Technology alone does not provide protection. An organisation is only as secure as its weakest link — and that is almost always a person.
ICSL Consulting develops bespoke training and awareness programmes for government agencies, businesses and security-critical organisations.
Briefings for board members, ministers and senior executives — what do decision-makers need to know about COMSEC?
How do you create a security culture that is practised every day, rather than merely documented in policies?
Bespoke training for different audiences — technical staff, operational users and management.
Practical training on current methods of attack against communications security.
Developing practical COMSEC policies that people can actually follow.
How should an organisation respond to a COMSEC incident? Exercise scenarios and processes.
There is no shortage of standard training material. ICSL develops programmes that fit your institution's specific threat landscape and organisational structure.
We have seen it often: a highly secure communications tool is provided — and goes unused. Particularly in government agencies and large organisations, success depends on acceptance, training and trust, not just technology.
Providers like to consider their solutions self-explanatory — practice tells a different story. ICSL creates documentation and training that reach the intended audience, including for third-party solutions.
From executive briefings to a COMSEC culture put into practice.
A practical assessment of your communications security — without marketing language, as a neutral third party.
Short, clear situation assessments for decision-makers — without technical jargon.
Who operates against which targets, and how? Assessments informed by operational context — for your senior leadership.
From the current state to the target architecture — prioritised, realistic within your budget, supported through deployment.
Internal usage and security policies that people actually follow in everyday work.
Assess emerging communications risks before they become operational threats.