Security awareness training built for teams moving fast on customer money
Kenyan fintechs onboard customers through an app, move money in seconds, and carry a support team that fraudsters specifically target - because a convincing call to customer support can unlock an account faster than hacking it. Engineering, support, and operations staff all need training that matches that pressure.
What fintech staff actually face
- Account-takeover attempts where a fraudster calls support pretending to be a locked-out customer, pushing for a PIN reset or account unlock without proper verification.
- SIM-swap fraud used to intercept OTPs for account access or password resets, often followed by a rapid cash-out.
- Fake "KYC verification" or "compliance review" emails targeting staff with access to customer onboarding documents.
- Phishing targeting engineering and DevOps staff with access to production systems or customer data stores.
- Social engineering calls impersonating a partner bank, Safaricom, or a regulator, pressuring staff to share integration credentials or customer data.
The Data Protection Act and Computer Misuse and Cybercrimes Act
Fintechs handle customer financial data covered by Kenya's Data Protection Act, and operate in a sector the Computer Misuse and Cybercrimes Act is specifically built to address. We map modules openly to both and recommend confirming current guidance with your compliance team or CBK/CMA liaison before citing a specific clause.
See Kenya's regulatory drivers →Frequently asked questions
Does this training satisfy a specific CBK or CMA licensing requirement?
We do not claim it satisfies a specific licensing clause. It is built to support the staff-awareness intent behind Kenya's Data Protection Act, and we recommend confirming any licence-specific security requirement directly with your regulator.
What is the single most common way fintechs lose customer accounts to fraud?
A convincing call to customer support, combined with a SIM-swap or spoofed caller ID, used to push through an account unlock or PIN reset without real verification. The fix is procedural: support staff need a verification process they follow even under pressure.
Can this training fit into a fast-moving engineering culture?
Yes. Modules are 3-7 minutes each, built to be assigned asynchronously without requiring a scheduled training session that pulls a whole team off sprint work.