Topics inside this course
Awareness and induction depth — not an accredited occupational qualification.
- What counts: lost laptop, mis-sent mail, malware symptoms, successful tailgating, vendor rumours
- Report immediately; don’t wait to be sure
- After-hours contact tree
- Preserve evidence; don’t cover up
- No-blame reporting
Built for the people who take the training
All staff, including after-hours and remote workers who otherwise wait until Monday.
What learners leave able to do
- Recognise events that must be reported even if they might be nothing
- Report immediately through the named channel, including after hours
- Preserve evidence instead of wiping a device from embarrassment
- Expect no blame for honest reporting
Modules you can expect
Structure may tighten when you localise from your own source pack in Kre8AI — this is the shape of the library title.
- 1If it might be an incident, it is
Waiting is the failure.
- 2How to report
Channel, after hours, what to include.
- 3What to preserve
Don’t wipe, don’t delete the mail.
- 4Privacy breaches too
Mis-sent personal information is in scope.
- 5Knowledge check
Short scored assessment.
Short scored assessment designed to be memorable. Contact tree must be localised before mandatory rollout.
Written for the workplace, not for the statute book alone
Security programmes fail at reporting. People are sure it is nothing, or they are embarrassed, or they cannot find the number at 21:00. This short course is the reporting spine: what counts, how fast, who to tell, what not to destroy.
Examples stay ordinary: a laptop in an Uber, a payroll file to the wrong person, a ransom note, a stranger in the office, a supplier “we think we were hacked” mail. POPIA/GDPR overlap is named so privacy incidents don’t go to a different unofficial uncle.
Generate from your procedure, contact tree, and NCSC/CISA staff pages in Kre8AI. Never invent an after-hours number. Export as SCORM or HTML. Keep the coach off the assessment if you use it as evidence of awareness.
Every other security title in the library should point here instead of inventing a second reporting story. Re-export when the SOC mailbox or on-call path changes.
Pair with ransomware, phishing, and cybersecurity awareness. Measure success by faster reporting, not by a harsher quiz.
Play the library demo, or generate incident-reporting awareness from your contact tree in Kre8AI.
What you would upload in Kre8AI
Incident reporting procedure, contact tree
- Your incident reporting procedure and contact tree
- NCSC / CISA staff reporting guidance
- POPIA / GDPR breach escalation overlap at staff level
Formats, coach and provenance
- Standalone HTML to play in the browser; SCORM 2004 for your LMS.
- Optional AI course coach on Growth and Scale — grounded in approved material; off on quizzes and final assessment by default. Course plays offline; coach needs a network.
- Built in Kre8AI and reviewed before we published it. Not a substitute for your organisation's own policy — review before you make it mandatory.
Get the SCORM package while you are here.
Same course, SCORM 2004. Load it to settle the tracking question — and keep it as a course your people can take after you review it.
Request the package
SCORM 2004 zip. We ask for an email so we know which LMS you are testing — and so we can send the download.

