Phishing Awareness Training for UK Staff
Phishing and Business Email Compromise (BEC) drive the majority of UK cyber incidents — DSIT's 2025 Breaches Survey puts phishing at the root of 84% of UK breaches. Gridisys delivers bite-size NCSC-aligned training, monthly simulated phishing campaigns and Microsoft 365 / Entra hardening so your people become your strongest control — not your weakest link. Free 10-seat pilot first.
84%
of UK cyber incidents begin with a phishing email (DSIT Breaches Survey 2025)
£3.4M
median cost of a UK BEC incident — 2025 DSIT findings
Included
Gridisys training — modules + monthly simulation included
<10 min
per module — built for busy staff, not a once-a-year chore
Cybersecurity Consulting + 24/7 SOC Monitoring
Every Gridisys engagement is built on two pillars — strategic consulting to design the right controls, and managed SOC monitoring to keep them effective.
Cybersecurity Consulting
UK consulting engagements: risk assessment, security architecture, conditional access design, compliance (Cyber Essentials, UK GDPR, FCA PS21/3, NIS2), incident-response planning. Board-ready documentation, no jargon, no surprise invoices.
- Risk assessment + security architecture review
- Conditional access + Entra ID hardening design
- Cyber Essentials / UK GDPR / FCA / NIS2 compliance support
- Incident response planning + tabletop exercises
- Vendor + supply-chain security assessment
- Board / DPO reporting + evidence pack
Managed SOC Monitoring · 24/7
AI-augmented Security Operations Centre — continuous monitoring across Microsoft 365 / Entra ID, Defender, on-prem, and cloud. UK-based analysts, sub-hour triage on critical alerts. No long contract required.
- 24/7 SIEM monitoring — Microsoft 365, Entra ID, Defender, Azure, on-prem logs
- BEC + mailbox-compromise + OAuth grant abuse detection
- Suspicious sign-in + conditional access drift alerting
- Ransomware + lateral-movement detection from EDR + Defender
- Sub-hour triage on critical alerts, monthly ops report
- Optional + integrated with consulting engagements
Most engagements start with consulting (1-2 weeks), then SOC monitoring (ongoing ) keeps the controls effective.
Pricing tailored to your needs
Every engagement is scoped to your environment and requirements. Book a free consultation for a tailored quote — no obligation.
What we cover
Practical, board-ready consulting — no jargon, no surprise invoices.
Simulated phishing campaigns
Realistic BEC, MFA reset, invoice-fraud and credential-harvest templates — quarterly or monthly. Click, reply and attachment-open tracking with per-user risk scoring.
NCSC-aligned bite-size modules
10-minute modules built from the NCSC's top-10 awareness topics. Monthly cadence keeps staff sharp, not once-a-year box-ticking.
Defender for Office 365 hardening
We tune anti-phishing policies, impersonation rules, high-risk-sender alerts and external-sender warnings so the obvious phish is blocked before your staff see it.
Entra ID MFA + conditional access
BEC starts with stolen credentials. We review MFA coverage, legacy-authentication blocks, conditional access for risky sign-ins and impossible-travel detection.
Phishing tabletop + IR prep
A 90-minute facilitated exercise walking leadership through a BEC / ransomware phishing scenario — including ICO 72-hour reporting and stakeholder comms.
Phishing-report button rollout
We deploy the Office 365 report-phishing button, train staff to use it and feed reported emails to your SOC for analysis — converting staff into sensors.
How we work
Pilot (week 1)
Free simulated phishing campaign on 10 of your staff. Click-rate baseline, department breakdown, optional results walk-through. No commitment.
Onboarding (week 2)
We onboard your staff to the awareness platform, configure Microsoft 365 report-phishing button and tune Defender anti-phishing policies.
Monthly module + quarterly simulation (ongoing)
Each month: a 10-min module per user. Each quarter: a fresh simulated phishing campaign with per-user risk scoring and a management report.
Defender + Entra hardening (concurrent)
Where the pilot surfaces BEC risk, we tune Defender and Entra — anti-phishing, impersonation, conditional access — typically delivered in one fixed-price engagement.
Quarterly review
Review click rates, repeat offenders, sector-relevant threat intel. Adjust the next quarter's campaign and module set based on real data.
Sectors we protect
Free phishing-awareness pilot — 10 of your staff, one simulated campaign
We'll run a realistic but safe simulated phishing campaign on 10 of your staff and send you the click report. No commitment, no card. If your click rate is over 15%, training is justified.