Technical cybersecurity training for development and defence teams

No generic OWASP slides. We teach secure coding and threat detection over the real flaws we find in our audits — often, over your own code.

Why generic technical training does not reduce vulnerabilities

An OWASP Top 10 course with textbook examples does not connect with what a developer sees day to day. Training that changes behaviour starts from real vulnerabilities, ideally found in your own code during an audit or pentest, and is delivered by whoever exploited them — not by someone who only read about them. The same applies to defence teams: teaching detection requires showing the traces a real attacker actually leaves, not a theoretical checklist.

Programmes we deliver

  • Secure coding: the OWASP Top 10 explained over real code, using the flaws we find in audits
  • Defence team training: what traces an attacker leaves and how to spot them before exfiltration
  • Dedicated training for Google Workspace and Microsoft 365 administrators on common misconfigurations
  • Bespoke sessions built from the findings of a previous audit or pentest, with the development team fixing live

How we prepare the technical training

  1. Technical assessment: We review the stack, the language and, where available, the report of a previous audit or pentest to build the training on real findings.
  2. Material built on your own code: Where possible, examples are built on your own code, anonymised where needed, not on textbook examples.
  3. Hands-on session: On-site, in small groups that allow live practice over the code, not just slides.
  4. Technical evaluation: A reinforcement exercise with new vulnerabilities to check the learning translates into code, not just a theoretical test.
  5. Compliance documentation: Attendance record and contents in the format an ISO 27001 or NIS2 auditor expects.

What the team receives

  • Training material built on your own code or real stack
  • Attendance record and evaluation per participant
  • Report on the team's most repeated failure patterns
  • Documentary evidence for ISO 27001 or NIS2 audits
  • Reusable reference guide for new joiners

When this training fits

  • Development teams carrying the same flaws audit after audit
  • Companies that have run a pentest and want the team to understand the findings, not just patch them
  • Defence (blue) teams that need to train detection with real techniques, not just MITRE ATT&CK theory
  • Google Workspace or Microsoft 365 administrators managing configuration with no dedicated security training

Frequently asked questions about technical training

How much does technical training cost?

A secure coding programme with several sessions and hands-on work over your own code is quoted per project, based on number of sessions and team size. We give a fixed price before starting, and the first scoping call is free.

Do you need access to our code to prepare the training?

It is not required, but it improves the result significantly. If you come from a pentest or code audit with us, we already have the findings; otherwise we work with anonymised snippets you provide or with examples in the same language and framework you use.

Is this the same as a source code audit?

No. A code audit finds and reports concrete vulnerabilities in your product; this training teaches the team not to make them in the future, often using the findings of a previous audit as teaching material. The usual sequence is to audit first, then train on what was found.

Do you also train detection, not just secure development?

Yes, it is a separate programme within this same technical training: we teach defence teams what traces an attacker leaves in logs, network traffic and endpoint behaviour, based on the techniques we use ourselves in pentesting and red team engagements.

Related resources

Request technical training