Course Outline
Basics, Social Engineering, and the Workplace
Module 1: Employee Cybersecurity Fundamentals
-
Understanding threats: A definition of cybersecurity and the critical role of every employee.
-
Digital hygiene and password management: Crafting strong passwords, leveraging password managers, and adhering to the "unique password per service" standard.
-
Clear desk and clear screen protocols: Ensuring physical information security within office spaces.
Module 2: Phishing and Social Engineering – Spotting the Threats
-
The psychology of attacks: Understanding social engineering and why cybercriminals exploit urgency, fear, or authority (e.g., CEO Fraud, BEC).
-
Deconstructing phishing: Analyzing message headers, hidden links, and malicious attachments using real-world examples.
-
Additional attack vectors: Recognizing Vishing (voice-based phishing) and Smishing (SMS-based phishing).
Module 3: Secure Remote and Mobile Operations
-
Network safety: The risks of public Wi-Fi (cafes, transit) and correct VPN usage.
-
Device security: Implementing disk encryption, screen locks, and avoiding unknown USB drives.
-
BYOD policies: Guidelines for using personal devices for business and maintaining data separation.
Tools, Regulations, and Incident Management
Module 4: Cybersecurity within Microsoft 365
-
Authentication: Practical implementation of Multi-Factor Authentication (MFA/2FA) for account access.
-
Secure data exchange: Managing permissions in OneDrive and SharePoint (avoiding "anyone with the link" access).
-
Collaboration: Secure practices in Microsoft Teams, including managing external guests and shared files.
Module 5: Personal Data Protection and GDPR Application
-
Data classification: Distinguishing between public, confidential, sensitive, and personal data.
-
GDPR in daily tasks: Avoiding common errors that lead to data breaches (e.g., misdirected emails, not using BCC).
-
Data handling: Best practices for securely transferring information to third parties and permanently disposing of documents.
Module 6: Managing Security Incidents
-
Recognizing incidents: Identifying breaches such as lost devices, ransomware, or accidental phishing clicks.
-
Reporting workflow: Knowing whom to contact and the required timeframes (roles of IT Helpdesk, Security Officer, and Data Protection Officer).
-
Immediate response rules: Isolating affected devices, staying calm, and strictly avoiding improvised fixes or evidence deletion.
Requirements
-
Basic proficiency with computers and web browsers.
-
Routine experience with standard office tools, such as e-mail, messaging apps, and document editing software.
-
No specialized IT background is necessary—technical concepts are presented through the perspective of business value and daily operations.
Target Audience
- Office and administrative staff, as well as mid-level management, from any department.
- Highly recommended for hybrid or fully remote employees.
- Regular users of the Microsoft 365 ecosystem.
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
get to understand more about the product and some key differences between RHDS and open source OpenLDAP.
Jackie Xie - Westpac Banking Corporation
Course - 389 Directory Server for Administrators
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions