Heights Consulting Group

Security Awareness Training and Phishing Simulation

Security awareness training is a recurring, delivered program: short, role-relevant sessions on the situations each group actually faces, simulated phishing that measures how people respond, and reporting that tells leadership whether behavior is changing, rather than an annual video watched to satisfy a checkbox.

What you receive

Part of
The decisions, records and oversight that turn security activity into something leadership can direct.
Engaged as
A defined piece of work, or as part of an ongoing vCISO engagement.
Sits under
Executive ownership of the cybersecurity program.

The problem

Why this comes up

The majority of incidents begin with a person: a credential typed into a convincing page, an invoice paid to a changed bank account, a file opened because it looked routine. The annual compliance video does not change what a person does on a Tuesday afternoon under pressure.

The organizations that have run training for years often cannot say whether it works, because the only measure they hold is completion. Completion is attendance. It is not behavior.

The service

What this engagement is

Who it is for

  • Organizations whose last awareness effort was a single annual module.
  • Finance teams and executives who are the targets of payment fraud and impersonation.
  • Companies whose insurer or framework expects recurring training with evidence.
  • Leadership teams that want to know whether the money spent on awareness is changing anything.

A program run across the year: brief sessions built around the scenarios each role meets, finance and executives on payment fraud and impersonation, everyone on credential theft and reporting, administrators on the attacks aimed at them. Simulated phishing campaigns test what the sessions taught, and reporting follows the results by group and over time.

The program is governed by the organization's policy and standards, and it feeds the security program's reporting, so leadership sees the human layer beside the technical one.

Scope

What Heights does

  • Role-based training program

    Sessions scoped to what each group is likely to face, on a cadence across the year rather than one event.

  • Simulated phishing campaigns

    Realistic campaigns run on a schedule, escalating in difficulty, with immediate coaching for anyone who acts on one.

  • Executive and finance targeting

    Payment fraud, impersonation and pretext scenarios aimed at the people who move money and sign approvals.

  • Reporting and incident culture

    A simple way to report a suspicious message, and recognition when people use it, so reporting rises as clicking falls.

  • Measurement and reporting

    Results by group and over time, presented to leadership with the rest of the program's reporting.

Timing

When organizations engage this

  • A phishing email reached someone who acted on it.
  • A payment was redirected, or nearly was, by a message that looked like the boss.
  • The insurer or a framework asks for training completion and phishing results.
  • Completion rates are high and nobody can say what changed.
  • New hires arrive between annual sessions and receive nothing.

What you receive

  • An annual program calendar with sessions and campaigns by role
  • Simulated phishing results by campaign, group and trend
  • Completion and behavior evidence formatted for insurers and assessors
  • A quarterly awareness report for leadership

Alignment

Frameworks this work touches

Establishing which of these apply to you

NIST CSF
A widely used structure for organizing a security program around outcomes rather than products. Its current version adds an explicit governance function, which is why it maps well onto executive-level work.
HIPAA
The HIPAA Security Rule requires administrative, physical and technical safeguards for electronic protected health information, including a documented risk analysis and risk management process. The Breach Notification Rule sets defined duties and timelines once a breach is discovered. HITECH extended enforcement and applies obligations directly to business associates.
PCI DSS
Prescriptive control requirements imposed through payment brand agreements wherever cardholder data is stored, processed or transmitted. Scope reduction is usually the highest-leverage decision available.
SOC 2
An examination performed by a licensed CPA firm against the AICPA trust services criteria. Security is always in scope; availability, confidentiality, processing integrity and privacy are added when relevant.
CMMC
NIST SP 800-171 sets the security requirements for protecting controlled unclassified information in non-federal systems. CMMC is the program under which contractors demonstrate that implementation, by self-assessment or third-party assessment depending on level.

The flagship

Awareness is a control, and like any control it needs an owner. The vCISO decides what behavior the program must change and reads the results beside the technical measures; this service delivers the program and produces the evidence.

Read about vCISO leadership

First steps

How an engagement begins

The same three steps whichever service you start with.

  1. A confidential conversation

    What prompted the enquiry, what you are obliged to do, and what leadership is being asked to answer for. No cost, no obligation.

  2. Scope agreed in writing

    What Heights will do, what stays with you, the working rhythm, and how progress will be reported.

  3. Work begins

    Delivered by your team, your providers or Heights, with expectations and acceptance criteria stated up front.

FAQ

Questions we are asked about this

Broader questions about executive security leadership are answered on the vCISO page.

Is simulated phishing fair to staff?

It is, when it is run to teach rather than to catch. Campaigns are announced as a program, results are reported by group rather than by name to leadership, and anyone who acts on a simulation gets a short explanation in the moment, not a reprimand.

The measure that matters is the reporting rate. A workforce that reports suspicious messages quickly is protecting the organization whether or not any individual clicked.

How much time does this take from staff?

Sessions are short by design, minutes rather than hours, and spread across the year so no one loses an afternoon. Role-based scoping means people are only trained on what applies to them.

Simulations take no scheduled time at all; they arrive as ordinary messages do.

Does this replace the policy and awareness work?

No. The policy and standards work establishes what the organization expects of people and governs the program. This service delivers the program on a recurring basis and measures it.

Many organizations begin with the governance work and add the delivered program when they want the human layer measured continuously.

Schedule a Confidential Consultation

Four questions, answered by the person who would be at your table. If Heights is not the right fit for what you need, you will hear that in the first conversation.

In Central Florida? Make it coffee, breakfast, lunch or a drink at the end of the day. Dan buys. Say so in the message and name a part of town.

A short description is enough, what prompted you to get in touch, and what a useful outcome would look like.

Sign in to the employee portal

For Heights employees. Accounts are created by Heights; if you expected one and it has not arrived, contact us.