Security awareness is about educating and empowering employees as the first line of defence. Most successful attacks still begin with a person being convinced to click, approve, or pay — and no technical control fully compensates for that.
As an active trainer and blogger, I run role-based programmes rather than one-size-fits-all slide decks: phishing and social engineering for everyone, secure coding for developers, privileged-access hygiene for administrators, and fraud and data-handling scenarios for finance and HR.
Programmes are reinforced with simulated phishing campaigns, short refresh modules, onboarding tracks, and measurable outcomes — click rate, report rate, and time-to-report — so you can demonstrate genuine behaviour change to auditors and leadership rather than mere training completion.
Why it matters
- The human layer is the most frequently targeted attack surface
- Role-based content stays relevant, so attention and retention rise
- Simulations turn awareness into measurable behaviour change
- Satisfies mandatory training requirements across major frameworks
My approach
How the engagement runs
Typical engagement: baseline phishing simulation, role-based curriculum design, live and recorded training delivery, ongoing simulation cycles, and metric reporting to leadership.


