Our core offering is interactive, in-person workshops. These are working sessions, not lectures.
People look at real examples, argue about which ones are fake, and get things wrong in a room
where it costs nothing. A typical workshop covers:
How attacks arrive
Phishing, spear phishing, business email compromise, malicious attachments, fake login pages,
and the increasing use of AI to write convincing English. Also the ones people forget, such
as text messages, phone calls, QR codes, and someone walking in wearing a hi-vis.
Reading an email properly
Sender domains, display-name spoofing, reply-to mismatches, urgency as a tactic, and the
specific pressure signature of a request pretending to come from a director.
Invoice and payment fraud
How changed bank details work, why "the finance director asked me to do it quickly" is the
whole attack, and what a verification step should look like.
Passwords and MFA
Why reuse is the real problem, how password managers work, and what to do when an MFA prompt
arrives that you did not trigger, which is a genuine attack in progress and widely ignored.
Data handling
Where company data is allowed to live, the risks of personal devices and shadow IT, and what
to do with a lost laptop or phone.
Reporting
Who to tell, how fast, and the firm commitment that nobody gets in trouble for reporting.
We tailor the examples to your business. A session for a firm of solicitors or accountants uses
conveyancing and payment fraud, one for a manufacturer uses supplier impersonation, and one for a
defence supplier covers the targeting that comes with being part of a sensitive supply chain.