AI Security Awareness Training

Your people are your largest attack surface.

Gneiss Group delivers practical, scenario-based security awareness training for Canadian mid-market firms in regulated industries. Built around how your teams actually work, not generic slide decks.

Photo coming soon
Raphael, Founder Security executive. Based in Vancouver, BC.
Regulated verticals
Legal Financial services Healthcare PIPEDA Quebec Law 25 Bill C-27 Services disponibles en français

What we offer

01 / Services

Security awareness training

Scenario-driven sessions your team will actually remember. We use narrative-based techniques to make threat recognition feel real, covering phishing, social engineering, AI-assisted attacks, and more.

Tabletop exercises

Live incident simulations for leadership teams. Structured around real-world scenarios including ransomware, data breach response, and regulatory notification timelines. Built to surface gaps before a real incident does.

Regulatory readiness

Training programs aligned to Canadian privacy law obligations including PIPEDA, Quebec's Law 25, and incoming Bill C-27 requirements. Documented, defensible, and audit-ready.

Virtual CISO (vCISO)

Fractional security leadership for organizations that need strategic direction without a full-time hire. We help you build policy, manage risk, report to the board, and make the right security investments at the right time.

How we work

Generic training doesn't change behaviour. We build sessions around your people, your systems, and the real threats facing your industry.

  • 1 Discovery. We learn your environment, including tools, workflows, regulatory obligations, and where your risk actually lives.
  • 2 Scenario design. Sessions and exercises are built around realistic situations your team will recognize, not abstract hypotheticals.
  • 3 Delivery. Live, facilitated sessions in person or remote, for executives and front-line staff alike.
  • 4 Documentation. Written materials you can hand to an auditor or regulator with confidence.

Who we work with

Legal

Law firms and in-house teams handling privileged client data and regulatory filings.

Financial services

Investment managers, advisors, and fintechs navigating OSC and FINTRAC obligations.

Healthcare

Clinics, health networks, and digital health companies managing sensitive patient records.

We work primarily with mid-market organizations, typically 50 to 500 employees, where the security team is small or shared and training has to count.

About

Gneiss Group is a boutique security awareness consultancy based in Vancouver, BC.

Founded by a security executive with a background building and securing SaaS products, Gneiss Group brings hands-on experience leading security teams, managing risk budgets, and seeing firsthand how often the human layer is the one that breaks, not the tools.

We exist because mid-market companies in regulated industries need security awareness training that's actually grounded in how threats work today, including AI-assisted phishing, deepfake voice attacks, and increasingly convincing social engineering. Most off-the-shelf training isn't built for that.

We build sessions around story and consequence, not bullet points. People retain what they engage with.

Security engineering SaaS / cloud environments People leadership Incident response Canadian regulatory context Scenario-based facilitation

Get in touch

Whether you're preparing for an audit, responding to a board ask about AI threats, or just know your team needs better training, reach out and we'll figure out if we're a fit.

Based in Vancouver, BC Working with organizations across Canada.
Remote and in-person delivery available.

Why now?

Canada's privacy landscape is shifting fast. Quebec's Law 25 is already in force. Bill C-27 is moving through Parliament. Organizations that build defensible training programs now are ahead of the compliance curve, rather than scrambling to catch up when enforcement ramps up.

PIPEDA Quebec Law 25 Bill C-27