immersive training

Cyber Security Awareness Month Training That Changes Behaviour.

October is the one month your board actually pays attention to cyber security. Don't waste it on a phishing email, a webinar nobody watched and a fresh poster for the kitchen.

We build programmes that put people inside the experience, where cyber threats feel real, personal and urgent. Because they are.

Runs in October. Runs in any month you want to, really.

why cyber security
awareness month
matters

Cyber Security Awareness Month is primetime for boosting your company's cyber defences. Not an excuse to wheel out the same tired slide deck... but a chance to change what people actually do when it counts.

You get budget, board attention and permission to interrupt people's day. Three things you don't get in February. The only question worth asking is what do you spend them on.

— What they're up against

Five attacks. Seconds to decide.

Your people could probably name all five. But naming them and handling them at four o'clock on a Friday are different skills entirely.

  • Phishing

    Phishing is still one of the easiest ways into a business. Your team has already sat through the "check the sender address" slide. Did it stick? Use the month to let them practice spotting suspicious messages under real conditions instead of hearing about them again. 

  • Ransomware

    One dodgy attachment, opened by one person having a busy Tuesday. Knowing that fact has never stopped a single attack... reacting correctly in the first ten minutes has. Give your people the chance to build that reaction before they need it

  • AI-Enabled Attacks

    AI is behind the current generation of scams. Voice calls that sound like your CFO, emails polished enough to fool the sceptics, and not a spelling mistake in sight to give it away. A checklist can't catch that. Instinct can, and instinct comes from rehearsal.

  • Social Engineering

    Nobody bothers with your firewall when they can just ask. Urgency and trust, weaponise, usually by someone friendly who has already done their homework on you. Teach your team to feel it happening under pressure, not just in a slide deck.

  • Business Email Compromise

    No malware, no alarms, no red screen. Just a supplier with new bank details, or someone senior asking for something urgent and slightly odd. It's the attack that takes the most money and looks the most like normal work. Pausing to verify should be a habit, not a policy.

— Why october usually fails

Why your cyber security awareness month is forgotten by November

Human error gets blamed for nearly every breach. Convenient, isn't it? One label, and the tired slide deck gets to stay another year. People don't click bad links because they're careless. They click because nobody ever let them practise saying no.

Picture the standard version. A company-wide email. Posters in the break room. A themed slide deck everyone has to endure. It achieves one thing:

boring the sh*t out of your team

Description text

Schemes like that are designed to educate, and education doesn't equal change. Change comes from practice, repetition and actually giving a toss. Our programmes engage your people first, then let them rehearse the decisions... spotting the message that isn't right, making the call, saying no to someone senior who's asking for something they shouldn't have.

what should your cyber
security awareness month
include?

01

Thanks to AI, phone scams are convincing enough to fool people who think they're unfoolable. Reading about vishing won't prepare anyone for a persuasive voice on the line. Taking the call will. 

02

Password Security

Don't skip the basics. Strong passwords and two-factor authentication are still two of the most effective barriers there are. Everyone's heard the lecture, so don't repeat it... focus on the habits people will actually keep.

03

Social Engineering

Hacking is rarely a genius in a basement defeating your firewall. Far more often it's someone talking a helpful colleague into handing over a detail they shouldn't. Much less exciting, we know.

04

Reporting suspicious activity

People can't report what they can't recognise, and won't report what they don't know how to report. Make it automatic: spot it, know who to tell, and have the confidence to speak up while you're still not sure. A fast report is often the difference between a near miss and an incident

05

Your leadership team has a specific job during an attack. Knowing it on paper isn't the same as doing it at speed with half the facts. Let them rehearse the decisions before they're making them for real.

06

Cyber Resilience

Awareness is a small part of resilience. Your team needs to see how their own actions connect to the security of the business, and see the consequences play out somewhere safe.

07

Security Culture

Reinforce the good behaviours, celebrate the catches, and make it clear security isn't the IT team's private hobby.

— let's do something about it

Here's the kind of thing we build.

Depth, duration and how far into your organisation we go is what separates them. Facilitated sessions happen at your premises, and everyone who can't be in the room gets the digital scenarios, so remote and hybrid teams aren't left reading about it.

The Scout

from £5,000

  • A facilitated escape room, a week of kit, and a SHIFT campaign for everyone who wasn't in the room. You get your baseline.

The Operative

from £12,000

  • A facilitated escape room, a week of kit, and a SHIFT campaign for everyone who wasn't in the room. You get your baseline.
Most Popular

The Strategist

from £20,000

  • Six to eight weeks of build-up, sessions across sites, a live CMD crisis simulation for your leadership team, and quarterly reporting.

The Architect

POA

  • A SPACE_ installation built for your organisation. Up to 1,500 people a day, custom scenario, weeks of content and activities.

Build Your Own

POA

  • A week across three countries. One day for two hundred people. A phone box and nothing else. A room built around the incident you had in March. Tell us the shape and we'll price that instead.

Not floating your boat? Good!

Every package above started life as something a client asked for that didn't exist yet. Which means the interesting version of this conversation is usually the one that starts "could you..."

Yes. Probably. A week across three countries? One day for two hundred people? A phone box and nothing else? A room built around the incident you had in March, with the debrief pointed straight at what went wrong? A programme that runs every quarter and never mentions October, not even once?

All of this is a normal week for us here. Just tell us three things: how many people, how many sites, and what you're actually trying to change. We'll tell you which example is closest and what it costs, and if none of them fit we'll say so. And build you something that does.

"Word spread so quickly we ended up with a waiting list, and people were stopping me in the corridor to tell me how much they loved it."

Andy Bagnall
CISO, The Telegraph

THe other eleven months.

Everybody does October. Then nothing for eleven months. Four weeks of effort protecting fifty-two weeks of exposure... how's that maths working out?

Every programme on this page runs in any month you like. October is just the one your board already agreed to fund. And no, we're not about to hand you a list of hashtag days to hang posters on. World Password Day has never changed anybody's behaviour.

The months that work are the ones where something is actually happening in your business:

You've had a near miss

The most teachable fortnight you will ever get, and it closes fast.

A wave of new starters

They turn up with the habits from their last job. Whoever gets to them first wins.

After a pen test or audit

You've got evidence and you've got attention. Use it before you lose it. 

A big change landing

New system, restructure, acquisition, offshoring. Every one of those rewrites who trusts who, and attackers read the news too.

Your quiet season

Use your quiet periods to make some changes and engage people who would otherwise be too busy to care.

November

The month everybody else stops. Nobody expects anything of you, which is exactly why it lands.

— people learn by doing

Why immersive experiences just work.

People learn by doing. Not by information overload, and not by being bored into submission. Our experiences drop your people into a scenario where they have to decide something, and get it wrong safely, and go again.

Every activity we build is designed for behaviour change and a security culture that survives past the month it happened in. No tickbox exercises and no fucking slide decks.

Free Cyber Security Awareness Month Resources

Run the month yourself, if you'd rather.

Everything here is built for the person who got handed "sort out October" and no budget. Take it, use it, put your own logo on the bits that need one. Free resources will only get you so far... but they'll get you further than a new Teams background.

The Clock, Not the calendar.

Pre-engagement runs six to eight weeks before your first session, and there's planning time on top of that. Kit and facilitators need two to four weeks, though we've moved faster when we've had to. Neither of those cares what month it is.

October is a brilliant month for engagement. The whole world is already talking about it, so you get to ride that instead of generating the interest yourself. Just remember the other eleven months exist too, and the quiet ones tend to land harder.

If your heart is set on October, wonderful, we'd love to build it. Ask us early though... everyone else wants that month as well.

FAQs

What is Cyber Security Awareness Month?

Cyber Security Awareness Month is an annual campaign held every October to encourage organisations to improve their cyber security knowledge and reduce human risk factors. Awareness is where it starts, not where it ends… treat it as a chance to change what your team actually does, not just what they know.

When is Cyber Security Awareness Month?

Do we have to run it in October?

Can you build something different from the packages?

Why is Cyber Security Awareness Month Important?

What Activities Work Best During Cyber Security Awareness Month?

How Do You Make Cyber Security Awareness Month Engaging?

What Should a Cyber Security Awareness Month Programme Include?

How Early Should We Start Planning?

How Much Does It Cost?

How Are Immersive Experiences Different From Traditional Awareness Training?

Stop Training. Start Rehearsing.

Tell us how many people, how many sites, and what you really want to change. We'll do the rest.