Skip to content
BISPRO

Cyber awareness · On-site or remote · 15 years in the field

Cyber awareness training — on-site or remote.

BISPRO only delivers cyber awareness training. Live sessions on-site or synchronous video — no automated e-learning. The content draws on 15 years of field observations across Grand Est: clients supported, incidents lived through, and — most importantly — organisations that lost everything for lack of backup and became clients AFTER the attack. Accredited Expert Cyber by the French State.

Partenariats & certifications

Recognition State & partnerships.

Awareness in numbers

Three figures to grasp the human stake.

80%

Of cyber compromises involve the human factor — phishing click, weak password, social engineering (Verizon DBIR 2025).

60%

Of SMBs hit by a major cyberattack go out of business within 12 months (CPME, ANSSI). We've seen this figure first-hand at non-clients who became clients too late.

15 years

Of field observations in Grand Est. The content isn't a white-label vendor kit — it's what we've seen, lived through and supported.

01 · FORMAT

On-site or video — your choice

Live facilitation by a cyber expert, never a pre-recorded course. The content is alive, dialogues with the room, adapts to field questions.

  • On-site sessions

    Sessions delivered physically at your premises by a BISPRO cyber expert. Group format (8 to 30 people per session), direct interaction, live demos (creating a fake site, session theft, weak password exploitation). It's the most impactful format — people remember what they've seen with their own eyes.

  • Synchronous video

    Same content as on-site, delivered live via Teams / Meet / Zoom. Fits multi-site organisations, remote workers, tight schedules. Not a passive webinar: cameras on, live Q&A, role-play, interactive polls. Recordable session for absentees on request.

  • No automated e-learning

    We don't sell platform access to be browsed alone at 11 pm. Our value is living content, real field feedback, dialogue with the room. A recorded video = 30% retention. A live session = 70%+. The difference shows on the day of a real attack.

  • Duration — 1h30 to 2h standard

    Reference format for all staff: 1h30 to 2h. The right balance — long enough to cover all essential risks, short enough to hold attention end-to-end. Deep technical format possible (half-day to full day) if the audience is limited to technical teams — not suitable for a broad employee audience.

02 · WHY BISPRO

15 years in the field, not generic slides

The content comes from what we've seen, supported, rebuilt. Including at companies that lost everything before becoming clients.

  • 15 years in the field, not generic slides

    The content isn't a kit bought from a vendor. It's built from 15 years of field observations: daily client work, audits, post-incident interventions, and — crucially — companies that were NOT clients before the attack and became clients after losing everything.

  • The case that recurs most: no backup

    Most post-ransomware cases seen over 15 years follow the same pattern: no backup, or backup on the same network so also encrypted. Business down for 2 to 4 weeks. Loss of accounting, HR, project and quotation data. Some organisations never restarted. These are the stories we tell — not to scare, to make people understand.

  • Anonymised lessons learned

    Each module draws on real cases told with respect for professional secrecy: the SMB that wired €47k to a fake supplier, the elected official who clicked on a fake prefecture email, the salesperson whose stolen M365 session was used to scam their clients for 3 weeks, the local authority ransomware-hit because an officer left their session open in plain sight.

  • Accredited Expert Cyber by the French State

    The trainer isn't a salesperson reciting a script. It's a field practitioner recognised by Cybermalveillance.gouv.fr and AFNOR (Expert Cyber label 2024-2026), with real understanding of attacks observed across Grand Est, in a multi-sector mix of SMBs, mid-market, public sector and industry.

03 · CONTENT

Risks covered in session

Exhaustive catalogue of attack vectors seen in France over the last 15 years. Each risk is explained, demonstrated where possible, illustrated with an anonymised real case.

  • Phishing & social engineering

    Fake HR emails, fake M365, fake delivery, fake supplier, fake CEO, fake bank advisor. Recognising weak signals (tampered URL, urgent tone, subtle typo, psychological pressure). Live demo: we create a fake BISPRO site in front of the room to show how technically simple a credible attack is.

  • CEO fraud (BEC) — diverted wire transfers

    The CFO gets an urgent email from the 'CEO' asking for a confidential transfer to a foreign account. Median observed cost: €47k at French SMBs. We unpack the typical scenario, review double-validation procedures, explain why the phone isn't a defence (vishing + voice deepfake 2025).

  • M365 / Google Workspace session theft

    Beyond the password: stolen session cookies, MFA bypass via MFA-bombing fatigue, fake Microsoft portal. Once the session is stolen, the attacker reads your mail, sends in your name, steals your contacts, scams your clients. Almost undetectable from the victim's side.

  • Ransomware — how it really starts

    One click, one activated Word macro, one stolen credential, one exposed RDP on the internet. 24 to 72 hours later: all files encrypted, ransom demand, business stopped. We show the full chain of a real intrusion. We explain why isolated immutable backup is NOT optional.

  • Passwords & MFA — real uses, real traps

    Reused passwords, shared passwords, post-its under the keyboard (still seen this year). Bypassable SMS MFA, authenticator app > SMS, FIDO2 physical key > everything. Demo: we crack a common 'complex' password in under 2 minutes with a consumer tool.

  • Remote work & mobile

    Public hotel or café Wi-Fi, personal smartphone used for work, account sharing in the family, unknown USB stick found in a car park, sensitive photos in iCloud / Google Photos. Work life has spilled into personal life — you need to know where to draw the line.

  • Social media & shadow IT

    LinkedIn posts that reveal the org chart (gold for targeted social engineering), office photos showing a password on a post-it, unmanaged WeTransfer file sharing, personal ChatGPT used to process client data. We map shadow IT and learn how to handle it.

  • Practical GDPR — not the boring module

    The day-to-day: who can I send what data to, how do I handle a leaking email, how do I destroy a hard drive from a departed colleague's computer, how do I fill in a processing register without spending 3 days on it. Practical, not legal.

04 · CONSEQUENCES

What actually happens

Not marketing dramatics. What we've observed in the field for 15 years, anonymised but real.

  • Business down 2 to 4 weeks

    Typical case post-ransomware without isolated backup: system encrypted on Monday, last usable backup found on Wednesday (11 months old), business data rebuilt from emails, paper invoices and memory. Partial recovery at D+15, normal at D+45. Meanwhile, no invoicing, no quoting, no production.

  • Permanent data loss

    The year's accounting, HR records, client contracts, work in progress, site photos, supplier quotes. No backup = definitive. Seen with my own eyes: an accountancy firm that lost 14 months of bookkeeping. Seen with my own eyes: an industrial SMB that lost 8 years of CAD R&D drawings.

  • Direct cost + hidden cost

    Ransom (if paid, which we advise against): €5k to €200k. Forensic + emergency provider restore: €10k to €80k. CNIL notification if personal data leaked + possible fine. Reputational damage, clients leaving, banker tightening conditions, insurer cancelling. Total observed cost: €80k to €250k at SMBs (CESIN, Hiscox).

  • Bankruptcies

    60% of SMBs hit by a major cyberattack go out of business within 12 months (CPME, ANSSI). We've seen it. Small organisations, 8 to 25 employees, that couldn't survive the cash-flow shock and loss of customer trust. This stat isn't a marketing argument — it's what we observe.

05 · IMPACT REDUCTION

Reducing the impact zone

We don't eliminate the cyber risk. We reduce the impact zone — the number of potential entry doors, the spread duration, the depth of the damage.

  • Recognise = don't click

    Goal #1 of awareness: that an employee recognises a malicious email before clicking. No need to be a geek — just know 5 to 8 weak signals and have the instinct to report to IT rather than click. This skill is transmitted in 1 to 2 sessions.

  • Reflex to report — not stay silent

    The second major effect: moving from a culture of silence ('I may have clicked but I won't say anything') to a culture of reporting ('I may have clicked, I'm calling IT right now'). We gain critical hours. Often the difference between contained incident and catastrophe.

  • Documented sensitive procedures

    Wire transfers > €5k with mandatory dual approval. Supplier bank-detail change only after a phone call to the usual number. Auditable admin access. Backups verified every quarter with restore test. Awareness raises the right questions with management.

  • Measurable impact-zone reduction

    If 28% of employees clicked before awareness and 6% click after, you've cut the attack surface by 5. In a 50-person organisation, that's 11 potential entry doors closed.

06 · AUDIENCES

Who awareness is for

A 10-person small business, a 200-person SMB, a multi-site public body, a NIS2 industrial. The format adapts, the core content is universal.

  • Small business & SMB

    Half-day on-site or remote format for the whole company. Flat-rate price, no annual commitment. Fits organisations without an internal CISO. Often requested after an incident at a neighbour or peer — we step in before it's your turn.

  • Public bodies

    Municipalities, intercommunal bodies, EPCIs, social action centres. Awareness for administrative staff, technical services, elected officials. Reinforced GDPR / CNIL compliance for public sector. Funding possible via cyber grants (FAREST, ANCT, France 2030). Multi-site delivery available.

  • Industry & mid-market — NIS2

    Essential or important entities under NIS2: structured, traceable programme, integrated into the ISMS, auditable proof for ANSSI. Often includes a separate executive module + employee module, as attack vectors differ.

  • Healthcare, legal, finance

    Sectors with strong confidentiality requirements: law firms, accountants, medical professions, finance, insurance. Reinforced programme on targeted vectors (BEC, sector-specific ransomware, patient / client / case data exfiltration).

07 · COMPLIANCE

Regulatory & contractual framework

NIS2, GDPR, cyber-insurance, State accreditation. Our attestation is designed to be audit-ready.

  • NIS2 — article 21.2.g

    The NIS2 directive mandates basic cyber-hygiene practices and cybersecurity training for staff. Our awareness attestation and the detailed contents covered are delivered at each session for inclusion in the ANSSI file.

  • GDPR — article 32

    GDPR organisational measures include training staff in data protection. Without an awareness programme, your GDPR compliance is incomplete. Our attestation and materials can be added to the processing register.

  • Cyber-insurance

    AIG, Hiscox, Beazley, Allianz, Generali, MMA — all carriers require proof of awareness at underwriting or renewal. Our nominative attestation + detailed programme satisfy most cyber-insurance questionnaires.

  • Cybermalveillance.gouv.fr & Expert Cyber

    BISPRO is accredited Expert Cyber by Cybermalveillance.gouv.fr and AFNOR (2024-2026), and listed on Cybermalveillance.gouv.fr. Guarantee of intervention by a State-qualified provider across 7 cyber themes, including awareness.

08 · FAQ

Frequently asked questions

Going further

Quote within 48 h

Schedule a
cyber awareness session.

Brief phone call to understand your context, then a flat-rate quote within 48 business hours. On-site or video. Delivered by a trainer accredited Expert Cyber by the French State.

Financing up to 63 months available* — *subject to approval

Cyber Awareness Training: Phishing Simulation & E-Learning | BISPRO