CMMC Level 2, NIST SP 800-171 and ISO 27001 support for the Defense Industrial BaseNorthern Virginia  |  Serving contractors nationwide

Security training that changes behavior

Most breaches start with a person, not a firewall. We train your workforce to spot attacks, your IT team to defend against them and your leadership to respond when one gets through. It is live, practical and built around your business.

Training programs

Delivered on-site in the DC region or live online. Every class includes attendance records and materials you can keep, which also satisfies the awareness and training requirements in NIST SP 800-171 (3.2.1 to 3.2.3).

Workforce security awareness

For all employees. A 60 to 90 minute live session that teaches people to recognize and report attacks, not just sit through slides.

60 to 90 minutesLive on-site or online. Groups of any size.

What we cover

  • Phishing, smishing and voice scams, using real examples from current campaigns
  • Business email compromise and wire fraud red flags
  • Passwords, MFA fatigue attacks and account takeover
  • Safe use of AI tools and what never to paste into them
  • Physical security, tailgating and lost devices
  • How to report, and why reporting fast matters more than being right

CUI handling and insider threat

For defense contractors. Role-based training that prepares your staff for the questions a CMMC assessor will ask them.

Role-based tracksGeneral staff, CUI handlers and system administrators.

What we cover

  • What CUI is, how it's marked and where it's allowed to live
  • Approved storage, sharing and transmission methods
  • Insider threat indicators and reporting obligations
  • Incident reporting, including DFARS 72-hour requirements
  • Assessment interview preparation for key staff

Hands-on defense training for IT teams

For IT staff and MSP technicians. Practical, lab-based training on hardening and defending the systems you actually run, taught from real security operations experience.

Full-day workshopHands-on labs, up to 12 participants per session.

Workshop tracks

  • Hardening Microsoft 365 and Entra ID: conditional access, MFA and logging
  • Endpoint defense: EDR configuration, application control and patching
  • Logging and detection: what to collect, what to alert on, what to ignore
  • Incident response first hour: containment, evidence and escalation
  • Attacker's view: live demonstration of common attacks and how to stop them

Executive tabletop exercises

For owners and leadership teams. A facilitated ransomware or data breach scenario that tests decisions, communication and your incident response plan.

2 to 3 hoursFacilitated exercise with a written after-action report.

What you get

  • A scenario tailored to your business, contracts and systems
  • Live facilitation with injects that escalate the situation
  • Decision points on ransom, disclosure, customers and DoD reporting
  • After-action report with gaps and recommended fixes
  • Evidence for the incident response testing requirement (3.6.3)

Managed phishing campaigns

Simulated phishing that measures real risk and trains people at the moment they click. We design, run and report on every campaign, so your team doesn't have to.

Baseline

An unannounced first campaign measures your true click and report rates.

Design

Lures built around your industry, vendors and the attacks hitting businesses like yours.

Run monthly

Varied difficulty and timing so people can't game it.

Teach at the click

Anyone who clicks gets a short, specific lesson on what they missed.

Report

Monthly trends for leadership: click rate, report rate, repeat clickers and risk by team.

ProgramIncludesBest for
Baseline assessmentOne campaign, results report and a live debrief with leadershipA first look at your real risk
Quarterly program4 campaigns a year, click-time training, quarterly reportsMeeting annual training requirements
Monthly program12 campaigns, click-time training, monthly reports and an annual live awareness sessionMeasurably reducing click rates

Every campaign is authorized in writing by your leadership before launch.

Training questions

Can training be delivered at our office?

Yes. We deliver on-site across the DC, Maryland and Virginia region, and live online for teams anywhere in the U.S.

Will employees be punished for clicking a simulated phish?

We recommend against it, and our programs are built around teaching, not shaming. People who feel safe reporting mistakes report real attacks faster.

Does this satisfy CMMC awareness and training requirements?

Our programs are designed to meet NIST SP 800-171 requirements 3.2.1 through 3.2.3, and we provide the attendance records and materials an assessor will ask to see.

Can you train our MSP's technicians too?

Yes. Many clients include their MSP in our hands-on defense workshops so everyone is configuring systems to the same standard.

Build a training plan for your team

Tell us your headcount and goals. We'll recommend a program and send a quote.

Schedule a training