Whitesec ID
Training & Certification

PECB-Certified Professional Training & Certification

Even the best technology fails when the people using it are not ready

  • PECB Certified
  • Cybersecurity Awareness
  • Phishing Simulation
  • Lead Implementer

As an official PECB partner we deliver internationally certified training alongside internal awareness programmes. Material is shaped around your sector, your risk profile, and the level your participants are actually at.

What you receive

  • Tailored curriculum and training material
  • Sessions led by internationally certified trainers
  • Evaluation report on participant understanding
  • Phishing simulation report and recommendations
  • Attendance certificates and PECB exam preparation
Context & Urgency

Why this matters now

Even the strongest technical controls still rest on human decisions: who clicks the link, who approves the access request, and who reports the anomaly early.

  • Awareness fades without repetition

    A standalone annual session rarely changes habits. Effective programmes combine short recurring material, simulation, and immediate feedback.

  • Generic material struggles to change behaviour

    The risks facing finance staff differ from those facing developers or the board. Material built around the role is far easier to apply.

  • Standards require evidence of competence

    ISO/IEC 27001 requires organisations to ensure the competence of personnel affecting information security, training records included.

Signs your organisation needs this

  • An employee has already fallen for a phishing email
  • Security policies are published but rarely understood by their audience
  • The technical team holds no internationally recognised certification
  • An auditor is asking for training evidence that was never documented

Any one of these is reason enough to start the conversation early.

Scope

What we cover

  • ISO 27001 Lead Implementer

    PECB-certified training for practitioners implementing an ISMS.

  • ISO 27701 Lead Implementer

    Deep dive into implementing a privacy information management system.

  • Risk Management ISO 31000

    A risk management framework that works across organisational functions.

  • Cybersecurity Awareness

    Employee awareness programmes with contextual, plain-language material.

  • Phishing Simulation

    Controlled simulations with behavioural analysis and follow-up.

  • Executive & Tabletop Exercise

    Management sessions and decision-making simulations under incident conditions.

How We Work

Clear stages, with no surprises along the way

Every stage has agreed deliverables, so progress is never in question.

  1. 01

    Needs Analysis

    Mapping participant profiles, sector risk, and learning objectives.

  2. 02

    Material Design

    Curriculum built around your business context and real case studies.

  3. 03

    Delivery

    Online, classroom, hands-on workshop, or in-house.

  4. 04

    Evaluation

    Measuring participant understanding before and after the session.

  5. 05

    Certification

    Preparation and support through the official certification exam.

Reference Basis

The standards and regulations we work from

Every recommendation traces back to the references below and can be verified independently.

  • ISO/IEC 27001:2022 clauses 7.2 & 7.3Requirements for competence and awareness of personnel.
  • PECB certification schemeThe internationally recognised Lead Implementer and Lead Auditor tracks.
  • ISO 31000:2018The risk management framework for cross-functional training.
  • Law No. 27 of 2022The basis for personal data protection awareness material.

Success indicators

Agreed upfront so the work is judged objectively rather than by impression.

  • Participant understanding before and after training
  • Change in click rate across phishing simulations
  • Number of staff achieving professional certification
  • How quickly employees report suspicious activity
Glossary

Terms that come up in these discussions

The vocabulary you will meet in documents, reports, and conversations with auditors.

Security Awareness
A continuous programme building safe habits across the whole workforce, not a one-off session before an audit.
Phishing Simulation
Deceptive emails sent under controlled conditions to measure employee behaviour and turn it into a teaching moment.
Lead Implementer & Lead Auditor
Two professional certification tracks: implementing a management system, and auditing one.
Tabletop Exercise
A scenario-based exercise that never touches production, used to test how the team makes decisions during an incident.
Frequently Asked

The questions we hear most

Still unanswered? Send your question and our team will reply on a working day.

Ready to build stronger security?

Talk your organisation's needs through with our team. Free, and without obligation.