How we help
We sit at the intersection of cyber security, human behaviour, and communication. Below is what that looks like in practice.
Security awareness & culture
For teams who want security to feel less like a lecture and more like a conversation.
- Shape awareness campaigns — themes, key messages, channels.
- Create plain-language content: emails, micro-lessons, guides, short videos.
- Facilitate live or virtual sessions on phishing, data handling, and secure habits.
- Support security champions and managers to talk about security with more confidence and care.
Human risk & behaviour
For programs that look beyond "click rates" and into how people actually work.
- Qualitative human-risk discovery through interviews and workflow mapping.
- Simple human-risk maps that show where behaviour and critical assets meet.
- Behaviour-focused recommendations for processes like onboarding, access, and data sharing.
- Design of psychologically safe phishing simulations and feedback experiences.
GRC training & communication
For GRC and compliance teams with strong frameworks on paper, and a gap in how people hear them.
- Translate policies, controls, and standards into clear, role-based guidance.
- Design short training modules aligned with your chosen frameworks (ISO 27001, HIPAA, GDPR, as needed).
- Draft internal communications around audits, new controls, and program changes.
- Create job aids: checklists, one-pagers, visuals that support recurring governance routines.
We are not your CISO or your entire security team.
We are your human‑centred extension.
How we work together
Security is technical, but it is also relational. We care about both.
Listen
We meet with your security, risk, and people owners to understand your goals, context, and constraints.
Map
We turn what we hear into simple maps: where people struggle, where risk lives, and where communication is needed.
Co-create
We design content, workshops, training, or campaigns with you — you keep ownership, we bring craft and structure.
Iterate
We learn from feedback, adjust, and help you embed new habits so efforts last beyond any one campaign.
Engagements are typically part-time, remote-first, and scoped around specific quarters or initiatives.