Pick the depth. The rule is the same everywhere.
The whole team learns to spot, stop and report the five scams that hit offices like yours - with the paper to prove it happened.
Your staff practise the moves until they’re reflexes: triage a suspicious inbox, verify a payment change by callback, set up a password manager, report in ten seconds.
Everything above plus The Heist - our scored 35-minute simulated attack - a first-hour tabletop, a leadership memo, and a 30-day plan with names on it.
Every starting price, and the full ladder, lives on the pricing page.
One heist, five doors. Walk through it.
This is the composite attack The Heist is built on - the scored 35-minute simulation inside the flagship drill. Step through it minute by minute and count the moments it could have stopped. In the session, your team lives it together, against the clock.
-
A password the bookkeeper has reused since 2019 - leaked in a breach years ago - still opens their work inbox. No alarm rings. The visitor doesn’t touch a thing. They read.
-
An unfamiliar device quietly syncs that inbox every night, and nothing flags it. They learn who pays, who approves, how everyone signs off - and that a supplier is owed $48,200 on Friday.
-
Accounts payable gets a call. It’s the owner’s voice - the pace, the impatience, even the joke. A few minutes of audio is enough to clone a voice now. “I’m boarding a flight. Their new account details are coming by email - please get it out before 5.”
-
The email lands inside the real invoice thread. Same signature, same footer, same PDF. “Please note our updated banking details for this payment.” The sender’s domain is one character off - and nobody is counting characters at 4:52 on a Friday.
-
The payment is keyed in. The invoice was due, the thread was real, the boss called ahead. The one callback that stops everything is the step under the most time pressure - so it’s the step that gets skipped.
-
The real supplier calls about their overdue invoice. Now it’s the bank, the insurer’s breach line and a very long week - and the money has been gone since Friday at 5:07.
It could have stopped five times.
Five ordinary moments - one at every door - and none of them needed a security expert. Just a reflex that still fires at 4:52 p.m. on a Friday, when everything looks right. Installing that reflex is what the drill does: your team beats a heist like this one together, and repeats the stop-moments until the right move is boring. Boring is the goal.
We train all five doors - email, the phone, passwords, devices & Wi-Fi, money movement - with your industry’s real examples: spot it, stop it, report it.
A composite training scenario - no real client, no real names; the amount is illustrative. The pattern is the one we drill.
Why teams remember it
- Live phishing simulation to real inboxes (an add-on, only ever with your signed authorization)
- Implementation of the 30-day plan (that’s the Security Tune-Up)
- Generic compliance-video content - if you want a video, honestly, they’re cheaper
Sector editions for dental, accounting and law included at no extra cost. Second sessions for split shifts, extra headcount and deep customization quoted plainly. Already had the Baseline Checkup? 100% of its fee credits toward any drill booked within 30 days.
Questions owners actually ask
How disruptive is this to a workday?
One room, one block of time, nothing installed. For clinics, an admin morning or a lunch block works well; for law and accounting firms, late afternoon. We schedule around your reality, evenings included.
Will anyone be embarrassed?
No - it’s our founding rule. Scores belong to pods, volunteers are always volunteers, and simulations report in aggregate only. The fastest way to make an office insecure is to make people afraid to report. We do the opposite.
What do you need from us?
A room, a TV or blank wall, your team for the booked block, and fifteen minutes of prep with whoever runs the office. We bring everything else, including the backup dongles.
Does this satisfy our insurer’s training requirement?
You receive a dated completion record listing the curriculum, headcount and provider - the document renewal questionnaires ask about. Insurers make their own decisions; we make your answer true and provable.
More on the full FAQ page - including “why should we trust you with our office?”, answered honestly.