Your people are your biggest security risk. Let’s fix that.
Most cyberattacks don’t break through firewalls – they walk through the front door because someone clicked the wrong link. Security Awareness Training (SAT) turns your team from your biggest vulnerability into your strongest line of defence.
- Reduces phishing click rates by 86% after 12 months
- Fully managed option – IronTree runs the entire programme for you
- Monthly training + real phishing simulations
- Compliance-ready documentation for POPIA and cyber insurers
Your antivirus protects your devices. Nothing is protecting the people using them.
If you run IT for a South African business, you’ve probably already done the hard work: endpoint protection, mail filtering, MFA, backups. Those controls stop the overwhelming majority of what comes at you quietly, day in, day out.
They were never built to stop the last step.
95% of South African data breaches involve a human element, not an unpatched server or a software vulnerability. Someone clicked a link that arrived in a convincing email. Someone shared a password over the phone with someone who sounded like IT. Someone approved a payment request that looked like it came from the MD. A person, acting in good faith, doing something that looked reasonable at the time.
The median time between a phishing email being opened and the link being clicked is 21 seconds. No filter, no alert, and no analyst gets there first. By the time anything in your security stack knows there’s a problem, the decision has already been made.
There’s a difference between a security tool and a security culture. A tool makes a decision on someone’s behalf. A culture changes the decision they make.
Security Awareness Training closes the gap that technology cannot. It’s the layer that makes every other control in your environment work harder.
95%
of South African data breaches involve a human element – not a system failure.
Source: CSIR, 2024
1 in 3
untrained employees clicks a phishing link. After 12 months of SAT: fewer than 1 in 20.
Source: KnowBe4 2025, 67.7M simulations
86%
reduction in phishing susceptibility after 12 months of continuous Security Awareness Training.
Source: KnowBe4 Phishing by Industry Benchmarking Report 2025
Why a once-a-year training session isn’t enough
Most staff have experienced the compliance version of security training: a once-a-year video, a tick-box quiz, and nothing again until next year. Meanwhile attackers update their tactics weekly. Annual training simply cannot keep up – and employees forget most of it within days.
What actually changes behaviour is short, continuous training combined with realistic phishing simulations that test whether the learning is sticking. The 86% reduction in phishing susceptibility comes from 12 months of ongoing training, not a single session. Results start showing within three months.
Why most programmes quietly die
Setting up campaigns, chasing completions, building simulations, and pulling reports adds up to 3-5 hours of admin every month – and admin is usually the first thing to fall off an already-stretched IT lead’s list. Most SAT programmes don’t fail because the content is poor, but rather because nobody has time to run them consistently.
That’s exactly why IronTree’s fully managed option exists.
Two ways to get started
Same platform. Same training library. Same phishing simulation engine. Same compliance documentation. The difference is how much of the heavy lifting we do for you.
SELF-MANAGED
You’re in the driver’s seat.
SAT Essentials
We set you up, show you the ropes, and you run the programme your way.
Best for: Self-sufficient teams of 5–50 people who have some internal IT or HR capacity and want to keep costs lean.
- We handle setup – platform configured, users imported, ready to go
- Full training library – pick and schedule campaigns from our content catalogue
- Phishing simulations – run them yourself whenever you need to test the team
- Dashboard & reporting – full visibility into who’s trained and how they’re doing
- Compliance docs – generate your own certificates and evidence as needed
- Email support – we’re here if something breaks
FULLY MANAGED
We run the whole programme for you.
SAT Complete
You focus on your business – we make sure your team stays sharp.
Best for: Regulated industries or teams of 10+ who don’t have the internal capacity (or appetite) to manage a security programme themselves.
- Full setup & configuration – we handle everything from day one, including ongoing user management
- Monthly campaigns, designed for you – we build and run your training programme every month
- Monthly phishing simulations – we create and launch them; you see the results
- Monthly executive reports + quarterly reviews – clear visibility without the spreadsheet-diving
- Compliance support – certificates, audit evidence, and documentation handled for you
- Dedicated Account Manager – one person who knows your business and your programme
- 4-hour support SLA
Most businesses that try to run SAT themselves give up within months. Not because the tool doesn’t work – because nobody has time to run it. SAT Complete removes that problem entirely.
Both plans are month-to-month and per-user – so you only pay for what you need.
What the programme covers
Short lessons, real habits, ongoing protection. Delivered in bite-sized modules.
Monthly training modules
Short video lessons and quizzes that fit into a normal working day. No all-day workshops, no death by PowerPoint. Content is role-based and updated regularly to reflect the current threat landscape – so your staff are always being trained on what’s actually happening, not what was common two years ago.
Real phishing simulations
IronTree sends your team realistic fake phishing emails to see who takes the bait – and then uses those moments as immediate teaching opportunities. The staff member who clicked learns exactly what to look for next time. This is the single most effective technique for changing behaviour.
Clear reporting
See who has completed training, who clicked on a simulation, and how your team’s phishing susceptibility is improving over time. That data is also exactly what POPIA regulators and cyber insurers increasingly ask to see as evidence of an active, ongoing training programme.
Compliance-ready documentation
Certificates, audit trails, and completion records are generated automatically. When a regulator, auditor, or insurer asks for evidence of your security training programme, it’s already there.
This is no longer just a security decision
Until relatively recently, security awareness training was something businesses knew they probably should get around to doing sometime soon. The reason for the shift has to do with more than just threat statistics.
POPIA
POPIA Section 19 requires responsible parties to take appropriate, reasonable technical and organisational measures to protect personal information. Organisational measures include staff training. A well-written policy that nobody has actually been trained on does not demonstrate reasonable steps – and ‘we did not know’ has never been a defence.
Financial sector: mandatory since June 2025
FSCA/PA Joint Standard 2 of 2024 (effective 1 June 2025) requires all financial institutions to conduct a comprehensive cybersecurity awareness training programme at least annually, covering all users and the governing body. For financial sector businesses, this is a regulatory requirement, not a recommendation.
Cyber insurance
Cyber insurers have significantly tightened their underwriting requirements. Documented training programmes, phishing simulation completion logs, and measurable risk reduction now appear routinely on underwriting questionnaires. A business without documented training may face higher premiums, reduced cover, or a disputed claim at exactly the wrong moment.
Enterprise procurement and supply chain
Enterprise procurement teams are pushing supply chain security requirements down to their smaller suppliers. RFPs increasingly include a security questionnaire. If you sell into large organisations, a documented SAT programme is increasingly something you answer for before the commercial conversation even starts.
POPIA requires:
- ‘Appropriate technical and organisational measures’ to protect personal data
- Staff training on data handling and breach escalation
- Documented incident response capability
- Proportionate protection across the whole organisation
Cyber insurers increasingly ask for:
- Documented SAT programme
- Phishing simulation completion logs
- Evidence of ongoing training – not a once-a-year session
- Measurable risk reduction over time
Not sure where your business stands? Start here.
FREE ASSESSMENT
Phishing Risk Score
Find out how exposed your business currently is to phishing attacks. 12 questions, 5 minutes, personalised score and recommendations. No obligation.
FREE DOWNLOAD
Phishing Cost Guide
The financial, compliance, and insurance case for Security Awareness Training on a single page. Share it with your CFO or MD.
Go deeper
Your staff clicked the link. Now what?
The difference between a security tool and a security culture – and why that distinction changes everything about how you approach the human layer of security.
The weakest link in your company’s security is not your firewall
Why the layer getting the least attention is the one attackers target most – and what South African businesses need to do about it.
Why Business Email Compromise keeps landing on law firms
How social engineering targets professional services firms specifically – and why awareness training is the only effective defence.
Ready to find out where your team stands?
Tell us about your business – how many staff you have, what industry you’re in, and what your biggest security concerns are. We’ll recommend the right option and put together a quote. No jargon, no obligation – just a straightforward conversation.
Get in touch
We're here when you need us
A real, human team in South Africa that knows your setup and picks up the phone. Call us or drop us a message and we’ll get back to you – usually the same day.
Phone
087 943 2278
Address
Unit 1 Westlake Square, Westlake, Cape Town
"*" indicates required fields