IHETC Business
Risk starts with a password, not an attack
The vast majority of incidents start with a reused credential or a fraudulent message. That is where most of the risk sits, not in technical sophistication.
Three topics, by return on effort
- 01
Digital hygiene for everyone
Passwords, two-factor, backups. Unspectacular, and responsible for most of the risk avoided.
- 02
Payment fraud, for exposed functions
Accounting, procurement, management. The costliest scenario, and the one requiring no technical skill from the attacker.
- 03
Incident response, for managers
What to do within the hour, who to notify, what to record. One hour well spent limits a week of damage.
What we do not teach
We do not train in penetration testing or offensive techniques. It is a regulated trade requiring a written mandate from the system owner, and distributing an offensive playbook outside that frame would be irresponsible. Our scope is defensive: understanding an attack to detect and contain it.
Awareness training that achieves nothing
An annual one-hour campaign, completed by everyone and forgotten by everyone, produces a completion rate and no change. What works is short, repeated, and tied to a real incident in the sector. We prefer four fifteen-minute sessions spread across the year over one session that ticks a box.