Managed Security Services

Security awareness training that changes behaviour.

Annual click-through training satisfies an auditor and changes nothing. SubRosa runs continuous simulation and short, specific teaching against the attacks your people actually receive, and reports the one number that matters: how many of them still click.

Phishing · Passwords · Social engineering · Data handling

Security awareness training, defined

What is security awareness training?

Security awareness training teaches the people in an organization to recognize and respond to the attacks aimed at them: phishing, social engineering, credential theft, unsafe data handling. It exists because most breaches begin with a person rather than a system: attackers target staff precisely because human judgement is easier to exploit than a patched server. Effective programmes are continuous and measured rather than an annual module, and most regulatory frameworks now require documented training as evidence of due diligence.

What we cover

The attacks your people actually get.

Interactive modules and live simulation across the topics that account for most real-world compromise.

Phishing & email security

Recognizing phishing indicators, reporting suspicious messages, and real-world phishing simulations run against your own staff.

Passwords & authentication

Strong credentials, password manager use, multi-factor authentication, and everyday account hygiene.

Social engineering

Pretexting, impersonation, physical tailgating, and the vishing and smishing techniques that bypass email filters entirely.

Data protection & mobile

Data classification, secure file sharing, privacy obligations, and securing mobile and remote working.

Why SubRosa

Taught by the people who run the attacks.

Built from real engagements

Our social engineering team phishes organizations for a living. The training teaches what is currently working against companies like yours, not a generic curriculum.

Measured, not attended

Success is a falling click rate and a rising report rate, tracked per team over time, not a completion percentage.

Audit-ready reporting

Documented training records and evidence of a continuous programme, delivered to you in the form auditors and insurers ask for.

The click rate is the number that matters.

Proof it actually worked.

Every round is measured against a baseline taken before any training runs, then broken down by team so you can see where the risk sits rather than an average that hides it. Completion records and simulation results come to you as a documented trail your auditors and insurers accept.

Measuring the programme
Phishing click rateSimulation rounds
  • Baseline14.2%
    no training yet
  • Round 29.6%
    after phishing module
  • Round 36.1%
    after social engineering
  • Round 43.8%
    current
Illustrative of a typical programmeCompletion tracked too

Ready to find out who clicks?

Start with a baseline simulation against your own staff. You will know within a fortnight where the risk actually sits.