Security awareness training
Security awareness training and phishing simulation in Canada
Cyber security training for employees with realistic phishing simulation, role-based modules and quarterly measurement.
Most breaches start with a person. Canada Create™ trains your people the way attackers test them: short, specific and often, with results you can show a regulator, an insurer or a board.
Get your training program proposal
Tell us how many people you have and your industry. Written proposal within one business day.
By submitting, you agree that Canada Create™ may contact you about your request. No spam, ever.
What security awareness training gives you
Fewer clicks, more reports
Measured every quarter, by department, with the trend over time.
Attacks caught early
One early report lets you block a campaign before it spreads.
Compliance records
Completion, simulation and attestation evidence for SOC 2, PHIPA, PCI DSS and insurers.
Training people do not resent
Short, role-specific and relevant to the emails they actually receive.
What is included in the training program
Baseline, train, simulate, measure, repeat.
- Baseline phishing simulationClick, credential and report rates measured before any training.
- Role-based trainingFinance, executives, admin, IT, clinical, legal and front-line modules.
- Ongoing phishing simulationMonthly or quarterly campaigns mirroring real Canadian attack themes.
- Just-in-time lessonsA two-minute lesson for anyone who clicks, on the spot.
- Report buttonOne-click reporting in Outlook or Gmail routed to analysts.
- Policy modulesAcceptable use, passwords and MFA, remote work, data handling and incident reporting.
- Onboarding and annual refresherEvery new hire trained, everyone refreshed yearly.
- Quarterly reportingResults by department with a plan for the next quarter.
Security awareness training pricing
Priced per user per year. Live sessions and custom modules quoted separately.
Awareness program
Quoted in writing, per user per year
Businesses of 5 to 500 staff that need measured training and simulation
- Baseline and ongoing phishing simulation
- Role-based training modules
- Report button
- Onboarding and annual refresher
- Quarterly reporting
Regulated program
By proposal
Healthcare, legal, finance, public sector and SaaS with framework requirements
- Everything in the awareness program
- Industry-specific privacy modules
- Policy attestation records
- Live sessions for leadership and high-risk roles
- Framework-mapped evidence for auditors
Training is included at a reduced rate in managed security programs.
People are the perimeter
Train them the way attackers test them
Cyber security training for employees that changes what they do, not just what they know
Most breaches start with a person: a clicked link, a fake invoice approved, a password typed into a lookalike page, a “CEO” asking for gift cards. Technology can block some of it. Only trained people stop the rest. Canada Create™ security awareness training gives Canadian businesses short, role-based training, realistic phishing simulations and quarterly measurement, so you can see who clicks, who reports, and how that changes over time. It is the program regulators, insurers and enterprise customers expect, delivered in a way employees do not resent.
What the program includes
Baseline phishing simulation
Before any training, we send a realistic simulated phishing campaign to measure where you actually start: click rate, credential entry rate, report rate and time to first report. No blame, no naming, just a number to improve.
Role-based training
Short sessions built for the risks each role faces. Finance and accounts payable learn invoice fraud and payment diversion. Executives and assistants learn impersonation and travel scams. Reception and admin learn pretexting and visitor risk. Developers and IT learn credential hygiene and secure configuration. Clinical, legal and financial staff learn the privacy rules that apply to the records they handle. Delivered live, recorded or in your learning system.
Ongoing phishing simulation
Monthly or quarterly campaigns that mirror what attackers are actually sending to Canadian businesses: parcel notices, Microsoft 365 password resets, CRA and payroll themes, vendor invoice changes and internal HR messages. Difficulty rises as your team improves. Anyone who clicks gets a two-minute lesson on the spot, not a lecture.
Report button and response
A one-click button in Outlook or Gmail that sends suspicious messages to our analysts, so reporting becomes a habit and real attacks get caught by the people who receive them.
Policy and onboarding modules
Acceptable use, password and MFA, remote work, data handling and incident reporting policies turned into short modules, with onboarding training for every new hire and an annual refresher.
Quarterly reporting
Click, report and completion rates by department, trend over time and a plan for the next quarter, in a format you can hand to an auditor, an insurer or a board.
Built for regulated industries
Healthcare organizations under PHIPA, financial firms under OSFI and provincial regulators, law firms with confidentiality obligations, public sector bodies and SaaS companies pursuing SOC 2 or ISO 27001 all have training requirements written into their frameworks. Our program produces the completion records, simulation results and policy attestations those frameworks ask for, and the content is adapted to the records your people actually handle.
Why simulations matter more than slides
An annual slideshow satisfies a checkbox and changes nothing. What changes behaviour is a realistic email arriving on a Tuesday afternoon, a moment of doubt, and the memory of the last time. Organizations that run regular simulations see click rates fall and report rates rise within a few quarters, and a rising report rate is the metric that actually stops attacks, because one early report lets your security team block a campaign before the tenth person opens it. Pair the program with managed security services and those reports go straight to analysts who can act.
Security awareness training pricing
The program is priced per user per year, with live sessions and custom modules quoted separately. Tell us how many people you have, which industry you are in and whether you need live, recorded or learning-system delivery, and you will have a written proposal within one business day.
Start your training program
Get a proposal in one business day, or call +1 (800) 808-9235 any time. Part of our cyber security services for Canadian businesses.
Talk to a strategist
Ready when you are!
Get a proposal in one business day.
Tell us your goals, budget and timeline. You get a plan, a price and a named strategist, with no long-term contract.
How the program runs
Live within two weeks, measured every quarter.
- Setup and baseline Week 1 to 2
Platform setup, report button, and a baseline simulation to measure the starting point.
- Core training Week 2 to 4
Role-based modules delivered live, recorded or in your learning system.
- Simulation cycle Monthly or quarterly
Realistic campaigns with rising difficulty and on-the-spot lessons.
- Policy and onboarding Ongoing
Policy modules, new-hire training and annual refreshers.
- Quarterly review Every quarter
Results by department, trend and next-quarter plan.
What clients say on Google
Reviews pulled live from our Google Business Profile.
Free review, no obligation
Not sure where to start? Send us what you have.
Share your current site, campaign or brief. A strategist reviews it and replies within one business day with a written recommendation and a fixed quote.
Why Canada Create™ for security awareness training
Real attack themes
Simulations built from what Canadian businesses actually receive.
BBB Accredited, A+
An A+ rating with the Better Business Bureau and zero complaints.
Industry-specific content
Modules adapted to health, legal, financial and public sector records.
Quoted in writing
Per-user pricing confirmed before you start. Proposal in one business day.
Reports that go somewhere
Paired with managed security, every report reaches an analyst.
24/7* support
Call +1 (800) 808-9235 any time, day or night.
Security awareness training questions
What is security awareness training?
A program that teaches employees to recognize and report phishing, fraud and other attacks, then measures whether they do, using realistic simulations and short role-based lessons.
What is a phishing simulation?
A safe, realistic fake phishing email sent to your staff to measure who clicks, who enters credentials and who reports, followed by a short lesson for anyone who falls for it.
How much does cyber security training for employees cost in Canada?
Programs are priced per user per year, with live sessions and custom modules quoted separately. You will have a written proposal within one business day.
How often should employees be trained?
Short training at onboarding and annually, plus monthly or quarterly simulations. Frequency beats length.
Will simulations upset our staff?
Not when they are run without blame or public naming. Results are reported by department, and the lesson for anyone who clicks takes two minutes.
Is training required for compliance?
SOC 2, ISO 27001, PCI DSS, PHIPA guidance and most cyber insurance policies require or expect regular security awareness training with records.
Can you train remote and hybrid teams?
Yes. Modules are delivered live online, recorded or through your learning system, and simulations reach every inbox wherever staff work.
Do you customize content for our industry?
Yes. Health, legal, financial, public sector and technology teams get modules built around the records and scams specific to them.
What happens when someone reports a real phishing email?
With the report button, it goes to analysts who can block the sender and warn the rest of your team. Paired with managed security, that response happens around the clock.
How do we measure success?
Falling click and credential rates, rising report rates and faster time to first report, tracked quarterly by department.


One click is all it takes
An annual slideshow changes nothing. Find out what your team would do with a real phishing email next Tuesday.

