognizing phishing indicators, reporting suspicious messages, and real-world phishing simulations run against your own staff.
Passwords & authentication
Strong credentials, password manager use, multi-factor authentication, and everyday account hygiene.
Social engineering
Pretexting, impersonation, physical tailgating, and the vishing and smishing techniques that bypass email filters entirely.
Data protection & mobile
Data classification, secure file sharing, privacy obligations, and securing mobile and remote working.
Taught by the people who run the attacks.
Built from real engagements
Our social engineering team phishes organizations for a living. The training teaches what is currently working against companies like yours, not a generic curriculum.
Measured, not attended
Success is a falling click rate and a rising report rate, tracked per team over time, not a completion percentage.
Audit-ready reporting
Documented training records and evidence of a continuous programme, delivered to you in the form auditors and insurers ask for.
Proof it actually worked.
Every round is measured against a baseline taken before any training runs, then broken down by team so you can see where the risk sits rather than an average that hides it. Completion records and simulation results come to you as a documented trail your auditors and insurers accept.
- Baseline14.2%no training yet
- Round 29.6%after phishing module
- Round 36.1%after social engineering
- Round 43.8%current
Ready to find out who clicks?
Start with a baseline simulation against your own staff. You will know within a fortnight where the risk actually sits.