Security Awareness Training — turn your staff into your strongest defence
Most breaches start with someone clicking the wrong thing — so we train the people, not just the tech.
Your firewalls and filters do a lot. But attackers know the fastest way in is a person, not a server. We train your staff to spot the trick before they click — regular, bite-sized, and built for real Kiwi businesses.
Your people are the front line
Most attacks don’t break in — they log in. Someone gets a convincing email, clicks a link or hands over a password, and the attacker walks straight past the tech.
That makes your staff the layer that matters most. Train them well & they become a human firewall — the last line that stops a threat the filters missed.
Why training beats hoping
A once-a-year lecture doesn’t stick
People forget a slideshow within weeks. Threats change constantly, so the training has to keep pace.
Attackers count on your staff being busy
A rushed inbox is exactly where a good phishing email lands. Regular practice builds the pause-and-check habit that stops it.
You can’t fix what you can’t see
Without testing, you’re guessing whether your team would spot a real attack. Simulated phishing shows you the truth — safely.
How the training works
Short, regular training
We run bite-sized sessions through the year — not one long annual lecture nobody remembers. A few minutes at a time, on the threats your staff actually face, so the good habits stay fresh.
Safe simulated phishing
We send harmless test emails that mimic the real thing. A click becomes a teachable moment, not a breach — and over time the reporting shows your click-rates dropping as your team gets sharper.
What you get
Ongoing training
Regular, plain-English lessons that fit around real work — no all-day sit-down required.
Simulated phishing tests
Safe, realistic tests that turn a slip into a lesson while nothing is actually at risk.
Clear reporting
Simple reports that show click-rates improving over time — proof your team is getting stronger.
A reporting habit
We teach staff to report suspicious emails, so the ones that get through still get caught.
Insurance & standards evidence
The records cyber-insurers and the SMB1001 (a tiered cyber-security standard) increasingly ask to see.
A pairing with email security
Training covers the people; cyber security tools cover the tech — belt & braces.
How we roll it out
1. Baseline
We start with a quick simulated phishing test to see where your team stands today — no blame, just a starting point.
2. Train & test
We run short lessons and ongoing simulations across the year, matched to the threats your staff are seeing.
3. Report & improve
You get regular reports showing progress, and we adjust the training where your team needs it most.
What it costs
Price depends on how many staff you have and what you’ve already got in place. It’s a per-person subscription, not a big one-off bill — and it’s modest next to the cost of one successful attack. Tell us your headcount & we’ll quote you a clear number.
Frequently asked questions
Is a one-off training session enough?
No. Threats change and people forget, so training has to be ongoing and regular — that’s the whole point. Short, repeated sessions beat one long annual lecture every time.
Won’t simulated phishing catch my staff out and embarrass them?
It’s designed to teach, not to shame. A click becomes a private teachable moment, and over time your team gets noticeably sharper — the reports prove it.
Do we really need this if we already have good email security?
Yes — they do different jobs. Email security screens the tech layer; training covers the people it can’t. You want both — belt & braces.
Does this help with our cyber-insurance?
Increasingly, yes. Insurers and the SMB1001 security standard now expect to see staff training and testing in place, and we can certify you against SMB1001. The reporting gives you the evidence they ask for.
How much time will it take my team?
Very little. Sessions are bite-sized — a few minutes at a time — and built to fit around real work rather than stop it.
We’re only a small team — is it worth it?
Especially then. Attackers target small businesses because they assume the defences are thin, and one tricked staff member can cost you dearly. Try our free cyber readiness self-check to see where you stand.
Give your team the training that sticks
Start with a quick chat & a baseline test — a small step that shows you exactly where your staff stand today.
Phone: +64 9 280 1780
Email: sales@itlive.co.nz