One Habit Worth Building
Hesitate on the message that wants something urgently. Everything else in the curriculum is scaffolding around that one reflex.
Short Lessons, Often
Five to ten minutes at a time, not a three-hour seminar in the conference room. Training people finish is training that changes what they do.
Simulated Phishing
Realistic test emails on an irregular schedule. The results tell you quietly who needs help, before a real one arrives at 11pm in February.
Records You Can Produce
Completion, scores, and dates, exportable. IRS Publication 4557 expects staff training, and expects you to show it happened.
Track Progress Across Your Firm
Who's finished, who's overdue, and how the click rate moves quarter to quarter. The bigger improvement is usually in reporting rather than clicking. People start forwarding the odd ones, which is how a firm finds out about a campaign early.
- Scenarios From Your World
Lessons built on IRS impersonation, client document requests, and payroll change emails, not a fictional widget company.
- Compliance Documentation
Training records tie back to your WISP, with reports you can hand over without assembling anything by hand.
- Follow-Up Where It's Needed
Anyone who clicks gets a short, specific lesson about the tells they missed. Nobody gets marched into a meeting about it.
- Credit for Reporting
Light leaderboards, with recognition aimed at people who forward suspicious mail. Reporting is the behavior you want, so that's what gets rewarded.
Q1 Training Progress
24
Enrolled
21
Completed
3
In Progress
Phishing Recognition
Avg Score: 94%
Password Security
Avg Score: 88%
Data Handling
Avg Score: 91%
IRS Compliance
Avg Score: n/a
Who It's For
Firms where the person under the most time pressure also has the most access
CPA & Tax Firms
Preparers and admins who open hundreds of client attachments a week and can't treat every one as a threat.
Legal Practices
Attorneys and paralegals, where wire instructions changed at closing is the expensive version of this mistake.
Financial Services
Role-based paths, because the front desk and the controller get shown very different bait.
Government Contractors
Dated, documented training records for CMMC and NIST requirements.
Last 3 Simulated Campaigns
IRS Refund Notice
Mar 202524
Sent
2
Clicked
18
Reported
Password Reset Request
Feb 202524
Sent
4
Clicked
15
Reported
Client Document Shared
Jan 202524
Sent
6
Clicked
12
Reported
The Test Emails Look Like the Real Ones
Our simulations copy the campaigns aimed at accounting firms: refund notices, password resets, a client document shared from an address that's almost right. They arrive at irregular intervals, because a test everyone expects on the first Monday of the month measures nothing at all.
Anyone who clicks gets feedback right away and a short lesson, not a talking-to. That matters more than it sounds. Punitive programs teach staff to hide mistakes, and the hidden click is the one that costs you a weekend. What you want is the person who clicked at 7am telling somebody by 7:05.
Frequently Asked Questions
How often should staff train?
Ongoing beats annual. One long session in January is forgotten by March, which is exactly when it's needed. We run short modules through the year and send simulated phishing at irregular intervals, since a test everyone expects only measures who checked the calendar.
What does the curriculum cover?
Phishing and impersonation, passwords and MFA, document handling, physical security, laptops and phones off-site, plus the taxpayer-data specifics from IRS Publication 4557. It works out to a few hours per person across a year, taken in small pieces.
How do the simulated phishing tests work?
We send a realistic but harmless test email. If somebody clicks or enters credentials, they get an immediate explanation of what they missed and a short follow-up lesson. Results roll up by team on your dashboard. The trend is the point, not naming anyone.
Does this satisfy the IRS training requirement?
It covers the training piece. Publication 4557 expects everyone handling taxpayer data to be trained, and expects records to exist. You get the content, the completion tracking, and exportable reports. Training is one requirement among several, so it belongs inside a security program rather than standing in for one.
Will this annoy people during busy season?
It will if you schedule it badly. We front-load before filing season, go quiet through the worst of it, and pick back up in the spring. A surprise five-minute module at 9pm on a Tuesday in February is how a firm learns to resent security.
