Awareness & Training

Security Awareness Training

Security awareness and training programs that transform your employees from the weakest link to an effective first line of defense

We design and deliver customized security awareness programs including phishing simulations, interactive workshops, and online training — with Arabic content aligned with the Saudi work environment.

What's included

  • Organization-wide awareness program covering all staff, from branch and call-center teams to head-office functions, delivered in Arabic and English.
  • Role-based learning paths tailored to risk exposure: frontline staff, finance and payments, IT and privileged users, HR, and executives.
  • Continuous phishing, smishing, and vishing simulation campaigns modeled on real lures targeting Saudi financial institutions, with safe just-in-time coaching for those who fall for them.
  • Core curriculum: social engineering, password and MFA hygiene, safe handling of customer and personal data under the PDPL, secure remote work, and incident reporting.
  • Behavioral measurement: phishing click and report rates, repeat-offender tracking, knowledge assessments, and a security-culture baseline and trend line.
  • Reinforcement assets: microlearning, posters, newsletters, and onboarding modules that keep awareness live between formal sessions.

Methodology & standards

01

1. Baseline and human-risk assessment: run a covert phishing simulation and a knowledge survey to measure the current human-risk posture before any training.

02

2. Program design: build role-based content and an annual campaign calendar mapped to SAMA CSF and NCA ECC awareness requirements and PDPL obligations.

03

3. Delivery: roll out e-learning, live and recorded workshops, and recurring simulation campaigns with immediate, non-punitive coaching.

04

4. Measurement and reporting: track click and report rates, completion, and repeat offenders, and brief management on the trend.

05

5. Continuous improvement: raise difficulty over time, target weak segments, and refresh content against emerging threats.

Deliverables

  • Human-risk baseline report with the initial phishing simulation results and a knowledge-gap analysis.
  • Twelve-month awareness plan and campaign calendar aligned to your regulatory obligations.
  • Arabic and English training content: e-learning modules, workshop decks, and microlearning assets.
  • Phishing simulation platform configuration and per-campaign performance reports.
  • Management dashboard and periodic reports showing behavior trends and repeat-offender remediation.
  • Awareness evidence pack (attendance, completion, and simulation metrics) ready for SAMA, NCA, and internal audit.

Regulatory controls it satisfies

SAMA Cyber Security Framework
Fulfills the framework's requirement for an ongoing cybersecurity awareness program covering all staff of member organizations.
NCA ECC-2:2024
Addresses the Cybersecurity Awareness and Training program controls, including role-based and continuous awareness.
PDPL
Trains staff on the lawful handling of personal data, supporting the awareness and accountability expectations of the law.
ISO/IEC 27001
Provides evidence for the Annex A control on information security awareness, education, and training.

Typical timeline

Awareness is an annual program, not a one-off: the baseline and first campaign launch within two to three weeks, then simulations and training run on a continuous monthly and quarterly cadence.

Common questions

Is the content in Arabic?

Yes. All core content is authored in professional Arabic for the Saudi workplace, with English versions for mixed teams, rather than generic translated material.

How do you handle employees who repeatedly fail phishing tests?

The approach is supportive, not punitive. Repeat clickers receive targeted micro-coaching and progressively tailored simulations, and management sees the trend without individuals being publicly shamed.