Training that people actually finish
Hour-long annual videos get skipped. Our program uses a short onboarding course for new hires, then brief monthly or quarterly lessons of a few minutes each on the threats valley businesses actually see: invoice and wire fraud, fake login pages, gift-card scams, QR-code phishing, MFA fatigue attacks and AI-generated voice and email impersonation.
Simulated phishing emails test what people do in their real inbox. Anyone who clicks gets an immediate, judgment-free micro-lesson. Over time, click rates fall and reporting rates rise, and you can see both in the reports.
Checks the compliance box, with proof
Security awareness training is an explicit requirement in several rules our clients face:
- HIPAA requires a security awareness and training program for the entire workforce.
- The FTC Safeguards Rule requires security awareness training for staff.
- PCI DSS requires a security awareness program, reviewed at least annually.
- Cyber insurance applications routinely ask whether staff are trained and phish-tested.
You get completion records by employee, phishing simulation results and an annual summary, ready to attach to an audit, an insurance application or your risk assessment.
Built for seasonal teams
Mountain businesses onboard waves of seasonal staff. New hires are enrolled automatically when their account is created, complete a short onboarding course in their first week, and are removed when they leave, so your records stay accurate without anyone chasing paperwork.
Signs it’s time for Security Awareness Training
- Your insurer or auditor asked for training records.
- Staff have clicked phishing links or bought gift cards for a fake “boss.”
- New hires never receive any security training.
- You handle patient, financial or card data.
- Your last training was a one-time video years ago.
If two or more of these sound familiar, take the free security check or book a free cybersecurity assessment.
How our Security Awareness Training process works
Baseline phish test
A first simulation shows where your team stands.
Enroll
Staff are enrolled automatically, with an onboarding course.
Train & test
Short recurring lessons and regular phishing simulations.
Report
Completion and phishing reports, plus an annual summary.
What’s included
- Onboarding security course for new hires
- Short monthly or quarterly lessons
- Simulated phishing campaigns
- Instant micro-training for anyone who clicks
- Phish-reporting button for Outlook
- Completion records by employee
- Annual compliance summary report
- Automatic enrollment and removal with staff changes
Who it’s for
- Healthcare practices and business associates
- Financial, tax and insurance firms
- Merchants taking card payments
- Any business renewing cyber insurance
What affects the price
Every quote is flat and in writing. These are the factors that move the number:
| Factor | Why it matters |
|---|---|
| Number of users | Training and phishing simulations are priced per user. |
| Frequency | Monthly or quarterly lessons and simulations. |
| Managed IT clients | Training can be bundled into your plan. |
Training for valley teams
From year-round offices in Edwards and Eagle to seasonal crews in Vail and Beaver Creek, training is delivered online so staff can complete it anywhere. Prefer in person? See our free workshops.
“Todd has helped get our team protected at a level we had no idea existed. As an Insurance Agency, we know the importance of protecting our clients data, Todd has taken that to a new level!”
Frequently asked questions
Is security awareness training required by law?
For many businesses, yes. HIPAA requires it for covered entities and business associates, the FTC Safeguards Rule requires it for covered financial businesses, and PCI DSS requires it for merchants. Cyber insurers commonly require it as a condition of coverage.
How often should employees get security awareness training?
Onboarding training for every new hire plus recurring training at least annually is the baseline. Short monthly or quarterly lessons with phishing simulations work far better than a single annual session.
What is a phishing simulation?
A safe, realistic test email sent to staff to see who clicks or enters credentials. It measures real-world behavior and turns mistakes into immediate training instead of real incidents.
Do you provide proof of training for audits and insurers?
Yes. You receive completion records by employee, phishing results and an annual summary that can be filed as evidence.
Can training be done in Spanish?
Multilingual training content is commonly available from training platforms; ask during your assessment and we will confirm options for your team.
brand