Skip to content
8bytes

Train the humans,
not the firewall.

Custom training programs, phishing campaigns, and tabletop exercises designed for the actual people who work at your company — not generic compliance content.

Programs

What we run.

Four awareness offerings, designed to be combined into a recurring programme rather than treated as one-off events. Effectiveness is measured, not assumed.

Phishing simulations

Realistic phishing campaigns matched to your industry threat landscape. Different difficulty tiers, multilingual, with safe landing pages and just-in-time training.

Custom training

Role-specific content for developers, finance, executives, and front-line staff. Real incidents from your sector instead of generic scenarios.

Tabletop exercises

Facilitated incident simulations for leadership and IR teams. Realistic scenarios, time-pressured decisions, no slide-decks.

Executive briefings

Board and C-suite security briefings. Threat landscape, peer-incident analysis, programme oversight — pitched for the audience.

Methodology

How we work.

01

Baseline assessment

Measure current awareness via an initial phishing test and a short anonymous survey. Establish the starting point honestly.

02

Programme design

Define audience segments, content cadence, simulation frequency, and success metrics. Programme is built to match your actual risk profile.

03

Content & campaign execution

Deliver training content and run simulations on the agreed cadence. Just-in-time micro-training when someone clicks.

04

Measurement & analytics

Phishing-rate, reporting-rate, training-completion, and behaviour-change metrics tracked monthly. No vanity completion percentages.

05

Continuous improvement

Quarterly review of programme effectiveness. Adjust difficulty, audience targeting, and content based on what is and isn't working.

Deliverables

What you receive.

Everything you need to fix what we found — and prove it to your auditors.

  • Phishing campaign reports per cycle (click rate, report rate, repeat offenders)
  • Training completion analytics by team and role
  • Tabletop exercise findings and improvement actions
  • Programme maturity assessment against industry baselines
  • Awareness programme roadmap (12–18 months)
  • Executive-summary dashboard updated monthly

FAQs

Common questions.

01

How realistic are your phishing tests?

We mirror current real-world campaigns affecting your industry. Lures are reviewed monthly against threat intel. We do not use lures that could cause lasting personal distress (bereavement, medical, immigration) — there is a clear ethical line.

02

Will employees know it is a test?

Not in advance, no — that defeats the purpose. After the click, they land on a clear "this was a phishing simulation" page with a short training moment. Repeat offenders get manager-level follow-up rather than public shaming.

03

Can training be delivered in multiple languages?

Yes. Content is localised, not just machine-translated. Common languages (Spanish, French, German, Japanese, Mandarin, Hindi) are supported as standard; others on request.

04

How do you measure effectiveness?

Phishing-click rate is the lagging indicator. Phishing-report rate is the leading indicator — it tells you whether people are actively recognising threats and using the reporting channel. We track both, plus repeat-offender rates and time-to-report.

05

Do you create custom content for our company?

Yes. Generic awareness content has poor engagement. We use real incidents from your sector, your tooling, and (with permission) anonymised real attempts against your organisation as case studies.

Get in touch

Ready to build a real programme?

Book a call

Free 30-min scoping call. No commitment.