Recognising scams, phishing and unsafe practice, aimed at staff and everyday users rather than specialists.
Recognising scams, phishing and unsafe practices before they cost you money. This is the training with the sharpest financial edge, because the most common way an organisation loses money is not a technical breach: it is somebody believing a convincing email.
Forget the caricature of a badly spelled email from a stranger. Current fraud is well written, correctly branded, and specific to your organisation.
It knows your director's name. It arrives on a Friday afternoon when you are busy. It refers to a real project. It asks for something plausible and slightly urgent. The login page it sends you to is a pixel-accurate copy.
None of this is defeated by being careful in a general sense. It is defeated by knowing the specific patterns, and by having a habit: any request to move money or change payment details is verified through a channel the request did not arrive on.
The most expensive attack most South African businesses will meet is an invoice with altered bank details. A supplier you genuinely use, an invoice you were genuinely expecting, an amount that is correct, and an account number that is not theirs.
It works because everything about it is legitimate except one line, and because paying suppliers is routine. The defence is a policy rather than a piece of software: bank detail changes are confirmed by phoning a number you already had, never a number on the invoice.
The most important outcome is that someone who has clicked something says so immediately.
In organisations where a mistake means humiliation, people stay quiet, and the hour that mattered is lost. In organisations where reporting is treated as helpful, most incidents end in nothing. That is a management decision as much as a training one, and we say so plainly during the session.
It does not make you unattackable, and we will not suggest otherwise. It shifts the odds substantially, and it makes the difference between an incident that ends in an awkward conversation and one that ends in a loss.
Everyone who has an email address at your organisation. Attackers do not restrict themselves to the technical staff, and the people they target most are usually the ones with least training.
Tell us where you are starting from and we will suggest a route.
Get in touch