Cybersecurity · People

Security Awareness Training

Training fails when it is an annual video nobody remembers. It works when it is short, specific and about the messages your staff genuinely receive — the fake invoice, the payroll change request, the multi-factor prompt that arrives unexpectedly.

We run awareness as an ongoing, low-friction programme with reporting that satisfies insurers and boards without consuming a working afternoon.

The problem

Generic training does not change behaviour

Most staff already know they should not click strange links. What they do not know is what a legitimate supplier thread looks like when it has been hijacked, why an unexpected approval prompt at 11pm matters, or who to tell when something feels off at 4:55 on a Friday.

There is also a cultural problem in many workplaces: reporting a mistake feels risky. If someone believes they will be blamed for clicking, they will stay quiet — and the window in which the incident could have been contained cheaply closes.

Effective awareness work targets both: practical recognition of current tactics, and a reporting route with no penalty attached.

What we do

How the programme runs

  1. 01

    Short, frequent modules

    A few minutes at a time, delivered on a schedule, covering one recognisable tactic each. Long sessions are retained less and resented more.

  2. 02

    Content matched to the role

    Finance staff get invoice and banking-change scenarios. Reception and administration get impersonation and phone-based pretexting. Leadership gets the approval requests that use their names.

  3. 03

    Practise the report, not just the spot

    Staff use the report button during training so the action is familiar. Every report receives an answer, which is what keeps the habit alive.

  4. 04

    Simulations without humiliation

    Phishing simulations are used to measure and coach, not to name individuals. Results are reported as trends, with targeted follow-up where a pattern appears.

  5. 05

    Onboarding from day one

    New staff receive a security introduction as part of their setup, including password practice, device rules and the escalation path.

  6. 06

    Reporting you can hand over

    Completion rates, simulation performance and policy acknowledgements exported for insurers, auditors and board packages.

Business outcome

What improves

  • Faster reporting of suspicious mail
  • Fewer approved fraudulent payments
  • Measured, documented compliance
  • Confident finance verification habits
  • Blame-free security culture
  • Evidence for cyber-insurance renewals

Where this fits

This work is delivered as part of the wider security programme described on cybersecurity services for St. Catharines organizations.

Questions

Frequently asked questions

How much staff time does this take?
Typically a few minutes per person per month, plus occasional simulations that take seconds when recognised. New-hire onboarding is a single short session.
Do insurers accept this as evidence?
Insurers generally ask whether staff training is delivered, how often, and what proportion of staff completed it. We provide that reporting directly, which is usually what the application form is asking for.
Should we tell staff simulations are happening?
Yes. Announcing that simulations are part of the programme, without saying when, keeps the exercise honest and keeps trust intact. The aim is a reporting reflex, not a gotcha.

Next step

Talk to Griffin IT Group about your St. Catharines IT environment

Tell us how your technology is set up today and what is getting in the way. We will walk through your environment, outline the gaps we see and recommend a practical path forward.