Course Outline
Foundations, Social Engineering, and the Work Environment
Module 1: Cybersecurity Essentials for Employees
-
Threat introduction: Understanding cybersecurity and the critical role of every employee.
-
Digital hygiene and password control: Crafting robust passwords, utilizing password managers, and adhering to the "unique password per service" principle.
-
Clear desk and clear screen policies: Ensuring physical information security within office spaces.
Module 2: Phishing and Social Engineering – Identifying Threats
-
The psychology of attacks: Defining social engineering and understanding why cybercriminals exploit urgency, fear, or authority (e.g., CEO Fraud, BEC).
-
Phishing anatomy: Analyzing message headers, concealed links, and malicious attachments (using exercises based on real-world examples).
-
Alternative attack vectors: Vishing (voice phishing) and Smishing (SMS phishing).
Module 3: Secure Remote and Mobile Work
-
Network security: The risks of public Wi-Fi networks (in cafes, transit) and the correct use of a VPN.
-
Device protection: Implementing disk encryption, screen locks, and avoiding untrusted USB drives.
-
Bring Your Own Device (BYOD) policy: Guidelines for using personal smartphones for business and maintaining data separation.
Tools, Law, and Incident Response
Module 4: Cybersecurity within the Microsoft 365 Environment
-
Authentication and verification: Practical implementation of Multi-Factor Authentication (MFA/2FA) for secure account access.
-
Secure data sharing: Managing file and folder permissions in OneDrive and SharePoint (avoiding broad "anyone with the link" access).
-
Communication and collaboration: Safely utilizing Microsoft Teams (managing external guests, controlling shared files).
Module 5: Personal Data Protection and GDPR in Practice
-
Information classification: Distinguishing between public, confidential, sensitive, and personal data.
-
GDPR in daily operations: Identifying common errors that lead to personal data breaches (e.g., misdirected e-mails, failure to use BCC).
-
Data sharing and disposal: Protocols for securely transferring information to third parties and permanently destroying documents.
Module 6: Responding to Security Incidents
-
Incident identification: Recognizing what constitutes a breach (lost devices, ransomware infections, accidental phishing link clicks).
-
Reporting procedures: Determining who to notify and the required timeframe (involving the IT Helpdesk, Security Officer, and Data Protection Officer).
-
Golden rules of response: Isolating the device from the network, maintaining composure, and strictly avoiding improvised "fixes" or evidence deletion.
Requirements
-
Fundamental proficiency with computers and web browsers.
-
Routine engagement with a standard office setting (e-mail, messaging applications, document processing).
-
No specialized IT expertise is necessary – all technical concepts are presented through the perspective of business value and routine processes.
Target Audience
- All office and administrative staff, along with mid-level managers, regardless of their specific department.
- This training is especially advisable for employees working in hybrid or fully remote arrangements.
- Regular users of the Microsoft 365 ecosystem.
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
get to understand more about the product and some key differences between RHDS and open source OpenLDAP.
Jackie Xie - Westpac Banking Corporation
Course - 389 Directory Server for Administrators
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions