TrainingData Risks

Where there are people, there is risk. The right data training turns it into an asset.

Where people meet technology, that risk can cost you badly. Our GDPR and cyber security awareness training is practical, plain-English and genuinely engaging – the understanding that turns your staff from your biggest data risk into your first line of defence. Not a legal lecture. Not a slideshow of regulations.

The human factorMost breaches start with a person, not a system.

Two courses, one theme

Different subjects. One common thread.

One theme: understanding how data moves through your organisation, and where the human risk sits. Run the two courses separately, or combine both into a single day.

Course 01

Cyber Security Awareness

Practical, real-world training in recognising and responding to threats. Pitched at staff who aren’t technical, because they’re usually the biggest vulnerability in any organisation’s security. No jargon, no scare tactics, and a lot more engaging than you’d think.

  • Spotting phishing, vishing and impersonation attacks
  • Password hygiene, multi-factor and account security
  • What to do the moment something looks wrong
  • Safe use of AI tools and cloud services

Course 02

GDPR Training

What the regulations actually mean for your organisation, in plain English. Not a recitation of the legislation, and not as dry as you’re expecting. A practical session on what staff need to know, what to do differently, and why it matters beyond the fine.

  • The basic definitions: what personal data is, and what counts as special-category
  • The core principles, and the lawful basis for using data
  • Consent versus legitimate interest, and when each one applies
  • Handling data requests, breaches and incidents in practice

Would your team spot it?

It only takes one convincing screen.

A convincing sign-in page is one of the oldest tricks there is, and it still works. This one gives itself away three times over. Noticing that, on a busy Tuesday, is the instinct our cyber security awareness training builds – and phishing is only the email version. The same trick arrives by phone and in person too.

Cyber security · phishing

  • The address. An “r” and an “n” faking an “m”: rnicrosoft, not microsoft. And http, not https.
  • The button.“Sumbit”, not Submit. Real companies proofread. Attackers are in a hurry.
  • The pressure. A login you didn’t go looking for, nudging you to act before you think.

In the room

Two exercises that make it stick.

Listen · vishing

A real attack, as it happens.

We listen in together on a genuine recorded vishing call – a scammer talking a real person round over the phone. You hear the friendliness, the manufactured urgency, and the exact moment it nearly works. Nothing lands the lesson quite like it.

Build · write your own

Now you try to fool the room.

We get people to write their own phishing email – and they immediately hit the attacker’s problems. You can’t use starbucks.com, so you’re stuck faking it. Once you know why phishers make the choices they do, you spot those same tells everywhere.

And on your own forms?

A pre-ticked box isn’t consent.

Under GDPR, consent has to be a genuine choice, freely given and clear. This sign-up screen breaks that three ways over – the kind of thing our GDPR training helps your team notice and put right.

GDPR · valid consent

  • Already ticked. Consent has to be a positive opt-in the person actually makes. A box that arrives ticked isn’t a choice.
  • Bundled together. Marketing, sharing with partners and training models are three different purposes. Each needs its own yes.
  • Vague.“Use my data to train models” doesn’t say what you’re agreeing to. Consent has to be specific and informed.

Compliance, done properly

Yes, it helps you meet your obligations.

If you need to demonstrate that your staff have had data protection or cyber security awareness training – whether for an audit, a contract, an insurer, or simply because it’s the right thing to do – we can help with that.

  • For an audit
  • For a contract
  • For an insurer
  • Because it’s right

The goal is understanding, not a signature on a register.

Staff who understand why data handling matters, and what the real risks look like, are worth far more than staff who sat through a session and ticked a box. We aim for the former, and the compliance record follows naturally.

The practical details

Where, when and how long: shaped around you.

The two courses run differently, because they’re doing different jobs. Here’s roughly what to expect from each.

Course 01

Cyber Security Awareness

Duration

Ninety minutes. Long enough to cover the ground properly, short enough that a room of non-technical staff stays genuinely engaged.

Delivery

On-site is always the preferred option – it’s easier to keep energy up and handle questions in the room. But if you need to do this via Teams, that's okay too.

Group size

Works well up to around twenty. Larger than that, worth a quick conversation.

Course 02

GDPR Training

Duration

Two hours to a full day. Why so vague? Well, the content is completely driven by what you need. A whole-staff overview is a different session from an in-depth day for data leads.

Delivery

On-site is better if possible – the energy you get in the room is really hard to replicate when everyone is just a small inch-square image. But we can do it via Teams if needs be.

Group size

Flexible, from a small group of senior staff to an all-hands session for the whole organisation.

Tailored

Both sessions are shaped around your organisation: your data, your systems, your staff’s actual responsibilities. Just tell us what you need when we speak.

Trusted where it matters

Built for organisations that can’t afford to get data wrong.

We’ve delivered data risk training across the public sector, education and professional services – all places with real data protection obligations and staff who need to understand them in practice, not just in theory.

Buy with confidence.

Every session comes with our standard training guarantee. If it isn’t right, we’ll put it right – no quibble, no small print.

Read the full guarantee →

Get a quote

Get a quote for your organisation.

Tell us which course you’re interested in – or both – roughly how many people, and when you’re thinking of running it. We’ll come back with a date and a price. Not sure what you need? We’re happy to talk it through first, and it’ll be Andrew who replies, not a call handler.

No obligation, no sales pressure. Just a straight answer on dates and price, usually within one working day.

Or send the details
Training Enquiry form

We’ll reply within one working day, usually sooner.