Skip to content
MakSisu Managed SecurityWorldwide

Managed security awareness · worldwide

Your team's security training, run for you.

MakSisu sets up, runs and reports on your entire security awareness program — interactive exercises your staff actually finish, phishing tests that measure real behaviour, and evidence your insurer and auditor accept.

  • No platform to learn
  • No content to build
  • One report per quarter

Managed end to end

Set up · run · reported

100+ exercises

Audit evidence

One report per quarter

100+

Interactive exercises

Phishing, ransomware, deepfakes

10 min

Monthly per person

First-person 3D, not video

1

Report per quarter

Auditor and insurer ready

Week 1

Fully set up

One contact from your side

Interactive live drill

Would your team catch this?

This is the exact high-stress scenario distributed teams face during payroll and tax cycles. Inspect it and test your eye.

From: IT Support <helpdesk@micr0soft.ca>

Subj: URGENT: Password expires in 2 hours

Priority 1

Hello Team,

Our security records show your Microsoft 365 credential certificate expires today. To avoid an immediate freeze on client files and email dispatch, verify your account now:

https://portal.office365-verify.ca/auth

"This mandatory security audit request was authorized by your Managing Partner."

— IT Security Services Desk

  1. Typosquatting domain A numeral 0 replaces the letter o in micr0soft.ca.
  2. Manufactured urgency A two-hour deadline triggers panic and bypasses careful reasoning.
  3. Deceptive target URL The link does not resolve to Microsoft infrastructure — it points to a third-party proxy.
  4. Borrowed authority Naming the Managing Partner deters junior staff from checking legitimacy.

Client profile

Built for firms where trust is the product.

If your business holds client data and your cyber-insurance renewal now asks "do you conduct security awareness training?" — this is for you. We work with firms of 10–250 people that have no internal security team.

Tax cycles

Accounting & bookkeeping

Tax season is phishing season.

Tax-authority impersonation, fake payment notices and client-spoofing emails spike every filing season. Your staff handle tax IDs and financials daily — they need reps, not slideshows.

Privilege

Legal services

Privilege doesn't survive a breach.

Regulators and law societies increasingly expect documented security training. We give you the program and the paper trail, mapped to client-confidentiality obligations.

Underwriting

Wealth & insurance

You sell risk — don't carry it.

Brokerages and advisors face the same questionnaires they hand to clients. Walk into your own renewal with completion records and falling phishing click-rates.

Hands-off operation

Three steps. Then it just runs.

You assign one contact. We handle everything else — your team only ever sees engaging, ten-minute exercises arriving on a sensible schedule.

  1. Step 01 · Week 1 Onboarding

    Set up

    We deploy a training portal under your branding, load a curriculum matched to your industry and threats, and enrol your staff. A baseline phishing test tells us where you're starting from.

  2. Step 02 · Ongoing Automated

    Run

    Monthly interactive exercises — phishing, ransomware, vishing, data handling — in first-person 3D scenarios, not videos. We chase stragglers and run quarterly simulated phishing so you never have to nag anyone.

  3. Step 03 · Quarterly Audit-ready

    Prove

    Every quarter you receive one report: completion rates, click-rate trends and a risk summary, formatted to hand directly to your insurer, auditor or board. That's the whole point.

Plans

Pay for outcomes, not seats on a platform.

Flat pricing in US dollars, charged in USD wherever you're based. Every plan includes the full interactive exercise library and a named human — not a ticket queue — who knows your business.

Prices exclude any sales tax, VAT or GST applicable in your jurisdiction.

Launch

Get a real program stood up fast.

$1,950 USD · one-time

10–50 staff

  • Training portal set up and staff enrolled
  • Industry-matched 12-module curriculum
  • Baseline phishing simulation and report
  • Policy-ready training records
  • 30 days of support included
Start with Launch

Most popular

Managed

Your program, run continuously.

$495 USD / month

Includes Launch setup · 3-month minimum

  • Everything in Launch
  • Monthly training assignments and follow-up
  • Quarterly phishing simulations
  • Quarterly insurer and auditor-ready report
  • New-hire onboarding within two weeks
  • Annual curriculum refresh
Book a walkthrough

Compliance+

For audits and frameworks.

$995 USD / month

ISO 27001 · SOC 2 · GDPR programs

  • Everything in Managed
  • Training mapped to your control framework
  • Audit evidence packages on demand
  • Annual live tabletop exercise
  • Policy review and awareness alignment
  • Direct line to a security professional
Talk compliance

Compliance & insurance

The paperwork is the product.

Training only counts if you can prove it happened. Everything we run produces records mapped to the obligations your auditor, regulator and insurer actually check.

EU & UK

GDPR

Article 32 expects staff handling personal data to be trained on the measures protecting it, and Article 39 makes awareness training an explicit DPO responsibility. We document who was trained, on what, and when.

Certification

ISO 27001

Clause 7.3 and Annex A 6.3 make security awareness a named requirement. Evidence packages arrive formatted to drop straight into your audit binder.

Attestation

SOC 2

The Common Criteria covering competence and internal communication both depend on awareness training. Your auditor asks for completion records; we produce them on demand.

Insurance

Cyber renewals

"Do you conduct security awareness training and phishing simulations?" Answer yes, with documentation, and qualify for coverage many insurers now decline without it.

Working under a regional privacy regime as well? Records map to PIPEDA, Québec Law 25, HIPAA and Australia's Privacy Act on request.

About

Run by a security professional, not a sales team.

MakSisu Technologies is a managed-service practice founded by a working cybersecurity professional, certified in ISO/IEC 27001 and ISO 22301 and holding CISA, CISM and ITIL. We're deliberately small: every client gets a curriculum chosen by someone who reads threat reports for a living, and a quarterly report written by someone who knows what your auditor — and your attacker — is actually looking for.

The exercise library covers phishing, ransomware, social engineering, AI-era threats like deepfakes and prompt injection, and privacy compliance. Your staff face realistic incidents in first person and build the reflexes that matter when a real one lands.

sisu /ˈsiːsuː/ · Finnish

Grit, resilience and calm defence.

MakSisu was founded by a veteran security practitioner to protect organisations that can't justify a full internal SOC. We build composure under pressure, not paranoia.

  • ISO/IEC 27001
  • ISO 22301
  • CISA
  • CISM
  • ITIL

Individual practitioner credentials, not an organisational certification of MakSisu Technologies. Details.

Direct consultation

Fifteen minutes. One live drill. No sales deck.

We'll run you through the same interactive exercise your staff would see, show you a sample quarterly report, and quote you on the spot. If it's not a fit, you'll know fast.

  • Fully remote delivery, worldwide
  • Response within one business day
  • English (français coming soon)
Company size (employees)

We use your email only to confirm this session. No list, no sequence.