Raising Awareness about Cybersecurity Risks and Countermeasures in the Corporate Environment

Spaziottantotto operates in consulting, professional training, and information technology.

The company originated from the Incubator of Innovative Enterprises of the Politecnico di Torino (I3P). Spaziottantotto won two awards for high-tech ideas in a competition promoted by the City of Turin in collaboration with the LINKS Foundation (formerly Istituto Mario Boella), I3P, the Province of Turin, the Chamber of Commerce, and the national agency for investment attraction and enterprise development, Invitalia (formerly Sviluppo Italia S.p.A.).

Additionally, the company received the “Galileo Ferraris – from idea to innovative enterprise” award for the best business plan and has received numerous accolades for the quality of the applications developed.

Over the years, it has paid particular attention to the field of security, acquiring high-level expertise in various sectors: cybersecurity, privacy protection, workplace safety, hygiene and food safety, environmental protection and waste management, quality systems management, and organizational and control models.

Recently, the company took part in the Cybersecurity SME project promoted by the Turin Chamber of Commerce, making free use of the CEI – Cyber Exposure Index – service, an initial assessment tool useful for stimulating appropriate strategies for monitoring and controlling the IT infrastructure. The report highlighted a significant risk level, revealing the need to deepen cybersecurity knowledge through targeted training.

Solution Description

Based on the company’s stated needs, a foundational cybersecurity training course was organized.

The course provides a comprehensive overview of current cyber threats and best practices to protect businesses. Its primary objective is to equip participants with a solid understanding of cyber risks and the most effective defensive strategies. It also aims to raise management’s awareness of organizational vulnerabilities, providing the skills needed to address them.

For the client company, a comprehensive vulnerability assessment of both the internal and external perimeter was carried out, accompanied by a simulated phishing campaign targeting the entire organization. The goal was to evaluate the current risk level (AS-IS), considering both technological assets and the human factor. At the end of the simulation, all staff had access to short training video tutorials designed to raise awareness and provide best practices on how to recognize and effectively counter cyber threats.

Results and Benefits

At the end of the course, participants understood the fundamental concepts of cybersecurity and learned how to assess specific threats. They acquired practical knowledge to effectively apply best practices, recognize cyberattacks, and respond appropriately, thereby improving the organization’s overall security.

Upon completion of the vulnerability assessment and phishing campaign activities, the client was provided with an operational strategic roadmap report for the implementation of technologies and processes to effectively improve the organization’s cybersecurity posture.

Perceived Social/Economic Impact

  • Greater awareness of cyber threats and mitigation strategies
  • Increase in corporate know-how
  • Interest in improving the business model by introducing services related to cybersecurity management
  • Intention to amplify the positive impact by promoting the course to their own clients as well

Measurable Data

26 people actively participated in the training session.

Services

Specialized

Training Path Analysis for Enterprises

EXPAND provides a customized training service, developed in...

Specialized

Fundamentals of Cybersecurity for Executives

The course provides a comprehensive overview of current...

Specialized

Testing and Design of IT-level Cyber Security Systems

EXPAND helps companies identify security gaps in their...