Kre8AI
Free course
15–25 min

Security incident reporting

When and how to report a suspected security incident — the spine every other security course should point to.

Duration
15–25 min
Format
HTML · SCORM 2004
Level
Awareness / induction
What it covers

Topics inside this course

Awareness and induction depth — not an accredited occupational qualification.

  • What counts: lost laptop, mis-sent mail, malware symptoms, successful tailgating, vendor rumours
  • Report immediately; don’t wait to be sure
  • After-hours contact tree
  • Preserve evidence; don’t cover up
  • No-blame reporting
Who it is for

Built for the people who take the training

All staff, including after-hours and remote workers who otherwise wait until Monday.

What learners leave able to do

  • Recognise events that must be reported even if they might be nothing
  • Report immediately through the named channel, including after hours
  • Preserve evidence instead of wiping a device from embarrassment
  • Expect no blame for honest reporting
Course outline

Modules you can expect

Structure may tighten when you localise from your own source pack in Kre8AI — this is the shape of the library title.

  1. 1
    If it might be an incident, it is

    Waiting is the failure.

  2. 2
    How to report

    Channel, after hours, what to include.

  3. 3
    What to preserve

    Don’t wipe, don’t delete the mail.

  4. 4
    Privacy breaches too

    Mis-sent personal information is in scope.

  5. 5
    Knowledge check

    Short scored assessment.

Short scored assessment designed to be memorable. Contact tree must be localised before mandatory rollout.

About this course

Written for the workplace, not for the statute book alone

Security programmes fail at reporting. People are sure it is nothing, or they are embarrassed, or they cannot find the number at 21:00. This short course is the reporting spine: what counts, how fast, who to tell, what not to destroy.

Examples stay ordinary: a laptop in an Uber, a payroll file to the wrong person, a ransom note, a stranger in the office, a supplier “we think we were hacked” mail. POPIA/GDPR overlap is named so privacy incidents don’t go to a different unofficial uncle.

Generate from your procedure, contact tree, and NCSC/CISA staff pages in Kre8AI. Never invent an after-hours number. Export as SCORM or HTML. Keep the coach off the assessment if you use it as evidence of awareness.

Every other security title in the library should point here instead of inventing a second reporting story. Re-export when the SOC mailbox or on-call path changes.

Pair with ransomware, phishing, and cybersecurity awareness. Measure success by faster reporting, not by a harsher quiz.

Play the library demo, or generate incident-reporting awareness from your contact tree in Kre8AI.

Typical source pack

What you would upload in Kre8AI

Incident reporting procedure, contact tree

  • Your incident reporting procedure and contact tree
  • NCSC / CISA staff reporting guidance
  • POPIA / GDPR breach escalation overlap at staff level
Delivery

Formats, coach and provenance

  • Standalone HTML to play in the browser; SCORM 2004 for your LMS.
  • Optional AI course coach on Growth and Scale — grounded in approved material; off on quizzes and final assessment by default. Course plays offline; coach needs a network.
  • Built in Kre8AI and reviewed before we published it. Not a substitute for your organisation's own policy — review before you make it mandatory.
For your LMS

Get the SCORM package while you are here.

Same course, SCORM 2004. Load it to settle the tracking question — and keep it as a course your people can take after you review it.

Request the package

SCORM 2004 zip. We ask for an email so we know which LMS you are testing — and so we can send the download.

We reply within one business day. No newsletter unless you ask for one.

Now imagine that, built from your policy.

Start a free trial, upload your policy, and kre8 your first course in minutes.