Skip to main content
Cybersecurity serviceTRAINING

Cybersecurity Training & Awareness

Awareness and technical training programs to make your team the first line of defense. From phishing simulations for the entire organization to advanced training for development and operations teams.

ENISASANSISO 27001NIS2
Typical duration
4 weeks
Deliverables
6+
Methodologies
ENISA · SANS · ISO 27001 A.6.3
Next response SLA
< 24h
6DeliverablesInternal analysisInternal Hodeitek analysis: real count of the deliverables and phases defined for this service.
4Process phasesInternal analysisInternal Hodeitek analysis: real count of the deliverables and phases defined for this service.
0Zero production impactInternal analysisInternal Hodeitek analysis: an operating commitment for the service, not an audited metric.

Why do you need Cybersecurity Training & Awareness?

90% of successful cyberattacks start with human error and your team isn't prepared

Generic compliance training is ineffective — your team forgets it the next day

You need training evidence for NIS2/ENS/ISO 27001 audits

Your developers write vulnerable code because they haven't received secure development training

What makes us different

Four pillars that apply to every service and every solution, not a one-off slogan.

Offensive + defensive + AI

The same team that attacks in the pentest runs the SOC and builds the AI models. Offensive insight informs defense, and AI is applied where we already operate, not bolted on as an extra layer.

Compliance in weeks, not months

HodeiShield, our own platform, automates continuous assessment, control mapping, and evidence generation — so manual work no longer sets the pace of regulatory compliance.

Sovereignty and proximity

Infrastructure on OVHcloud (France/EU). You speak with the people who sign off on the work, not an account manager who forwards your request to another department.

Our own product

HodeiShield isn't a third-party product we resell: we build and operate it ourselves, and that's what lets us offer faster compliance and evidence that's always current.

What's included

Deliverables and results you will receive with this service.

Phishing Simulations

Periodic simulated phishing campaigns customized for your organization. Click rate metrics, incident reporting, and progress tracking over time.

Company-Wide Awareness

Cybersecurity awareness program: interactive modules, videos, quizzes, and micro-learnings tailored to each department.

Technical Training for IT/DevOps

Hands-on workshops on hardening, incident response, forensic analysis, and security tool usage.

Secure Development (SecDevOps)

Training in OWASP, SAST/DAST, secure code review, and CI/CD with security gates for development teams.

Tabletop Exercises

Security incident simulations with management and key teams. They test response capability and internal coordination.

Reporting and Certification

Progress dashboard, improvement metrics, and training certificates valid for compliance audits.

Methodology

Discovery, execution, delivery, and follow-up — the framework we follow on every project.

Discovery

Discovery

We measure your current awareness level with a baseline phishing test and understand your organization's sector, size, and languages.

Execution

Execution

We design and roll out the program: phishing campaigns, awareness modules, and technical training tailored to each department.

Delivery

Delivery

We deliver individual certificates and a progress dashboard with improvement metrics, ready for your next compliance audit.

Follow-up

Follow-up

Periodic reports tracking metric evolution and content adjustments based on each campaign's results.

How we work

Structured methodology to ensure measurable and repeatable results.

1

Initial Assessment

We measure your organization's current awareness level with a baseline phishing test.

2

Program Design

We adapt content, frequency, and channels to your company: sector, size, languages, and corporate culture.

3

Execution

Rollout of campaigns, trainings, and exercises according to the agreed schedule.

4

Measurement and Improvement

Periodic reports with improvement metrics, sector benchmarks, and recommendations.

Operational example

A real scenario of how we work, not a marketing figure.

A simulated phishing campaign impersonates a regular vendor asking to change the bank details on an invoice. Employees who click get a short, in-the-moment lesson on that specific technique, and the finance team gets a heads-up to reinforce verification of bank-detail changes before paying.

Is it for your company?

This service is designed for organizations that identify with these profiles.

All companies — the human factor is universal
Organizations needing NIS2/ENS/ISO 27001 compliance
Development teams requiring secure coding skills
Management looking to measure and improve security culture

Compared to a generalist integrator

No names — here's how we work differently, with verifiable facts.

CriteriaGeneralist integratorHodeitek
FocusDozens of business lines; cybersecurity is just one of them100% cybersecurity and AI
Point of contactAn account manager who forwards your request to another departmentDirect contact with the founders
Regulatory complianceOne-off reports per regulation, manual evidence managementHodeiShield automates evidence and cross-framework NIS2/ENS/DORA mapping
ProductResells third-party licensesBuilds and operates HodeiShield, its own platform

Regulatory compliance

How what this service already includes relates to NIS2, DORA, and the AI Act — article by article, with no invented coverage.

  • Framework
    NIS2
    Article
    Art. 21(2)(g)
    What it requires
    Apply basic cyber hygiene practices and cybersecurity training.
    How this service helps
    The company-wide awareness program and the reporting with training certificates provide documentary evidence of that training — a program with metrics and certification, not a one-off talk.

Informational mapping, not legal advice: it describes how what we already do in this service helps comply with or provides evidence for each article — it doesn't replace a compliance assessment tailored to your organization.

Frequently asked questions

What's your response SLA?
First response within 24 business hours of reaching out. If what you need is an exposure assessment, we deliver it in full within 48 business hours.
Is the training online or in-person?
Both. We offer an online platform with interactive content and in-person workshops for advanced technical training.
Can you customize the content for our sector?
Yes. We tailor scenarios, examples, and phishing campaigns to your company's sector and context.
How do you measure effectiveness?
We measure phishing click rates, quiz results, reported incidents, and progress over time with specific metrics.
Does it include certificates for audits?
Yes. We generate individual certificates and compliance reports valid for ISO 27001, ENS, and NIS2 audits.
How is the training program priced?
We don't publish a fixed rate: it depends on the number of employees, languages, and modules you need. After the initial assessment, you receive a proposal with defined scope and price.
How are you different from a generalist integrator?
A generalist integrator often resells a generic LMS; at Hodeitek the phishing scenarios and technical content are designed by the same team that runs the SOC and does pentesting, aligned with ENISA, SANS, and ISO 27001 A.6.3. You deal directly with the founders.

Turn your team into the first line of defense

Talk to our team of experts to design a plan tailored to your organization's needs.

Response within 24h