General staff
Recognising phishing, social engineering and account compromise, with the reporting route made explicit.
Training works when people recognise the thing when it happens to them. Sessions are built around scenarios drawn from real assessment and investigation work, and pitched at the group in the room.

Teams that recognise a real attempt and know exactly who to tell.
Recognising phishing, social engineering and account compromise, with the reporting route made explicit.
Secure configuration, logging, patching discipline and how findings from an assessment should be worked.
First-hour actions, evidence preservation and the handover into a forensic examination.
Risk ownership, disclosure obligations and the decisions only executives can make during an incident.
Tell us what the estate looks like and what concerns you about it. We will say plainly whether this engagement is the right one.
Contact Cyber Keen