Cybersecurity training delivered by the people running the attacks

Most cybersecurity training is delivered by people who have never exploited a vulnerability. We teach what we find in audits: the real mistakes teams make, explained by the team that exploits them.

Why generic cybersecurity training changes nothing

The usual format —an annual video, a ten-question quiz and a certificate— ticks the box and changes no behaviour. It fails for three reasons: it uses generic examples nobody recognises as their own, it is delivered by someone who has never seen a real incident, and it addresses the whole workforce identically when a developer and someone in finance need different things. Training that works starts from concrete findings —ideally from an audit of your own organisation—, adapts to the audience profile, and repeats in short sessions instead of concentrating into one day a year.

Training programmes we deliver

  • Employee awareness: how an attacker gets in through email, the phone and corporate messaging
  • Secure coding: the OWASP Top 10 explained over real code, using the flaws we find in audits
  • Defence team training: what traces an attacker leaves and how to spot them before exfiltration
  • Leadership and board session: risk, legal accountability and what to ask your technical team
  • Readiness for the NIS2 (article 20) and ENS (op.per.4) training requirement, with documentary evidence for the auditor
  • Dedicated training for Google Workspace and Microsoft 365 administrators on common misconfigurations
  • Bespoke sessions built from the findings of a previous audit or penetration test

How we prepare the training

  1. Baseline assessment: We understand the audience profile, the sector and which incidents or previous findings exist. Without this, training ends up generic.
  2. Material adaptation: We build the examples on your reality: your technologies, your workflows and, where available, anonymised findings from your own audit.
  3. Delivery: On-site or online sessions, in groups small enough to allow questions. Live practice where the audience allows, not just slides.
  4. Evaluation: We measure comprehension at the close and, where appropriate, with a reinforcement exercise weeks later. A pass rate is not a behaviour change.
  5. Compliance documentation: We deliver attendance records, contents and evaluation in the format a NIS2, ENS or ISO 27001 auditor expects to find.

What you receive

  • Training material adapted to your organisation, reusable internally
  • Attendance record and evaluation per participant
  • Results report highlighting where the team showed most uncertainty
  • Documentary evidence for NIS2, ENS or ISO 27001 audits
  • Onboarding material for new joiners
  • Recording of online sessions, where agreed

When this service fits

  • Companies required to evidence cybersecurity training under NIS2, ENS or ISO 27001
  • Development teams carrying the same flaws audit after audit
  • Organisations that have just suffered an incident and want to close that route
  • Companies that have run a pentest and want the team to understand the findings, not just patch them
  • Companies with high turnover where security onboarding is unresolved
  • Leadership teams that need to understand their exposure to decide budget

Frequently asked questions about cybersecurity training

How much does it cost to train a team in cybersecurity?

It depends on format and number of sessions. An employee awareness session, online and around 90 minutes, starts from a fixed price per group. A secure coding programme with several sessions and hands-on work over your own code is quoted per project. We give a fixed price before starting, and the first scoping call is free.

Do you run phishing simulations as part of the training?

Phishing simulation is a separate service: it is an offensive exercise that measures real behaviour, not a class. The two complement each other well —the usual sequence is to simulate first to find where the problem is, then train on the results— but they are contracted separately. If what you want is to measure, start with phishing simulations.

Does the training count as evidence for NIS2 or the ENS?

Yes, and it is one of the common reasons for contracting it. NIS2 requires cybersecurity training for management bodies in article 20, and the ENS includes staff awareness and training among its measures. We deliver attendance records, contents covered and evaluation in the format an auditor expects, which is what actually gets asked for in the review.

Can you train our team on the use of artificial intelligence?

Yes, but we cover that from the safe AI use service, because it is not just a session: it also involves discovering which tools are in use and drafting the policy the training explains. If you only need the training session, it can be contracted standalone within that service.

Is the training on-site or online?

Both. Awareness sessions work well remotely and allow larger groups. Secure coding and technical team sessions perform better on-site, because they include hands-on work and discussion over code. We are based in Valencia and travel across Spain depending on the project.

Related resources

Request a training proposal