Instead of a one-off training, we design and help run a year-round, measurable information security awareness programme that becomes part of your organisational culture.

// Why it matters

Why Information Security Awareness Program matters

Awareness is not something said once and forgotten; it becomes behaviour through repetition, examples and feedback. A programme approach helps your employees recognise threats and make the right behaviour a habit, which makes your technical defences more effective.

// Scope

What does it cover?

Programme design

We design the annual awareness programme and calendar around your audience and risks.

Role-based training

We prepare separate content for employees, managers and software teams and deliver hands-on training.

Phishing simulations

We measure behaviour with controlled fake-email scenarios and give instant feedback.

Communication campaigns

We keep the topic alive all year with emails, posters and short briefings.

Policy and KVKK content

We convey information security policies and personal data responsibilities clearly.

Measurement and improvement

We measure participation and behaviour change and improve the programme from results.

// Method

How do we proceed?

  1. Current-state and risk analysisWe determine the current awareness level and priority risks.
  2. Programme and calendar designWe prepare a programme covering goals, content, channels and calendar.
  3. Delivering training and campaignsWe run the training and communication campaigns as planned.
  4. Simulation and measurementWe run simulations and measure results.
  5. Reporting and next periodWe report results and build the plan for the next period.
// Deliverables

What do we deliver?

  • Annual awareness programme and calendar
  • Role-based training content
  • Campaign and briefing materials
  • Phishing simulation reports
  • Participation and behaviour measurement reports
  • Executive summary and improvement recommendations
// Who is it for?

Who is this service for?

Those with regular awareness obligations under ISO 27001 and KVKKOrganisations with many or dispersed employeesThose who want to reduce phishing-related incidentsManagers who want to build a security culture
// FAQ

Frequently asked questions

What is the difference between a programme and a one-off training?

A one-off training gives information; a programme turns information into behaviour through repetition, simulations and measurement and lets you show its effect.

Doesn’t testing employees hurt morale?

Simulations are for teaching, not blaming. Results are reported as overall trends, not individuals.

Is the content tailored to our organisation?

Yes. We adapt content to your sector, the systems you use and employee roles.

// Related services

Services you can combine

// Information request

Get information about Information Security Awareness Program

Fill in the short form and we will get back to you as soon as possible. For a more detailed preliminary assessment you can also use the needs-analysis form below.

    Open the detailed needs-analysis form

    If you share your current situation in a few questions, we can give you a clearer preliminary assessment and scope proposal.

      Focus topics

      Let’s talk about Information Security Awareness Program

      Share your needs and current situation, and we will define the right scope and roadmap together.