Skip to main content

Cyber Risk Essentials · Cyber Awareness Programme

Cyber Awareness Training that changes what your people do

Cyber Risk Essentials is CRS's managed Cyber Awareness Programme. It brings together three things — instructor-led classes, phishing simulations and online training — run for you as one continuous programme, with the evidence POPIA, auditors and cyber insurers ask for.

Classes
Quarterly, instructor-led
Simulations
Randomised, every 3–5 weeks
Online training
Monthly, self-paced

What Cyber Risk Essentials includes

Three ways of learning, each doing a different job. Classes explain, simulations test, online training keeps it fresh — and every result feeds the same reports.

Classes

Quarterly, instructor-led

Live sessions with a CRS facilitator — the part people remember, and where they can ask questions.

  • Quarterly instructor-led cyber awareness sessions for all staff
  • Executive Lunch-and-Learn: a 90-minute session on AI exploitation, deepfake voice and video fraud, CEO impersonation and boardroom cyber governance
  • Tailored to your sector, your audience and recent threat-actor activity
  • On-site, virtual or hybrid

Simulations

Randomised, every 3–5 weeks

Realistic phishing tests that employees cannot predict — practice where a mistake costs nothing.

  • Current South African lures: QR-code phishing, Microsoft 365 login spoofing, CEO fraud and SARS-themed emails
  • Anyone who clicks is automatically assigned remedial training — no IT intervention
  • Run by an outside party, so staff do not recognise and dismiss the campaign

Online training

Monthly, self-paced

Short modules people complete in their own time, so awareness is kept up between classes.

  • Monthly self-paced online training for every employee
  • Continuous remedial training automatically assigned to anyone who falls behind
  • Completion tracked and reported, so you can show who has been trained

Around all three

  • Dark web monitoring for compromised employee credentials, with alerts so passwords are reset before they are used
  • Automated monthly compliance reports for regulators, auditors and cyber insurers
  • Managed end to end by CRS — nobody on your team has to run campaigns or chase completions

Classes tailored to you, with new topics as threats change

Off-the-shelf awareness content goes stale and rarely fits the business in front of it. CRS runs classes to your requirement, and keeps adding topics so the programme stays current year after year.

Built around your requirement

Tell us who is in the room and what worries you. A class can be pitched at all staff, at a single team, or at the executive committee and board — and anchored in your sector's threats.

New topics, consistently

Attackers change their methods every few months, so the content does too. Each quarterly class is an opportunity to bring in what has emerged since the last — AI-assisted scams and deepfakes were not on anyone's slides two years ago.

Your policies, your incidents

Run a session on a policy you have just introduced, a finding from your last audit, or a near-miss your team would rather not repeat. Organisations coming out of an incident use exactly this to change behaviour quickly.

Delivered the way you work

On-site at your premises, virtually, or a mix of both, scheduled around your operations — including separate sessions for shifts, branches or regions.

Topics we already cover

  • Spotting phishing and email fraud
  • QR-code phishing
  • CEO fraud and business email compromise
  • Deepfake voice and video fraud
  • Vishing (phone-based social engineering)
  • AI-assisted social engineering
  • Leaked credentials and the dark web
  • Handling personal information under POPIA
  • Your own company policies
  • Executives' personal attack surface

Need something that isn't here? Tell us the topic and we will build the class around it.

What changes when your people are trained

Firewalls and filters stop a great deal, but most breaches still start with a person opening, clicking or trusting something they should not have.

Fewer clicks, and proof of it

Click rates are measured from the first simulation onward, so improvement is something you can see month by month rather than assume.

A habit, not an annual tick-box

Simulations every few weeks, online training every month and a live class every quarter keep awareness current. A once-a-year video is forgotten by the next phishing email.

Leaders who understand their own risk

Executives are the people deepfake and CEO-fraud attacks impersonate and target. The Executive Lunch-and-Learn is aimed squarely at them.

Leaked credentials caught early

Dark web monitoring runs between campaigns, so an employee whose password has leaked is told before an attacker uses it.

Illustrative programme

A manufacturer is hit by a spear-phishing email that gets past its filter. At baseline, 35% of employees click the first simulation. With simulations every few weeks, monthly online training, quarterly classes and remedial training for every click, the click rate falls to 4% within six months — and the business can show its insurer the trend.
A worked example of how the programme is designed to perform, not a named customer result.

Why it is cost-effective

The cheapest-looking option is often the one that costs the most staff time, or the one that quietly stops running. Pricing is quoted per organisation.

Nobody internal has to run it

Building campaigns, chasing completions and compiling reports is weeks of IT and security time a year. With a managed programme, that time goes back to the work you hired those people for.

One programme instead of four purchases

A training platform, a facilitator for live classes, an executive briefing and dark web monitoring are usually bought separately. Here they are one programme with one relationship.

Evidence that can lower what insurance costs

Many cyber insurers offer better premiums or terms to organisations that can show active, measured awareness training. The monthly reports are structured to be exactly that evidence at renewal.

The expensive part is the click

Most breaches involve a person — 80–90% by the programme's own benchmark. Reducing how often your people are fooled addresses the cause, rather than paying for what follows.

How the options compare

Cyber Risk Essentials compared with a self-service training platform and an internal programme
CapabilityCyber Risk EssentialsSelf-service platformRun internally
Who runs the campaignsCRS, as a managed serviceYour IT or security teamYour IT or security team
Live instructor-led classesQuarterly, for all staffNot usually includedOnly if someone builds them
Executive and board sessionIncludedNot usually includedRarely
Dark web credential monitoringIncludedA separate purchaseA separate purchase
Compliance and insurer reportingAutomated, monthlyReports you compileReports you compile
South African context (POPIA, FSCA, local lures)Built inVariesDepends on the team
Simulation credibilityExternal — staff can't spot itExternalStaff recognise their own IT team's tests

Regulatory compliance, evidenced

Regulators and auditors do not ask whether you intend to train staff; they ask you to show it. The programme produces that record as a by-product of running.

POPIA

Section 19 requires appropriate, reasonable organisational measures to protect personal information. Training records and monthly reports give your Information Officer something concrete to point to.

FSCA Joint Standard

Financial services firms must document how they manage cyber risk. Completion rates and simulation results form part of that documentation.

ISO/IEC 27001:2022

Annex A control 6.3 — information security awareness, education and training — expects training to be delivered and evidenced. The reports are that evidence for your ISMS.

GDPR

For organisations handling EU residents' data, the same records demonstrate staff are trained in their data-protection responsibilities.

Cyber insurance

Underwriters increasingly ask for proof of active awareness management with measurable outcomes: click-rate trends, completion records and credential monitoring.

Board governance

Directors carry governance obligations under POPIA and the Companies Act. The executive session covers what those mean in a world of AI-driven fraud.

Every month, automatically, you receive

  • Training completion rates
  • Phishing simulation click-rate trends
  • Remedial training assigned and completed
  • Improvement over time

Awareness training is one control within a compliance programme. It supports your obligations; on its own it does not make an organisation compliant.

Who it is for

Any organisation with employees — human risk is universal
Organisations looking to reduce cyber insurance premiums by demonstrating active controls
Companies with high email communication volume and phishing exposure
Organisations needing documented compliance evidence for POPIA or GDPR
C-suite and boards wanting to understand their personal risk from AI/deepfake exploitation
Organisations following a security breach or near-miss who need rapid culture improvement

Already running SMBsecure? It includes self-paced awareness training and phishing simulations. Cyber Risk Essentials adds the live classes, executive sessions and fully managed service on top.

Frequently asked questions

Is Cyber Risk Essentials the same as cyber awareness training?

Yes. Cyber Risk Essentials is the name of CRS's managed Cyber Awareness Programme. It is made up of three parts: instructor-led classes (quarterly, plus an Executive Lunch-and-Learn), randomised phishing simulations every 3–5 weeks, and monthly self-paced online training — with dark web credential monitoring and automated compliance reporting around them.

Can CRS tailor classes to our organisation, or cover a topic that isn't listed?

Yes. Classes are built around your requirement — your sector, your audience (all staff, a specific team, or executives and the board), your policies and recent incidents. New topics are brought in as threats change, and you can ask for a subject that is not on the list. Classes can be delivered on-site, virtually or in a hybrid format.

How much does cyber awareness training cost?

Pricing is quoted per organisation, based mainly on headcount and which parts of the programme you need. Request a proposal using the form on this page and a member of the CRS team will come back to you.

How often does CRS run phishing simulations?

Randomised phishing simulations are run every 3–5 weeks, ensuring employees cannot predict when they are being tested. Simulations use current threat templates relevant to South African conditions — including QR code phishing, Microsoft 365 login spoofing, CEO fraud, and SARS-themed lures. Employees who click automatically receive remedial training without requiring IT team intervention.

What does the Executive Lunch-and-Learn cover?

The Executive Lunch-and-Learn is a 90-minute facilitated session designed for C-suite executives, board members, and senior management. It covers AI-powered social engineering, deepfake voice and video fraud, vishing (voice phishing) targeting executives, boardroom governance obligations under POPIA and the Companies Act, and how executives can personally reduce their attack surface. The session is tailored to the organisation's sector and recent threat actor activity.

Does the programme generate documentation for POPIA and cyber insurance compliance?

Yes. The programme produces automated monthly compliance reports showing training completion rates, phishing click rate trends, remedial training assignments, and measurable improvement over time. These reports satisfy POPIA information officer requirements, FSCA documentation obligations, and cyber insurance underwriter evidence requirements for active security awareness management.

Can this programme help reduce cyber insurance premiums?

Many cyber insurers offer reduced premiums or improved policy terms for organisations that can demonstrate active, documented security awareness training with measurable outcomes. The Cyber Risk Essentials programme is specifically structured to generate the documentation insurers require — including click rate trend data, training completion records, and dark web credential monitoring evidence — supporting premium negotiation at renewal.

What does the dark web credential monitoring component provide?

CRS monitors dark web forums, combolists, paste sites, and infostealer marketplaces for employee credentials associated with your organisation's email domains. When compromised credentials are detected, affected employees and the security team are alerted — enabling password resets and account remediation before attackers exploit the exposure. This continuous monitoring component runs in the background between phishing simulation campaigns.

Plan your Cyber Awareness Programme

Tell us roughly how many people you have, who the classes are for and any topics you want covered. A member of the CRS team will come back with a proposal.

What are you looking for?

Your details

Which solution(s)?

Cyber Risk Essentials

When works for you?