Cybersecurity training delivered by the people running the attacks

Five programmes, one principle: we teach what we find in audits, not a generic syllabus. Pick the one that matches who receives it — leadership, technical teams or the whole workforce.

Why generic cybersecurity training changes nothing

The usual format —an annual video, a ten-question quiz and a certificate— ticks the box and changes no behaviour. It fails for three reasons: it uses generic examples nobody recognises as their own, it is delivered by someone who has never seen a real incident, and it addresses the whole workforce identically when a board member, a developer and someone in finance need different things. Training that works starts from concrete findings —ideally from an audit of your own organisation—, adapts to the audience profile, and repeats in short sessions instead of concentrating into one day a year.

Pick the programme that matches the audience

  • Training for leadership and boards: risk, legal accountability and the NIS2 and DORA training requirement
  • Technical training for development and defence teams: secure coding over the OWASP Top 10 and early detection
  • Employee awareness: how an attacker gets in through email, the phone and corporate messaging
  • Safe AI use training: what not to paste into ChatGPT or Copilot, and how to spot a shadow AI risk
  • Regulatory workshops: working sessions on NIS2, DORA or the ENS for the team implementing compliance

How we prepare the training

  1. Baseline assessment: We understand the audience profile, the sector and which incidents or previous findings exist. Without this, training ends up generic.
  2. Material adaptation: We build the examples on your reality: your technologies, your workflows and, where available, anonymised findings from your own audit.
  3. Delivery: On-site or online sessions, in groups small enough to allow questions. Live practice where the audience allows, not just slides.
  4. Evaluation: We measure comprehension at the close and, where appropriate, with a reinforcement exercise weeks later. A pass rate is not a behaviour change.
  5. Compliance documentation: We deliver attendance records, contents and evaluation in the format a NIS2, DORA, ENS or ISO 27001 auditor expects to find.

What you receive

  • Training material adapted to your organisation, reusable internally
  • Attendance record and evaluation per participant
  • Results report highlighting where the team showed most uncertainty
  • Documentary evidence for NIS2, DORA, ENS or ISO 27001 audits
  • Onboarding material for new joiners
  • Recording of online sessions, where agreed

When this service fits

  • Companies required to evidence cybersecurity training under NIS2, DORA, ENS or ISO 27001
  • Development teams carrying the same flaws audit after audit
  • Organisations that have just suffered an incident and want to close that route
  • Companies that have run a pentest and want the team to understand the findings, not just patch them
  • Companies with high turnover where security onboarding is unresolved
  • Leadership teams that need to understand their exposure to decide budget

Frequently asked questions about cybersecurity training

How much does it cost to train a team in cybersecurity?

It depends on the programme and number of sessions. An employee awareness session, online and around 90 minutes, starts from a fixed price per group. A technical programme with several sessions and hands-on work over your own code, or a leadership session, are quoted per project or per session. We give a fixed price before starting, and the first scoping call is free.

Does the training count as evidence for NIS2, DORA or the ENS?

Yes, and it is one of the common reasons for contracting it. NIS2 requires cybersecurity training for management bodies in article 20, DORA requires something equivalent for financial entities, and the ENS includes staff awareness and training among its measures. We deliver attendance records, contents covered and evaluation in the format an auditor expects, which is what actually gets asked for in the review.

Can you train our team on the use of artificial intelligence?

Yes, it is its own programme: we teach what may and may not be pasted into ChatGPT, Copilot or other assistants, and how to spot a shadow AI risk. If you only need the training session, it is contracted on its own. If you also need to discover which AI tools your team is actually using and draft a usage policy, that is a broader project we offer through the safe AI use service.

Is the training on-site or online?

Depends on the programme. Awareness and leadership sessions work well remotely and allow larger groups. Technical team sessions and regulatory workshops perform better on-site, because they include hands-on work and group discussion. We are based in Valencia and travel across Spain depending on the project.

Specialised services

Related resources

Request a training proposal