South Africa

Staff training built for invoice fraud, SARS phishing, and POPIA

Thandiwe in accounts gets an email: a supplier has "updated their banking details," please use the new account for the next payment. Sipho gets an SMS claiming his parcel is held at a depot, pay a small fee to release it. Both are scams South African teams see constantly. We build training around that reality and map it openly to POPIA and the Cybercrimes Act.

Illustration representing security awareness training for organizations in South Africa
Regulatory drivers

Two laws are pushing staff training up the priority list

POPIA (Act 4 of 2013)

South Africa's data protection law requires responsible parties to implement appropriate, reasonable technical and organizational measures to secure personal information, overseen by the Information Regulator. We treat staff training as a measure that supports this obligation, not as a quoted legal requirement with a fixed cadence.

Cybercrimes Act (19 of 2020)

Creates offences for unauthorized access, data interference, and cyber fraud or forgery, with sections commencing in phases from December 2021. It is the legal backdrop for why phishing, invoice fraud, and vishing are prosecutable crimes - useful context for why staff should report attempts rather than quietly ignore them.

South Africa-specific modules

Fraud patterns taught as dedicated modules, not a generic deck

  • Invoice & BEC fraud - recognizing a "banking details have changed" email and why finance staff should always confirm by phone, using a number they already had.
  • SARS eFiling phishing - spotting fake SARS emails and SMS, especially around tax season, that link to a lookalike eFiling login page.
  • Fake courier & delivery SMS - never paying a "clearance fee" or entering card details through a link in a delivery text.
  • Vishing as a bank fraud department - recognizing callers who claim to be a bank's fraud team and pressure someone to read out an OTP or confirm a "suspicious transaction."
  • SIM-swap & port-out fraud - spotting a SIM swap in progress and protecting the mobile line tied to banking apps and OTPs.
See the full All-Staff Core track →

See the South Africa-specific modules in action

Book a free demo and we'll walk through the POPIA-aligned training for your sector.

Frequently asked questions

Does POPIA require staff cybersecurity training?

POPIA (the Protection of Personal Information Act, 4 of 2013) requires responsible parties to implement appropriate, reasonable technical and organizational measures to secure personal information, and the Information Regulator oversees compliance. We did not find a clause that sets an exact training frequency, so we describe training as supporting that security obligation rather than quoting a specific cadence as a legal requirement.

What does the Cybercrimes Act cover?

The Cybercrimes Act, 19 of 2020 creates offences for unauthorized access, data interference, and cyber fraud or forgery, and sets reporting duties for electronic communications service providers. Sections commenced in phases from December 2021; which specific sections apply to your organization is worth confirming with legal counsel rather than assuming from the Act's title alone.

What scams do South African staff actually report?

The pattern we hear about most: invoice fraud where a supplier's banking details are "updated" by email and the real payment is redirected, SARS eFiling phishing around tax season, fake courier or delivery SMS asking for a small "clearance fee," and vishing calls posing as a bank's fraud department asking someone to confirm an OTP.

Is this training only for financial services companies?

No. We built sector pages for financial services, healthcare, and retail/e-commerce, plus an All-Staff Core track that covers invoice fraud, SARS phishing, and courier-SMS scams for any South African organization, regardless of sector.