Governance and Risk Advisory

Cyber Risk

Security Culture as a Service (SCaaS)

Many organizations believe that cyber security awareness training for employees needs to be as serious as the topics covered.


Too often, this turns into uninspired “check-the-box” exercises. The result? Greater exposure to security events because employees are unprepared to recognize real threats or respond to evolving tactics.

It’s time for a change – a culture change that helps employees internalize a cyber security and data privacy mindset and “own” their role in keeping data safe. A new era of stronger security can start with Kroll’s Security Culture as a Service (SCaaS).

Kroll’s SCaaS is field-proven to help employees embrace strong data security attitudes and practices in their everyday activities.  

Cyber Security Awareness Programs Customized for Your Industry, Organization and/or Stakeholder Roles

From our experience investigating thousands of cyber incidents, we have seen how virtually every security compromise can ultimately be traced to a human factor. Our findings are supported by a wide range of annual open-source surveys and reports that show employees and related third parties are responsible for 60%-90% of incidents, including those involving paper data sources and lost devices. 

Kroll’s SCaaS experts focus on the human risks most relevant to your organization, whether they be industry-related or role-based.  You can expect us to have frank discussions with leaders and a cross-section of your staff about digital and physical security factors that put data at risk. In fact, this emphasis on communication is a fundamental part of our approach to building a security culture.

Kroll’s unique approach to creating a security culture taps into the expertise and insights of cyber security, marketing and communications professionals who understand the power of creative storytelling. Together with an understanding of your goals and needs, we translate our findings into engaging, influential training.  

Four Steps to Customize a Culture-changing Program
  1. Understand your business strategy, key risks and current corporate culture.
  2. Engage with your key user communities to confirm risk areas and brainstorm the big ideas for your program.
  3. Develop your tailored and measurable security culture program, along with messages and methods aligned to your business.
  4. Provide direct or supplemental expertise to drive implementation (e.g., strategy, content development, training and coaching).
Bespoke Cyber Security Awareness Programs for Organizations at Every Maturity Level

Whether you already have a robust security culture or want to start fresh, you’ll find what you want with Kroll’s wide range of SCaaS services. Here are two of our most popular programs:


Kroll SCaaS Training Kick-Starter Package

Kroll SCaaS Pop-Up Health Check


Educate employees about identifying cyber threats and avoiding them.

Dynamic onsite “refresher” sessions with employees to reinforce good security practices and identify problematic gaps.

Delivery Mode

SCORM-compliant e-learning training modules , videos, games, etc. 
For a tailored look and to make content more relevant for employees, we can add your organization’s logo and policy references to materials.

Onsite conference-style booths set-up in high-traffic areas, such as an office foyer or common workspace to generate hype and engagement.

Sample Topics Covered

  • Phishing (intro)

  • Internet safety

  • Ransomware

  • Physical security

  • Password

  • Mobile devices

  • Privacy and social media

  • Personal security and privacy settings on mobile phones, tablets or laptops

  • Secure social media profiles, e.g., Facebook, Instagram, WhatsApp, WeChat

  • Insight and takeaways to protect home networks and corporate devices used at home

  • BYOD corporate policy and awareness

  • Identifying security incidents at work, home and play



 Assessment module provides metrics on completion rates, scores and areas that employees require more training, clarification, etc.

 Booth visitors receive on-the-spot “diagnosis” for real-life potential issues and ways to improve cyber safety with a basic “treatment plan.”

Employees learn how easy it is to be part of a safer, security-conscious workplace, and how these skills are transferable to their personal lives.

Your Kroll SCaaS Program Can Be Customized to Include Some or All the Following Elements


  • Security culture program
  • Executive support toolkit
  • Performance measurement and metrics
  • Resourcing augmentation
  • Coaching and mentoring


  • Activity planning
  • Phishing exercises
  • eLearning module development (general or customized)
  • Gamified learning and development
  • Face-to-face training (technical and non-technical)


Tailored user community messaging relevant to your business, such as:

  • Directors/CXOs (understanding and accountability for security)

  • HR (security within the employee lifecycle)

  • Procurement (security related to external parties)

  • Application development (security within the SDLC)

  • Infrastructure (security across the network and supporting infrastructure)

  • Service desk/center (security within the end-user environment)

Supported by a variety of materials developed under your brand guidelines:

  • Email templates

  • Intranet input

  • Brochures

  • News articles

  • Videos

  • Infographics

  • Posters

Engage Your Teams to Foster a Strong Data Privacy and Security Culture

From strategic guidance to tactical decision-making to bringing it all together with dynamic operational activities, Kroll’s SCaaS solutions support you every step of the way. To learn what Kroll’s SCaaS clients around the world are saying about the difference our training is making – and how you can achieve meaningful improvements in employee security engagement – contact one of our SCaaS experts today.

/en/services/cyber-risk/governance-advisory/cyber-security-culture-scaas /-/media/feature/services/cyber-risk/governance-risk-advisory-desktop-banner.jpg service

Cyber Governance and Risk

Contact Us

Other Areas We Can Help

Cyber Risk

Cyber Risk

Global, end-to-end cyber risk solutions.

Cyber Risk
Cyber Risk Retainers

Cyber Risk Retainers

Secure a true cyber risk retainer with elite digital forensics and incident response capabilities.

Cyber Risk Retainers
Incident Response and Litigation Support

24x7 Incident Response

Compliant notifications, reputation-saving remediation, and litigation support.

24x7 Incident Response
Cyber Risk: The New Due Diligence Frontier, Identity Monitoring

Penetration Testing Services

Assess clients' info security through simulated attacks using real-world hacker techniques.

Penetration Testing Services
Has COVID-19 Impacted Your Ability to Preserve Evidence for Future Litigation?

Ransomware Preparedness Assessment

Helps your organization avoid ransomware attacks by examining 14 crucial security areas and attack vectors.

Ransomware Preparedness Assessment
Kroll Responder

Kroll Responder

Mature your cyber security with unparalleled visibility and constant protection.

Kroll Responder
Anti-Bribery & Corruption Benchmarking Report – 2020

Data Collection and Preservation

Collection and preservation of all electronic evidence including email servers, networks, and more.

Data Collection and Preservation
Managed Security Services

Managed Security Services

Managed security services to augment security operations centres and incident response capabilities.

Managed Security Services



ALM Intelligence Pacesetter Research – Cybersecurity Services 2020


CVE-2020-1472 (Zerologon) Exploit Detection Cheat Sheet


Kroll Ransomware Attack Trends – 2020 YTD

Cyber Risk

Insider Threat Case Study: Digital Forensics Reveals Fraud, Potential Regulatory Concerns

Cyber Risk


KAPE Intensive Training and Certification Live Webcast Sessions



Lunch & Learn: Navigating Increased Transactional Risk Scrutiny



10 Essential Cyber Security Controls for Increased Resilience and Better Insurance Coverage