1
Facilitator arrives 30 minutes early
Full printed card deck, prop kit, and envelopes. Setup is invisible — cards face-down, props in place, room looks normal when your team walks in.
2
Pre-session card game while people arrive
Each person picks up 3 trivia cards and 2 fish cards. They challenge each other before the session even starts — right answers win cards, wrong answers earn a fish. The game begins before you call order.
3
Thirteen cards. Real attack scenarios.
Each card is a real threat — display name spoofing, vendor fraud, reply-chain phishing. The group discusses, commits to an answer, and finds out what attackers are counting on them to miss.
4
Debrief + action sheet
Three closing questions. Three actions they can take this week. Completion certificates emailed within 24 hours. WILDCARD follow-up within 24 hours if anything came up during the session worth addressing.
🏢
The Room
♠ Your location
— Table that fits the group (or semicircle of chairs)
— Projector or screen (optional — cards work without it)
— Lunch or snacks if running at noon
🤝
The Buy-In
♠ Manager or owner
— 5 minutes of intro time from leadership: "This is important, we want you here."
— Employee names for CAPG documentation (if filing)
— That's it. We handle the rest.

Alberta employers can reclaim 50% of eligible training costs — up to $5,000 per employee per year. GoPhish qualifies. A session for 10 people at $1,750 costs ~$875 after the grant.

📋
What We Provide
♠ Ready to submit
— Course description + learning objectives
— Trainer credentials and qualifications
— Itemized invoice per attendee
🏢
What You Bring
♠ Your side of the application
— Alberta.ca Account for Organizations (allow 3–5 days)
— Business registration + WCB account number
— Employee names for each trainee
Submit 30+ days before your session date
Full CAPG guide — eligibility, steps, timelines →

We bring everything. You bring your team.

Thirteen cards. Seventy-five minutes. Your whole team leaves knowing how to read an attack before it lands.

Questions? play@gophishing.ca

Looking for virtual instead →