Programmes
Access is a
decision.
Technology can be patched. Judgement has to be trained. Five programmes, each with a fixed scope. Most clients begin with a board briefing.
Speak
Board briefings and keynotes
A 90 minute board session on insider, social engineering and AI risk, a keynote from Jamie, or a half or full day leadership scenario exercise.
Helps you show: Directors’ cyber literacy and an annual exercise, as the Cyber Governance Code asks.
Assess
Insider risk assessment
Four to six weeks of interviews, role based risk assessment and a review of people controls, ending in a board report and a 90 day roadmap. A failure to prevent fraud risk assessment can be added.
Helps you show: Work aligned to NPSA insider risk guidance, ISO 27001 people controls and reasonable fraud prevention procedures.
Test
Social engineering penetration testing
Phishing, phone, helpdesk reset and deepfake call tests, plus tailgating and site entry. Blame-free: we measure how quickly people report, not just who clicked.
Helps you show: Phishing and social engineering testing for PCI DSS, and evidence for insurer proposal forms.
Train
Human risk and AI literacy training
Role based workshops for leaders, finance, helpdesk and HR, and safe use training for AI tools. Annual programmes can include a managed training platform.
Helps you show: Measured staff training, and AI literacy measures for teams using AI.
Retain
Insider risk partner
A named senior lead, quarterly board metrics, an annual exercise, a security champions network and management of your training platforms.
Helps you show: Ongoing evidence for boards, auditors and insurers.
Why now
Obligations, not fear
Failure to prevent fraud has been an offence since September 2025, and the defence is having reasonable procedures. The Cyber Governance Code asks boards to own cyber risk and to measure training. Insurers ask what you do about people.
We help boards and teams act on the people parts of the Cyber Governance Code, NPSA insider risk guidance and fraud prevention procedures. We never claim to make you compliant.
Start a conversation
Begin with a confidential briefing.
Discreet, candid and without obligation. Tell us what prompted the question and we will tell you honestly whether we can help.
Book a board briefing