Recognising scams, phishing and unsafe practice, aimed at staff and everyday users rather than specialists.

What this course covers

Recognising scams, phishing and unsafe practices before they cost you money. This is the training with the sharpest financial edge, because the most common way an organisation loses money is not a technical breach: it is somebody believing a convincing email.

What you will learn

  • How phishing actually looks now, which is nothing like the old jokes about spelling
  • Business email compromise: the urgent request that appears to come from a director
  • Invoice fraud, and why changed bank details deserve a phone call
  • Checking a link before clicking, and a sender before replying
  • Passwords, reuse, and why one leak becomes many
  • Two-factor authentication, and the ways attackers try to talk you past it
  • Public wifi, personal devices and working away from the office
  • What to do in the first ten minutes after realising you clicked

Who this is for

  • Whole teams, which is where it works best
  • Organisations that have had a near miss and want it not to repeat
  • Finance and administrative staff, who are targeted deliberately
  • Anyone who handles payments, payroll or supplier details
  • Businesses that have been told to do awareness training and want it to be useful

The attacks that actually work

Forget the caricature of a badly spelled email from a stranger. Current fraud is well written, correctly branded, and specific to your organisation.

It knows your director's name. It arrives on a Friday afternoon when you are busy. It refers to a real project. It asks for something plausible and slightly urgent. The login page it sends you to is a pixel-accurate copy.

None of this is defeated by being careful in a general sense. It is defeated by knowing the specific patterns, and by having a habit: any request to move money or change payment details is verified through a channel the request did not arrive on.

The invoice one, specifically

The most expensive attack most South African businesses will meet is an invoice with altered bank details. A supplier you genuinely use, an invoice you were genuinely expecting, an amount that is correct, and an account number that is not theirs.

It works because everything about it is legitimate except one line, and because paying suppliers is routine. The defence is a policy rather than a piece of software: bank detail changes are confirmed by phoning a number you already had, never a number on the invoice.

Culture matters more than knowledge

The most important outcome is that someone who has clicked something says so immediately.

In organisations where a mistake means humiliation, people stay quiet, and the hour that mattered is lost. In organisations where reporting is treated as helpful, most incidents end in nothing. That is a management decision as much as a training one, and we say so plainly during the session.

What this course does not do

It does not make you unattackable, and we will not suggest otherwise. It shifts the odds substantially, and it makes the difference between an incident that ends in an awkward conversation and one that ends in a loss.

Who should attend

Everyone who has an email address at your organisation. Attackers do not restrict themselves to the technical staff, and the people they target most are usually the ones with least training.

Interested in this course?

Tell us where you are starting from and we will suggest a route.

Get in touch