Training, Talks & Live Hacking

Your people are the weakest link. Or your strongest defence.

We show your team how attacks really unfold: with live hacking on demo systems, with real findings from our penetration tests and with cases from our time as cybercrime investigators with the criminal police. No off-the-shelf training: first we talk about what is on your mind, an old pentest report, an incident, a compliance requirement. The programme grows out of that, as a talk, a full-day seminar or a series.

  • Real findings from pentests
  • Cases from investigative work
  • No standard programme

What ends up on the screen in a live hacking session

A charging cable that types

What the audience sees
A cable or stick looks like any other. Plugged in, it pretends to be a keyboard and types commands within seconds, faster than anyone can look.
What sticks
No unknown USB device on a company machine, not even a charging cable from a trade-fair booth. A found stick goes to IT, not into the laptop.

Click through six typical demos. Everything runs on our systems, none of it on yours.

Formats and topics

There is no off-the-shelf programme. The building blocks here are examples of what we deliver regularly. Before every session we talk to you: what is the occasion, who is in the room, what should change afterwards? We cut the format from that.

Talk or keynote

Live hacking

A real attack, performed in real time and explained step by step so that non-technical people follow it too. For staff assemblies, kick-offs, customer events, trade fairs and management meetings. A password that falls in seconds stays in people's heads longer than any policy.

  • 45 to 90 minutes, with Q&A on request
  • USB, passwords, Wi-Fi, web shop, phishing, cloned voice: attacks you can touch
  • Only on prepared demo systems, never on your data
  • Also as a programme item at other people's events
Jump to a demo:
Training

Cyber security for employees

Phishing, CEO fraud, fake invoices, passwords, mobile devices and how to react when something goes wrong. With exercises and case studies, half or full day.

At your place, remote or elsewhere

  • In-house: a room, a projector, a power socket, nothing more
  • Remote via Teams or Zoom, live hacking included
  • At third-party events: chambers, associations, conferences, customer events
  • German or English
  • From a workshop of eight to a full staff assembly
Seminar

Cyber security for executives

Liability and duty of care, NIS2, the business impact of an incident, emergency organisation and decision paths. Compact, no technical background required.

Talks on single topics

One topic, 30 to 60 minutes, for specialists or the whole workforce. For example:

  • Phishing & vishing
  • Social engineering
  • Deepfakes & AI fraud
  • Physical security & tailgating
  • Passwords & MFA
  • Ransomware
  • NIS2 for decision-makers
  • Shadow IT & OSINT
Technical seminar

Blue teaming for IT teams

The attacks we run as a red team, seen from the defender's side: what they look like in the logs, where they get stuck and which configuration would have stopped them. Typical findings from pentests, hardening Active Directory, networks and cloud, detection and response. On request along your own pentest report. For admins who want to know what the next test would find.

Training series

Multi-part programmes

Several modules that build on each other, spread over weeks, for example staff, management and IT in turn. Also as an open series through chambers, associations or training providers.

Individual, like a pentest

A training session that has nothing to do with your daily work is worth nothing to you. So we ask first what is on your mind, and build the programme around it:

  • The last pentest report
  • An incident from the past
  • A compliance requirement such as NIS2, ISO 27001 or TISAX
  • Your industry, size and processes
  • Results of a phishing simulation
  • A concrete occasion: staff assembly, kick-off or trade fair

Which format fits you?

Three answers, one suggestion. We settle the fit to your occasion in the call.

Who is in the room?
How much time is there?
What should come out of it?
Our suggestion

Live hacking talk

Examples from everyday office life: phishing, phone calls, USB devices, mobile devices, what to do when something goes wrong.

The live attack takes centre stage, theory only as much as needed.

Ask about this format

From real cases, not from the textbook

Our examples come from penetration tests we carried out ourselves and from investigations with the criminal police: the reception desk that waved the fake technician through, the password on a sticky note in the server room, the transfer approved after a call with a cloned voice. Anonymised, but that is how it happened.

If you already have results, the training gets even more concrete: findings from your pentest report, whichever provider wrote it, click rates from your phishing simulation, an incident from your past. Your employees then see not just any attack, but the one that would have worked on them. What may appear on screen is agreed with you beforehand.

How an attack chain breaks

An attack needs every step. One person who hesitates at the second and reports it ends it.

That is the exact moment we practise: notice, pause, report. Without guilt and without anyone being singled out.

Your results as teaching material
Pentest report, phishing simulation, past incidents: what actually happened at your company has more impact than any outside example. Anonymised wherever people are involved.
Demo systems, never your data
Every attack runs against purpose-built target systems. On request we show anonymised results from your own pentest, agreed with you beforehand.
Nobody gets exposed
Employees should report suspicious things without fearing their own inbox. Whoever clicked in a test stays anonymous.

Training is no longer optional

Several frameworks now require regular training. Our content follows these requirements, and you receive the agenda in advance for your records. Whether that satisfies your obligation is a question for you and your advisers.

01

NIS2 / Section 38 BSIG

Management bodies of essential and important entities in Germany must attend regular training on IT security risk management. Article 21(2) of NIS2 additionally requires cyber hygiene practices and training for staff.

02

ISO 27001

Control A.6.3 requires awareness and training for all personnel, regularly and documented. A live format covers the content and stays in people's heads longer than a click-through module.

03

TISAX / VDA ISA

The catalogue requires trained and aware staff, especially where people have access to prototypes and customer data. Live formats on physical security fit particularly well here.

From the first call to delivery

  1. 1

    Conversation

    What is on your mind: a pentest report, an incident, a compliance requirement, a staff assembly? Plus audience, time and place. Half an hour is usually enough.

  2. 2

    Tailoring

    We pick demos and examples to match your industry, size and occasion. On request your own results go in, agreed on what may be shown.

  3. 3

    Delivery

    On site or remote. We bring the laptop, the demo environment and the hardware, you provide the room and a projector.

  4. 4

    Afterwards, as needed

    A follow-up call, material for the workforce, a refresher after six months or a phishing simulation to measure what stuck. None of it is mandatory, all of it is possible.

Training and measurement belong together

Training changes behaviour, a simulation shows whether it did and for how long. Many customers combine both: the training first, a phishing or vishing campaign a few weeks later, then a short refresher with the real results from their own company.

Frequently asked questions

No. All attacks run against demo systems that we bring along or operate in our own cloud environment. Your infrastructure is not touched. If you want to show your own examples, for instance from a pentest at your company, we agree beforehand what may appear on screen in anonymised form.
Talks run 30 to 90 minutes, training sessions half or a full day, series stretch over several dates. Interactive workshops work best with up to about 20 people. Talks and live hacking sessions also carry in front of several hundred.
Yes, live hacking included. We share the screen of the attack machine and the target systems, and use breakout rooms for small-group exercises. In our experience the impact is greater on site, especially for hardware attacks such as USB devices or lockpicking.
A room, a projector or screen with HDMI and a power socket. We bring the laptop, the demo systems and the radio and USB hardware. Internet helps but is not required, the demos also run offline.
We price by format and preparation effort, not by headcount. A talk with live hacking costs differently from a full-day seminar tailored to your industry. After the briefing call you receive a fixed-price quote including preparation and travel.
Platforms scale well and make sense for annual mandatory modules. A live format works differently: the group experiences the attack together, and whoever has a question gets an answer on the spot, with examples from their own environment. Many customers combine both, the platform for the year, the live hacking as opener or refresher.
Yes, at chambers, associations, conferences and customer events. Organisers get in touch with a date, the audience and the time slot, and we agree the rest together.
Yes, gladly. The report does not have to be ours. We read it in advance, pick the findings that suit the workforce or the IT team, and build the demos around them. The same goes for the results of a phishing simulation or an incident from your past. What gets shown, in anonymised form, is agreed together with you.

Tell us the occasion and the audience

A staff assembly next month or a training series for the whole company: write to us or book a short call straight away.