The largest information losses rarely begin with a break-in. They begin with a conversation that seemed ordinary, a favour that seemed minor, and a relationship that raised no doubts for many months.
Conventional information security training focuses on procedure: what is permitted, what is not, how to mark documents. That is necessary but insufficient. A procedure offers no protection where an employee has no idea they have become a subject of interest — because nobody is asking them for anything forbidden.
This course fills that gap. It teaches people to recognise soft influence — the gradual, patient construction of a relationship of dependency, in which each step feels like the natural consequence of the last, and the moment a line is crossed is effectively invisible to the person concerned.
A defensive perspective, not an operational one. The course describes these mechanisms so that participants can recognise them in themselves and in colleagues. It does not teach how to apply them and contains no operational material.
Dependency does not appear in a single moment. It is built in stages, each of which is harmless on its own — which is precisely why it works.
The starting point is not seniority but access and susceptibility. Who has sight of documents, systems or decisions — and who is currently going through something that lowers their guard: financial difficulty, conflict at work, feeling undervalued, family trouble, ambition without prospects of promotion.
Contact is made in circumstances that raise no suspicion: an industry conference, a professional network, a mutual acquaintance, an offer of expert collaboration, an invitation to a paid lecture or consultation. The other party is competent, likeable and genuinely interested in what the participant has to say.
For weeks or months no request for information is made. What appears instead is attention, recognition and understanding — often more than at work. This is the most important stage and the hardest to recognise from the inside, because the relationship delivers a real, tangible emotional benefit.
The request concerns something unprotected: a view on the market, a publicly available study, an explanation of how some process works, a pointer to the right person. Granting it breaks no rule — and that is the point. A precedent is set, along with a sense that the collaboration is already under way.
Something is given in return: a fee for an expert opinion, an invitation to travel, a gift, help with a private matter. Each subsequent request goes only marginally further than the last. Individually each looks like a small step, yet the sequence leads a very long way.
At some point the mere fact of the collaboration to date becomes a source of pressure — no threat needs to be made. It is enough to know that explaining it to a manager would be difficult and costly. The longer the silence lasts, the harder it becomes to break.
The practical conclusion. The only point at which reacting is still easy is stages two and three — before anything has happened. That is why the training focuses on recognising early signals rather than on what to do afterwards.
The other party shows markedly more interest in your work than the setting would suggest. They keep returning to professional topics even when the occasion is private or social.
The questions do not concern protected material but who is responsible for what, who takes decisions, who is in conflict with whom, and who has access to which systems. Apparently harmless information — and highly valuable.
An offer of a fee, a trip or a consultancy on terms clearly better than the market, with a vaguely defined scope of work or no expectation of a specific deliverable.
A suggestion not to inform your employer — justified by concern for your comfort, the other party's confidentiality, or the idea that "it is nothing important anyway". A request for discretion towards your own organisation is a signal in itself.
Moving the conversation to a personal phone, an encrypted messenger or a private address, while avoiding work email and official correspondence.
The other party quickly becomes aware of your problems — financial, professional or personal — and offers help before you ask. The kindness appears exactly where you are most exposed.
The programme is matched to the group — training for operational staff looks different from training for senior management and security units.
Who gathers information about institutions and companies, and why. The difference between classic espionage, open-source collection and influencing decisions. Which data carries value even when it is not classified.
Reciprocity, commitment and consistency, authority, liking, scarcity, time pressure. How these work on someone who knows the theory — and why knowledge alone is not enough.
The six stages examined through cases made public in Poland and other NATO states. Analysis of the point at which a reaction was missing, and why.
Risk factors on the human side: financial situation, grievance, ambition, isolation, addiction. On the organisational side: no reporting channel, a culture of shooting the messenger, excessive privileges, uncontrolled turnover.
How a professional profile on social media becomes a starting point. Fake recruiter and analyst accounts, invitations to paid expert panels, bogus job offers, requests for "a short conversation about the market".
How to end a conversation that crosses a line, politely and effectively. Whom to notify and in what form. Why reporting protects the person reporting above all. How to act when contact occurred long ago and was never reported.
Exercises, not lectures. More than half the time is spent on scenarios: participants work through transcripts and sequences of events, identify the point at which a reaction was called for, and practise phrasing a refusal that does not close the door on legitimate professional contact.
Core — 3–4 hours, for a broad group of employees. Recognising signals and rules of conduct.
Extended — one day, with scenario workshop and case analysis. For senior management and staff in particularly exposed roles.
For security units — two days. Additionally: building an awareness programme, conducting the conversation after a report, cooperation with the services, documenting incidents.
Participants recognise the situation at a stage where nothing has yet happened and stepping back carries no cost at all. That is the only moment at which reacting is genuinely easy.
The training changes how a team thinks about reporting unusual contact — from "telling on someone" to a routine step that protects the person reporting first and foremost.
The summary includes anonymised conclusions from the workshop: which situations participants found hardest, and which organisational gaps are worth closing first.
Tell us how many participants you have and where they work. We will propose a format, a programme and a date — the first conversation is free.
Ask about training