Generic phishing training teaches people to spot generic phishing.
Off-the-shelf security awareness is cheap and everyone hates it, mostly because it describes attacks that do not resemble the ones your staff actually receive. The material that would make it relevant already exists in your incident reports and your own procedures.
Why this particular course is painful
The library course is about someone else's company
Threats change faster than annual training
Your security team are not instructional designers
How Kre8AI handles it
Scenarios built from incidents that actually happened to you
Turn a new threat into a course in a day
Use your security team's recordings, not their calendar
The rules you are actually training against
We are not lawyers and this is not legal advice. Check your obligations with someone who is.
POPIA and breach notification
Section 22 obliges you to notify the Information Regulator and affected data subjects of a compromise. Staff need to recognise and escalate an incident quickly enough for you to meet that obligation, which is a training problem before it is a process problem.
Your own security policy
Awareness training should teach your acceptable use, your escalation path and your reporting channel. Building from your policy means the course tells people what to do in your organisation rather than in general.
Cyber insurance and client due diligence
Insurers and enterprise clients increasingly ask for evidence of a security awareness programme. Completion data reports to your LMS, and the authoring record shows what was covered.
Distributed and multi-site workforces
Where staff are spread across sites with uneven connectivity, the standalone HTML export runs without an LMS connection, which removes an argument for skipping the training.
Questions we get about this
Can Kre8AI run simulated phishing campaigns?
Is it safe to upload incident reports?
How short can a course be?
Can we produce it in more than one language?
This page was last reviewed for accuracy in July 2026. If anything here about another product is out of date or unfair, tell us and we will correct it.
Build this course first.
Bring the policy document to a 30-minute scoping call. We will tell you honestly what Kre8AI would produce from it.
Other use cases: compliance training, security awareness, onboarding.
