User training in cybersecurity

Social engineering methods and defense strategies

User training in cybersecurity

The growing number of cyberattacks, new regulatory requirements (e.g. NIS2, DORA), and increasing digital complexity demand that not only IT teams but also regular employees are well-prepared to deal with threats. End users are often the weakest link in the security chain — targeted by attackers through social engineering, phishing, or manipulation.

01

Social Engineering & Attacker Tactics

  • Explanation of key techniques: phishing, smishing, baiting, vishing, tailgating, pretexting, and more.

  • Real-world attack scenarios from the Czech Republic and abroad.

  • Practical tips on how to recognize and respond to suspicious behavior.

02

Real Examples & Practice-Based Demonstrations  

  • Simulation of phishing-themed email campaigns.               

  • Analysis of security incidents caused by human error.


  • Case studies, including anonymized incidents from banking, healthcare, and the public sector.

03

Interactive Discussion & Participant Engagement

  • Open floor for questions and experience sharing.                            

  • Discussion of everyday situations where attacks might occur.


  • Short quizzes to verify attentiveness and encourage engagement.

04

Optional Follow-Up: Phishing Campaign

  • Targeted phishing simulation as an optional post-training service.

  • Results help evaluate the training’s effectiveness and identify weak points.


  • Includes detailed reporting, recommendations, and follow-up training suggestions.

Organizational benefits of user training:



Heightened Awareness & Risk Reduction

  • Users will better recognize manipulative tactics and common attack patterns.
  • Proactive prevention of incidents caused by human error.


Regulatory Compliance

  • Meets awareness training requirements under NIS2, DORA, and ISO/IEC 27001.
  • Supports internal and external audits and regulatory inspections.


Efficiency & Measurable Outcomes

  • Option for recurring training (e.g. annually) and periodic phishing simulations.
  • Cost-effective knowledge transfer without the need to build in-house teams.

What does the training look like in practice?

Icon

Initial Consultation

Understanding your environment, audience, and organizational needs

Icon

Core Training Session

Delivered online or onsite, approx. 1.5–2 hours

Icon

Interactive Content

Live examples, discussion, simulations

Icon

(Optional) Phishing Simulation

Planning, execution, and detailed results

Icon

Recommendations & Follow-Up

Next-step proposals and training refinement

Why work with BDO?


01 Regulatory Expertise 

We understand DORA, NIS2, ISO/IEC 27001, GDPR, and the expectations of both European and national supervisory authorities.

02  Independence & Trust 

We do not sell proprietary technology – we offer truly objective and trustworthy security management.

03  Scalable Service 

Our offering ranges from advisory and mentoring to full CISO role coverage, whether on a monthly or multi-year basis.

04  Certified expertise

Our professionals hold certifications including CCISO, CISSP, OSCP, CRTP, eCPPT, BSCP, CEH, CRT, CPSA and more. They have hands-on experience from banks, insurance companies, and ICT service providers.

Main contacts

Martin Hořický

Martin Hořický

Partner • Digital Services
View bio
kovalcik

Marek Kovalčík

Chief Information Security Officer • Digital Services
View bio