Before You Book
Live vs LMS, real per-team pricing, behavior change timeline, staff pushback, and HIPAA / PCI / SOC 2 / NIS2 compliance coverage. None of these require a contract to read.
Humans remain the breach surface in 60–74% of incidents in the Verizon DBIR era, and KnowBe4 / Proofpoint-style self-serve modules sustain around 20% engagement by the 90-day mark. Live sessions create a vivid, rehearsed memory under instructor pressure — the exact rehearsal a staff member runs the next time a wire request, voice clone, or OAuth consent grant actually arrives, not after an LMS checkbox they clicked six months ago.
Regulators treat the two differently. HIPAA §164.308(a)(5), PCI-DSS v4.0 Req. 12.6, SOC 2 CC1.4, NIS2 Art. 20, DORA Art. 13, and the FTC Safeguards Rule all require "awareness" training, but our regulator-facing audit notes consistently show live workshops carry more weight than LMS completion tickboxes. Auditors ask participants what they remember; live sessions give them something to say.
Compare LMS vs. live training — Book a session →
$150 Individual (60 min, 1:1), $390 Executive (90 min, leadership-only), $900 Business (2 hours, unlimited team size). No per-seat math, no annual contract, no auto-renew — one flat rate covers everyone you want in the room.
Compare that to KnowBe4's Diamond tier, which runs around $8,750 per year at 100 employees, or Proofpoint's comparable tier which often lands in five figures annually. Our $900 covers every member of your team in one live session, and the next refresh runs at the same flat rate — no renewal squeeze, no surprise invoice. Book a session →
Behavior shifts within 24–72 hours of the session. The moment a suspicious wire request, voice clone, or OAuth consent arrives, the team member recalls the live walkthrough and acts differently. The session builds a rehearsed muscle memory — URL inspection, callback verification, MFA-fatigue refusal, breach-notification clock — rather than a passive checkbox tick that fades the same week.
Be honest about decay — the Verizon DBIR shows phishing click rates rebound after roughly four months without reinforcement. Mature programs re-run annually; high-risk roles (finance, HR, executives) every six months. We encourage that rhythm and offer same-flat-rate follow-up sessions so refresher training doesn't have to fight a procurement cycle.
Book your first session — Book a session →
Sessions run 60–90 minutes individually and 2 hours for a team — we schedule around shift changes, lunch periods, all-hands, and recurring ops meetings. Nobody loses a full shift. Most clients pair the team session with a monthly ops meeting so attendance is built in.
It's an instructor with real incident walkthroughs, not a gamified video — no leaderboards, no flashing badges, no cartoon avatars. Compliance officers consistently give us the highest satisfaction ratings because staff don't complain about it. Engineers and clinicians tell us it feels like a real talk, not a checkbox.
Pick a time that works — Book a session →
Yes. Every booking produces a written attendance record (participants + date), a session PDF summary, and a session-to-control map showing which topics map to HIPAA §164.308(a)(5), PCI-DSS v4.0 Req. 12.6, SOC 2 CC1.4, NIS2 Art. 20, DORA Art. 13, the FTC Safeguards Rule, GLBA §314.4, NYDFS Part 500, and the CMMC awareness domain.
We have clients who showed our attendance record at OCR HIPAA audits, PCI QSA walkthroughs, SOC 2 Type II control testing, NYDFS Part 500 exams, and EU NIS2 supervisory reviews. The session is built around the human-factor controls auditors actually probe — phishing recognition, MFA hygiene, incident reporting, vendor verification, breach-notification timing.
See the compliance crosswalk — Book a session →
Individual ($150), Executive ($390), or Business team ($900 flat, unlimited users). Industry-specific content. Real instructors. Attendance records for your compliance file.