Training  ·  people

93% of breaches
start with a click.

Phishing drills. POPIA training. AI tool adoption. Tabletop drills. Your team learns to spot, report, and respond before the real incident lands.

Hands-on. Your tools. Your scenarios. Sticky.

Try it yourself

Five red flags. Can you spot them?

A real-world CEO-fraud pattern. Click anything that looks wrong. Average untrained staff find 2. This is what the first day of training looks like.

inbox · unread
From: Sybrand de Kock <>Today, 16:42
To: Finance Team <[email protected]>

Finance team,

before close of business today. We're closing a contract that has to clear by tonight.

:

Beneficiary: NORTHFIELD HOLDINGS
Bank: First National Bank
Account: 6231 7847 2901
Amount: R 1,842,500.00
Reference: NFH-INV-0421

Please confirm by reply once processed. I'm in back-to-back meetings so don't call — just get it done.

Thanks.

Red flags found

0/5

Click anything that looks suspicious in the email. Hover to re-read what each one means.

How to play

Hover anywhere in the email — your cursor will turn into a pointer over a suspicious bit. Click to confirm. Found flags appear as numbered tiles above; click any tile to read what was wrong.

42%

Untrained staff click simulated phishing links

KnowBe4 Industry Benchmark, 2024

8%

Click rate after 3 months of monthly training

Imbertech engagement record

3%

Of untrained staff report suspicious emails to IT

KnowBe4, 2024

45%+

Report rate after training programme

Imbertech engagement record

What we teach

Six programmes, built around how people learn.

01

AWARENESS

Security Awareness

Realistic phishing simulations using your company branding. Custom scenarios based on attacks targeting your industry in SA right now.

02

POPIA

POPIA & Data Protection

Every department trained on personal-information handling, consent, and breach response. Plain language. Real examples from their daily tasks.

03

AI

AI & Automation Adoption

Hands-on training on the specific AI tools you've deployed. Prompt engineering, output verification, daily-workflow integration.

04

TOOLS

IT Skills Development

Training on your actual tools in your actual environment. People learn by doing the work they'll be doing tomorrow.

05

DRILLS

Incident Response Drills

Tabletop exercises simulating real incidents. Your team rehearses the response before they need it for real.

06

CUSTOM

Custom Programmes

Designed around your requirements, tech stack, and current skill level. One-off workshops or ongoing monthly sessions.

Formats

Pick the shape, we handle the rest.

3-4 hours

Half-Day Workshop

Best for: Security awareness, POPIA basics, tool-specific training

Presentation · live demos · hands-on exercises · take-home guide

Capacity: Up to 30

6-7 hours

Full-Day Intensive

Best for: System migrations, AI adoption, incident-response drills

Theory + extended practice + scenario exercises + Q&A

Capacity: Up to 20

2 hours/session, ongoing

Monthly Programme

Best for: Continuous security awareness, gradual AI adoption, skills growth

Monthly session + phishing simulations + progress tracking

Capacity: Flexible

Real scenarios we drill

Three attacks. All current.

The CEO fraud email

Your CFO receives an email from the CEO (spoofed) asking for an urgent wire transfer. 4:30pm Friday. Urgent tone. New bank details. Ten minutes to decide. We simulate the exact scenario and teach the verification steps that prevent an R2M mistake.

The helpful USB drive

Someone leaves a branded USB drive in your parking lot. Or your lobby. Staff find it, plug it in to see what's on it. We explain what a Rubber Ducky is, what happens in the 3 seconds after plug-in, and why curiosity is the most-exploited vulnerability.

The Teams message from 'IT'

Your staff get a Teams message from 'IT Support' asking them to verify credentials for a 'security update'. Looks legit. Company logo. Slightly misspelled domain. 30% of untrained staff fall for it. After training, they screenshot it and send it to real IT.

How a programme runs

Five stages, baseline to behaviour change.

01

Assess

Baseline assessments. Phishing simulations, knowledge tests, skills evaluations. We know where your team stands before we design anything. Every choice grounded in the data.

02

Design

Custom programme built around your tools, your workflows, your risk profile. Every exercise uses scenarios relevant to your industry and your systems.

03

Deliver

Hands-on sessions. On-site, remote, or hybrid. Your team learns by doing. Short theory, long practice.

04

Practise

Real exercises on your systems. Phishing simulations. Tabletops. Tool-specific tasks. We move on once people are confident.

05

Follow up

30-day adoption check. Click rates dropping? Tools being used daily? Training isn't done until behaviour changes. If it hasn't, we adjust and run another round.

Train your people.
Stop reading post-mortems.

Free baseline drill. We run a phishing simulation against your team, share the click rate, and quote a programme that fits the gap.