Skip to main content
IHETC Business

IHETC Business

Risk starts with a password, not an attack

The vast majority of incidents start with a reused credential or a fraudulent message. That is where most of the risk sits, not in technical sophistication. The path starts from those everyday practices, the ones a whole organisation can actually hold.

Three topics, by return on effort

  1. 01

    Digital hygiene for everyone

    Passwords, two-factor, backups. Unspectacular, and responsible for most of the risk avoided.

  2. 02

    Payment fraud, for exposed functions

    Accounting, procurement, management. The costliest scenario, and the one requiring no technical skill from the attacker.

  3. 03

    Incident response, for managers

    What to do within the hour, who to notify, what to record. One hour well spent limits a week of damage.

Our scope: defence, end to end

We do not train in penetration testing or offensive techniques. It is a regulated trade requiring a written mandate from the system owner, and distributing an offensive playbook outside that frame would be irresponsible. Our scope is defensive: understanding an attack to detect and contain it.

Awareness training that changes reflexes

An annual one-hour campaign, completed by everyone and forgotten by everyone, produces a completion rate and no change. What works is short, repeated, and tied to a real incident in the sector. We prefer four fifteen-minute sessions spread across the year over one session that ticks a box.

The base you build on

The cybersecurity area of the base holds 18 modules available with no further production, and the catalogue rule applies here as everywhere: 10 supervised hours per credit. That volume is what allows a company need to be covered from the very first rollout.

modules available
18
open with no technical prerequisite
10

Official catalogue rule, without exception.

supervised per credit
10 h
Risk starts with a password, not an attack — IHETC Business | IHETC — IHETC