Accounting & bookkeeping
Tax season is phishing season.
Tax-authority impersonation, fake payment notices and client-spoofing emails spike every filing season. Your staff handle tax IDs and financials daily — they need reps, not slideshows.
Managed security awareness · worldwide
MakSisu sets up, runs and reports on your entire security awareness program — interactive exercises your staff actually finish, phishing tests that measure real behaviour, and evidence your insurer and auditor accept.
Managed end to end
Set up · run · reported
100+ exercises
Audit evidence
One report per quarter
100+
Interactive exercises
Phishing, ransomware, deepfakes
10 min
Monthly per person
First-person 3D, not video
1
Report per quarter
Auditor and insurer ready
Week 1
Fully set up
One contact from your side
Interactive live drill
This is the exact high-stress scenario distributed teams face during payroll and tax cycles. Inspect it and test your eye.
From: IT Support <helpdesk@micr0soft.ca>
Subj: URGENT: Password expires in 2 hours
Hello Team,
Our security records show your Microsoft 365 credential certificate expires today. To avoid an immediate freeze on client files and email dispatch, verify your account now:
https://portal.office365-verify.ca/auth
"This mandatory security audit request was authorized by your Managing Partner."
— IT Security Services Desk
micr0soft.ca.
Client profile
If your business holds client data and your cyber-insurance renewal now asks "do you conduct security awareness training?" — this is for you. We work with firms of 10–250 people that have no internal security team.
Tax season is phishing season.
Tax-authority impersonation, fake payment notices and client-spoofing emails spike every filing season. Your staff handle tax IDs and financials daily — they need reps, not slideshows.
Privilege doesn't survive a breach.
Regulators and law societies increasingly expect documented security training. We give you the program and the paper trail, mapped to client-confidentiality obligations.
You sell risk — don't carry it.
Brokerages and advisors face the same questionnaires they hand to clients. Walk into your own renewal with completion records and falling phishing click-rates.
Hands-off operation
You assign one contact. We handle everything else — your team only ever sees engaging, ten-minute exercises arriving on a sensible schedule.
We deploy a training portal under your branding, load a curriculum matched to your industry and threats, and enrol your staff. A baseline phishing test tells us where you're starting from.
Monthly interactive exercises — phishing, ransomware, vishing, data handling — in first-person 3D scenarios, not videos. We chase stragglers and run quarterly simulated phishing so you never have to nag anyone.
Every quarter you receive one report: completion rates, click-rate trends and a risk summary, formatted to hand directly to your insurer, auditor or board. That's the whole point.
Plans
Flat pricing in US dollars, charged in USD wherever you're based. Every plan includes the full interactive exercise library and a named human — not a ticket queue — who knows your business.
Prices exclude any sales tax, VAT or GST applicable in your jurisdiction.
Get a real program stood up fast.
$1,950 USD · one-time
10–50 staff
Most popular
Your program, run continuously.
$495 USD / month
Includes Launch setup · 3-month minimum
For audits and frameworks.
$995 USD / month
ISO 27001 · SOC 2 · GDPR programs
Compliance & insurance
Training only counts if you can prove it happened. Everything we run produces records mapped to the obligations your auditor, regulator and insurer actually check.
EU & UK
Article 32 expects staff handling personal data to be trained on the measures protecting it, and Article 39 makes awareness training an explicit DPO responsibility. We document who was trained, on what, and when.
Certification
Clause 7.3 and Annex A 6.3 make security awareness a named requirement. Evidence packages arrive formatted to drop straight into your audit binder.
Attestation
The Common Criteria covering competence and internal communication both depend on awareness training. Your auditor asks for completion records; we produce them on demand.
Insurance
"Do you conduct security awareness training and phishing simulations?" Answer yes, with documentation, and qualify for coverage many insurers now decline without it.
Working under a regional privacy regime as well? Records map to PIPEDA, Québec Law 25, HIPAA and Australia's Privacy Act on request.
About
MakSisu Technologies is a managed-service practice founded by a working cybersecurity professional, certified in ISO/IEC 27001 and ISO 22301 and holding CISA, CISM and ITIL. We're deliberately small: every client gets a curriculum chosen by someone who reads threat reports for a living, and a quarterly report written by someone who knows what your auditor — and your attacker — is actually looking for.
The exercise library covers phishing, ransomware, social engineering, AI-era threats like deepfakes and prompt injection, and privacy compliance. Your staff face realistic incidents in first person and build the reflexes that matter when a real one lands.
sisu /ˈsiːsuː/ · Finnish
MakSisu was founded by a veteran security practitioner to protect organisations that can't justify a full internal SOC. We build composure under pressure, not paranoia.
Individual practitioner credentials, not an organisational certification of MakSisu Technologies. Details.
Direct consultation
We'll run you through the same interactive exercise your staff would see, show you a sample quarterly report, and quote you on the spot. If it's not a fit, you'll know fast.
Your calendar invite and drill access are on the way to .