Cybersecurity Awareness
CISA
1 point
2 modules
This course can be customised to align with your organisation’s cybersecurity policy, information security rules, incident reporting process and data-handling procedures.
It is useful for organisations that need employees to recognise common cyber threats and understand the everyday behaviours that support safer information handling. It may be useful alongside POPIA in a Nutshell and other data privacy or information security awareness courses.
overview
Cyber risk is also a compliance issue
Cybersecurity threats keep changing. Employees may face phishing emails, fake login pages, malware, social engineering, suspicious links, unsafe attachments, compromised accounts, risky collaboration requests, mobile-device exposure or pressure to act quickly before checking.
The exact threat may change, but many of the useful employee habits stay more consistent: pause, verify, protect access, handle information carefully, question urgency and report concerns early.
This course helps employees understand how ordinary workplace behaviour can create or reduce cyber risk, without expecting them to become technical security specialists.
Cybersecurity awareness also supports wider legal and regulatory responsibilities. POPIA requires reasonable technical and organisational measures to protect personal information, and a security compromise may need to be reported to the Information Regulator and affected people. Joint Standard 2 of 2024 creates more direct cybersecurity training requirements for financial institutions within its scope.
The course
Connect cyber habits to compliance
The course introduces the basic concepts of cybersecurity, why cybersecurity matters, who is responsible for cybersecurity in the workplace, and the common threats employees may encounter.
It covers social engineering, phishing, malware, insider threats, relevant data protection laws, the South African Cybercrimes Act and practical rules for staying secure online and in the physical workplace.
The focus is on employee judgement: reporting concerns, using strong passwords, handling emails securely, collaborating safely, securing mobile devices and using the internet more carefully.
Scenario-based examples connect these risks and rules to the emails, devices, requests and information-handling decisions employees encounter at work.
Core idea
A suspicious email may become a compliance and reporting issue before anyone calls it a cyber incident.
Why it matters
Some organisations face direct training duties
For organisations that process personal information, POPIA requires reasonable technical and organisational safeguards. It also requires security compromises to be reported to the Information Regulator and affected people. The Regulator can investigate and take enforcement action.
Employees therefore need to recognise possible incidents and report them through the organisation’s process before important information is lost or delayed.
The Cybercrimes Act creates criminal offences for conduct such as unlawful access, interference and cyber fraud. It does not create a universal cybersecurity training duty for every employer.
Joint Standard 2 of 2024 is more direct. Financial institutions within its scope must maintain a comprehensive cybersecurity awareness programme for users, provide user refresher training at least annually, update content as risks evolve and provide training to the governing body.
This course supports this employee-awareness layer.
Build employee cybersecurity awareness around the compliance duties your organisation carries.
Cybersecurity training helps employees understand how everyday actions can affect information security, personal information protection and organisational risk. Employees may click links, open attachments, use passwords, share files, work on mobile devices, respond to urgent requests or handle sensitive information.
Training gives employees practical awareness of the cyber risk moments where they should pause, check, protect access or report a concern. It also supports the organisation’s wider security and data protection measures.
There is no single rule requiring every South African employer to provide the same cybersecurity training. The applicable requirements depend on the organisation, its sector and the information it handles.
POPIA requires organisations to take reasonable technical and organisational measures to protect personal information. Employees therefore need to understand secure information handling and when to report a possible security compromise.
More direct requirements apply in some regulated sectors. Joint Standard 2 of 2024 requires financial institutions within its scope to maintain a comprehensive cybersecurity awareness programme for all users. This course supports the employee-awareness layer, but it does not replace sector-specific legal or regulatory advice.
Many general cybersecurity courses focus mainly on personal cyber hygiene. This course places those everyday behaviours in a workplace compliance context.
It connects phishing, passwords, devices, email and incident reporting to organisational policies, the protection of personal information, the Cybercrimes Act and, where applicable, financial-sector cybersecurity requirements.
It remains employee awareness training rather than technical cybersecurity training.
No training can guarantee that cyber incidents will not happen. Cybersecurity depends on technical controls, policies, monitoring, governance, supplier management, incident response and employee behaviour. This course supports the employee-awareness layer by helping people recognise common cyber risk moments and practise safer information-handling habits.
The course can be customised to reflect your organisation’s approved cybersecurity policy, password requirements, reporting process, device-use rules, email security practices, internal contacts, terminology and relevant workplace scenarios. The standard course does not assume that these organisation-specific elements are already included.
For some South African financial institutions, cybersecurity awareness training is a direct regulatory requirement. Joint Standard 2 of 2024 requires institutions within its scope to maintain a comprehensive awareness programme for all users, provide user refresher training at least annually, add new content as risks evolve and provide training to the governing body.
This course can support the user-awareness requirement by helping employees recognise common cyber threats, protect access, handle information securely and report concerns. If it is intended for governing-body training, it should be customised to address governance-level cyber risk and resilience responsibilities. Financial institutions should still check the full scope of their sector-specific obligations.
e-learning library
Related courses
These employee awareness topics may also be relevant to your industry.
Fill in your details below to receive a quote.