Training built on how fraud actually reaches African teams
Mobile money and POS fraud, BVN and OTP scams, SIM-swap attacks, and a WhatsApp message that looks like it came from the MD. We build each country page around the fraud pattern and the regulator your team already answers to, starting with a full Nigeria build-out.

Where we've built a full training program
Nigeria
Full sector build-out: NDPA, CBN, banks, fintechs, insurance, pensions, telcos.
View training →Ghana
Data Protection Act 2012 + Bank of Ghana cyber directives - sector pages in progress.
Kenya
Data Protection Act 2019 + CBK guidance - sector pages in progress.
South Africa
POPIA + SARB/PASA guidance - sector pages in progress.
The fraud playbook repeats, even where the law is different
- Lagos
- Accra
- Nairobi
- Kampala
- Johannesburg
- Cairo
Illustrative - represents the kind of phishing signal pattern a simulation program surfaces across a distributed team, not live attack data.
Frequently asked questions
Do you only cover Nigeria?
Nigeria is the only African market with a full sector build-out today: NDPA and CBN-mapped training across banking, fintech, insurance, pensions, and telecoms. Ghana, Kenya, and South Africa are next on the roadmap. We would rather tell you that plainly than publish a thin page with no real content behind it.
What do African organizations actually get phished with?
The patterns we see most across the continent: mobile money and POS "wrong transfer, refund it" scams, BVN/NIN/OTP requests from someone claiming to be the bank, SIM-swap attacks used to intercept one-time passcodes, and WhatsApp messages impersonating a managing director asking for an urgent transfer.
Is this training only relevant under Nigerian law?
No. The fraud patterns (mobile money fraud, SIM-swap, impersonation) show up across African markets even where we have not yet built dedicated sector pages. The All-Staff Core track covers the shared ground; Nigeria-specific modules go deeper where we have confirmed the regulatory detail.