Security Culture as a Service (SCaaS)

Many organizations believe that cyber security awareness training for employees needs to be as serious as the topics covered.


Too often, this turns into uninspired “check-the-box” exercises. The result? Greater exposure to security events because employees are unprepared to recognize real threats or respond to evolving tactics.

It’s time for a change – a culture change that helps employees internalize a cyber security and data privacy mindset and “own” their role in keeping data safe. A new era of stronger security can start with Kroll’s Security Culture as a Service (SCaaS).

Kroll’s SCaaS is field-proven to help employees embrace strong data security attitudes and practices in their everyday activities.  

Cyber Security Awareness Programs Customized for Your Industry, Organization and/or Stakeholder Roles

From our experience investigating thousands of cyber incidents, we have seen how virtually every security compromise can ultimately be traced to a human factor. Our findings are supported by a wide range of annual open-source surveys and reports that show employees and related third parties are responsible for 60%-90% of incidents, including those involving paper data sources and lost devices. 

Kroll’s SCaaS experts focus on the human risks most relevant to your organization, whether they be industry-related or role-based.  You can expect us to have frank discussions with leaders and a cross-section of your staff about digital and physical security factors that put data at risk. In fact, this emphasis on communication is a fundamental part of our approach to building a security culture.

Kroll’s unique approach to creating a security culture taps into the expertise and insights of cyber security, marketing and communications professionals who understand the power of creative storytelling. Together with an understanding of your goals and needs, we translate our findings into engaging, influential training.  

Four Steps to Customize a Culture-changing Program
  1. Understand your business strategy, key risks and current corporate culture.
  2. Engage with your key user communities to confirm risk areas and brainstorm the big ideas for your program.
  3. Develop your tailored and measurable security culture program, along with messages and methods aligned to your business.
  4. Provide direct or supplemental expertise to drive implementation (e.g., strategy, content development, training and coaching).
Bespoke Cyber Security Awareness Programs for Organizations at Every Maturity Level

Whether you already have a robust security culture or want to start fresh, you’ll find what you want with Kroll’s wide range of SCaaS services. Here are two of our most popular programs:


Kroll SCaaS Training Kick-Starter Package

Kroll SCaaS Pop-Up Health Check


Educate employees about identifying cyber threats and avoiding them.

Dynamic onsite “refresher” sessions with employees to reinforce good security practices and identify problematic gaps.

Delivery Mode

SCORM-compliant e-learning training modules , videos, games, etc. 
For a tailored look and to make content more relevant for employees, we can add your organization’s logo and policy references to materials.

Onsite conference-style booths set-up in high-traffic areas, such as an office foyer or common workspace to generate hype and engagement.

Sample Topics Covered

  • Phishing (intro)

  • Internet safety

  • Ransomware

  • Physical security

  • Password

  • Mobile devices

  • Privacy and social media

  • Personal security and privacy settings on mobile phones, tablets or laptops

  • Secure social media profiles, e.g., Facebook, Instagram, WhatsApp, WeChat

  • Insight and takeaways to protect home networks and corporate devices used at home

  • BYOD corporate policy and awareness

  • Identifying security incidents at work, home and play



 Assessment module provides metrics on completion rates, scores and areas that employees require more training, clarification, etc.

 Booth visitors receive on-the-spot “diagnosis” for real-life potential issues and ways to improve cyber safety with a basic “treatment plan.”

Employees learn how easy it is to be part of a safer, security-conscious workplace, and how these skills are transferable to their personal lives.

Your Kroll SCaaS Program Can Be Customized to Include Some or All the Following Elements


  • Security culture program
  • Executive support toolkit
  • Performance measurement and metrics
  • Resourcing augmentation
  • Coaching and mentoring


  • Activity planning
  • Phishing exercises
  • eLearning module development (general or customized)
  • Gamified learning and development
  • Face-to-face training (technical and non-technical)


Tailored user community messaging relevant to your business, such as:

  • Directors/CXOs (understanding and accountability for security)

  • HR (security within the employee lifecycle)

  • Procurement (security related to external parties)

  • Application development (security within the SDLC)

  • Infrastructure (security across the network and supporting infrastructure)

  • Service desk/center (security within the end-user environment)

Supported by a variety of materials developed under your brand guidelines:

  • Email templates

  • Intranet input

  • Brochures

  • News articles

  • Videos

  • Infographics

  • Posters

Engage Your Teams to Foster a Strong Data Privacy and Security Culture

From strategic guidance to tactical decision-making to bringing it all together with dynamic operational activities, Kroll’s SCaaS solutions support you every step of the way. To learn what Kroll’s SCaaS clients around the world are saying about the difference our training is making – and how you can achieve meaningful improvements in employee security engagement – contact one of our SCaaS experts today.

/en-ca/services/cyber-risk/governance-advisory/cyber-security-culture-scaas /-/media/feature/services/cyber-risk/governance-risk-advisory-desktop-banner.jpg service

Governance and Risk Advisory

Contact Us


Cyber Risk

Qakbot Malware Now Exfiltrating Emails for Sophisticated Thread Hijacking Attacks

Cyber Risk
Cyber Risk

Insider Threat Case Study: Digital Forensics Reveals Fraud, Potential Regulatory Concerns

Cyber Risk
Cyber Risk

10 Fundamental Work From Home Cyber Security Tips

Cyber Risk
Cyber Risk

Kroll Alert on 2020 Tax Season Cyber Schemes

Cyber Risk