Hozit Domain Hosting — Smart technology. Powerful results.010 502 2517 · info@hozit.co.za · 24/7 Support
Level 1 B-BBEE100% Black Owned24/7 SupportSouth African Technology Partner
Build a Security-Aware Workforce

Reduce human risk with practical cybersecurity awareness training and phishing simulations

Hozit helps organisations strengthen employee security behaviour through awareness programmes, simulated phishing campaigns, role-based training, executive briefings, reporting and continuous improvement.

Service Overview

Professional IT support for growing and established organisations

Technology controls alone cannot prevent every cyber incident. Employees remain a key part of an organisation’s defence against phishing, business email compromise, social engineering, credential theft and data loss.

Hozit provides structured cybersecurity awareness training and phishing simulation services designed to improve real-world security behaviour.

Programmes can be delivered as once-off training, recurring campaigns, role-based workshops or a fully managed annual awareness programme.

Training can be aligned to the organisation’s policies, technology environment, risk profile and selected compliance obligations.

The objective is not only to improve knowledge, but to help employees recognise threats, make safer decisions and report suspicious activity quickly.

Business Challenges

Common IT problems we help solve

Phishing susceptibility

Employees may click malicious links or submit credentials.

Weak password habits

Reused or predictable passwords increase account-compromise risk.

Business email compromise

Staff may act on fraudulent payment or account-change instructions.

Low reporting rates

Suspicious messages may not be reported quickly enough.

Remote-work risk

Home networks, personal devices and public Wi-Fi introduce additional exposure.

Policy awareness gaps

Employees may not understand security and acceptable-use requirements.

Privileged-user risk

Administrators and executives are high-value targets.

Inconsistent onboarding

New employees may start work without essential security guidance.

Training fatigue

Long or repetitive sessions may not change behaviour.

Limited measurement

Management may lack clear data on human cyber risk.

What Is Included

Comprehensive managed IT support services

The final scope is tailored to the organisation's users, systems, locations, risks and internal capabilities.

Cybersecurity awareness assessment

Assess current training, policies, reporting behaviour and employee risk.

Human-risk baseline

Establish an initial view of knowledge, behaviour and phishing susceptibility.

Awareness programme strategy

Define audiences, topics, frequency, objectives and success measures.

Annual training programme

Deliver scheduled awareness activities throughout the year.

Employee cybersecurity induction

Train new employees on essential security responsibilities.

General employee awareness training

Cover common threats and safe working practices.

Executive cybersecurity awareness

Provide senior leadership with targeted risk and decision-making guidance.

Board cybersecurity briefing

Explain cyber risk, accountability, incident readiness and governance.

Privileged-user awareness

Train administrators and users with elevated access.

Finance-team fraud awareness

Address invoice fraud, payment diversion and business email compromise.

HR security awareness

Cover personal information, recruitment scams and employee-data handling.

Sales-team security awareness

Address customer data, public communication and mobile working risks.

IT-team security awareness

Reinforce privileged access, change control and incident reporting.

Remote-worker security training

Cover home networks, personal devices, VPNs and secure collaboration.

Contractor security awareness

Provide targeted training for temporary and third-party users.

Phishing awareness training

Teach employees to identify suspicious messages, links and attachments.

Spear-phishing awareness

Explain targeted phishing using personal or organisational context.

Business email compromise training

Cover impersonation, payment fraud and mailbox compromise indicators.

Smishing awareness

Teach employees to identify malicious SMS messages.

Vishing awareness

Teach employees to recognise fraudulent voice calls.

QR-code phishing awareness

Explain malicious QR codes and unsafe scanning behaviour.

Social engineering awareness

Cover manipulation, urgency, authority and trust abuse.

Password security training

Promote strong, unique passwords and password-manager use.

Multi-factor authentication training

Explain MFA benefits, approval fatigue and secure usage.

Credential theft awareness

Teach users how fake login pages and token theft work.

Data protection awareness

Cover safe handling of confidential and personal information.

POPIA awareness training

Explain employee responsibilities relating to personal information.

Email security awareness

Cover suspicious senders, attachments, links and spoofing.

Safe web-browsing training

Teach users to identify unsafe websites and downloads.

Malware awareness

Explain malicious files, fake updates and unsafe software.

Ransomware awareness

Teach employees how ransomware commonly enters organisations.

USB and removable-media awareness

Address unknown devices and unauthorised storage.

Mobile-device security training

Cover screen locks, apps, updates, backups and device loss.

Public Wi-Fi awareness

Explain safe connectivity and VPN use.

Cloud collaboration security

Cover secure sharing in Microsoft 365 and other cloud services.

Microsoft Teams security awareness

Teach safe meeting, file-sharing and external-chat practices.

SharePoint security awareness

Cover permissions, external sharing and confidential data.

OneDrive security awareness

Explain secure file storage, sync and sharing.

Microsoft 365 security awareness

Address identity, mailbox, sharing and collaboration risks.

Safe use of AI tools

Explain confidential-data, account and prompt-security risks.

Generative AI awareness

Teach employees how to use AI tools without exposing sensitive information.

Secure social media use

Address oversharing, impersonation and organisational information leakage.

Physical security awareness

Cover tailgating, unattended devices and visitor control.

Clean-desk awareness

Promote secure handling of documents and visible information.

Secure printing awareness

Reduce exposure of confidential printed information.

Incident reporting awareness

Teach users how and when to report suspicious activity.

Lost-device reporting

Explain immediate steps after device loss or theft.

Data-breach reporting

Help employees recognise and escalate possible data exposure.

Policy awareness sessions

Explain selected organisational security policies.

Acceptable-use training

Clarify permitted and prohibited use of company systems.

BYOD security awareness

Explain employee responsibilities when using personal devices.

Secure remote-access awareness

Cover VPN, MFA and safe access to business systems.

Phishing simulation planning

Define campaign objectives, target groups and approved scenarios.

Baseline phishing simulation

Measure initial employee susceptibility.

Email phishing simulations

Send controlled simulated phishing messages.

Credential-harvest simulations

Measure response to approved fake login scenarios without collecting real passwords.

Attachment-based simulations

Test response to approved simulated malicious attachments.

Link-click simulations

Measure interaction with suspicious links.

Business email compromise simulations

Test payment and authority-based fraud scenarios.

Executive impersonation simulations

Assess response to approved leadership-impersonation scenarios.

Supplier impersonation simulations

Test response to vendor and invoice-change fraud.

HR-themed simulations

Use approved recruitment, payroll or policy scenarios.

IT-support simulations

Test response to password-reset and account-warning messages.

Seasonal phishing simulations

Use approved tax, holiday, delivery or event themes.

Targeted phishing simulations

Run controlled campaigns for selected high-risk groups.

Smishing simulations

Test approved SMS-based awareness scenarios where supported.

Vishing simulations

Test approved voice-based social engineering scenarios where supported.

QR phishing simulations

Use controlled QR-code scenarios.

Phishing landing pages

Use safe educational pages for simulation outcomes.

Just-in-time training

Provide immediate learning after risky simulation behaviour.

Positive reinforcement

Acknowledge employees who correctly report simulated threats.

Repeat-offender coaching

Provide targeted follow-up for employees requiring additional support.

High-risk-user training

Provide focused training to users with repeated risky behaviour.

Department-level analysis

Compare results across approved organisational groups.

Role-based risk analysis

Assess simulation results by job function.

Click-rate reporting

Measure interaction with simulated phishing links.

Credential-submission reporting

Measure approved simulated credential-entry behaviour.

Reporting-rate measurement

Track how many employees report suspicious simulations.

Time-to-report measurement

Measure how quickly simulations are reported.

Repeat-risk measurement

Identify recurring risky behaviour over time.

Human-risk scoring

Develop selected employee or group risk indicators.

Security culture surveys

Measure employee confidence, attitudes and reporting behaviour.

Knowledge assessments

Use quizzes and checks to measure learning.

Pre-training assessment

Measure baseline awareness before training.

Post-training assessment

Measure improvement after training.

Monthly awareness report

Provide management with results, trends and recommendations.

Quarterly executive report

Summarise human-risk trends and programme performance.

Board reporting support

Provide concise awareness and phishing metrics for governance reporting.

Compliance evidence reporting

Provide selected attendance, assessment and campaign records.

Training attendance tracking

Track participation and completion.

Training completion certificates

Provide selected proof of completion.

Learning reminders

Send approved reminders to incomplete participants.

Awareness newsletters

Provide short security updates and practical guidance.

Security tip campaigns

Deliver recurring bite-sized awareness messages.

Security awareness posters

Provide workplace and digital awareness materials.

Monthly cyber themes

Run focused campaigns around selected security topics.

Cybersecurity awareness month programme

Deliver an enhanced awareness campaign during October.

Microlearning modules

Provide short, focused learning content.

Live virtual training

Deliver instructor-led online awareness sessions.

On-site training

Deliver instructor-led sessions at approved locations.

Recorded training modules

Provide reusable training content where included.

Interactive workshops

Use practical examples and discussion-based learning.

Executive tabletop exercise

Test leadership response to a simulated cyber incident.

Phishing response exercise

Test reporting, triage and escalation procedures.

Business email compromise exercise

Test finance, management and IT response to fraud.

Ransomware awareness exercise

Test employee and management understanding of ransomware response.

Incident communication exercise

Test internal communication during a cyber event.

Awareness policy development

Develop or update cybersecurity awareness policies.

Training standard development

Define minimum learning requirements by role.

Phishing simulation policy

Document rules, privacy, governance and campaign approval.

Awareness calendar development

Plan annual themes, simulations and training activities.

Programme governance

Define ownership, approvals, reporting and improvement processes.

Managed awareness programme

Operate training, campaigns, reporting and follow-up on behalf of the organisation.

Continuous improvement

Refine content and targeting based on results and emerging risks.

Business Benefits

Why organisations choose managed IT support

Reduced phishing risk

Employees become better at recognising suspicious messages and requests.

Faster threat reporting

Clear reporting guidance helps security teams respond earlier.

Improved security culture

Recurring engagement makes security part of everyday work.

Measurable human-risk data

Simulations and assessments provide clear performance metrics.

Targeted improvement

High-risk teams receive focused training rather than generic content.

Stronger fraud prevention

Finance and executive teams improve their response to impersonation and payment fraud.

Better compliance evidence

Attendance, assessments and reports support selected assurance requirements.

Continuous behaviour improvement

Regular campaigns reinforce safer decisions over time.

Our Methodology

From discovery to ongoing improvement

1

Assess current awareness

Review existing training, policies, incidents and employee risk.

2

Define audiences

Identify employees, executives, privileged users and high-risk teams.

3

Set programme objectives

Define required behaviour, topics and performance measures.

4

Establish a baseline

Run approved assessments or phishing simulations.

5

Deliver training

Provide relevant awareness content through selected channels.

6

Run simulations

Conduct controlled phishing and social-engineering campaigns.

7

Measure behaviour

Track clicks, reporting, completion and knowledge improvement.

8

Provide targeted coaching

Support users and teams requiring additional guidance.

9

Report to management

Provide trends, risks, completion and recommended actions.

10

Improve continuously

Adjust content, frequency and scenarios based on results.

Engagement Options

Flexible IT support models

Once-off awareness workshop

Deliver focused cybersecurity training for selected audiences.

Annual awareness programme

Provide structured training and campaigns throughout the year.

Managed phishing simulation

Plan, run and report controlled phishing campaigns.

Executive and board training

Provide leadership-focused cybersecurity awareness.

Role-based training

Deliver targeted learning for finance, HR, IT and privileged users.

New employee induction

Provide cybersecurity onboarding for new starters.

Remote workforce programme

Focus on mobile, home-network and cloud-collaboration risks.

Fully managed human-risk programme

Operate awareness, simulations, reporting and follow-up continuously.

Technology Coverage

Platforms and technologies we support

Support is subject to the agreed scope, vendor requirements, licences and available technical documentation.

Cybersecurity Awareness Phishing Simulation Social Engineering Business Email Compromise Spear Phishing Smishing Vishing QR Phishing Password Security Multi-Factor Authentication Microsoft 365 Microsoft Teams Exchange Online SharePoint OneDrive Remote Work Security Mobile Security Cloud Security Data Protection POPIA Awareness Ransomware Awareness Incident Reporting Security Culture Human Risk Management Microlearning Security Assessments Knowledge Testing Executive Training Board Awareness Role-Based Training Security Metrics Compliance Reporting Security Newsletters Tabletop Exercises Generative AI Security BYOD Security
Industries

Managed IT support across key sectors

Why Hozit

A practical technology partner for your organisation

Practical training content

Training focuses on real workplace situations and decisions.

Measurable outcomes

Simulations, assessments and reporting demonstrate progress.

Role-based approach

Content can be tailored to executives, finance, HR, IT and general users.

Flexible delivery

Choose on-site, virtual, recorded or managed programme options.

Continuous improvement

Campaigns are refined using actual employee behaviour and trends.

Integrated cybersecurity support

Hozit can also assist with monitoring, incident response, email and endpoint security.

Example Scenarios

How managed IT support can be applied

These are illustrative examples and are not presented as named customer case studies.

Invoice fraud prevention

Finance teams learn to verify payment and banking-detail changes.

Microsoft 365 phishing

Employees learn to identify fake login and account-expiry messages.

Executive impersonation

Staff practise responding to urgent requests that appear to come from leadership.

Remote-work security

Employees learn safer home-network, VPN and device practices.

New employee onboarding

New starters receive security guidance before accessing critical systems.

Repeated phishing risk

Targeted coaching is provided to users who require additional support.

Frequently Asked Questions

Managed IT support FAQs

What is cybersecurity awareness training?

It teaches employees how to recognise threats, protect information and respond safely.

What is a phishing simulation?

A phishing simulation is a controlled test using safe messages that resemble real phishing attempts.

Do simulations collect real passwords?

No. Approved simulations should not collect or store real employee passwords.

Can you train all employees?

Yes. Programmes can cover general employees, contractors, executives and privileged users.

Do you provide executive training?

Yes. Executive and board-focused cybersecurity sessions are available.

Can training be delivered online?

Yes. Training can be delivered virtually, on-site or through recorded modules where included.

How often should phishing simulations be run?

Frequency depends on risk, employee size and programme objectives, but recurring simulations are generally more effective than once-off testing.

Will employees know the simulation is coming?

The organisation approves the programme, but individual campaign timing is usually not announced in advance.

Can campaigns be customised?

Yes. Scenarios can reflect approved industry, departmental and organisational risks.

Can you target finance teams?

Yes. Finance-specific simulations can cover invoice fraud and payment diversion.

Can you train remote workers?

Yes. Remote-work training covers home networks, public Wi-Fi, devices, VPNs and cloud collaboration.

Do you provide POPIA awareness?

Yes. Training can include employee responsibilities for handling personal information.

How are results measured?

Results may include clicks, simulated submissions, reports, completion, assessment scores and time to report.

Do you provide reports?

Yes. Management and executive reports can include trends, high-risk areas and recommendations.

Can you provide certificates?

Selected training programmes can include completion certificates.

What happens when an employee fails a simulation?

The employee can receive immediate education and targeted follow-up training.

Can phishing simulations upset employees?

Campaigns should be governed carefully, approved by management and designed to educate rather than punish.

Can the programme support ISO 27001?

Training records and awareness activities can support selected information-security management requirements.

Can you run a full annual programme?

Yes. Hozit can manage training, simulations, reporting and continuous improvement throughout the year.

How do we request a quotation?

Provide your employee count, locations, preferred delivery method, required frequency and target groups.

Related Services

Build a stronger technology environment

Improve the reliability and security of your IT environment

Speak to Hozit about your users, infrastructure, support challenges and technology priorities.

Request an IT Assessment
Request a Quote WhatsApp