Service reference

Turn your team into your strongest defence

Five-minute monthly modules and phishing simulations built around the attacks your sector actually receives.

Clear scope · friendly support · practical advice

Last reviewed

The short version

Included as standard

Everything here is covered by the agreed fee. Anything outside it is quoted in advance.

  • Monthly micro-training modules (under 5 minutes each)
  • Realistic phishing simulation campaigns
  • Spear-phishing tests targeting high-risk roles
  • New starter security induction programme
  • Compliance-specific modules (FCA, GDPR, DORA)
  • Executive-level training on whaling and BEC attacks
  • Detailed reporting on click rates and completion
  • Automated remedial training for users who fail simulations

The person the attacker is actually targeting

Attackers rarely start with a zero-day or a brute-force run at your firewall. They start with a person. Someone clicks a link in an email that looked legitimate. Someone replies to what seemed to be a request from their CEO, possibly built with AI voice cloning. Someone types credentials into a pixel-perfect copy of a real login page.

The government’s Cyber Security Breaches Survey 2025/2026 found that 38% of UK businesses experienced a phishing attack, and that 69% of the businesses and charities breached rated phishing the most disruptive attack they faced. It is the most common threat your staff meet and the one most likely to hurt.

Technical defences matter. Cybersecurity services and managed detection and response catch a great deal. They will not catch every phishing email, every social engineering call or every impersonation attempt. The last control is the person at the keyboard, and training decides which way that goes.

Why annual security awareness training does not change behaviour

Most companies tick the box with one annual session: a long slideshow, a quiz, a certificate nobody opens again. It does not hold. Within a month or so, people are back to their old habits.

Effective training is short, frequent and immediately relevant. Our programme sends one module a month, each under five minutes, covering a single topic with real examples drawn from attacks on UK businesses. Short content gets finished. Hour-long content gets skipped.

Phishing simulations that mirror real attacks

Phishing simulation is the part of the programme that actually tells you something. We send realistic fake phishing emails to your team and measure who clicks, who reports and who hands over credentials.

Our simulations are not generic. We craft campaigns that mirror the specific threats facing your industry. For financial services firms, that means fake wire transfer requests, spoofed investment platform notifications, fraudulent invoice emails from known suppliers, and impersonation of regulatory bodies. These are the exact techniques attackers use against hedge funds, PE firms, and wealth managers in London.

Users who click a simulated phishing link see an immediate coaching page that explains what they missed, what the red flags were, and how to handle similar emails in future. This real-time feedback is significantly more effective than retroactive training because the mistake is fresh and the lesson sticks.

If you are still deciding whether simulated phishing is worth running, we set out the evidence separately — what click rates really tell you, where the numbers mislead, and what changes after a year — in anti-phishing testing for London firms.

The roles attackers go after first

Finance teams, executive assistants and senior leadership are the most targeted people in any organisation. They move money, they carry authority, and their email addresses are usually easy to find. A standard simulation does not stretch them.

So we run quarterly spear-phishing campaigns aimed specifically at those roles, using personalised, well-researched approaches. They test whether your highest-risk people can spot a convincing impersonation, which is the thing general training never quite reaches.

Why punishing the clicker lowers your reporting rate

This is the single biggest determinant of whether a programme works, and it is the easiest part to get wrong.

The NCSC is explicit on this point: naming, shaming or disciplining staff who fall for a phishing simulation is counterproductive. It does not reduce clicking. It reliably reduces reporting — and reporting is the metric that actually protects you. A user who clicks and tells you within two minutes is far more valuable than one who clicks, panics, and says nothing for a week.

Practically, that means:

  • No leaderboards of who clicked, at any stage of the programme.
  • Never send simulation results to a clicker’s line manager as a performance matter.
  • Make reporting a single button, and thank every person who uses it — including the false positives.
  • Measure report rate as the headline metric, not click rate.

Firms that only track click rate optimise for silence. The organisations that detect real attacks early are the ones where reporting a mistake is socially free.

A one-off phishing assessment to start

The one-off assessment is a straightforward way to find out where you stand. It is a single fixed fee, quoted on enquiry, and it covers one realistic simulation of your own staff, immediate coaching for anyone who clicks, a board-ready report and a 30-minute debrief. You keep the report whatever you decide next.

For larger teams the same test prices per seat, per month, with continuous simulations rather than a one-off. The ongoing programme — quarterly simulations, continuous training for repeat clickers, a monthly board report — is priced the same way. One test is a snapshot; risk moves as staff and tactics change, so tell us your headcount and we will put a figure to whichever suits you.

What security awareness training costs

Across the UK market this is priced per user, per year. What moves it is whether simulation and management are included. Realistic 2026 ranges:

  • Platform-only licence (you run it): £15–£30 per user/year
  • Fully managed programme (the provider runs campaigns, triages reports and produces board reporting): £35–£60 per user/year
  • Add-on quarterly spear-phishing for high-risk roles: typically £1,000–£2,500 per year for a finance/exec cohort

For a 50-person London firm, a managed programme is usually £1,750–£3,000 per year. That is materially less than the excess on most cyber insurance policies.

Training evidence for Cyber Essentials, ISO 27001 and DORA

Awareness training is one of the few controls that turns up in almost every framework a London firm meets:

Framework Requirement
Cyber Essentials Not a technical control, but user education underpins the password and malware requirements — see our v3.3 breakdown
ISO 27001 Annex A 6.3 requires documented, ongoing awareness education with evidence of completion
DORA Article 13 mandates ICT security awareness programmes, including for senior management
FCA operational resilience Expects demonstrable staff capability to recognise and escalate incidents
Cyber insurance Increasingly a condition of cover, and one insurers audit after a claim

The practical implication: keep the completion records. Most firms can describe their training but cannot evidence it, and evidence is what an auditor or insurer asks for.

Programme targets to measure against

These are the targets we set with a firm starting from no formal programme. They are goals to work toward, not results we are claiming on your behalf:

Metric Typical starting point Target by month 6
Phishing click rate 25–35% Under 5%
Report rate Under 5% Above 60%
Median time to report Never / days Under 10 minutes
Training completion Above 90%
Repeat clickers Under 3% of staff

Click rate falling while report rate stays flat is a warning sign, not a success — it usually means people have learned to recognise your simulations rather than phishing.

Roll it out without annoying everyone

  1. Baseline first, quietly. Run one simulation before any announcement, so you have an honest starting number.
  2. Announce the programme, not the test. Tell staff a programme is starting and why. Do not tell them when simulations will arrive.
  3. Deploy the report button before the first campaign. Asking people to report with no mechanism guarantees a bad first result.
  4. Start monthly and short. Five minutes, one topic. Quarterly hour-long sessions do not change behaviour.
  5. Brief the executive team separately. They are the most targeted and the most likely to ask for an exemption. Exempting them is how business email compromise succeeds.
  6. Review at 90 days. Adjust difficulty to your actual report rate rather than a vendor default.

Hand auditors the evidence with monthly reporting

Every month you get simulation click rates, report rates, completion rates and the trend over time. We show which departments and roles are moving and which need more attention, then adjust the programme rather than repeating it.

For FCA-regulated firms, those reports are the evidence that your training meets expectations under SYSC, DORA and GDPR. When an auditor asks what you are doing about human risk, you hand them the dashboard instead of describing it.

Last reviewed , and maintained by the Nerdster engineering team.

Tell us what would make IT easier

Share what is causing problems or taking up time. Our London team replies during business hours.

We respond within 2 hours during business days. Your data is handled per our privacy policy.

Contact details

0330 043 7414

Mon-Fri 8am-6pm

[email protected]

We reply within 2 hours

71-75 Shelton Street

Covent Garden, London WC2H 9JQ

IT assessment

A review of your IT, your security posture and your compliance readiness, free of charge.

  • 30-minute consultation call
  • Infrastructure & security review
  • Compliance gap analysis
  • Custom recommendations report

What you get from us

Measure the change, not the attendance

You get click rate, report rate and median time to report, tracked month by month against agreed targets. Report rate is the headline number, because a user who clicks and tells you in two minutes is worth more than one who says nothing.

Run training people actually finish

A 45-minute annual slideshow rarely changes what people do at their desks. Modules run under five minutes, arrive monthly, and cover one topic with real examples — short enough that finishing them is not a management exercise.

Simulate the attacks you actually get

Phishing simulations mirror the attacks aimed at your sector. Fake invoices, spoofed CEO requests, compromised supplier notifications — the tactics attackers genuinely use against financial services firms.

FAQ

Frequently asked questions

How is this different from the free training in Microsoft 365?

Microsoft's built-in attack simulation is useful but limited. Our programme combines custom phishing campaigns tailored to your industry, curated training content, spear-phishing of high-risk individuals, detailed analytics, and automated remediation workflows. We also manage the entire programme so your IT team does not have to.

Will our team resent being tested?

We design the programme to be educational, not punitive. Users who click phishing simulations receive immediate coaching that explains what they missed and how to spot similar attacks. There is no public shaming or disciplinary angle.

How often do you send phishing simulations?

We run 1-2 simulated phishing campaigns per month across your organisation, plus targeted spear-phishing tests for high-risk roles (finance, executive assistants, senior leadership) quarterly.

What topics does the training cover?

Phishing recognition, password hygiene, multi-factor authentication, social engineering, safe browsing, removable media risks, physical security, data handling, and regulatory obligations. Modules rotate monthly and update as threats evolve.

What does the one-off phishing assessment include?

One realistic simulation of your own staff, immediate training for anyone who clicks, a branded board report and a 30-minute debrief. It is a single fixed fee, quoted on enquiry, and the report is yours to keep whatever you decide to do next. For larger organisations the same test prices per seat instead.

Can you provide compliance evidence for audits?

Yes. We provide completion reports, simulation results, and trend data showing improvement over time. These satisfy training requirements under FCA SYSC, DORA, GDPR Article 39, and Cyber Essentials.