Course Outline
Core Concepts, Social Engineering, and the Workplace
Module 1: Cybersecurity Fundamentals for Staff
-
Understanding threats: Defining cybersecurity and explaining why every employee plays a critical role.
-
Digital hygiene and password strategy: Developing strong credentials, utilizing password managers, and adhering to unique password practices.
-
Clear desk and clear screen protocols: Implementing physical information security within the office space.
Module 2: Phishing and Social Engineering – Identifying Threats
-
The psychology behind attacks: Explaining social engineering and why cybercriminals exploit urgency, fear, or authority (including CEO Fraud and BEC).
-
Anatomy of phishing: Analyzing message headers, concealed links, and dangerous attachments through exercises using realistic examples.
-
Alternative attack channels: Covering Vishing (voice-based phishing) and Smishing (SMS-based phishing).
Module 3: Secure Remote and Mobile Operations
-
Network security: Discussing the risks of public Wi-Fi (in cafes or transit) and the correct use of VPNs.
-
Device safeguards: Implementing disk encryption, screen locks, and avoiding unknown USB drives.
-
Bring Your Own Device (BYOD) guidelines: Regulations for using personal smartphones for business and ensuring data separation.
Tools, Compliance, and Incident Management
Module 4: Cybersecurity within Microsoft 365
-
Authentication and verification: Practical application of Multi-Factor Authentication (MFA/2FA) for secure account access.
-
Secure data exchange: Managing permissions for files and folders in OneDrive and SharePoint to prevent unintended broad access.
-
Collaborative communication: Using Microsoft Teams securely, including managing external guests and controlling shared content.
Module 5: Personal Data Protection and GDPR Application
-
Data classification: Differentiating between public, confidential, sensitive, and personal information.
-
GDPR in daily workflows: Avoiding common errors that lead to data leaks, such as misaddressed emails or failure to use BCC.
-
Data handling and disposal: Rules for securely transferring information to third parties and permanently deleting documents.
Module 6: Managing Security Incidents
-
Recognizing breaches: Identifying incidents such as lost devices, ransomware infections, or accidental clicks on phishing links.
-
Reporting mechanisms: Clarifying who to notify and required timeframes, including the roles of the IT Helpdesk, Security Officer, and Data Protection Officer.
-
Immediate response guidelines: Isolating affected devices from the network, maintaining composure, and avoiding unauthorized fixes or evidence destruction.
Requirements
-
Fundamental proficiency with computers and web browsers.
-
Routine use of standard office tools, including email, messaging applications, and document processing software.
-
No specialized IT background is necessary; all technical concepts are presented from a business perspective, focusing on everyday operational processes.
Target Audience
- Administrative and office staff, as well as mid-level managers across all departments.
- Strongly recommended for employees engaged in hybrid or fully remote work.
- Daily users operating within the Microsoft 365 ecosystem.
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
get to understand more about the product and some key differences between RHDS and open source OpenLDAP.
Jackie Xie - Westpac Banking Corporation
Course - 389 Directory Server for Administrators
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions