Skip to main content
IHETC Business

IHETC Business

Risk starts with a password, not an attack

The vast majority of incidents start with a reused credential or a fraudulent message. That is where most of the risk sits, not in technical sophistication.

Three topics, by return on effort

  1. 01

    Digital hygiene for everyone

    Passwords, two-factor, backups. Unspectacular, and responsible for most of the risk avoided.

  2. 02

    Payment fraud, for exposed functions

    Accounting, procurement, management. The costliest scenario, and the one requiring no technical skill from the attacker.

  3. 03

    Incident response, for managers

    What to do within the hour, who to notify, what to record. One hour well spent limits a week of damage.

What we do not teach

We do not train in penetration testing or offensive techniques. It is a regulated trade requiring a written mandate from the system owner, and distributing an offensive playbook outside that frame would be irresponsible. Our scope is defensive: understanding an attack to detect and contain it.

Awareness training that achieves nothing

An annual one-hour campaign, completed by everyone and forgotten by everyone, produces a completion rate and no change. What works is short, repeated, and tied to a real incident in the sector. We prefer four fifteen-minute sessions spread across the year over one session that ticks a box.

Risk starts with a password, not an attack — IHETC Business | IHETC — IHETC