Skip to content

The human side of security

Security Awareness and Incident Readiness

Security runs through the choices your people make every day. We help your team work securely, recognise the attacks aimed at them, and be ready when one gets through.

Book a discovery call

Your people are the front line

Your people make small security decisions all day, often without noticing, like which link to trust or how to handle a customer's record. Most are harmless. A few can open a gap an attacker can use.

Phishing and social engineering aim straight at those choices, and the lures keep getting sharper as attackers write them with AI. A team that has been trained to recognise them, and that knows what to do and what to report, is far less likely to hand over the credentials that lead to account compromise.

Even so, something will get through eventually. The time lost working out what to do next is time the business cannot afford, so a plan already in place and a team that has practised it let you contain an incident far faster.

How we help

Working securely comes down to three things: the everyday habits of your team, how your engineers build, and whether you are ready when something goes wrong. We cover that whole picture, from awareness through to secure engineering and a response you have practised. Take the parts you need, or all of it.

Awareness and secure habits

Phishing awareness

We run realistic phishing against your team, then train on what people fell for, so they learn what to look for, what to avoid, and what to report.

Password and access habits

Plain guidance on passwords, multi-factor authentication and access, so the everyday handling of credentials stops being the easy way in.

Handling data the right way

Clear, practical expectations for how your people work with customer and company data, sized to how your team actually operates day to day.

Secure engineering

Secure coding

Working sessions for your engineers on the flaws that keep recurring, and how to stop writing them. That now includes the mistakes AI coding assistants reintroduce.

Threat modelling

We sit with your engineers and work through how a feature could be abused before it is built, so design-stage weaknesses are caught early. You get a short list of the risks worth designing against.

Incident readiness

An incident response plan and playbooks

A plan and playbooks written for your environment, setting out who decides, who acts, who is told inside the company and who would need to be told outside it when something serious happens.

A simulated incident exercise

We run an unfolding scenario with your team. The people who make the calls practise making them, the internal and external communications get rehearsed, and you walk through the technical response together, so the gaps in your plan, tooling and access surface while it is still only an exercise.

What you walk away with

A team that works securely as a matter of habit, engineers who build with security in mind, and a response you have practised before you need it. It is what a customer's security review looks for, and what lets you contain an incident when one happens.

And if you would like us to keep the training and exercises going as the team grows and changes, that is work we are happy to take on.

Want to see where the people side sits against the rest of your security? The Custos Secure Baseline scores your whole programme and shows where awareness and readiness rank against everything else.

See the baseline

Custos was founded by Liran Aknin, who has run security operations and hardened cloud environments in production. The work is delivered to that standard.

Who you work with

Get your team ready

A 30-minute discovery call to scope the awareness, engineering and readiness work for your team.

Book a discovery call