Pumpkin
    Security Training

    Security Awareness Training Your Staff Won't Resent

    Short lessons, simulated phishing that teaches instead of punishes, and the completion records IRS Publication 4557 expects. Built around a firm's calendar rather than a compliance vendor's.

    One Habit Worth Building

    Hesitate on the message that wants something urgently. Everything else in the curriculum is scaffolding around that one reflex.

    Short Lessons, Often

    Five to ten minutes at a time, not a three-hour seminar in the conference room. Training people finish is training that changes what they do.

    Simulated Phishing

    Realistic test emails on an irregular schedule. The results tell you quietly who needs help, before a real one arrives at 11pm in February.

    Records You Can Produce

    Completion, scores, and dates, exportable. IRS Publication 4557 expects staff training, and expects you to show it happened.

    Track Progress Across Your Firm

    Who's finished, who's overdue, and how the click rate moves quarter to quarter. The bigger improvement is usually in reporting rather than clicking. People start forwarding the odd ones, which is how a firm finds out about a campaign early.

    • Scenarios From Your World

      Lessons built on IRS impersonation, client document requests, and payroll change emails, not a fictional widget company.

    • Compliance Documentation

      Training records tie back to your WISP, with reports you can hand over without assembling anything by hand.

    • Follow-Up Where It's Needed

      Anyone who clicks gets a short, specific lesson about the tells they missed. Nobody gets marched into a meeting about it.

    • Credit for Reporting

      Light leaderboards, with recognition aimed at people who forward suspicious mail. Reporting is the behavior you want, so that's what gets rewarded.

    Training Progress Tracker

    Q1 Training Progress

    87% Complete

    24

    Enrolled

    21

    Completed

    3

    In Progress

    Phishing Recognition

    Avg Score: 94%

    Passed

    Password Security

    Avg Score: 88%

    Passed

    Data Handling

    Avg Score: 91%

    Passed

    IRS Compliance

    Avg Score: n/a

    Not Started

    Who It's For

    Firms where the person under the most time pressure also has the most access

    CPA & Tax Firms

    Preparers and admins who open hundreds of client attachments a week and can't treat every one as a threat.

    Legal Practices

    Attorneys and paralegals, where wire instructions changed at closing is the expensive version of this mistake.

    Financial Services

    Role-based paths, because the front desk and the controller get shown very different bait.

    Government Contractors

    Dated, documented training records for CMMC and NIST requirements.

    Phishing Simulation Results

    Last 3 Simulated Campaigns

    IRS Refund Notice

    Mar 2025

    24

    Sent

    2

    Clicked

    18

    Reported

    Password Reset Request

    Feb 2025

    24

    Sent

    4

    Clicked

    15

    Reported

    Client Document Shared

    Jan 2025

    24

    Sent

    6

    Clicked

    12

    Reported

    The Test Emails Look Like the Real Ones

    Our simulations copy the campaigns aimed at accounting firms: refund notices, password resets, a client document shared from an address that's almost right. They arrive at irregular intervals, because a test everyone expects on the first Monday of the month measures nothing at all.

    Anyone who clicks gets feedback right away and a short lesson, not a talking-to. That matters more than it sounds. Punitive programs teach staff to hide mistakes, and the hidden click is the one that costs you a weekend. What you want is the person who clicked at 7am telling somebody by 7:05.

    Frequently Asked Questions

    How often should staff train?

    Ongoing beats annual. One long session in January is forgotten by March, which is exactly when it's needed. We run short modules through the year and send simulated phishing at irregular intervals, since a test everyone expects only measures who checked the calendar.

    What does the curriculum cover?

    Phishing and impersonation, passwords and MFA, document handling, physical security, laptops and phones off-site, plus the taxpayer-data specifics from IRS Publication 4557. It works out to a few hours per person across a year, taken in small pieces.

    How do the simulated phishing tests work?

    We send a realistic but harmless test email. If somebody clicks or enters credentials, they get an immediate explanation of what they missed and a short follow-up lesson. Results roll up by team on your dashboard. The trend is the point, not naming anyone.

    Does this satisfy the IRS training requirement?

    It covers the training piece. Publication 4557 expects everyone handling taxpayer data to be trained, and expects records to exist. You get the content, the completion tracking, and exportable reports. Training is one requirement among several, so it belongs inside a security program rather than standing in for one.

    Will this annoy people during busy season?

    It will if you schedule it badly. We front-load before filing season, go quiet through the worst of it, and pick back up in the spring. A surprise five-minute module at 9pm on a Tuesday in February is how a firm learns to resent security.

    Start Before the Next Filing Season

    Get the modules, the simulations, and the records running while there's still room in the calendar. Training in October is training. Training in March is an interruption.