Security & IntelligenceSecurity training
Security awareness training your staff will remember
For companies that want every employee to spot phishing, use strong passwords and two-factor authentication, and handle information with care. Short, practical sessions in English or Italian, built on real examples from your own work, with agreed phishing simulations to keep skills fresh.
- Real examples
- messages like the ones your team gets
- English or Italian
- in the language your team speaks
- All year round
- short refreshers and agreed simulations
Action required: your mailbox closes today
We detected unusual activity on your account. To keep your mailbox, confirm your password within 2 hours.
- SenderNot your company’s domain
- PressureA deadline to make you rush
- RequestIT never asks for your password
- LinkA look-alike login page
- Phishing and fake invoices
- Passwords and 2FA
- Handling confidential files
- Working on public Wi-Fi
Example of a phishing email used in training · not a real message
01Why it matters
Many attacks start with a single message
A convincing email, a fake invoice, a call from “IT”. Technology helps, but people who recognize the trick stop it before it starts.
Phishing and fake invoices
Emails that copy suppliers, banks or your own IT team to steal passwords or money.
Reused passwords
One password leaked from a website can open email, VPN and cloud accounts.
Working from anywhere
Hotel and café Wi-Fi, shared computers and devices left unlocked.
Requests under pressure
A “manager” asking for an urgent transfer, a “supplier” changing bank details.
02What your staff learn
Practical habits, not lectures
Each session is short and built around examples from your sector and your tools. People leave knowing what to look for and what to do when in doubt.
- Spotting phishing, fake texts and phone scams
- Strong passwords and a password manager
- Two-factor authentication on key accounts
- Handling confidential information
- Public Wi-Fi, travel and remote work
- Company policies, explained simply
- How and to whom to report a doubt
- Short refreshers through the year
Phishing simulations, agreed and fairPlanned with management, run with care
- Scope agreed with managementin writing, before anything starts Signed
- Staff told simulations may happenat the kickoff session Done
- Test email: fake delivery noticesent during week 2 Planned
- Debrief with the whole teamwhat to spot, what to do Planned
- Results
- team totals, no names
- Goal
- learning, not blame
- INFOStaff reported an email
- OKIT: phishing, blocked
- OKRemoved from all inboxes
- OKThanks sent to reporter
03Training topics
What we cover, topic by topic
We pick the topics that fit your risks and your roles. Everyone gets the basics, and some roles get more.
Phishing and social engineering
Spot fake emails, texts and calls, including those that use your suppliers’ names.
- Sender, links and attachments
- Fake invoices and bank detail changes
- Phone and text message scams
Passwords and 2FA
Fewer, stronger passwords and a second factor where it counts.
- Password managers in practice
- Setting up two-factor authentication
- What to do after a leak
Handling information
Who can see what, and how to share it safely.
- Confidential documents and labels
- Sharing links and attachments
- Clean desk, printing and disposal
Unsafe networks and travel
Working safely outside the office.
- Public Wi-Fi and VPN
- Laptops and phones on the move
- Trade fairs and hotels
Company policies
Your rules, explained so people follow them.
- Acceptable use and devices
- Remote work rules
- How to report an incident
Ongoing training
Short refreshers so habits stick.
- Short sessions through the year
- Agreed phishing simulations
- Updates when new scams appear
How sessions run
In person or online
At your offices or by video call, in small groups.
English or Italian
Sessions and materials in the language your team speaks.
Built for your company
Examples from your sector, your tools and your suppliers.
By role
Extra focus for finance, HR, management and IT admins.
04How we work
From the first meeting to habits that stick
We plan training with you, keep it short and come back to it over time. That is what makes it work.
-
Agree the goals
Who takes part, which risks matter most, which language and which format.
With management -
Tailor the content
Examples from your sector, your tools and the messages your staff really receive.
Your real examples -
Train
Short, practical sessions in person or online, with exercises and time for questions.
In EN or IT -
Keep it fresh
Short refreshers and agreed phishing simulations, with team results and no blame.
No names, no blame
05Questions
What managers ask before booking
Tell us how many people, which languages and which roles. We will suggest a format that fits.
Simulations only by agreement. We run phishing simulations only with written approval from management, and we share results at team level.
How long are the sessions?
Short. Most staff need about an hour per topic, with extra time for roles that handle money, personal data or admin access. We agree the format with you.
Do you run phishing simulations?
Yes, but only with written approval from management. Results are shared at team level, without naming or shaming anyone. The goal is to learn, not to catch people out.
Can the training be in English and Italian?
Yes. Sessions and materials are available in both languages, even within the same company.
Is the training the same for everyone?
No. Everyone gets the basics. Finance, HR, management and IT administrators get extra examples based on the risks they face.
Do we get training records?
Yes. You receive attendance and topic records that you can keep with your security and privacy documentation.
Want your team to spot the next phishing email?
Tell us how many people, which languages and which roles. We reply by email with a proposal for a first session.