Bastani Security
Book a program call
The monthly retainer · Toronto & GTA

One drill changes a team. A rhythm keeps it changed.

Most training fades by spring, and every new hire quietly reopens the gap. The Security Partner Plan is the rhythm that keeps readiness real: a monthly check-in with a live scorecard, safe phishing practice for the team, a micro-lesson on this month's scam, every new hire trained in their first quarter, and one number to call when an email feels wrong. It continues what the drill starts - which is why it's available to offices we've worked with.

  • A monthly 45-minute check-in and a live readiness scorecard leadership can glance at
  • Safe phishing practice - authorized in writing, aggregate results only, no shaming, ever
  • Your insurance-questionnaire answers kept honestly current, all year
Book a program call See the year
Readiness that doesn't decay

Behaviour change fades without reinforcement, and every new hire reopens the gap. The plan is built for exactly that: monthly reps, quarterly micro-drills, and new-hire cohorts that catch people in their first weeks - so the habit from drill day becomes the way the office works.

One accountable person, not a portal

You get a person who knows your office - not a login to a video library. The monthly check-in is a conversation with someone who remembers what was fixed in March, what stalled in June, and which new hire hasn't done the drill yet. Big questions become scoped work with published prices; small ones are just answered.

Evidence you can actually show

Every month, a one-page scorecard: report rate, simulation results, training coverage. Every quarter, a plain-language summary shaped for cyber-insurance renewals and client security questionnaires - a running record of real diligence, kept current so renewal week is boring. Practical readiness, never a guarantee: no plan makes anyone immune, and we say so.

The year, mapped

A program your team goes through - not a one-off.

Security awareness isn't a day; it's a habit. Here's the twelve-month arc, and exactly what lands on your desk at each step.

  1. 1
    Month 1 - Onboard The baseline and the standing authorization

    We start from your delivered engagement - the checkup score or drill report is the baseline. Leadership signs one standing simulation authorization (re-confirmed annually), the reporting channel is confirmed, and the first monthly scorecard is drawn so every month after has a line to measure against.

    Your baseline scorecard, carried over from the checkup or drillThe standing simulation authorization, signed once, re-confirmed annuallyThe monthly rhythm booked: check-in day, simulation window, report format
  2. 2
    Every month The rhythm: practice, one lesson, one conversation

    Each month the team gets one real-but-safe phishing simulation tuned to your sector - the fake invoice, the boss-voice ask, the QR trap - with no malware and no real credential capture. Anyone who clicks gets a quick, warm coaching moment, never a name on a board. A two-minute micro-lesson keeps one habit front of mind, and the 45-minute check-in keeps leadership current without homework.

    One safe phishing simulation (monthly on Standard and Premium; quarterly on Essentials)A two-minute micro-lesson on this month's scam, for the whole teamThe 45-minute check-in and the one-page scorecard: report rate, results, coverage
  3. 3
    Every quarter New hires folded in, and a fresh pressure test

    Anyone hired during the quarter gets the new-hire cohort session - so turnover never quietly reopens the gap. A short remote micro-drill runs a scenario the team hasn't seen, because nobody should be coasting on last quarter's lesson. On Standard and Premium, we also review your Microsoft 365 or Google Workspace security score monthly, so configuration drift gets caught while it's small.

    New-Hire Cyber Onboarding for everyone who joined that quarterA quarterly 20-minute remote micro-drill on a fresh scenarioMonthly Microsoft 365 / Google Workspace secure-score review (Standard and Premium)
  4. 4
    Every year The refresher, the re-score, and the trend line

    Once a year the team re-drills with all-new scenarios - alumni remember last year's - and the office is re-scored against its baseline. Leadership sees the curve, not a claim: report rate up, coverage complete, questionnaire answers still true. Standard includes the annual 90-minute refresher; Premium includes the full three-hour Cyber Fire Drill, a leadership tabletop, and quarterly executive briefings.

    The annual refresher drill with a fresh scenario pack (tier-dependent depth)A year-over-year trend report against your original baselineRenewed, dated certificates and an updated insurer answer pack
What each person can do

Every employee, levelled up - step by step.

The program isn't abstract "awareness." It's a skill ladder. Here's what a staff member can actually do as they move through it.

1
After month one
Every staff member knows the reporting channel cold and has used it at least once - because the first simulation lands early, and reporting it is the win condition.
2
After the monthly reps
They spot a suspicious email on their own, report it the way the office has agreed, and treat any urgent money-or-data request as something to verify before acting.
3
After the micro-lessons
They carry one concrete habit per month - like confirming a banking change by phoning a known number, never the one in the email.
4
After a quarterly micro-drill
Under a little time pressure they make the right call in a scenario they have never seen, and know who to tell while it is happening.
5
After new-hire onboarding
A brand-new employee reaches the team's readiness in their first quarter, with a verification cheat-sheet sized to their role - instead of being the untrained gap.
6
By the annual re-score
Verifying out-of-band, reporting fast, and resisting urgency are reflexes - and the trend report shows the movement in numbers, not adjectives.
Membership

One monthly fee. The whole program.

Priced by team size, billed monthly, all in CAD plus HST. Six-month minimum; cancel-friendly terms after that, walked through on the call.

Essentials
$349/mo + HST
A 5–15 person office that finished a checkup or drill and wants a security person without a heavy lift.
  • Monthly 45-minute check-in and the one-page scorecard
  • Quarterly safe phishing simulation and quarterly new-hire cohort
  • The "is this email legit?" line, and annual insurer-questionnaire help
Book a program call
Most popular
Standard
$649/mo + HST
A 10–30 person office that wants monthly practice and its Microsoft 365 or Google Workspace watched.
  • Everything in Essentials, with the simulation monthly instead of quarterly
  • Monthly Microsoft 365 / Google Workspace secure-score review
  • The annual 90-minute refresher drill included, certificates renewed
Book a program call
Premium
$1,199/mo + HST
A 15–50 person office - often a clinic or firm with regulatory weight - that wants leadership in the loop.
  • Everything in Standard, plus quarterly executive briefings
  • The full annual Cyber Fire Drill and a leadership tabletop included
  • Priority coordination if something happens - we convene the specialists, starting with your insurer
Book a program call

Prefer to start smaller? Most teams begin with a one-off Cyber Fire Drill, then roll into the program.

What changes

A year in, here's what's different.

Your team treats verifying a payment or banking-change request as automatic - phone a known number, never the one in the email - because the reps never stopped.
Readiness stays current all year, so a new hire in month nine reaches the same readiness the team had on drill day, without anyone remembering to arrange it.
You hold a monthly, plain-language record of real diligence to put in front of a cyber-insurer or a client security questionnaire - no renewal-week scramble.
Leadership sees the trend line at a glance every month, and the one or two things to fix next are always named, owned and dated.

Program questions.

Why is the plan only for offices you've worked with?

Because the plan continues what an engagement starts. The scorecard needs a baseline, the simulations need the no-shame culture the drill establishes, and you deserve to know how we work before committing to a rhythm. Start with the Baseline Security Checkup or a drill - the plan conversation happens naturally at the debrief.

Is the monthly phishing safe to run on our own staff?

Yes. Every simulation is real-but-safe: no malware, no real credential capture, and never any public shaming. Results are reported in aggregate; anyone who clicks gets a short, warm coaching moment, not a name on a board. One standing authorization covers the program, signed by leadership and re-confirmed annually.

What does it cost, and is there a commitment?

Essentials is $349 a month, Standard $649, Premium $1,199 - plus HST, with a six-month minimum, monthly after that. Retainer clients also get priority scheduling and 10% off project work. The prices are published because that's how we do every price.

What's explicitly not included?

Incident response - if something happens we coordinate the specialists, starting with your insurer's breach line, but live response is delivered by response firms, not us. Hardening projects are quoted separately (retainer clients get 10% off). And the Q&A line is fair-use: quick questions are always free; big questions become scoped work with a published price.

Will this help with our cyber-insurance renewal or a client questionnaire?

It's built to. The monthly scorecard and quarterly summary give you a running, dated record of real training, testing and review - exactly the evidence renewal forms and client questionnaires ask for, kept current instead of reconstructed the week they land. Practical readiness, not a guarantee: no plan makes anyone immune, and we put that in writing.

Make your team the firewall.

Book a 20-minute call. We'll size the program to your team, send one quote, and pick a kickoff date.

Book a program call (647) 835-6368