Protection

Training and awareness

Train your employees in security best practices

§ 01 · Overview

What is security training?

Security training and awareness sessions teach the best practices for protecting your systems, networks and applications. The goal is to sharpen vigilance and build everyday cybersecurity reflexes.

Objectives

These security sessions enable your employees to:

  • Understand cybersecurity stakes and threats

  • Strengthen web application security

  • Secure system administration

  • Secure Active Directory administration

  • Train technical teams

§ 02 · Approach

The HELX approach

For technical audiences, we cover identifying and remediating web vulnerabilities, as well as securing servers and infrastructure. We also offer awareness sessions focused on best practices, data protection and digital risk management. Participants learn to build security in from the design stage of an application and to adopt secure system management habits.

§ 03 · Formats

Our general awareness sessions

One- to two-hour sessions to better understand threats, build the right reflexes and reduce human risk. Open to everyone, our workshops aim to **change behaviors** and pass on **simple, effective habits** against cyberattacks.

Ransomware simulation

Audience: executives, managers, CIOs. A live attack to grasp the impact of ransomware: locked systems, data leaks, critical decisions to make. A realistic immersion that brings home the strategic stakes of a compromise.

Me, an employee: the perfect target?

Audience: all employees (non-technical). A concrete, accessible session to understand how our everyday tools (email, passwords, browsers, personal tools) can be exploited, and to adopt simple reflexes to avoid the traps.

§ 04 · Approach

Our technical training courses

Two- to three-day courses to build technical skills, understand current attack methods and apply solid security practices. Aimed at technical audiences, they help you secure your environments and applications for the long run, with concrete cases and realistic hands-on scenarios.

§ 05 · Technical training

Web application security

An intensive two- to three-day technical course for professionals who want a deep understanding of the threats facing modern web applications and how to respond to them effectively.

Target audience: developers, technical project managers, software architects and DevSecOps specialists who want to secure their applications from the earliest stages of development.

Prerequisites: good command of HTML, CSS and JavaScript (DOM, events, AJAX requests); knowledge of at least one server-side language (PHP, Python, Node.js, Java, .NET, etc.) and of databases.

Learning objectives: understand the critical vulnerabilities of web applications (OWASP Top 10 and beyond), learn to detect them, exploit them in a controlled setting, then fix them effectively. Participants also learn to adopt a DevSecOps mindset and build security into the entire software development lifecycle.

§ 06 · Web application security

The program covers in depth

  • The most common vulnerabilities: XSS, SQL injection, CSRF, SSRF, IDOR, etc.
  • REST and GraphQL API security: authentication, authorization, input/output control
  • Authentication-related flaws: session management, cookies, JWT tokens
  • Secure development best practices: filtering, validation, separation of responsibilities
  • Building security into DevOps processes: secure CI/CD, automated security testing, code review
  • Hands-on workshops and supervised CTF-style (Capture The Flag) challenges

Each module alternates between theory, live demonstrations and hands-on exercises in a secure test environment. The course is built on OWASP standards and draws on real-world cases to reinforce the learning.

By the end of the course, participants are able to design, audit and maintain web applications that stand up to modern attacks.

§ 08 · Technical training

Corporate network security

An intensive two- to three-day technical course focused on securing Active Directory (AD) infrastructures and corporate networks against modern threats, internal and external alike.

Target audience: system and network administrators, security engineers and infrastructure managers who want to understand, test and strengthen the security of Windows/AD environments in the enterprise.

Prerequisites: good knowledge of Windows Server and Active Directory; solid grounding in system and network administration (TCP/IP, DNS, DHCP, authentication, GPOs, etc.).

Learning objectives: understand the most frequent attack vectors on internal networks, identify the weaknesses of an Active Directory environment, reproduce the attacks (post-exploitation, privilege escalation, lateral movement, etc.), and learn to remediate them through concrete hardening and securing actions.

§ 09 · Corporate network security

The program covers in depth

  • Review of Active Directory fundamentals and network dependencies (DNS, LDAP, Kerberos, NTLM)
  • Analysis of common flaws: Kerberoasting, Pass-the-Hash, Pass-the-Ticket, NTLM Relay, DCSync, AS-REP Roasting, etc.
  • AD mapping and privilege escalation with tools such as BloodHound, SharpHound and Mimikatz
  • Detection and hardening: audit of sensitive configurations, privileged account management, network segmentation, monitoring
  • AD hardening best practices: LAPS, tiering, ACL control, logging, GPO hardening
  • Hands-on workshops: attack simulations and countermeasures in a test environment (AD lab)

Each session combines theory, technical demonstrations and hands-on exercises. The course is built on realistic scenarios, letting participants apply what they learn immediately in a simulated AD environment.

By the end of the course, participants are able to assess the security of their Active Directory infrastructure and put concrete hardening measures in place.

§ 11 · Methodology

Methodology

Our training process comes down to two very simple steps:

  1. 01

    Scoping your needs

    We work through your needs with you to determine the right format: a short, low-technicality awareness session or a longer training course for your teams.

  2. 02

    Presentation and workshops

    Our experts present the content of our courses and awareness sessions to your teams from a theoretical angle. Then come hands-on workshops for a training course, or demonstrations for an awareness session.

Our other protection services

FAQ

Frequently asked questions

What formats do you offer?

Two formats: three-day technical courses in small groups (one to four people, developers or IT administrators), and one-hour general awareness sessions, engaging and demonstration-driven, for up to twenty-five people per session.

How much does it cost?

€4,250 excl. VAT per technical training session (up to four participants) and €1,700 excl. VAT per awareness session, with a 15% discount for small businesses, SMBs and non-profits.

What makes your awareness sessions different?

No finger-wagging slide deck. We run real live hacking demonstrations (phishing, session hijacking, simulated ransomware): watching an attack succeed sticks far longer than an hour of slides.

Are the courses adapted to our context?

Yes: the examples and hands-on exercises are built on your technologies (languages, frameworks, infrastructure), not on generic textbook cases.

On site or remote?

Both. Awareness sessions work best on site, where the demonstrations have their full effect; technical courses work equally well in either format.

Tell us about your project.

Let us talk through your needs and expectations and build the right service for you.