Topics inside this course
Awareness and induction depth — not an accredited occupational qualification.
- Email, voice and messaging social engineering patterns
- Urgency, authority and payment diversion tactics
- Second-channel verification before acting
- How to report without fear of looking foolish
- Finance and HR high-risk request scenarios
Built for the people who take the training
Anyone with an email inbox or messaging app used for work: staff, executives, finance, and frontline teams.
What learners leave able to do
- Recognise common phishing and vishing patterns
- Pause before clicking, transferring funds, or sharing credentials
- Verify unusual requests through a second channel
- Report suspected messages without blame
Modules you can expect
Structure may tighten when you localise from your own source pack in Kre8AI — this is the shape of the library title.
- 1What phishing looks like now
Beyond the obvious bad spelling.
- 2Voice and chat attacks
Vishing and collaboration-tool impostors.
- 3Money and data requests
CEO fraud, vendor invoices, payroll changes.
- 4Verify before you act
Second channels your organisation already has.
- 5Report it
Who to tell and what to preserve.
- 6Knowledge check
Short assessment for mandatory annual training.
Short scored assessment designed for annual mandatory assignment.
Written for the workplace, not for the statute book alone
Phishing training fails when it is a quiz of trick screenshots with no link to how your organisation actually verifies a CEO request or a vendor invoice. This course centres on judgement: what looks off, who to call, and how to report without fear of looking foolish.
Social engineering is not only email. Voice calls, instant messages, and fake collaboration invites sit beside classic phishing. Finance and HR get extra attention because payment diversion and payroll diversion still succeed when urgency overrides process.
Keep it short enough for annual mandatory training. Extend it with your own redacted examples once you generate the draft in Kre8AI from your playbook. That is how learners recognise the tone and logos attackers already copy from you.
Export to your LMS as SCORM, or run as HTML. Enable the AI coach if you want learners to ask clarifying questions about the approved material after the lesson — not during assessments unless you choose that. The course plays offline; the coach needs a network.
Pair this module with a wider cybersecurity awareness course if you want depth on passwords and devices, or keep it as a short standalone assignment after a live phishing simulation. Either way, the goal is fewer successful clicks and faster reporting — not a perfect score on a puzzle. Measure success by report volume quality, not by how hard the quiz was.
Play it free in the browser; SCORM download stays behind the form on this page. To publish the same topic under your brand, generate a phishing module from your own incident samples in Kre8AI.
What you would upload in Kre8AI
Phishing playbook, redacted samples, verification procedures
- Security awareness policy / phishing response playbook
- Examples of real (redacted) phishing attempts against your organisation
- Finance and HR verification procedures for payment and data requests
Formats, coach and provenance
- Standalone HTML to play in the browser; SCORM 2004 for your LMS.
- Optional AI course coach on Growth and Scale — grounded in approved material; off on quizzes and final assessment by default. Course plays offline; coach needs a network.
- Built in Kre8AI and reviewed before we published it. Not a substitute for your organisation's own policy — review before you make it mandatory.
Get the SCORM package while you are here.
Same course, SCORM 2004. Load it to settle the tracking question — and keep it as a course your people can take after you review it.
Request the package
SCORM 2004 zip. We ask for an email so we know which LMS you are testing — and so we can send the download.

