Course Outline
Foundations, Social Engineering, and the Workplace Environment
Module 1: Essential Cybersecurity for Employees
-
Understanding threats: The scope of cybersecurity and the role of every employee in protecting the organization.
-
Digital hygiene and password management: Crafting strong passwords, utilizing managers, and adhering to unique password policies per service.
-
Clear desk and clear screen protocols: Ensuring physical information security within office spaces.
Module 2: Recognizing Phishing and Social Engineering Threats
-
Attack psychology: Explaining social engineering and the use of urgency, fear, or authority by cybercriminals (e.g., CEO Fraud, BEC).
-
Phishing analysis: Examining message headers, hidden links, and malicious attachments using real-world examples.
-
Additional attack vectors: Voice phishing (Vishing) and SMS-based phishing (Smishing).
Module 3: Securing Remote and Mobile Work
-
Network security: The risks of public Wi-Fi in transit or cafes and the proper use of VPNs.
-
Device security: Implementing disk encryption, screen locks, and avoiding unverified USB drives.
-
BYOD policies: Guidelines for using personal smartphones for business and maintaining data separation.
Tools, Regulations, and Incident Response
Module 4: Cybersecurity within Microsoft 365
-
Authentication and verification: Practical use of Multi-Factor Authentication (MFA/2FA) for secure account access.
-
Secure data sharing: Managing permissions in OneDrive and SharePoint to prevent unintended access via public links.
-
Collaboration security: Safe practices for Microsoft Teams, including external guest management and file sharing controls.
Module 5: Applying GDPR and Personal Data Protection
-
Data classification: Distinguishing between public, confidential, sensitive, and personal data.
-
GDPR in daily tasks: Avoiding common errors that lead to data breaches, such as emailing the wrong recipient or neglecting BCC usage.
-
Data lifecycle management: Protocols for securely transferring data to third parties and permanently deleting documents.
Module 6: Managing Security Incidents
-
Identifying breaches: Recognizing incidents such as lost devices, ransomware infections, or accidental clicks on phishing links.
-
Reporting workflows: Determining who to notify and the required timeframe, involving IT Helpdesk, Security Representatives, and Data Protection Officers.
-
Initial response protocols: Disconnecting affected devices, maintaining composure, and avoiding unauthorized troubleshooting or evidence removal.
Requirements
-
Proficiency with basic computer operations and web browsers.
-
Regular use of standard office applications, including email, messaging platforms, and document editors.
-
No advanced IT expertise is necessary; all technical concepts are presented through the perspective of business impact and daily workflows.
Target Audience
- Office, administrative staff, and mid-level managers across all departments.
- Strongly recommended for employees working in hybrid or fully remote setups.
- Daily users within the Microsoft 365 ecosystem.
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
get to understand more about the product and some key differences between RHDS and open source OpenLDAP.
Jackie Xie - Westpac Banking Corporation
Course - 389 Directory Server for Administrators
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions