Tailor-made security training bites
Not every security problem calls for a full training program. Sometimes your team hits a specific gap: a vulnerability class that keeps showing up in code reviews, a new technology nobody on the team has secured before, or an architecture decision where the security implications aren’t clear. That’s what Custom Focus Sessions are for. I build a short, focused session around exactly the topic your team needs, based on a brief scoping call beforehand.
What kind of topics work well
Each engagement starts with a short call where we figure out what your team actually needs. No generic slides, no material recycled from other trainings. Here are some examples of what teams typically ask for:
How the sessions work
Sessions run between 2 and 4 hours, depending on the topic. That’s long enough to get into real depth for a focus topic, short enough to fit into a workday without losing people’s attention or binding the team for too long.
I prepare every session individually. There are no pre-built modules I pull from a shelf. The content matches what came out of our scoping call, down to the specific tech stack, language, and architecture your team works with. Where it makes sense, I include interactive elements using Workshop Board so participants stay engaged rather than passively watching slides. Sometimes I even include live demos to show how to exploit vulnerabilities or how to secure a particular feature.
Why this training is built around exercises
An investigation among 194 industry developers (Gasiba, Lechner, Pinto-Albuquerque et al., ICSE-SEET 2021) found that 51% recognized vulnerable code and 40% could write a secure version. Recognizing a flaw and writing the fix are different skills. So I teach through exercises aimed at concepts, not through a lecture and not through a catalog of isolated cases. The same survey that names hands-on formats, including capture-the-flag events, also says secure-coding training should focus on concepts rather than specific cases.
Delivery options and recording
Sessions can run remotely via video call — no travel overhead on either side. Remote is an option; on-site delivery at your location works just as well. If you want, I can record the session so your team can revisit the material later. Over time, several of my clients have built up their own internal library of these recordings. New team members get instant access to focused, relevant security training from day one, without having to wait for some next scheduled session.
Standards mapping, if you need a file for an auditor
The curriculum is cut to your stack, your roles, and your risk profile. As a separate deliverable I can map each module actually taught against the frameworks you name: NIS2, DORA, PCI DSS, IT-Grundschutz, or others. The mapping is a claim about the session you booked. It is not an audit opinion and not a certification.
A quiz instead of a feedback form
A satisfaction sheet mostly measures how people felt. A quiz with a pass mark measures whether someone can apply what the modules actually covered.
I write the questions so they follow the curriculum modules. You get a result you can file: who sat it, which modules, pass or fail. I can write the quiz, or you write it and I review it in a fixed number of review rounds.
A 2019 paper on measuring security-awareness programs (Jayatilaka et al., IT Professional 2019) cites a SANS survey of more than 1,500 security professionals in 91 countries: under 7% had a metrics framework for their awareness programs. Kirkpatrick's ladder is reaction, then knowledge, then behavior. A feedback form is reaction. The quiz is knowledge. It does not measure later behavior.
Mapping without a measurement is a curriculum claim with no check. A quiz without a mapping is a score with no stated requirement. Together they are an evidence pack you hold, and a reviewer weighs. They do not make you compliant. What each framework actually asks, and what this pack can supply, is on the regulatory context page.
Get started
If you have a specific security topic on your mind, get in touch and we’ll set up a short scoping call to figure out the right session for your team.