news

From 1 July 2026 Metrofile Cloud is back to IronTree. Same team. Same service. A name we’ve originally built and have carried with pride for over 20 years.

Your people are your biggest security risk. Let’s fix that.

Most cyberattacks don’t break through firewalls – they walk through the front door because someone clicked the wrong link. Security Awareness Training (SAT) turns your team from your biggest vulnerability into your strongest line of defence.

Your antivirus protects your devices. Nothing is protecting the people using them.

If you run IT for a South African business, you’ve probably already done the hard work: endpoint protection, mail filtering, MFA, backups. Those controls stop the overwhelming majority of what comes at you quietly, day in, day out.

They were never built to stop the last step.

95% of South African data breaches involve a human element, not an unpatched server or a software vulnerability. Someone clicked a link that arrived in a convincing email. Someone shared a password over the phone with someone who sounded like IT. Someone approved a payment request that looked like it came from the MD. A person, acting in good faith, doing something that looked reasonable at the time.

The median time between a phishing email being opened and the link being clicked is 21 seconds. No filter, no alert, and no analyst gets there first. By the time anything in your security stack knows there’s a problem, the decision has already been made.

There’s a difference between a security tool and a security culture. A tool makes a decision on someone’s behalf. A culture changes the decision they make.

Security Awareness Training closes the gap that technology cannot. It’s the layer that makes every other control in your environment work harder.

95%

of South African data breaches involve a human element – not a system failure.

Source: CSIR, 2024

1 in 3

untrained employees clicks a phishing link. After 12 months of SAT: fewer than 1 in 20.

Source: KnowBe4 2025, 67.7M simulations

86%

reduction in phishing susceptibility after 12 months of continuous Security Awareness Training.

Source: KnowBe4 Phishing by Industry Benchmarking Report 2025

Why a once-a-year training session isn’t enough

Most staff have experienced the compliance version of security training: a once-a-year video, a tick-box quiz, and nothing again until next year. Meanwhile attackers update their tactics weekly. Annual training simply cannot keep up and employees forget most of it within days. 

What actually changes behaviour is short, continuous training combined with realistic phishing simulations that test whether the learning is sticking. The 86% reduction in phishing susceptibility comes from 12 months of ongoing training, not a single session. Results start showing within three months.

Why most programmes quietly die

Setting up campaigns, chasing completions, building simulations, and pulling reports adds up to 3-5 hours of admin every month – and admin is usually the first thing to fall off an already-stretched IT lead’s list. Most SAT programmes don’t fail because the content is poor, but rather because nobody has time to run them consistently.

That’s exactly why IronTree’s fully managed option exists.

Two ways to get started

Same platform. Same training library. Same phishing simulation engine. Same compliance documentation. The difference is how much of the heavy lifting we do for you. 

SELF-MANAGED

You’re in the driver’s seat.

SAT Essentials

We set you up, show you the ropes, and you run the programme your way.

Best for: Self-sufficient teams of 5–50 people who have some internal IT or HR capacity and want to keep costs lean.

FULLY MANAGED

We run the whole programme for you.

SAT Complete

You focus on your business – we make sure your team stays sharp.

Best for: Regulated industries or teams of 10+ who don’t have the internal capacity (or appetite) to manage a security programme themselves.

Most businesses that try to run SAT themselves give up within months. Not because the tool doesn’t work – because nobody has time to run it. SAT Complete removes that problem entirely.

Both plans are month-to-month and per-user – so you only pay for what you need.

What the programme covers

Short lessons, real habits, ongoing protection. Delivered in bite-sized modules.

Monthly training modules

Short video lessons and quizzes that fit into a normal working day. No all-day workshops, no death by PowerPoint. Content is role-based and updated regularly to reflect the current threat landscape – so your staff are always being trained on what’s actually happening, not what was common two years ago.

Real phishing simulations

IronTree sends your team realistic fake phishing emails to see who takes the bait – and then uses those moments as immediate teaching opportunities. The staff member who clicked learns exactly what to look for next time. This is the single most effective technique for changing behaviour.

Clear reporting

See who has completed training, who clicked on a simulation, and how your team’s phishing susceptibility is improving over time. That data is also exactly what POPIA regulators and cyber insurers increasingly ask to see as evidence of an active, ongoing training programme.

Compliance-ready documentation

Certificates, audit trails, and completion records are generated automatically. When a regulator, auditor, or insurer asks for evidence of your security training programme, it’s already there.

This is no longer just a security decision

Until relatively recently, security awareness training was something businesses knew they probably should get around to doing sometime soon. The reason for the shift has to do with more than just threat statistics.

POPIA

POPIA Section 19 requires responsible parties to take appropriate, reasonable technical and organisational measures to protect personal information. Organisational measures include staff training. A well-written policy that nobody has actually been trained on does not demonstrate reasonable steps – and ‘we did not know’ has never been a defence.

Financial sector: mandatory since June 2025

FSCA/PA Joint Standard 2 of 2024 (effective 1 June 2025) requires all financial institutions to conduct a comprehensive cybersecurity awareness training programme at least annually, covering all users and the governing body. For financial sector businesses, this is a regulatory requirement, not a recommendation.

Cyber insurers have significantly tightened their underwriting requirements. Documented training programmes, phishing simulation completion logs, and measurable risk reduction now appear routinely on underwriting questionnaires. A business without documented training may face higher premiums, reduced cover, or a disputed claim at exactly the wrong moment.

Enterprise procurement teams are pushing supply chain security requirements down to their smaller suppliers. RFPs increasingly include a security questionnaire. If you sell into large organisations, a documented SAT programme is increasingly something you answer for before the commercial conversation even starts.

POPIA requires:

Cyber insurers increasingly ask for:

Not sure where your business stands? Start here.

FREE ASSESSMENT

Phishing Risk Score

Find out how exposed your business currently is to phishing attacks. 12 questions, 5 minutes, personalised score and recommendations. No obligation.

FREE DOWNLOAD

Phishing Cost Guide

The financial, compliance, and insurance case for Security Awareness Training on a single page. Share it with your CFO or MD.

Go deeper

ITWeb

Your staff clicked the link. Now what?

The difference between a security tool and a security culture – and why that distinction changes everything about how you approach the human layer of security.

MyBroadband

The weakest link in your company’s security is not your firewall

Why the layer getting the least attention is the one attackers target most – and what South African businesses need to do about it.

Tech4Law

Why Business Email Compromise keeps landing on law firms

How social engineering targets professional services firms specifically – and why awareness training is the only effective defence.

Ready to find out where your team stands?

Tell us about your business – how many staff you have, what industry you’re in, and what your biggest security concerns are. We’ll recommend the right option and put together a quote. No jargon, no obligation – just a straightforward conversation.

Get in touch

We're here when you need us

A real, human team in South Africa that knows your setup and picks up the phone. Call us or drop us a message and we’ll get back to you – usually the same day.

Phone

087 943 2278

Address

Unit 1 Westlake Square, Westlake, Cape Town

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
This field is hidden when viewing the form