Is this for you?
- You need awareness training that satisfies EASA Part-IS, ISO/IEC 27001 or an insurer's requirement, and you want it to be worth the hour.
- Your pilots, technicians and engineers switch off at generic security content.
- You have had phishing or invoice-fraud attempts and want the whole company to recognize the next one.
- You want a measurement, not just attendance.
What you get
- Role-based sessions. Four tracks of 45 to 60 minutes, live over video or on site: flight crew (EFB, connectivity, GNSS and ADS-B awareness), maintenance and technicians (records integrity, portable devices, supplier tools), engineers (design data, source and update pipelines), and office and management (email, payments, social engineering). Recorded for later hires.
- Phishing simulations. A baseline campaign before the sessions and a follow-up after, with realistic aviation-themed lures, run with your consent and without shaming anyone.
- Before-and-after report. Click and report rates by group, what changed, and what to reinforce, in a form you can show an authority, an insurer or a customer.
- Reference cards. One page per role with the five things that matter most, for the crew room and the workshop wall.
- Annual refresh. Optional: a shorter session and a new simulation each year, with the trend.
How it runs
- Week 1BaselineA short call to agree the roles and the scenarios, then the baseline phishing simulation.
- Weeks 2–3SessionsDelivered by role, live, at times that fit rosters; each recorded.
- Week 4Follow-up simulation and reportThe second campaign, the report, and reference cards.
What I need from you
A list of staff by role and email address, agreement from management on the simulation (I provide the wording to announce it), and 45 to 60 minutes per person.
Questions I get asked
Live or recorded?
Live, because the questions are where the learning happens, with the recording kept for people who join later.
Does this satisfy Part-IS or ISO/IEC 27001 awareness requirements?
Yes. Attendance is recorded, the content is documented, and the before-and-after report is the kind of evidence an auditor looks for.
How large a group?
Any size, but sessions work best under 25 people so that they stay a conversation.
Will staff be embarrassed by the phishing test?
No. Results are reported by group, not by name, the announcement makes clear that it is training, and the point of the second run is to show the group how far it has come.
Start with a 45-minute readiness call
Tell me what you build or operate. You leave the call with your three most important next steps, whether or not we work together; if this engagement fits, a fixed-scope proposal and quote follow within a few days.
Ask about training