Lebone Marang and Summer Security Awareness

Security Is a Human Habit.
We Help You Build It.

Most security incidents do not start with sophisticated hackers. They start with one rushed click on one convincing email. Our awareness platform turns your people from your greatest risk into your strongest line of defence.

POPIA-Aware Programme
Measurable Behaviour Change
Continuous, Not Annual
Strategic Partner

Info-Tech Research Group

Behaviour Measured

Baseline, track, and demonstrate how human-layer risk actually changes over time

Habits Trained

Short, regular, role-aware training that builds reflexes instead of zoning people out

Incidents Reported

A workforce that flags suspicious mail in seconds instead of hoping someone else did

Our Awareness Point of View

Annual Training Does Not Change Behaviour

A once-a-year e-learning module satisfies a checkbox and changes nothing. Behaviour changes through short, regular practice and real, safe feedback: the same way every habit is built.

Our programme design draws on Info-Tech Research Group’s security awareness best practice: measure first, train to the actual risk, simulate realistically, and report the trend to the board.

Our Continuous Awareness Cycle

01Baseline
02Train
03Simulate
04Measure
05Improve
The Challenges We Help You Solve

Does Any of This Sound Familiar?

These are the human-layer risk patterns we see most often. If more than two are true in your organisation, your awareness programme needs attention.

Phishing Still Works

Convincing emails still get clicks, because attackers are more creative than a static filter is strict.

Weak Password Habits

Shared logins, reused passwords, and credentials on sticky notes undermine even strong technical controls.

Data Handled Casually

Sensitive customer and staff data moves through personal email and unmanaged sharing links.

Once-a-Year Training

Compliance training once a year keeps the auditors quiet but builds no lasting reflexes.

Nobody Knows the Risk

Leadership has no visibility of how susceptible the organisation actually is to human-layer attack.

Silence After Suspicion

People who spot something odd stay quiet because reporting feels like an accusation, not a contribution.

Your firewalls, encryption, and patching are all undermined by one untrained click. Technical controls cannot compensate for an unprepared workforce; together, they are formidable.

Our Approach and Deliverables

A Programme, Not a Product

At Lebone Marang and Summer, we run awareness as a continuous programme: baseline your real behaviour, train to your actual risks, simulate realistic attacks, and prove the trend to your board.

01How We Work

  • Baseline susceptibility assessment across departments and roles
  • Role-aware training tracks for staff, finance, executives, and IT
  • Realistic simulated phishing campaigns with safe, instant feedback
  • Just-in-time coaching at the moment of a simulated mistake
  • Quarterly behaviour reporting for executives and the board
  • POPIA-aligned data handling content for all staff
  • Continuous programme tuning based on what the data shows

What You Receive

  • Baseline Susceptibility Report
  • Role-Aware Training Curriculum
  • Simulated Phishing Campaign Plan
  • Campaign Results and Trend Analysis
  • Executive and Board Reporting Pack
  • POPIA Data Handling Module
  • Incident Reporting Playbook
  • Programme Improvement Roadmap

Business Outcomes We Deliver

Organisations partnering with us can expect to:

  • Measurable reduction in susceptibility across every campaign cycle
  • Staff who report suspicious messages in minutes, not days
  • Confidence with regulators and clients that human-layer risk is managed
  • Executives who can see, in numbers, how the programme is working
  • A security culture where awareness is everyone’s job, not IT’s
  • Reduced likelihood and impact of phishing-driven incidents
  • A durable habit, refreshed continuously instead of annually

Why Lebone Marang and Summer

We treat your people as the asset, not the problem. Programmes built on blame teach staff to hide mistakes; programmes built on practice teach them to react well.

Our awareness methodology is grounded in Info-Tech Research Group’s human-layer security research, adapted to South African regulatory context including POPIA.

Train the Habit. Measure the Change.

How prepared are your people, really?

Let us run a baseline assessment and show you, in plain numbers, where your human-layer risk actually stands.

Strategic Partner

Info-Tech Research Group