Kre8AI
Use case

Generic phishing training teaches people to spot generic phishing.

Off-the-shelf security awareness is cheap and everyone hates it, mostly because it describes attacks that do not resemble the ones your staff actually receive. The material that would make it relevant already exists in your incident reports and your own procedures.

The problem

Why this particular course is painful

The library course is about someone else's company

Stock awareness content uses invented scenarios with invented systems. Staff complete it, learn nothing transferable, and the click rate does not move.

Threats change faster than annual training

A new attack pattern hits your organisation in April and the next training refresh is in November. The gap is where the incidents happen.

Your security team are not instructional designers

The people who understand the threat are the least available to build a course about it, and the handover between security and L&D loses most of the specificity that made it useful.
What changes

How Kre8AI handles it

Scenarios built from incidents that actually happened to you

Upload your incident write-ups and procedures. Branching scenarios generate from them, so the learner practises against the attack pattern your organisation genuinely sees.

Turn a new threat into a course in a day

When something new lands, the source material is usually already written: the advisory, the internal note, the post-incident review. Generating a short course from it is an afternoon, not a quarter.

Use your security team's recordings, not their calendar

Record a fifteen-minute conversation with the person who understands the threat. Kre8AI transcribes it and builds from it, which costs them a quarter of an hour rather than a fortnight.
South African context

The rules you are actually training against

We are not lawyers and this is not legal advice. Check your obligations with someone who is.

POPIA and breach notification

Section 22 obliges you to notify the Information Regulator and affected data subjects of a compromise. Staff need to recognise and escalate an incident quickly enough for you to meet that obligation, which is a training problem before it is a process problem.

Your own security policy

Awareness training should teach your acceptable use, your escalation path and your reporting channel. Building from your policy means the course tells people what to do in your organisation rather than in general.

Cyber insurance and client due diligence

Insurers and enterprise clients increasingly ask for evidence of a security awareness programme. Completion data reports to your LMS, and the authoring record shows what was covered.

Distributed and multi-site workforces

Where staff are spread across sites with uneven connectivity, the standalone HTML export runs without an LMS connection, which removes an argument for skipping the training.

Straight answers

Questions we get about this

Can Kre8AI run simulated phishing campaigns?
No. Kre8AI builds the training; it is not a phishing simulation platform. If you run simulations, the results are a good source document for the course.
Is it safe to upload incident reports?
Read our security page before you decide, and redact anything you would not want processed outside your organisation.
How short can a course be?
Short. A single-module refresher built from one advisory is a legitimate use, and often a better one than an annual monolith nobody finishes.
Can we produce it in more than one language?
Yes. Translate a course into another language from the authoring interface, with narration regenerated in the target locale. Ask us on the scoping call which languages matter to you and we will be specific about voice coverage.

This page was last reviewed for accuracy in July 2026. If anything here about another product is out of date or unfair, tell us and we will correct it.

Build this course first.

Bring the policy document to a 30-minute scoping call. We will tell you honestly what Kre8AI would produce from it.

Other use cases: compliance training, security awareness, onboarding.