Nearly every incident starts with a person — a convincing email, a payment request that looked like it came from a director, a login prompt that was not quite right. The traditional answer is an annual training session that everybody sits through and nobody remembers. We run it as short online courses a few minutes at a time, with simulated phishing that reflects what is actually being sent to businesses now. Anyone who clicks gets follow-up training automatically, and you get reporting that shows where the risk sits rather than a completion tick.
Measured, not ticked
Training people will actually do, and reporting you can show
What is included
- Baseline assessment of where the risk currently sits
- Short online courses, a few minutes at a time
- Simulated phishing based on what is being sent now
- Automatic follow-up training for anyone who clicks
- Policy distribution and acknowledgement tracking
- Reporting by user, team and department
- Evidence for Cyber Essentials, insurers and client questionnaires
What changes
You can see where the risk actually is
A baseline, then a number that moves — by person and by team, rather than a folder of completion certificates.
People engage with it
A few minutes online at a time, delivered continuously, instead of one long session in January that everybody has forgotten by March.
The questionnaire answers itself
Completion records and phishing results already documented when an insurer, auditor or client asks what training you run.
Method
How Commstec works
Assess
Document what exists, including the parts nobody wants to discuss.
Standardise
Remove the variation that causes most incidents.
Secure
Apply controls and prove they are working.
Operate
Run it day to day against agreed measures.
Improve
Review quarterly with real data, not a slide.