Skip to content
← All workshops

Workshops · business and government

They don't attack your system.
They attack your procedure.

Ninety minutes for the staff who authorise payments, receive invoices, handle paperwork and hold other people's data. Targeted fraud doesn't arrive as a virus: it arrives as an email that looks like ordinary work. This is how to recognise it and what to verify before approving.

90 min
A single session, on site or remote
6
Attack contexts inside everyday operations
1 protocol
The confirmation agreement, signed off by whoever runs the area

Who it is for

For administrative and operational staff between 25 and 45 who handle money, documents or other people's data every day. No IT background needed.

Administration and finance

Whoever enters, validates and releases payments, receives invoices and deals with suppliers. This is where the money goes in a single transfer.

Front desk, service and HR

Whoever receives files, IDs and third-party data all day, and cannot afford to stop opening what gets sent to them.

Public agencies and regulated bodies

Government areas handling citizen data and paperwork, where a slip costs more than money: it carries an administrative consequence.

What they walk out with

  1. 01

    Targeted fraud isn't caught by reading the email more carefully: it's caught by verifying through a second channel.

  2. 02

    Six contexts where it gets in — the payment, the supplier, the identity, the file, third-party data and access — and what to check in each one.

  3. 03

    A written protocol — who confirms, at which number, who gets told and how fast — to print and hang where the decisions get made.

The 90-minute agenda

The examples are real emails, invoices and calls recreated on screen, matched to your industry or your agency.

  1. 0 to 10 min

    Why your team, and why now

    How a target is picked before the first email is written: the published org chart, the transparency directory, staff social media, an invoice that circulated. The attacker arrives knowing your name, your role and who you report to.

  2. 10 to 28 min

    The payment and the supplier

    The urgent instruction that seems to come from a superior, and the bank-account change notice from a long-standing supplier. Both move money, both arrive by email, and both are stopped by the same verification.

  3. 28 to 45 min

    The identity and the file

    The domain with one letter changed, the reply that leaves for another inbox, and the work account that is already compromised. Plus the file you actually were expecting: the CV, the quote, the receipt, the supposed system update.

  4. 45 to 60 min

    Third-party data and access

    What the law requires when you hold client or citizen data, with the clocks that start running and the sanction ranges in each case, said without lawyers. Shared accounts, the workstation left unlocked, the work WhatsApp group, and the file emailed to a personal account to finish at home.

  5. 60 to 78 min

    Exercise: approve it or stop it?

    Six recreated cases — email, invoice, call and message — that the group settles out loud. This is the block where people argue, not listen.

  6. 78 to 90 min

    The protocol

    Filled in during the session: which operations require confirmation, who confirms, at which number, who gets told, and how fast. Whoever runs the area signs it off and it stays with your organisation, to print and hang where the decisions get made.

After the session

Certificate of attendance

It arrives as a PDF at the address each person writes on the attendance sheet, in their name, with the workshop, its length, the date and the standard it is designed against.

It is a certificate of attendance: it records that the person was in the session. It is not a competency certificate or a certification.

To issue them we ask the organiser for a simple list with each attendee's name. It is used only to produce the certificates and is destroyed as soon as they are sent.

CONSTANCIA DE PARTICIPACIÓNSimpleCodeSe otorga la presente constancia aNombre de la personapor su participación en el tallerProtecting the operationDuración · 90 min Modalidad · Presencial Fecha · 00/00/0000 Lugar · XalapaTaller diseñado con base en el estándar EC0217.01 de CONOCER.No es un certificado de competencia ni una certificación.Folio · SC-0000 · simple-code.cloudFacilitadorSimpleCode

Request the workshop

How they are designed

Our workshops are designed against CONOCER competency standard EC0217.01 (delivery of in-person group training): clear objectives, a teaching sequence, exercises and a check on what was learned. They are not certified courses; they are workshops built following that standard.

Workshop: Protecting the operation

$3,999 MXNper group · up to 20 people

Ninety minutes with your team, at your site or by video call, with the confirmation protocol agreed during the session.

  • 90 minutes: six attack contexts and a group decision exercise
  • A certificate of attendance as a PDF for every attendee
  • Examples matched to your industry or your agency
  • Whoever runs the area attends and signs off the protocol at the end
  • On site in Xalapa and nearby, or remote anywhere
  • Groups over 20 people: quoted on request
Request the workshop

Questions about the workshop

Do we need to have taken the first workshop?

No. They are independent and stand on their own. The first protects each person's private life; this one protects the organisation's operation. If your team takes both, better — half of all office fraud starts on somebody's personal phone.

How technical is it?

Direct, but not technical. It talks about emails, invoices, accounts and paperwork, not protocols or networks. The only terms introduced — lookalike domain, second-channel verification and third-party data — are explained once and used throughout.

Does it work for a government agency?

Yes, and the examples are swapped for public-sector ones: paperwork, the front counter, registries and contracted suppliers. The third-party data block separates what the law requires of a private company from what it requires of a public body, with each one's response deadlines and sanction ranges. They are orders of magnitude to size up the risk, not legal advice.

What exactly is the protocol?

A short agreement the group fills in during the session: which operations require confirmation, who confirms, at which number, who gets told and how fast. Whoever runs the area signs it off at the end and it stays with your organisation.

Why do you ask the head of the area to attend?

Because the workshop ends with a permission only the person in charge can grant: to stop an urgent operation in order to verify it, and to report a mistake without it costing a telling-off. If that sentence isn't said in the room, the team leaves knowing what to do but not feeling allowed to do it.

What data do you need for the certificates?

Only two things: each attendee's name, in a simple list from the organiser, and the email each person writes on the attendance sheet on the day. Nothing else. That is what we use to produce and send the PDFs, and the lists are destroyed as soon as the emails go out: we do not keep them or use them for anything else.

The other workshop

Length
60 min
Who it is for
Families and community groups

Workshop: How to protect your money and your family online

Digital scams and social engineering explained without a single technical word, through the house, the keys and whoever rings the doorbell. For adults who never had security training.

  • No prior knowledge: everything is explained through daily life
  • The five doors scams come through, and the tell for each one
  • A certificate of attendance as a PDF for every attendee
$2,999 MXNper group · up to 20 people
See the workshop

Do you also need a website?

The other half of SimpleCode: custom sites, dashboards and tools with AI built in. Same team, same way of explaining things.

One session today saves your people a fraud tomorrow.