Topics inside this course
Awareness and induction depth — not an accredited occupational qualification.
- Phishing, malware and social engineering in everyday tools
- Passwords, MFA and device hygiene habits
- Safe sharing of data and credentials
- How and when to report a suspected incident
- Why one-off exceptions create organisation-wide risk
Built for the people who take the training
All staff, including remote and hybrid workers, contractors with system access, and managers who approve access or spend.
What learners leave able to do
- Spot common threats: phishing, malware, weak authentication and social engineering
- Use passwords, MFA and device hygiene as everyday habits
- Report incidents through your organisation’s channel without delay
- Understand why “just this once” exceptions create risk for everyone
Modules you can expect
Structure may tighten when you localise from your own source pack in Kre8AI — this is the shape of the library title.
- 1The threats you will actually meet
Messages, links, attachments and impostors.
- 2Authentication that holds
Passwords, MFA and session hygiene.
- 3Devices and places of work
Laptops, phones, home networks and clean desks.
- 4Sharing and exceptions
When “just this once” becomes an incident.
- 5Report without delay
Channels, urgency and no-blame reporting.
- 6Knowledge check
Short scored assessment for induction records.
Scored knowledge check suitable for annual refresher records. Coach stays off assessments by default.
Written for the workplace, not for the statute book alone
Cybersecurity awareness only works when it is short enough to assign, specific enough to change behaviour, and honest about what the organisation already expects. This course covers the threats most learners will actually meet: suspicious messages, unsafe links and attachments, credential reuse, unattended devices, and sharing data with the wrong person or the wrong tool.
It is written for induction and annual refreshers. It is not a technical hardening course for IT teams, and it does not replace privileged-access or developer security training. Pair it with your own policies so examples match your email client, your MFA product, and your real reporting path — including after hours.
Managers get the same behavioural expectations as everyone else, plus a reminder that approving exceptions without a ticket is how shadow IT and shared passwords survive. Contractors with system access are in scope because attackers do not distinguish between payroll and a temporary login.
When you build the package in Kre8AI from your source pack, every claim can stay cited to those documents. Publish as SCORM or HTML. The optional learner coach — available on Growth and Scale — answers from the approved course and sources, not from unrestricted model knowledge. Keep the coach off assessments by default so checks stay fair.
Organisations that already run annual security campaigns can treat this as the reusable core: same outcomes every year, refreshed examples from your own incident queue. That is cheaper than rewriting a Storyline deck each time the threat landscape shifts, and it keeps the evidence trail reviewers expect.
Play the course in the browser, or take the SCORM package into your LMS after a short form. To ship the same topic under your brand, start a trial and generate it from your own security policies.
What you would upload in Kre8AI
InfoSec policy, acceptable use, incident reporting
- Your information security policy and acceptable use policy
- Incident reporting procedure
- Sector guidance (e.g. ISO 27001 awareness extracts, NCSC or local CERT tips)
Formats, coach and provenance
- Standalone HTML to play in the browser; SCORM 2004 for your LMS.
- Optional AI course coach on Growth and Scale — grounded in approved material; off on quizzes and final assessment by default. Course plays offline; coach needs a network.
- Built in Kre8AI and reviewed before we published it. Not a substitute for your organisation's own policy — review before you make it mandatory.
Get the SCORM package while you are here.
Same course, SCORM 2004. Load it to settle the tracking question — and keep it as a course your people can take after you review it.
Request the package
SCORM 2004 zip. We ask for an email so we know which LMS you are testing — and so we can send the download.

