Training & Simulation

Cyber crisis simulation, social engineering training, and intelligence workshops - delivered to teams, executives, and institutions.

We build training for the room it's delivered in.

Most security training is content delivery. A deck gets reused, people sit through it, and it's gone inside a month.

We build each session for the organization in the room. A bank asking for a crisis simulation gets one built on their systems, their jurisdiction, and their actual response plan - not a generic incident with the names changed. If you have an incident response plan, we can assess it first and build a simulation designed to test where it breaks. If you've already been through something, we can rebuild it and walk through what happened and why.

Conference and masterclass formats are the exception - those are necessarily more general, fictional but built on real cases. Everywhere else, we rarely run the same session twice. That's the point.

A scenario built on your organization - your systems, your jurisdiction, your suppliers, your regulator - and run in real time with your people making the decisions. Not a tabletop walkthrough of what should happen, but a situation that develops based on what they actually do.

Three ways in. If you have an incident response plan, we can assess it first and build a simulation designed to test the places it's thin. If you've been through an incident already, we can rebuild it and run it again with what you know now. Or we build from scratch against a threat that's realistic for your sector and your exposure.

What surfaces is usually not technical. It's who waits for authorization that never comes, which decision has no clear owner, what gets escalated too late, and how quickly the plan stops being consulted.

Format
Executive, technical, or cross-functional
Duration
Half or full day, multi-day for larger exercises
Delivery
In person preferred

How people are actually targeted: identified, researched, approached, and used as the way in. Built on real technique rather than the phishing-awareness version - pretexting, authority and urgency, channel selection, and why a particular person gets chosen over the one sitting next to them.

Where the engagement calls for it, we can build the session on the organization's own exposure - what's publicly reconstructable about your reporting lines, and who a capable outsider would actually approach. People take the material differently when the example is their own team.

This is training, not testing. Nobody is contacted and nothing is attempted. Authorized simulation is a separate engagement under separate rules.

Format
All staff, or targeted at high-exposure roles
Duration
Half day standard, full day with organization-specific build
Delivery
In person or virtual

Why people make the decisions they make under pressure, and why security programs that assume rational actors keep failing. Delivered by a practitioner with master's degrees in clinical psychology and criminology, not adapted from a security curriculum.

Covers how manipulation actually works - compliance, authority, reciprocity, and urgency - alongside the conditions that make people vulnerable to it: fatigue, ambiguity, hierarchy, and the fear of being wrong in front of colleagues. Also the other direction: how offender behavior and motivation shape who gets targeted, and why.

This tends to be the session that changes how leadership thinks about the problem, because it explains behavior their policies have been treating as carelessness.

Format
Executive, leadership, or security teams
Duration
Half or full day
Delivery
In person or virtual

The training your policy, insurer, or regulator requires - delivered so people retain it. Same coverage a compliance program calls for, built around real cases and current technique rather than a reused deck and a quiz.

If you need the box checked, we'll check it properly. Where there's appetite for more, the same session can be built on your organization's own exposure, which raises the ceiling considerably.

Format
All staff, onboarding, or annual refresh
Duration
Half day, or shorter modules for ongoing programs
Delivery
In person or virtual

A real incident, taken apart in detail. What the initial access actually was, how it moved, what the defenders saw and when, which decisions helped and which cost time, and where the whole thing could have been stopped.

Sessions can be built on public incidents relevant to your sector, or on something you experienced yourself. Reconstructing your own incident tends to be the more valuable version - the details are already familiar, so the session can spend its time on what went wrong in the response rather than on establishing the facts.

Format
Technical teams, security, and engineering
Duration
Half day per incident, multi-day for a series
Delivery
In person or virtual

How an Engagement Is Built

01

Scoping

A conversation first. What prompted this, who's in the room, and what you need them to walk out with. Whether the goal is testing a plan, preparing a leadership team, meeting a requirement, or working through something that already happened - the answer changes what gets built. We'll also tell you at this stage if the session you're asking for isn't the one that would actually help.

02

Build

We construct the session against your organization. Where relevant, that means your systems, your jurisdiction, your suppliers, your regulator, and your response plan - and where useful, your own external exposure. If there's a plan to test, we assess it first and design the scenario around where it's thin. Conference and masterclass formats are the exception: those are built to be general, fictional but grounded in real cases.

03

Delivery

We run it, in person wherever possible. Sessions are participatory rather than presented - decisions get made, consequences follow, and the material adapts to how the room actually responds. Afterward you get a written debrief: what surfaced, where the gaps were, and what we'd recommend addressing first.

Cost

Training is priced on delivery, not on subject. Two components: travel, which is either billed or reimbursed at cost, and a per-attendee fee. That fee varies by region, and we'll give you the number for yours when we scope.

What it doesn't depend on is the topic or how much work goes into building it. A simulation constructed entirely around your organization and a standard awareness session cost the same to deliver to the same group in the same place. The bespoke build isn't an upgrade you pay for - it's how we work.

Format
Half day, full day, multi-day, or ongoing programs
Delivery
In person preferred, virtual considered for lecture formats
Contact