Governance and Risk Advisory

Cyber Risk

Security Culture as a Service (SCaaS)

Many organizations believe that cyber security awareness training for employees needs to be as serious as the topics covered.


Too often, this turns into uninspired “check-the-box” exercises. The result? Greater exposure to security events because employees are unprepared to recognize real threats or respond to evolving tactics.

It’s time for a change – a culture change that helps employees internalize a cyber security and data privacy mindset and “own” their role in keeping data safe. A new era of stronger security can start with Kroll’s Security Culture as a Service (SCaaS).

Kroll’s SCaaS is field-proven to help employees embrace strong data security attitudes and practices in their everyday activities.  

Cyber Security Awareness Programs Customized for Your Industry, Organization and/or Stakeholder Roles

From our experience investigating thousands of cyber incidents, we have seen how virtually every security compromise can ultimately be traced to a human factor. Our findings are supported by a wide range of annual open-source surveys and reports that show employees and related third parties are responsible for 60%-90% of incidents, including those involving paper data sources and lost devices. 

Kroll’s SCaaS experts focus on the human risks most relevant to your organization, whether they be industry-related or role-based.  You can expect us to have frank discussions with leaders and a cross-section of your staff about digital and physical security factors that put data at risk. In fact, this emphasis on communication is a fundamental part of our approach to building a security culture.

Kroll’s unique approach to creating a security culture taps into the expertise and insights of cyber security, marketing and communications professionals who understand the power of creative storytelling. Together with an understanding of your goals and needs, we translate our findings into engaging, influential training.  

Four Steps to Customize a Culture-changing Program
  1. Understand your business strategy, key risks and current corporate culture.
  2. Engage with your key user communities to confirm risk areas and brainstorm the big ideas for your program.
  3. Develop your tailored and measurable security culture program, along with messages and methods aligned to your business.
  4. Provide direct or supplemental expertise to drive implementation (e.g., strategy, content development, training and coaching).
Bespoke Cyber Security Awareness Programs for Organizations at Every Maturity Level

Whether you already have a robust security culture or want to start fresh, you’ll find what you want with Kroll’s wide range of SCaaS services. Here are two of our most popular programs:


Kroll SCaaS Training Kick-Starter Package

Kroll SCaaS Pop-Up Health Check


Educate employees about identifying cyber threats and avoiding them.

Dynamic onsite “refresher” sessions with employees to reinforce good security practices and identify problematic gaps.

Delivery Mode

SCORM-compliant e-learning training modules , videos, games, etc. 
For a tailored look and to make content more relevant for employees, we can add your organization’s logo and policy references to materials.

Onsite conference-style booths set-up in high-traffic areas, such as an office foyer or common workspace to generate hype and engagement.

Sample Topics Covered

  • Phishing (intro)

  • Internet safety

  • Ransomware

  • Physical security

  • Password

  • Mobile devices

  • Privacy and social media

  • Personal security and privacy settings on mobile phones, tablets or laptops

  • Secure social media profiles, e.g., Facebook, Instagram, WhatsApp, WeChat

  • Insight and takeaways to protect home networks and corporate devices used at home

  • BYOD corporate policy and awareness

  • Identifying security incidents at work, home and play



 Assessment module provides metrics on completion rates, scores and areas that employees require more training, clarification, etc.

 Booth visitors receive on-the-spot “diagnosis” for real-life potential issues and ways to improve cyber safety with a basic “treatment plan.”

Employees learn how easy it is to be part of a safer, security-conscious workplace, and how these skills are transferable to their personal lives.

Your Kroll SCaaS Program Can Be Customized to Include Some or All the Following Elements


  • Security culture program
  • Executive support toolkit
  • Performance measurement and metrics
  • Resourcing augmentation
  • Coaching and mentoring


  • Activity planning
  • Phishing exercises
  • eLearning module development (general or customized)
  • Gamified learning and development
  • Face-to-face training (technical and non-technical)


Tailored user community messaging relevant to your business, such as:

  • Directors/CXOs (understanding and accountability for security)

  • HR (security within the employee lifecycle)

  • Procurement (security related to external parties)

  • Application development (security within the SDLC)

  • Infrastructure (security across the network and supporting infrastructure)

  • Service desk/center (security within the end-user environment)

Supported by a variety of materials developed under your brand guidelines:

  • Email templates

  • Intranet input

  • Brochures

  • News articles

  • Videos

  • Infographics

  • Posters

Engage Your Teams to Foster a Strong Data Privacy and Security Culture

From strategic guidance to tactical decision-making to bringing it all together with dynamic operational activities, Kroll’s SCaaS solutions support you every step of the way. To learn what Kroll’s SCaaS clients around the world are saying about the difference our training is making – and how you can achieve meaningful improvements in employee security engagement – contact one of our SCaaS experts today.

/en/services/cyber-risk/governance-advisory/cyber-security-culture-scaas /-/media/feature/services/cyber-risk/governance-risk-advisory-desktop-banner.jpg service

Contact Us

Stay Ahead with Kroll

Kroll Business services

Business Services

Technology-enabled legal and business solutions for corporate restructurings, settlement administrations, issuer services, agent and trustee services, and other complex support needs.

Business Services
Comprehensive Due Diligence Solution

Compliance and Regulation

End-to-end governance, advisory and monitorship solutions to detect, mitigate and remediate operational security, legal, compliance and regulatory risk.

Compliance and Regulation
Corporate Finance

Corporate Finance and Restructuring

Comprehensive corporate finance, investment banking and restructuring support to clients, investors and stakeholders.

Corporate Finance and Restructuring
Cyber Risk

Cyber Risk

Incident response, digital forensics, breach notification, managed detection services, penetration testing, cyber assessments and advisory.

Cyber Risk
Environmental, Social and Governance Advisory Services (ESG)

Environmental, Social and Governance

Advisory and technology solutions, including policies and procedures, screening and due diligence, disclosures and reporting and investigations, value creation, and monitoring.

Environmental, Social and Governance
Governance, Risk, Investigations and Disputes

Investigations and Disputes

World-wide expert services and tech-enabled advisory through all stages of diligence, forensic investigation, litigation and testimony.

Investigations and Disputes
Valuation Advisory


Valuation of businesses, assets and alternative investments for financial reporting, tax and other purposes.




ALM Intelligence Pacesetter Research – Cybersecurity Services 2020


CVE-2020-1472 (Zerologon) Exploit Detection Cheat Sheet


Kroll Ransomware Attack Trends – 2020 YTD

Cyber Risk

Insider Threat Case Study: Digital Forensics Reveals Fraud, Potential Regulatory Concerns

Cyber Risk