Personal security training has a completion problem. The training event goes well. Instructors cover the material. Operators understand the concepts. And then the training ends, and the list of tools to acquire, accounts to create, and configurations to apply alone later grows until it becomes a project no one finishes.

The consequence is not that operators skipped a homework assignment. It is that the training produced no change in actual security posture.

Why Supply Lists Fail

A supply list requires the operator to make decisions alone that the training should have made with them.

Which specific device? The recommendation said “de-Googled Android”, but there are multiple options, each with different tradeoffs, and the operator does not have the context to choose correctly without guidance.

Which password manager, and how do I migrate without locking myself out of my accounts? This is a multi-hour process that requires understanding of the specific credential set being migrated, and it is the most common point where operators stop.

How do I verify the router configuration is actually doing what I think it is? Without someone walking through the verification process, most people configure and assume.

Supply lists also assume that the operator will sustain motivation to complete an individually daunting security migration after returning from training to their regular work tempo. Most do not. Not because they do not care, but because the friction of starting from scratch, alone, without the structure of the training environment, is too high.

What a Configured Kit Produces

FFP-201 is built around a different model. Every piece of hardware issued during the course is configured and working before the student goes home on Day 5. Not configured in the sense of “the initial setup is complete and you need to migrate your data later.” Configured in the sense of: hardened smartphone with operating system installed, accounts set up, and behavioral practice already established through five days of using the device under instruction. Password manager migrated and hardware-key protected. Travel router configured and tested. Live PACE plan that has been running since Day 1 afternoon.

The operator returns to their unit with a working security posture, not a project.

The hardware list from FFP-201 includes a hardened smartphone, hardware security key, travel router, home/travel network security appliance, Raspberry Pi field kit, signal-shielded bag, and twelve months of encrypted VPN and identity-protection service. Every item is student-retained and fully configured at graduation.

The Practice Gap

Beyond the configuration question, there is a practice gap that supply lists cannot close.

Setting up a password manager is not the same as using one correctly under the friction of normal operations. Knowing that a PACE plan exists is not the same as having run one, including the fallback procedures that activate when the primary path is disrupted.

FFP-201 runs the live PACE plan through the course itself, starting Day 1 afternoon. Students make mistakes. Those mistakes are graded as they happen, not discovered six months later when the plan is needed and fails. By graduation, the plan is not a document. It is a practiced operational behavior.

This mirrors the FFF-401 model for fixed-wing UAS training: students build and fly the actual platform they will operate, rather than studying one on a slide. The principle is the same. Equipment you have configured, tested, and used under instruction is fundamentally different from equipment you have read about.

See the full FFP-201 hardware list and course details.