The Scenario
A 150-person SA medical scheme has had three near-miss phishing incidents in the last six months, including one where a finance team member nearly paid an invoice rerouted via business email compromise. The IT manager wants a simple awareness pack to roll out to all staff.
The Brief
Produce a complete phishing awareness training pack: a one-page staff guide, a five-question quiz, three sample phishing emails for analysis, and a reporting workflow.
Deliverables
- A one-page staff guide covering: how to spot phishing, the four common SA attack patterns (BEC, fake SARS, fake banking, fake DHL), and what to do if you clicked something
- Three annotated sample phishing emails (BEC, banking lookalike, fake delivery), each with the red flags called out and a teaching paragraph
- A five-question multiple-choice quiz suitable for the company learning management system
- A reporting workflow describing how staff escalate suspected phishing, who triages it, and what feedback they get back
Submission Guidance
Generic phishing training fails because the examples feel American. The strongest SA phishing awareness uses local context: SARS letterhead, Capitec login pages, Takealot order confirmations. Pick local examples that staff will actually recognise.
Submit Your Work
Your submission is graded against the rubric on the right. If you pass, you get a public Badge URL you can share on LinkedIn. There is no draft save, so work offline first and paste your finished response here.