Counterintelligence informed security awareness

Security awareness based on real attacker behavior.

Enterprise OPSEC for the office. Training that teaches a workforce the technical realities of modern cybercrime, so people can protect their personal lives and the corporate network at the same time.

Real

Sanitized field stories and recent incident case files, not invented scenarios.

Controlled

Technical demonstrations showing what an attacker sees and does, run in a contained environment.

Versioned

Course, module, transcript, and export version identifiers on every completion record.

Praeven Tradecraft Series

Two programs. Selected against the workforce, not the seat count.

Program selection should match the workforce, customer requirements, data environment, and evidence needs.

SOC 2 Security Awareness Core

A versioned workforce program focused on common security decisions, reporting expectations, attacker methods, and practical defensive behavior.

  • Real incident case files
  • Controlled technical demonstrations
  • Scenario based decisions
  • Insider threat recognition and reporting
  • Customer specific reporting orientation
  • Assessments and acknowledgments
  • Completion and content version records
Discuss the core program

Defense industrial base

CMMC Level 2 Workforce Awareness Extension

An extension covering FCI and CUI orientation, insider threat recognition and reporting, organization specific handling instructions, and evidence references for applicable Awareness and Training requirements.

  • General security awareness support
  • Insider threat recognition and reporting
  • CUI and FCI orientation
  • Organization specific reporting instructions
  • Evidence export
  • Customer responsibility matrix
Discuss CMMC awareness support

Role based training for personnel with assigned security duties is separately scoped.

Evidence produced for customer review

What a reviewer opens.

The evidence package is designed to help a customer demonstrate assignment, completion, assessment, acknowledgment, and content versioning.

Evidence categories and the fields each record carries.
RecordFields captured
AssignmentLearner identifier, course, assignment date, due date, and administrator.
CompletionStart and completion timestamps, time zone, and completion status.
AssessmentAttempts, final score, passing threshold, and result.
AcknowledgmentAcknowledgment status and the exact text accepted by the learner.
VersionCourse, module, transcript, and export version identifiers.
AdministrationExport date, administrator identity, certificate identifier, and renewal date where applicable.

Final sufficiency remains subject to the customer control environment and reviewer judgment.

Method

Why the demonstrations are the program.

A workforce that has watched an attack succeed makes different decisions than a workforce that has read about one.

Case file first

Every module opens on a documented incident with a source, not a hypothetical.

Demonstration second

The attack is shown from the attacker side in a contained environment.

Decision third

Scenario exercises put the learner at the moment where the outcome is still open.

Reporting last

Organization specific reporting instructions, taught without blame so people report early.

Prepare. Anticipate. Protect.

Review the workforce, evidence, and delivery requirements.

Praeven confirms program scope, customer responsibilities, delivery method, accessibility needs, and the evidence package before proposing training.