Skip to main content
Home/Services/Cyber Awareness Training
Security Testing

Cyber Awareness Training

Turn your employees into your strongest security layer

SOC 2 HIPAA PCI-DSS ISO 27001 NIST CSF GDPR CMMC
engagement log Cyber Awareness Training testing
day 01scopetargets confirmed · rules of engagement signedagreed
day 01reconattack surface mappedcomplete
day 02findingLow phishing awareness among non-technical staffcritical
day 03findingPassword reuse across personal and work accountshigh
day 04triagereviewed and countersigned by a Lorikeet pentesterpublished
day 04delivertickets opened in your tracker201
afterretestfixes verified · included in scopeno charge
retest included human countersigned report your auditor accepts
Annual subscriptiontypical duration $5,000/yearfixed scope, from 8deliverables 8methodology stages
Scope

What this engagement covers

The service

Human error is the #1 cause of data breaches. Our Cyber Awareness Training platform delivers interactive, engaging security training to your entire organization. Employees complete bite-sized courses, pass knowledge checks, and earn certificates - while you get a compliance-ready dashboard showing completion rates, risk scores, and audit evidence. Built for SOC 2, HIPAA, PCI-DSS, and ISO 27001 compliance requirements.

What we test

Our platform covers all critical security awareness topics: phishing recognition and email security, password hygiene and multi-factor authentication, social engineering tactics and defense, data handling and classification, remote work security, physical security best practices, incident reporting procedures, compliance-specific modules (HIPAA, PCI-DSS, GDPR), mobile device security, and insider threat awareness.

Method

How we run it

We deploy a branded training portal for your organization with role-based course assignments. New hires get onboarded automatically, and recurring annual training is scheduled and tracked. Courses use interactive scenarios, short videos, and real-world examples - not boring slideshows. Admins get a live dashboard with completion tracking, department comparisons, and exportable audit reports. The platform integrates with your HR system for automatic user provisioning.

01

Deploy branded awareness portal

02

Import employee roster and assign roles

03

Configure course paths by department/role

04

Launch initial training campaign

05

Track completion and quiz performance

06

Generate compliance reports for auditors

07

Schedule recurring annual refresher training

08

Provide ongoing platform support and updates

Deliverables

What you receive

Findings land in your tracker as you go, not only in a PDF at the end. Retest is in scope, not a change order.

  • Branded training portal for your organization
  • Interactive course library (20+ modules)
  • Automated onboarding for new employees
  • Role-based course assignments
  • Completion certificates for each employee
  • Admin dashboard with analytics and reporting
  • Compliance audit reports (SOC 2, HIPAA, etc.)
  • Annual training schedule management
Typical results

What we usually find

The issues this engagement surfaces most often. Yours will differ, but this is the shape of it.

Low phishing awareness among non-technical staff Password reuse across personal and work accounts Failure to recognize social engineering tactics Improper data handling and sharing practices Missing incident reporting knowledge Weak physical security awareness Mobile device security gaps Compliance knowledge gaps in regulated roles
Fit

Who this is for

Companies needing SOC 2 security awareness training
Healthcare organizations with HIPAA training requirements
Financial firms with PCI-DSS awareness mandates
Remote-first companies needing distributed training
Organizations with compliance audit deadlines
Companies that want to reduce phishing click rates
Standards this supports

Findings are mapped to SOC 2, HIPAA, PCI-DSS, ISO 27001, NIST CSF, GDPR, CMMC, so the report drops into an audit package rather than needing to be translated first. If you need the readiness work behind one of those, that is a separate engagement.

Next

Scope it in one call

Tell us what is in scope and we come back with a fixed price and a start date. No discovery-call maze, no hourly estimate that moves.

Lory waving

Hi, I'm Lory! Need help finding the right service? Click to chat!