Security awareness training for the people who already work with you.
F Creative Studio 360 teaches staff in any country how to recognise a fraudulent message, call or request, and what to do next.
Tools stop some messages. People still have to decide.
The programme follows the situations described by CISA and the learning approach in NIST SP 800-50. Examples use the mail, chat and payment habits of the organisation, not a generic story.
F Creative Studio 360 does not send a simulated message unless that exercise is written into the scope. Reports go to the contact you name, and a copy can go to hello@fcreativestudio360.com.
- People meet the message first
- A filter can miss a message. The person who opens it still decides whether to click, pay, or hand over a code.
- One annual session fades
- A single briefing is easy to forget. A programme repeats the situations people actually see, in the tools they already use.
- The same lesson, different jobs
- Finance, executives and front-line staff are asked for different things. The examples should match the work, not a generic slide.
- A record you can show
- Completion, and the result of any authorised exercise, is written down so you can show what the programme covered.
What the programme covers
The same sequence works in any country. Content is adjusted to the roles and the rules that apply where you operate.
- Everyday habits
- Passwords, a second factor, what to do with an unexpected attachment, and how files and customer data should be shared.
- Mail and messages
- Phishing in email, smishing in text messages, vishing on a call, and pretexting, where someone invents a reason you should act now.
- What the message is asking for
- Payment changes, gift cards, login codes, and requests that use a real colleague’s name. People practise stopping before they act.
- Authorised exercises
- A simulated message can be included when you authorise it in writing. It measures what people do. It is not a surprise attack, and it is not sent to anyone outside the list you approved.
- The role in front of them
- Modules can follow the job: executives, finance, human resources, IT, or a team with its own process. Industry examples are used when they match the work.
- What happens after a miss
- People who need another pass get a short follow-up, as agreed in the programme. The point is the next decision, not a scoreboard.
How a programme runs
Office, remote and hybrid staff take it online. A team in more than one country can share the programme and still see examples that match their work.
- 1
Agree the audience
Who is included, which roles need their own examples, and whether simulated messages are in scope.
- 2
Teach the situations
Short sessions on the messages, calls and requests people in that organisation actually receive.
- 3
Measure, if you asked for it
An authorised exercise, with a record of what people reported and what they acted on. Difficulty changes only as the programme agrees.
- 4
Hand back the record
Completion, the exercise result when there was one, and what to repeat. The programme does not end with a single session unless that is all you asked for.
What you receive
- Sessions matched to the roles you named.
- A completion record for the people who took part.
- An exercise report, when simulated messages were in scope.
- A note on who needs a follow-up, without publishing a league table of staff.
- A suggestion for what to repeat, and when.
Standards the programme can support
F Creative Studio 360 maps the record to the awareness expectation that applies where you operate. The usual references are PCI DSS, ISO/IEC 27001, the HIPAA Security Rule and the NIST Cybersecurity Framework.
The Essential Eight and CPS 234 are added only when the organisation is measured against them. A completion record is not a certification.
Common questions
What does a security awareness programme include?+
Training on passwords, mail, data handling and social engineering, shaped to the roles you name. F Creative Studio 360 can add authorised phishing exercises when they are written into the scope. It is a programme for your people. It does not certify the organisation.
Where do you deliver this?+
For organisations in any country. Sessions and exercises are delivered online, so office, remote and hybrid teams can take the same programme. A local rule, such as the Essential Eight or CPS 234, is added only when that organisation is measured against it.
How is this different from a single briefing?+
A briefing can introduce the topic. This programme repeats it, and it can measure what people do when an authorised exercise is included. You choose whether it is one session or a sequence.
Will staff be phished without knowing?+
No exercise is sent until the organisation has authorised it in writing, including who is on the list. Whether people are told a campaign is underway is your decision. Messages are not sent to customers or to anyone outside that list.
Does this meet a compliance requirement?+
Many standards expect people to be trained, including PCI DSS, ISO/IEC 27001 and the HIPAA Security Rule. The programme can be mapped to the obligation that applies where you operate, and you receive a completion record. Completing training is not, by itself, a certification.
How much does it cost, and how long does it take?+
It depends on how many people are included, whether exercises are in scope, and how often the programme repeats. A scoping conversation with F Creative Studio 360 is the way to get a quote and a sensible start date. There is no obligation to proceed.
Start with the people who receive the messages.
F Creative Studio 360 will look at who should be included and whether an exercise belongs in the first round, then say what a sensible programme includes.
