The weak link is never the computer
You can have the best infrastructure in the world: if people cannot use it - or fall for the first phishing email - the value is lost. Xion IT Group provides consulting and staff training on IT subjects: security and privacy, day-to-day business computing, data protection and Office automation.
Consulting and training on the systems side
Consulting:
- setting up the working environment to get the most out of it;
- creating rules and procedures that streamline office processes;
- advice on printing systems.
Training:
- using computers and peripherals;
- privacy law and correct handling of data;
- office software specific to particular professions.
Consulting and training on the Office side
Consulting and design:
- tailoring documents and spreadsheets;
- building multimedia presentations;
- developing databases in Microsoft Access;
- email templates and procedures that join Office applications together.
Training:
- side-by-side coaching on site and remotely;
- a dedicated telephone help desk for Microsoft Office;
- classroom courses in Milan, Lecco and Bergamo.
Training that shows up in the accounts
An hour a day lost wrestling with Excel is over 200 hours a year per person. The right training pays for itself in weeks - and on the security side, a single incident avoided is worth more than the entire course.
The training people are asking for in 2026
The catalogue has moved on along with the threats and the tools. This year’s most frequent requests:
- Security awareness — recognising phishing, business email compromise and social engineering, with practical simulations;
- AI literacy — using ChatGPT, Copilot and similar tools productively and safely: what to upload, what never to upload, how to check the output (the full programme);
- GDPR in practice — not the theory of the Regulation but what to do at your desk: email, attachments, retention, requests from data subjects;
- Microsoft 365 properly — Teams, OneDrive and SharePoint used well: the difference between having them and getting value from them;
- Excel from where people actually are — courses pitched at the participants’ real level, measured beforehand rather than declared.
How we build a training programme
- Assessing the need — short interviews and, where useful, an entry test: training addresses the real gap, not a standard syllabus;
- Design — short, practical modules built on the company’s own cases rather than abstract examples;
- Flexible delivery — on site, in the classroom (Milan, Lecco, Bergamo) or remotely, in sessions as short as an hour so work does not stop;
- Assessment and certificate — a final test and a certificate, which also serves as evidence of compliance, since both the GDPR and NIS2 require documented training;
- Periodic refreshers — because one-off training evaporates within six months.
A concrete example
After a phishing simulation at a company of thirty people, 40% had clicked the test link. Two practical training sessions and three months later, the second simulation stopped at 7% — and those who did click reported it immediately, which is exactly the behaviour that saves a company. Training does not make people infallible: it makes them quick to react.
Why security training usually does not work
Almost every company we meet has already run a course on IT security. Almost none of them has seen behaviour change. There are three reasons and they are always the same.
It happens once. A two-hour session in January does not last until December. The attacks change, the people change, and very little is remembered two months later.
It talks about threats in the abstract. Explaining what phishing is in general achieves little. What works is showing the email that would actually reach that person in that role: the fake invoice to the accounts department, the fake CV to HR, the fake urgent request from the owner to the bookkeeper.
Nothing is measured. Without a measurement before and after, nobody knows whether it helped, and the following year the same course is run again.
Simulation, done properly
The method that works is sending test emails built like the real ones and watching what happens. But how it is done changes the outcome completely.
It is not there to catch anyone out. If the exercise turns into a list of names to show the boss, the result is that whoever makes a mistake hides it — which is precisely the most dangerous behaviour. The useful figure is the aggregate: how many clicked, how many entered credentials, how many reported it.
Reporting matters more than clicking. The aim is not to eliminate mistakes, which is impossible: it is to shorten the time between the click and the report. A company where somebody clicks and raises the alarm within two minutes is far safer than one where nobody clicks but nobody would know what to do.
The training arrives immediately afterwards. Anyone caught by the simulation receives, in that same moment, an explanation of what they should have noticed. That is when people genuinely learn, and it lasts far longer than a classroom session.
What we teach, concretely
The four situations worth spending time on, because they are the ones that cause the real damage:
- the request to change bank details, and the rule that defuses it — always verify on a different channel from the one that carried the request;
- the fake login page, and how to recognise an address that is not what it appears to be;
- urgency as a warning sign: haste is the attacker’s main instrument, and “by this evening” is almost always a red flag;
- what to do after getting it wrong, meaning who to tell, immediately, without fear of consequences. This is the most important lesson of all.
Alongside these sits the practical part on using the tools correctly — passwords, second factor, handling shared files — which is less dramatic and cuts out a surprising number of everyday problems.