Vault Cyber Academy. Lead through the incident, don't just respond to it.
A one- or two-day in-classroom course for command staff, supervisors, and executives. Decision frameworks, tabletop exercises, and the vocabulary to talk to IT, the FBI, and the press when it actually matters.
Tailored to who’s in the room.
Same nine-module structure, different examples, different tabletops, different decision frameworks.
Law-enforcement command staff
Chiefs, sheriffs, captains, lieutenants, and supervisors. Focus on agency-as-target attacks, community partner incidents, evidence-handling, mutual-aid coordination, and leading press during a cyber event.
Business executives & owners
Owners, executives, controllers, and IT leads. Focus on wire-fraud + vendor BEC defense, insurance + audit posture, employee training programs, and the leadership decisions that shape recovery.
Nine modules over one or two days.
The two-day version goes deeper on the tabletop, the communications module, and the 90-day plan. The one-day version covers all nine at higher altitude.
Threat landscape
What attackers are actually doing in 2026. Wire-fraud, voice-clone, ransomware, BEC chains, vendor compromise. Patterns drawn from active investigations.
Attack surface
What in your agency or business an attacker would reach for first. Email, accounts, vendors, public records, third-party SaaS.
Detection + reporting
What good looks like, what missing looks like, and how to read what your IT vendor is telling you (or not telling you).
First-hour decisions
Who you call, what you preserve, what you don't touch. The decisions that protect evidence, contain damage, and keep options open.
Tabletop exercise
A live walk-through of a realistic incident. Your team makes the calls. We surface the gaps before they're real.
Communications
How to brief your board, your insurer, your community, and your reporters during and after a cyber incident.
Compliance + reporting
Notification windows, sector-specific obligations, working with the FBI and your state AG. What’s required vs what's optional.
Recovery + lessons learned
What recovery actually costs in time, money, and trust. How to convert an incident into operational improvement.
90-day plan
Each attendee leaves with a personalized 90-day action checklist and the vocabulary to defend the plan to their leadership.
Pre/post assessment.
Every attendee takes a short pre-assessment before day one and a post-assessment after the course ends. You get a cohort report showing the average lift, where the room changed the most, and which modules need follow-up.
Cohorts typically move 10–15 percentage points on the composite score, with the largest gains in “first-hour decisions” and “communications.” You can hand the report to your board, your insurer, or your council to demonstrate the training’s impact.
Booking + format.
- On-site at your agency or business. 1- or 2-day intensive. Single cohort or program-cohort series.
- Best with 12–30 attendees. Larger cohorts available; multi-day rotation if needed.
- Course workbook, handouts, tabletop scenarios, pre/post assessment, cohort report, 90-day action plans.
- Pete teaches every cohort personally. No T1/T2 subcontractors. No vendor consultants.
- Flat-rate per-cohort pricing, scoped to track + duration + group size. Travel billed at cost for distant agencies.
- Schedule a 20-minute scoping call to map your cohort and pick a date.

Active law-enforcement cyber-fraud supervisor. 10+ years investigating the patterns covered in this training.
Map your cohort, pick a date.
A 20-minute scoping call to talk through your audience, the incidents that prompted the training, and which of the two tracks fits best. You’ll get back a one-page proposal with dates, pricing, and tabletop options within one business day.