One drill changes a team. A rhythm keeps it changed.
Most training fades by spring, and every new hire quietly reopens the gap. The Security Partner Plan is the rhythm that keeps readiness real: a monthly check-in with a live scorecard, safe phishing practice for the team, a micro-lesson on this month's scam, every new hire trained in their first quarter, and one number to call when an email feels wrong. It continues what the drill starts - which is why it's available to offices we've worked with.
- A monthly 45-minute check-in and a live readiness scorecard leadership can glance at
- Safe phishing practice - authorized in writing, aggregate results only, no shaming, ever
- Your insurance-questionnaire answers kept honestly current, all year
Behaviour change fades without reinforcement, and every new hire reopens the gap. The plan is built for exactly that: monthly reps, quarterly micro-drills, and new-hire cohorts that catch people in their first weeks - so the habit from drill day becomes the way the office works.
You get a person who knows your office - not a login to a video library. The monthly check-in is a conversation with someone who remembers what was fixed in March, what stalled in June, and which new hire hasn't done the drill yet. Big questions become scoped work with published prices; small ones are just answered.
Every month, a one-page scorecard: report rate, simulation results, training coverage. Every quarter, a plain-language summary shaped for cyber-insurance renewals and client security questionnaires - a running record of real diligence, kept current so renewal week is boring. Practical readiness, never a guarantee: no plan makes anyone immune, and we say so.
A program your team goes through - not a one-off.
Security awareness isn't a day; it's a habit. Here's the twelve-month arc, and exactly what lands on your desk at each step.
- 1Month 1 - Onboard The baseline and the standing authorization
We start from your delivered engagement - the checkup score or drill report is the baseline. Leadership signs one standing simulation authorization (re-confirmed annually), the reporting channel is confirmed, and the first monthly scorecard is drawn so every month after has a line to measure against.
Your baseline scorecard, carried over from the checkup or drillThe standing simulation authorization, signed once, re-confirmed annuallyThe monthly rhythm booked: check-in day, simulation window, report format - 2Every month The rhythm: practice, one lesson, one conversation
Each month the team gets one real-but-safe phishing simulation tuned to your sector - the fake invoice, the boss-voice ask, the QR trap - with no malware and no real credential capture. Anyone who clicks gets a quick, warm coaching moment, never a name on a board. A two-minute micro-lesson keeps one habit front of mind, and the 45-minute check-in keeps leadership current without homework.
One safe phishing simulation (monthly on Standard and Premium; quarterly on Essentials)A two-minute micro-lesson on this month's scam, for the whole teamThe 45-minute check-in and the one-page scorecard: report rate, results, coverage - 3Every quarter New hires folded in, and a fresh pressure test
Anyone hired during the quarter gets the new-hire cohort session - so turnover never quietly reopens the gap. A short remote micro-drill runs a scenario the team hasn't seen, because nobody should be coasting on last quarter's lesson. On Standard and Premium, we also review your Microsoft 365 or Google Workspace security score monthly, so configuration drift gets caught while it's small.
New-Hire Cyber Onboarding for everyone who joined that quarterA quarterly 20-minute remote micro-drill on a fresh scenarioMonthly Microsoft 365 / Google Workspace secure-score review (Standard and Premium) - 4Every year The refresher, the re-score, and the trend line
Once a year the team re-drills with all-new scenarios - alumni remember last year's - and the office is re-scored against its baseline. Leadership sees the curve, not a claim: report rate up, coverage complete, questionnaire answers still true. Standard includes the annual 90-minute refresher; Premium includes the full three-hour Cyber Fire Drill, a leadership tabletop, and quarterly executive briefings.
The annual refresher drill with a fresh scenario pack (tier-dependent depth)A year-over-year trend report against your original baselineRenewed, dated certificates and an updated insurer answer pack
Every employee, levelled up - step by step.
The program isn't abstract "awareness." It's a skill ladder. Here's what a staff member can actually do as they move through it.
One monthly fee. The whole program.
Priced by team size, billed monthly, all in CAD plus HST. Six-month minimum; cancel-friendly terms after that, walked through on the call.
- Monthly 45-minute check-in and the one-page scorecard
- Quarterly safe phishing simulation and quarterly new-hire cohort
- The "is this email legit?" line, and annual insurer-questionnaire help
- Everything in Essentials, with the simulation monthly instead of quarterly
- Monthly Microsoft 365 / Google Workspace secure-score review
- The annual 90-minute refresher drill included, certificates renewed
- Everything in Standard, plus quarterly executive briefings
- The full annual Cyber Fire Drill and a leadership tabletop included
- Priority coordination if something happens - we convene the specialists, starting with your insurer
Prefer to start smaller? Most teams begin with a one-off Cyber Fire Drill, then roll into the program.
A year in, here's what's different.
Program questions.
Why is the plan only for offices you've worked with?
Because the plan continues what an engagement starts. The scorecard needs a baseline, the simulations need the no-shame culture the drill establishes, and you deserve to know how we work before committing to a rhythm. Start with the Baseline Security Checkup or a drill - the plan conversation happens naturally at the debrief.
Is the monthly phishing safe to run on our own staff?
Yes. Every simulation is real-but-safe: no malware, no real credential capture, and never any public shaming. Results are reported in aggregate; anyone who clicks gets a short, warm coaching moment, not a name on a board. One standing authorization covers the program, signed by leadership and re-confirmed annually.
What does it cost, and is there a commitment?
Essentials is $349 a month, Standard $649, Premium $1,199 - plus HST, with a six-month minimum, monthly after that. Retainer clients also get priority scheduling and 10% off project work. The prices are published because that's how we do every price.
What's explicitly not included?
Incident response - if something happens we coordinate the specialists, starting with your insurer's breach line, but live response is delivered by response firms, not us. Hardening projects are quoted separately (retainer clients get 10% off). And the Q&A line is fair-use: quick questions are always free; big questions become scoped work with a published price.
Will this help with our cyber-insurance renewal or a client questionnaire?
It's built to. The monthly scorecard and quarterly summary give you a running, dated record of real training, testing and review - exactly the evidence renewal forms and client questionnaires ask for, kept current instead of reconstructed the week they land. Practical readiness, not a guarantee: no plan makes anyone immune, and we put that in writing.
Make your team the firewall.
Book a 20-minute call. We'll size the program to your team, send one quote, and pick a kickoff date.