Yes – employee training is a standard part of almost every retainer agreement I sign.
Human error still causes ~85 % of incidents in Poland, therefore ongoing awareness programmes are treated as a core component (not an optional extra).
What is typically included in the retainer training package
| Activity | Frequency (typical retainer) | Format |
|---|---|---|
| Security awareness workshop | 2–4 times per year | On-site or live online |
| Phishing simulation campaigns | Every 2–4 months | Real-life simulated attacks + report |
| Incident response tabletop exercises | 1–2 times per year | Scenario-based (ransomware, leak…) |
| Short “lunch & learn” sessions | Monthly or quarterly | 30–45 min on hot topics |
| New-employee onboarding module | Automatic for every newcomer | Video + quiz |
| Policy & procedure training | After every major policy update | Live or recorded |
Most popular topics (2024–2025)
- Recognising phishing & CEO fraud
- Secure password & MFA usage
- Safe use of USB devices and mobile phones
- Incident reporting – what to do in the first 5 minutes
- GDPR / data protection basics
- Social engineering red flags
All materials are provided in Polish and English, and every participant receives a personalised certificate.
Result for my retainer clients: phishing click rate drops on average from ~28 % to under 4 % within the first 12 months.