RAKSHA

Security Awareness & Training Advisor

← Hub Human Risk v1.0

Client Profile

WHY

Over 90% of successful breaches start with human error — a phishing click, a weak password, or an accidental data share. Technology controls alone cannot stop a well-crafted spear phishing attack or a motivated insider. Your people are either your greatest vulnerability or your most effective last line of defence.

WHAT

A structured Security Awareness and Training program combines simulated phishing attacks, role-based learning modules, policy acknowledgements, and continuous reinforcement — covering password hygiene, social engineering, safe data handling, incident reporting, and compliance obligations tailored to each role's actual risk exposure.

HOW

We start with a baseline phishing simulation to measure your team's current click rate. We then build a quarterly training calendar using short, engaging modules from our OEM partners. We track improvement over time and provide board-level reporting on human risk reduction. If your team scores well, we don't push unnecessary renewals.

Available OEM Vendors (18)

PlatinumGoldSilverBronzeTrade
1

Trend Micro PLATINUM

Email Security — full platinum delivery

2

Check Point PLATINUM

Harmony Email & Collab — full platinum delivery

3

Cisco PLATINUM

Secure Email Gateway — full platinum delivery

4

Fortinet GOLD

FortiMail — gold delivery

5

KnowBe4 GOLD

Security awareness & phishing simulation — gold delivery

6

Proofpoint GOLD

Email Protection & SAT — gold delivery

7

Trellix GOLD

Email Security — gold delivery

8

Threatcop GOLD

Security awareness training — gold delivery

9

Sophos SILVER

Sophos Email — silver delivery

10

Barracuda SILVER

Email Security Gateway — silver delivery

11

Cofense SILVER

Phishing detection & response — silver delivery

12

Kaspersky SILVER

Secure Mail Gateway — silver delivery

13

Microsoft SILVER

Defender for Office 365 — silver delivery

14

Varonis SILVER

Email security & DLP — silver delivery

15

Fortra BRONZE

Email security solutions — bronze advisory

16

Cloudflare BRONZE

Email security — bronze advisory

17

Mimecast TRADE

Email security — procurement only

18

Google TRADE

Workspace email security — procurement only

Trend Micro PLATINUM

Phish Insight — cloud-based phishing simulation & training

2

Sophos PLATINUM

Phish Threat — simulated phishing attacks & training modules

3

KnowBe4 GOLD

World's largest security awareness & training platform

4

Proofpoint GOLD

Security Awareness Training — integrated with email security

5

Threatcop GOLD

People security management & awareness training platform

6

Barracuda SILVER

PhishLine — phishing simulation & awareness platform

7

Mimecast TRADE

Awareness Training — procurement & license fulfillment

Vendor-neutral. Customer-first. We recommend what you need — nothing more.

Program Readiness Dashboard
Overall Program Score0%
0
Implemented
0
In Progress
0
Not Started
0
Gap Identified
Critical ModulesLoading...
High Priority ModulesLoading...
Training Modules — 8 Domains
Implementation Roadmap
1
Baseline Assessment
Week 1–2
  • Launch baseline phishing simulation across all employees
  • Measure click rate, report rate, and credential submission rate
  • Survey current awareness levels and knowledge gaps
  • Identify high-risk departments and roles
  • Select OEM platform and configure tenancy
2
Program Design
Week 3–4
  • Define annual training calendar with quarterly phishing campaigns
  • Map training modules to roles (IT, Finance, HR, Executive, All-Staff)
  • Customise phishing templates for your industry and brand style
  • Configure automated training triggers for users who click phishing
  • Set KPIs: target click rate <5%, report rate >25%
3
Launch & Reinforce
Month 2–6
  • Deploy all-staff core awareness training (phishing, passwords, data handling)
  • Run monthly simulated phishing campaigns with varied templates
  • Launch role-based modules for finance, IT, and executives
  • Distribute policy acknowledgement for acceptable use and data classification
  • Publish monthly human risk scorecard to management
4
Measure & Mature
Ongoing / Quarterly
  • Quarterly review of click rates and training completion rates
  • Refresh training content to reflect new threat trends
  • Board-level human risk report annually
  • Integrate awareness metrics into security risk register
  • Benchmark against industry average click rates
Human Risk — Business Impact
Phishing attack leading to credential theft or ransomware₹50L – ₹10Cr+ incident cost
Employee clicks phishing leading to BEC / wire fraudAverage loss: ₹1.5Cr per incident
Accidental data sharing / email misdirectionDPDP / regulatory breach exposure
Weak passwords leading to account takeoverLateral movement and data exfiltration risk
No incident reporting culture — delayed responseAverage breach containment delayed 200+ days
No awareness program — non-compliance (ISO, DPDP, RBI)Audit findings + regulatory penalties
Raksha Technologies
Cybersecurity Procurement Advisory · www.raksha.co.in