← Back to In a Box services In a Box · Annual Programme

Someone on your team just clicked a phishing link. How many others would?

Security awareness training built around your organisation — AI data leakage, phishing simulations, and role-specific modules. Not a generic video library your staff will click through and forget.

What's in the box

Your people are your largest attack surface — and the threat has changed. Phishing emails are now indistinguishable from legitimate messages because attackers are using the same AI tools your staff use every day. Sixty-three percent of AI-assisted phishing emails bypass standard email filters.

We build a programme around your actual risk profile. If staff are using ChatGPT or Copilot to draft client documents, they need to understand what data leaves your network when they do. If your sector is targeted by business email compromise, that's the emphasis. The training is relevant to their daily work — not abstract security theory.

The programme runs on an annual cycle with quarterly phishing campaigns and metrics reporting, so you can demonstrate ongoing improvement to auditors and insurers.

Deliverables

  • Tailored awareness programme aligned to your risk profile and sector
  • AI data leakage module — what staff should and shouldn't put into AI tools
  • Quarterly phishing simulation campaigns with AI-crafted scenarios
  • Role-specific training modules (general staff, finance, leadership)
  • Metrics dashboard showing click rates, report rates, and improvement trends
  • Compliance evidence for Essential Eight, ISO 27001, and insurer requirements
  • Annual programme review and recommendations

Business benefits

  • Measurable reduction in phishing susceptibility — benchmarked quarterly
  • Compliance evidence that staff are trained, not just told
  • Documented AI usage policy reduces your data leakage exposure
  • Quarterly metrics give leadership visibility into security culture

Engagement process

Risk profilingWe assess your sector, threat landscape, AI tool usage, and existing policies to design a relevant programme.
Programme designTraining modules and phishing scenarios are built around your actual risks, including AI-enabled threats, and tailored to different roles.
Baseline campaignInitial phishing simulation establishes your current susceptibility — the benchmark everything is measured against.
Quarterly cyclesEach quarter: phishing campaign, targeted training for those who need it, and a metrics report for leadership.
Annual reviewProgramme effectiveness review, trend analysis, and recommendations for the next cycle.
Train your team

How many of your staff would click a well-crafted phishing link today?

A baseline simulation tells you exactly where you stand. Most organisations are surprised by the answer.

Run a baseline simulation

Kaurna Acknowledgement

We acknowledge and pay our respects to the Kaurna people, the traditional custodians of the ancestral lands on which we work. We acknowledge the deep feelings of attachment and relationship of the Kaurna people to country and we respect and value their past, present and ongoing connection to the land and cultural beliefs.

Kaurna Acknowledgement

We acknowledge and pay our respects to the Kaurna people, the traditional custodians of the ancestral lands on which we work. We acknowledge the deep feelings of attachment and relationship of the Kaurna people to country and we respect and value their past, present and ongoing connection to the land and cultural beliefs.