Questions & Objections

Questions? Good.

Everything you wanted to ask but weren't sure was a stupid question. It isn't. We get these a lot.

Before we start

Why awareness
was never the point.

The security industry has spent decades chasing awareness. Modules, posters, phishing tests, intranet campaigns, newsletters, lunch-and-learns. An entire infrastructure built around one goal: make people aware.

It worked. People are aware. They still click.

96% of employees who took a risky security action knew it was risky at the time. Read that again. They weren't missing the information. They had it, and acted against it anyway. So what exactly is more information going to fix?

Awareness is the knowledge layer. What a phishing email looks like, why reusing that password is a bad idea, what to do with a request that feels off. It matters... nobody acts on a threat they can't recognise. But knowing has never been the thing standing between your organisation and a breach.

So where does awareness actually sit? (Engagement + Awareness) × Culture = Instinct.

Awareness is a payload, and a payload needs a delivery mechanism that works. Engagement is that mechanism: genuine attention and real emotional signal, because without those the brain doesn't bother encoding what it's being shown. Fire the payload without the mechanism and it never lands. That's twenty years of e-learning in one sentence.

Then look at where culture sits. Outside the bracket. Culture doesn't add to what engagement and awareness build, it multiplies it, which means it can also wipe it. A culture of fear equals zero. Not reduced... zero.

What comes out of the other side is instinct. The person who pauses before clicking, not because they remembered a policy, but because something trained by experience flags it as wrong first. The colleague who escalates the odd request instead of dealing with it alone, because that is simply what people do here. The response that holds up when someone is tired, distracted, and being actively worked on by somebody who does this for a living.

None of that can be delivered in a module. It gets designed, rehearsed, and repeated until it runs without effort.

Which is why nearly every question below has the same answer buried somewhere inside it.

Awareness multiplied by a culture that doesn't back it still equals zero.

The Behaviour Formula is the framework behind everything we build. Engagement earns the attention. Awareness is the knowledge that lands once it has. Culture is the multiplier that either compounds the behaviour or cancels it outright. Instinctive behaviour is the output, and it's the only security outcome that actually matters.

How we think about this

The Behaviour Formula: Three stages. One outcome.

The Attention

Engagement

The creation of genuine attention and emotional signal. Without those two things the brain doesn't bother encoding what it's being shown, so nothing downstream has anything to work with. Engagement isn't about making training fun. It's about earning attention you currently don't have.

The Knowledge

Awareness

The knowledge layer: what good looks like, what a threat looks like, what to do about it. Awareness is a payload, and a payload needs a delivery mechanism that works. Send it on its own and you get a workforce that can pass a quiz and still click at 4pm on a Friday.

The Multiplier

Culture

Where behaviour becomes normal. You can run the best session in the world and people can leave genuinely fired up, then walk straight back into an environment that undoes all of it before the week is out. Culture is what people do when nobody is watching.

The Outcome

Instinct

Security behaviour that requires no conscious effort, under pressure, distraction or fatigue. The right call made in two seconds because the pattern is embedded deeply enough to run on its own. Built through repeated practice in conditions that simulate real pressure. Not once a year, and not in a low-stakes click-through.

Read the full argument on The Behaviour Formula page, or take the free Behaviour Formula Check(opens in new tab) to see where your programme is losing people.

The Basics

Isn't this just a game?

No. Though we understand why it looks like one from the outside.

The escape room format is a delivery mechanism, not the point. What we're actually doing is placing people inside a realistic, high-pressure scenario and making them practise the decisions that determine whether your organisation gets breached or doesn't. The story is fiction. The behaviours it rehearses are entirely real.

There's a meaningful body of research behind why this works. Immersive, experience-based learning produces measurably better retention, higher confidence in applying skills, and more durable behaviour change than any instruction-based alternative. The game isn't the gimmick. The game is the science.

THE NEUROSCIENCE OF IMMERSIVE LEARNING →

What are the actual learning outcomes?
How is this different from e-learning or annual compliance training?
We've tried gamification before and it didn't work. Why is this different?

Cost & Value

This costs more than our current training. How do you justify that?

Fair question. Let's actually look at it.

Your current training costs less per head. It also doesn't change what people do. So what you're actually paying for is the audit trail, not the outcome. That's a defensible position for compliance. It's a bad position for risk reduction.

Immersive training costs more to deliver because it does more. The organisations that benchmark it properly find that the cost difference is marginal against the savings from incidents that didn't happen, breaches that didn't escalate, and response times that improved because people had already practised. IBM's 2025 data puts the average cost difference between organisations with tested security programmes versus those without at approximately £1.2 million per breach.

We're not cheap. We're also not a line item you complete and forget.

THE FINANCIAL CASE FOR BETTER TRAINING →(opens in new tab)
IMMERSIVE LEARNING ROI CALCULATOR →

How is pricing structured?

Logistics & Practicalities

Our teams are remote or distributed. Can this still work for us?

Yes. And the short answer is: a programme that only works at HQ isn't a programme.

Every product in our ecosystem is either fully digital and solo-capable, ships to wherever your people are, or is specifically designed to pull distributed teams into a shared narrative even when they're not in the same room. SHIFT delivers immersive, narrative-led scenarios through a browser with no downloads, no setup, and no facilitation required. ALT works solo or as a group on people's own devices. CTRL+Vish is location-agnostic by design. ESC is a physical kit that ships to any location with a team and a table. With a train-the-trainer programme in place, regional offices run their own sessions without waiting for central coordination.

There's also a pre-engagement layer worth knowing about. Before a live event runs, distributed teams can be pulled into the narrative through digital challenges, in-character communications, and cross-location missions that require teams in different sites to coordinate. By the time the main experience kicks off, remote colleagues aren't watching from the outside. They've already played their part.

Remote isn't a constraint. It's a design problem we've already solved.

HOW WE WORK WITH HYBRID & DISTRIBUTED TEAMS →

How much space do I need?
How long does a session take?
Can you train all of our people, not just a subset?

Does it fit us?

We already do cyber security awareness training. Why would we need this?

Because knowing and doing are different things.

Your programme might be telling people what a phishing email looks like. That's information. Behaviour is what happens when a message that looks almost right arrives at 4pm on a Friday, when someone's halfway through something else and not paying close attention. That gap is where incidents happen. And information alone doesn't close it.

We're not asking you to stop what you're doing. We're asking you to be honest about what it's achieving. If your incident data is improving, great. If completion rates are the main thing going up, that's a different story.

TAKE THE BEHAVIOUR FORMULA CHECK →(opens in new tab)

Will this meet our compliance requirements?
Is this suitable for non-technical staff?

Still got a question we didn't answer?

Book a call and we'll give you a straight answer.
No pitch, no pressure.