Financial Services

Security awareness training built around how South African financial fraud actually works

Banks, insurers, and asset managers carry the heaviest regulatory expectation for staff cybersecurity awareness in South Africa, and the fraud is specific: invoice redirection, vishing calls posing as the fraud department, and phishing timed around SARS deadlines. Frontline, operations, and finance staff all need training that matches it.

What financial services staff actually face

  • Invoice and BEC (business email compromise) fraud - an email claiming a client or supplier's banking details have changed, timed around a real payment run.
  • Vishing calls impersonating the bank's own fraud department, pressuring a customer or staff member to confirm an OTP "to stop a suspicious transaction."
  • SARS eFiling phishing emails and SMS, especially around provisional and annual tax deadlines, linking to a lookalike login page.
  • SIM-swap and port-out fraud targeting both clients and staff whose mobile line is tied to internal MFA or client-facing banking apps.
  • Social engineering aimed at call-centre and operations staff who have standing access to client account and policy data.

POPIA and the Cybercrimes Act

POPIA and the Cybercrimes Act both point toward appropriate security measures and make this kind of fraud a prosecutable crime, which staff training commonly supports. We map modules openly to both and recommend you verify current FSCA or Information Regulator guidance with your compliance team before citing a specific clause to an examiner.

See South Africa's regulatory drivers →

Ready to see this training in action?

Book a free demo and we'll show you the exact modules your team would complete.

Frequently asked questions

Does this training satisfy FSCA or Information Regulator expectations?

It is built to support the staff-awareness intent behind POPIA and the Cybercrimes Act. We recommend confirming current FSCA or Information Regulator guidance with your compliance team before representing this as satisfying a specific requirement.

Can call-centre and claims staff get a shorter, role-specific version?

Yes. All-Staff Core covers the shared fraud patterns (invoice fraud, vishing, SARS phishing) in short modules, and the Financial Services Add-On layers on frontline-specific content without repeating the basics.

How do you handle sensitive financial scenarios in training without real client data?

All fraud scenarios use fictional names, accounts, and policy numbers. No real client data, logos, or live links are used in simulations.