Course Outline
Core Concepts, Social Engineering, and the Workplace Environment
Module 1: Cybersecurity Essentials for Employees
-
Understanding threats: Defining cybersecurity and explaining why every employee plays a vital role.
-
Digital hygiene and password strategy: Developing robust passwords, leveraging password managers, and adhering to the "one password per service" principle.
-
Clear desk and clear screen policies: Managing physical information security within the office.
Module 2: Phishing and Social Engineering – Identifying Threats
-
The psychology of attacks: Understanding social engineering and why cybercriminals exploit urgency, fear, or authority (e.g., CEO Fraud, BEC).
-
Deconstructing phishing: Analyzing message headers, hidden links, and malicious attachments using authentic case studies.
-
Alternative attack vectors: Addressing vishing (voice phishing) and smishing (SMS phishing).
Module 3: Securing Remote and Mobile Work
-
Network security: Understanding the risks of public Wi-Fi (in cafes or transit) and the proper use of VPNs.
-
Device protection: Implementing disk encryption, screen locks, and avoiding untrusted USB drives.
-
Bring Your Own Device (BYOD) policies: Guidelines for using personal smartphones for business and ensuring data separation.
Tools, Regulations, and Incident Response
Module 4: Cybersecurity within the Microsoft 365 Ecosystem
-
Access verification: Practical implementation of Multi-Factor Authentication (MFA/2FA) for secure logins.
-
Secure data sharing: Controlling file and folder permissions in OneDrive and SharePoint to prevent unrestricted "anyone with the link" access.
-
Collaborative communication: Safely using Microsoft Teams, including managing external guest invitations and shared files.
Module 5: Personal Data Protection and Practical GDPR Application
-
Data classification: Distinguishing between public, confidential, sensitive, and personal information.
-
GDPR in daily operations: Avoiding common pitfalls that lead to data breaches, such as emailing the wrong recipient or neglecting BCC.
-
Data lifecycle management: Rules for securely transferring information to third parties and permanently deleting documents.
Module 6: Handling Security Incidents
-
Identifying incidents: Recognizing breaches, such as lost devices, ransomware infections, or accidental phishing clicks.
-
Reporting protocols: Determining who to notify and the required timelines, involving the IT Helpdesk, Security Plenipotentiary, and Data Protection Officer.
-
Immediate response guidelines: Isolating affected devices from the network, maintaining composure, and avoiding DIY repairs or deletion of evidence.
Requirements
-
Foundational proficiency with computers and web browsers.
-
Regular use of standard office applications, including e-mail, messaging platforms, and document editors.
-
No prior IT expertise is necessary – all technical concepts are framed through business value and routine workflows.
Target Audience
- Office and administrative staff, as well as mid-level management, across all departments.
- Hybrid or fully remote workers, for whom this training is particularly critical.
- Daily users of the Microsoft 365 ecosystem.
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
get to understand more about the product and some key differences between RHDS and open source OpenLDAP.
Jackie Xie - Westpac Banking Corporation
Course - 389 Directory Server for Administrators
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions