Cybersecurity & Data Protection

Technology stops most attacks. The ones that get through are aimed at people — and no firewall you own defends against a message that persuades someone to act.

The threat

What social engineering actually looks like now.

The attack types below share one thing: none of them exploit a technical vulnerability. They exploit the fact that a person was expecting a message roughly like this one.

Phishing

Email that impersonates someone the recipient already trusts.

Still the entry point for the majority of breaches, and no longer recognisable by bad spelling. Modern lures replicate real internal systems and arrive into a context the recipient was already expecting.

Smishing

SMS phishing, landing on the device people trust most.

Your email security investment offers no protection here at all. Text messages carry an assumption of legitimacy that email lost years ago, and they arrive on personal devices outside any managed estate.

Quishing

QR codes that carry the payload past every filter.

A QR code is an image, so it passes link scanning untouched, and the destination is invisible until the phone has already opened it. Printed codes placed in real premises are the hardest variant to detect.

Deepfake & voice cloning

A familiar face or voice, synthesised on demand.

A few seconds of public audio is enough to clone a voice convincingly. Verification procedures that rely on recognising a colleague on a call no longer hold, and staff need a different test.

Business email compromise

A real invoice, a real supplier, altered bank details.

The highest-value attack per incident, and the quietest. It usually begins with one compromised or spoofed mailbox and ends with a legitimate-looking payment leaving on schedule.

AI-assisted campaigns

Targeted quality, at untargeted volume.

Generative tools removed the trade-off between how tailored a lure is and how many people receive it. Every recipient can now get a message written for them specifically, at the cost of a generic one.

What we deliver

Services in this practice.

Awareness programmes

Role-tiered training built around your own operating context, not generic corporate examples. Separate content for front-line staff, data handlers and executives, because they face different attacks.

Simulation and testing

Phishing, smishing, vishing and QR exercises run on a measured cycle. We report on report rate and time-to-report, not just click rate — a workforce that clicks less but reports nothing is more dangerous, not less.

Data protection compliance

Nigeria Data Protection Act and GAID: registration, compliance audit returns, DPO support, data protection impact assessments and cross-border transfer review. UK GDPR equivalents where you operate in both.

Breach readiness

The NDPA gives you 72 hours from awareness, not from the end of your investigation. We design the recognition, escalation and notification path that makes that deadline achievable.

ISO/IEC 27001 and 42001

Information security and AI management systems, from gap analysis through implementation to certification audit. Detailed on the ISO certification page.

Impersonation response

Monitoring for lookalike domains, structured evidence packaging, and coordinated reporting to registrars and national CERTs. For any organisation whose brand is worth faking, this is the gap training alone cannot close.

How a programme runs

Measured, phased, handed over.

01

Baseline

A simulation before any training, so improvement can be evidenced to a regulator or a board rather than asserted.

02

Train by role

Tiered delivery. A field officer, a registry operator and a director face different threats and need different sessions.

03

Re-test

A second exercise at 30 days, then quarterly, with scenario difficulty rising as the workforce improves.

04

Transfer

Train-the-trainer certification so your own people sustain the programme without recurring external cost.

Delivered at federal scale, across six zones

In 2021 our Director designed and delivered the information security awareness programme for the Standards Organisation of Nigeria, reaching approximately 1,500 staff across all six geopolitical zones. She had earlier run the organisation's video conferencing rollout across eleven offices in the same six zones.

That is why our delivery model assumes what a federal agency actually looks like: zonal and state offices rather than one headquarters, uneven connectivity, and a large share of staff who do not sit at a desk. A programme designed for a single corporate office does not survive contact with that.

We never punish the user

Simulation results are reported in aggregate. Individual results are used for support and coaching, never for disciplinary action. Programmes that punish failure destroy the reporting culture they were built to create — and the reporting culture is the entire point.

Find out what your click rate actually is.

A baseline simulation is the cheapest way to learn where you stand. It takes about two weeks and gives you a number you can take to your board.

Start a conversation