We design and deliver customized security awareness programs including phishing simulations, interactive workshops, and online training — with Arabic content aligned with the Saudi work environment.
What's included
- Organization-wide awareness program covering all staff, from branch and call-center teams to head-office functions, delivered in Arabic and English.
- Role-based learning paths tailored to risk exposure: frontline staff, finance and payments, IT and privileged users, HR, and executives.
- Continuous phishing, smishing, and vishing simulation campaigns modeled on real lures targeting Saudi financial institutions, with safe just-in-time coaching for those who fall for them.
- Core curriculum: social engineering, password and MFA hygiene, safe handling of customer and personal data under the PDPL, secure remote work, and incident reporting.
- Behavioral measurement: phishing click and report rates, repeat-offender tracking, knowledge assessments, and a security-culture baseline and trend line.
- Reinforcement assets: microlearning, posters, newsletters, and onboarding modules that keep awareness live between formal sessions.
Methodology & standards
1. Baseline and human-risk assessment: run a covert phishing simulation and a knowledge survey to measure the current human-risk posture before any training.
2. Program design: build role-based content and an annual campaign calendar mapped to SAMA CSF and NCA ECC awareness requirements and PDPL obligations.
3. Delivery: roll out e-learning, live and recorded workshops, and recurring simulation campaigns with immediate, non-punitive coaching.
4. Measurement and reporting: track click and report rates, completion, and repeat offenders, and brief management on the trend.
5. Continuous improvement: raise difficulty over time, target weak segments, and refresh content against emerging threats.
Deliverables
- Human-risk baseline report with the initial phishing simulation results and a knowledge-gap analysis.
- Twelve-month awareness plan and campaign calendar aligned to your regulatory obligations.
- Arabic and English training content: e-learning modules, workshop decks, and microlearning assets.
- Phishing simulation platform configuration and per-campaign performance reports.
- Management dashboard and periodic reports showing behavior trends and repeat-offender remediation.
- Awareness evidence pack (attendance, completion, and simulation metrics) ready for SAMA, NCA, and internal audit.
Regulatory controls it satisfies
Typical timeline
Awareness is an annual program, not a one-off: the baseline and first campaign launch within two to three weeks, then simulations and training run on a continuous monthly and quarterly cadence.
Common questions
Is the content in Arabic?
Yes. All core content is authored in professional Arabic for the Saudi workplace, with English versions for mixed teams, rather than generic translated material.
How do you handle employees who repeatedly fail phishing tests?
The approach is supportive, not punitive. Repeat clickers receive targeted micro-coaching and progressively tailored simulations, and management sees the trend without individuals being publicly shamed.
From the same practice