Security Awareness Training

In a time when cyberattacks keep getting more sophisticated, strong security awareness is essential. At Tozetta we train employees to recognize and effectively prevent phishing, malware and social engineering.

Discover below how we build a culture of digital resilience within your organization, from basic training to technical deep dives.

  • Tailored per organization and sector
  • Interactive, energetic sessions
  • Realistic attack simulations
Preparing a security awareness training at Tozetta

[ 01 ]Security Awareness

What is security awareness?

You can patch technology, but not behavior. Security awareness is about increasing employees' awareness, so they recognize phishing, social engineering and other cyber threats and know how to respond.

01

What is security awareness?

Security awareness is the extent to which employees recognize cyber threats such as phishing, social engineering and malware, and know how to respond correctly. Technology alone doesn't protect an organization, the people behind it need to be just as capable of recognizing these threats.
02

Why does it matter?

As much as 70% of data breaches are caused by human error, not technical vulnerabilities. Hackers increasingly target employees directly, through phishing emails, CEO fraud or phone-based deception.
03

Who delivers the training?

Our trainings are delivered by young, energetic trainers with hands-on experience as ethical hackers. They show employees, from real practice, how a cybercriminal actually operates.

[ 02 ]Type of training

Basic vs. technical training

Not every target audience needs the same training. Pick a level below and see which topics it covers.

For the whole organization

The Basic Security Awareness Training is relevant for everyone within the organization. Employees learn how to recognize and prevent phishing, social engineering and other cyber threats, making the entire organization better protected.

Recognizing phishing

Learning to recognize suspicious emails, links and attachments before clicking.

01

Social engineering

Recognizing when someone is using a pretext to try to extract confidential information.

02

Password hygiene & MFA

Applying strong passwords and multi-factor authentication correctly and consistently.

03

Responding safely and alertly

Knowing who to notify and how, when something suspicious happens, so damage stays limited.

04

Our trainers in action

From boardroom to theater hall: this is what a Tozetta security awareness session looks like.

Ian van der Wurff presenting 'How a hacker operates' to a packed room
Kevin van den Eshof presenting during a cybersecurity training

Certifications

Our ethical hackers are broadly certified

From OffSec to Hack The Box: the Tozetta team sets the bar high with internationally recognized, hands-on certifications. We put that in-depth expertise to work in every pentest, so organizations can count on thorough, high-quality security research.

OSCP

OSCP

Offensive Security Certified Professional

OSWE

OSWE

Offensive Security Web Expert

OSEP

OSEP

Offensive Security Experienced Penetration Tester

OSED

OSED

Offensive Security Exploit Developer

OSCE3

OSCE3

Offensive Security Certified Expert 3

CPTS

CPTS

HTB Certified Penetration Testing Specialist

CWEE

CWEE

HTB Certified Web Exploitation Expert

CWES

CWES

HTB Certified Web Exploitation Specialist

AED

AED

Android Exploit Developer

APIsec

APIsec

API Penetration Testing

eWPT

eWPT

Web Application Penetration Tester

BED

BED

Browser Exploit Design

Corelan

Corelan

Windows Expert-Level Stack Exploit Dev

OSCP

OSCP

Offensive Security Certified Professional

OSWE

OSWE

Offensive Security Web Expert

OSEP

OSEP

Offensive Security Experienced Penetration Tester

OSED

OSED

Offensive Security Exploit Developer

OSCE3

OSCE3

Offensive Security Certified Expert 3

CPTS

CPTS

HTB Certified Penetration Testing Specialist

CWEE

CWEE

HTB Certified Web Exploitation Expert

CWES

CWES

HTB Certified Web Exploitation Specialist

AED

AED

Android Exploit Developer

APIsec

APIsec

API Penetration Testing

eWPT

eWPT

Web Application Penetration Tester

BED

BED

Browser Exploit Design

Corelan

Corelan

Windows Expert-Level Stack Exploit Dev

Kevin van den Eshof

We take away the mystique around cybercrime. By showing how a cybercriminal really operates, participants understand not just what to do, but especially why.

Kevin van den Eshof

Co-founder & Private Investigator, Tozetta

[ 03 ]Why Tozetta

Why a security awareness training with Tozetta?

Tozetta's security awareness trainings are tailored to your specific needs and industry. We take your risks, company culture and target audience into account, and believe in learning by doing: our trainings are interactive and use realistic attack simulations.

Want to test directly how resilient your organization is in practice? A social engineering test is the practical follow-up step to an awareness training.

Fully tailored Interactive approach Realistic simulations
Get in touch
Preparing a security awareness training at Tozetta
POM

Almost immediately after the training we saw several improvement points show up in our backlog. Multiple JIRA tickets appeared right away for things the team wanted to address as a result of the session. When people take immediate action after a training, you know the content really stuck.

[ 04 ]Our process

How does a security awareness training work?

Tozetta team discussing the approach for a security awareness training
01

Introduction & needs

In a no-obligation conversation we map out the level, target audience and main risks of your organization.

02

Tailored training program

We put together a program that fits your sector, culture and chosen level: basic or technical.

03

Training & simulation

An interactive session, on location at your office or at Tozetta in Utrecht, with real-world examples and realistic simulations.

04

Evaluation & follow-up advice

Afterwards we discuss the results and advise on next steps to keep awareness up to date.

Ian van der Wurff, ethical hacker

I've capped off 5+ years of experience as an ethical hacker with an OSCP, OSED, OSWE, OSEP & OSCE3 certification. During our security awareness trainings I show employees exactly how an attacker thinks and operates, so the theory becomes immediately recognizable.

OSCP
OSED
OSWE
OSEP
OSCE3

[ 05 ]Investment

Security Awareness Training investment

The investment for a Security Awareness Training depends on group size, duration and chosen level: basic or technical.

Get in touch for a tailored proposal, including prices, timing and topics.

What does a security awareness training cost?

Security Awareness Training investment

At Tozetta we bring the highest quality to every training. Every engagement comes with the following added value:

  • Training program fully tailored to your organization and sector
  • Delivered by experienced ethical hackers with hands-on experience
  • Interactive and based on realistic attack simulations
  • On location at your office, or at Tozetta in Utrecht
  • Concrete follow-up advice after the training

Basic Training

For the whole organization

On request

  • Recognizing phishing & social engineering
  • Password hygiene & MFA
  • Real-world examples tailored to your sector
  • Suitable for all employees
Get in touch

Technical Training

For IT staff & developers

On request

  • OWASP Top 10 risks
  • Secure coding & hardening
  • Thinking like an ethical hacker
  • Delivered by an ethical hacker
Get in touch

Frequently asked security awareness training questions

What is a cyber security awareness training?
A cyber security awareness training is a training aimed at increasing employees' awareness of cybersecurity. Employees get acquainted with the world of cybercrime and receive tips to prevent your organization from becoming a victim.
Why is a cyber security awareness training important?
A cyber security awareness training is important because employees are often the weakest link in an organization's security. By far most data breaches or hacks are caused by human error. By increasing awareness, employees can contribute to a safer working environment.
What are the benefits of a cyber security awareness training?
The benefits of a cyber security awareness training include increasing employee awareness, reducing the risk of cyberattacks and data breaches, and increasing the organization's safety and productivity.
What is covered during a cyber security awareness training?
During a cyber security awareness training, topics covered include phishing, social engineering, safe password use, and recognizing suspicious activity on the network. At Tozetta, no cyber security awareness training is the same. We respond to the organization's specific request. To properly demonstrate the urgency and importance, we make sure to give practical examples relevant to your company.
How long does a cyber security awareness training take and how often should you repeat it?
The duration of a cyber security awareness training can vary from a few hours to several days, depending on the content and the organization's needs. A cyber security awareness training should be repeated periodically to ensure employees' awareness stays up to date and to address new threats. Hackers are constantly finding new and better techniques. Employees need to stay continuously informed about this.
How do I schedule a cyber security awareness training?
At Tozetta we respond to your needs. By getting in touch, we schedule a no-obligation conversation. In this conversation we want to get to know your company a bit better. Based on our knowledge of your organization and the needs you have, we can put together a proposal. In it you can expect prices, timing, dates and topics.

Ready to train your employees?

Get in touch without obligation and discover what our security awareness trainings can mean for your organization.