Training and Phishing is a combined service with two parts:
- Security Awareness Training provides security and compliance courses for people across your business.
- Phishing Simulations sends realistic spoof emails, including sign-in scenarios, to help your people recognise attempts to steal credentials.
The two parts are linked. For example, if someone is caught out by a phishing simulation, targeted training can be assigned to them automatically.
Training and Phishing is an add-on to your HackRisk subscription. You can add it through the subscription management process, and it is charged per person.
Enrol your users
Once you have added Training and Phishing, you need to enrol your users. The enrolment tab only appears when your subscription includes at least one training user. You can enrol people in several ways from the admin section.
- Connect to Microsoft 365 Exchange. This imports every user into the training service automatically, and keeps them in step over time, adding or removing people as they join or leave your business.
- Limit synchronisation to specific groups. If you would rather not enrol everyone, you can restrict the sync to chosen groups.
- Upload a CSV. Download the CSV template so your data is in the right format, then upload it.
- Add people individually. Enter a person's details into a form.
Once users are added, you can manage them from the same screen.
Courses
The course library includes courses specific to UK organisations, plus a wider information security library available to everyone.
UK compliance courses
- Anti-Money Laundering
- Anti-Slavery
- Anti-Tax Evasion
- The Data Protection Act
- The Bribery Act (UK): Introduction
- The Bribery Act (UK): Understanding Compliance
- AI Agents (UK)
- Data (Use and Access) Act 2025
- GDPR for Your Business, Parts 1 to 4
Other compliance courses
These are not labelled UK-specific, but are often relevant depending on your sector. For example, PCI DSS applies to any business handling card payments.
- GDPR, GDPR (Advanced) and GDPR Essentials
- Network and Information Security Directive (NIS 2)
- ISO 27001: Awareness
- PCI DSS, PCI DSS Essentials and PCI DSS 4.x
- Protecting Payment Card Information
- Protecting Personal Data (GDPR)
These are available to all users.
- Phishing, Smishing, Vishing and Quishing (QR Code Phishing)
- Social Engineering
- Secure Passwords & Authentication
- Multi-Factor Authentication (MFA) Fatigue Attacks
- Secure Email Use and Email Thread Hijacking
- Ransomware, Malware, and Spyware & Adware
- Data Breaches, Information & Data, and Protecting Your Online Privacy
- Public Wi-Fi, Secure VPN Use and Home Network Security
- Working Remotely and Security at Home
- Mobile Device Security and Removable Media
- Physical Security and Clear Desk Policy
- Cloud Security and Using Third Party Services Securely
- Secure Internet Use and Using Social Media Safely
- Videoconferencing Securely and File Sharing in the Workplace
- Patching & Updating and Online Payments
- Denial of Service Attacks (DOS)
- The Insider Threat, What Makes a Cyber Criminal? and The Internet of Things
Phishing simulations
Phishing simulations send realistic spoof emails to the people you have enrolled. Each person is assessed across three stages: whether they opened the email, whether they visited the linked site, and whether they entered credentials.
Results feed into your HackRisk score, based on each person's performance in the most recent simulation. If someone is compromised in a simulation, targeted training can be assigned to them automatically.