Course Outline
Foundations, Social Engineering, and the Work Environment
Module 1: Cybersecurity Basics for Employees
-
Understanding threats: The definition of cybersecurity and the critical role of every employee in maintaining it.
-
Digital hygiene and password management: Strategies for creating strong passwords, utilizing password managers, and adhering to the unique credential rule.
-
Clear desk and clear screen policies: Maintaining physical information security within office spaces.
Module 2: Phishing and Social Engineering – Threat Recognition
-
Attack psychology: An overview of social engineering and why cybercriminals exploit urgency, fear, or perceived authority (e.g., CEO Fraud, BEC).
-
Phishing mechanics: Techniques for analyzing message headers, hidden links, and malicious attachments, supported by exercises using real-world examples.
-
Additional attack vectors: Covering vishing (voice phishing) and smishing (SMS phishing).
Module 3: Secure Remote and Mobile Work
-
Network security: The risks associated with public Wi-Fi networks (e.g., in cafes or transit) and correct VPN implementation.
-
Device protection: Utilizing disk encryption, screen locks, and avoiding unverified USB drives.
-
BYOD policies: Guidelines for using personal smartphones for business tasks and maintaining data separation.
Tools, Law, and Incident Response
Module 4: Cybersecurity in the Microsoft 365 Environment
-
Authentication and verification: Practical implementation of Multi-Factor Authentication (MFA/2FA) for secure account access.
-
Secure data sharing: Managing permissions for files and folders in OneDrive and SharePoint, specifically avoiding broad "anyone with the link" access.
-
Communication and collaboration: Secure protocols for Microsoft Teams, including managing external guests and controlling shared files.
Module 5: Personal Data Protection and GDPR in Practice
-
Information classification: Distinguishing between public, confidential, sensitive, and personal data.
-
GDPR in daily operations: Identifying common errors that lead to data breaches, such as incorrect recipient selection or neglecting BCC usage.
-
Data lifecycle management: Protocols for secure third-party data transfer and permanent document deletion.
Module 6: Responding to Security Incidents
-
Identifying incidents: Recognizing signs of a breach, such as lost devices, ransomware infection, or phishing clicks.
-
Reporting protocols: Understanding the reporting hierarchy, timeframes, and the roles of the IT Helpdesk, Security Plenipotentiary, and Data Protection Officer.
-
Immediate response rules: Disconnecting affected devices, maintaining composure, and strictly avoiding unauthorized remediation attempts or evidence destruction.
Requirements
-
Fundamental proficiency with computers and web browsers.
-
Regular engagement with standard office workflows, including e-mail, messaging applications, and document management.
-
No specialized IT background is necessary, as all technical concepts are contextualized through business value and everyday operational processes.
Target Audience
- Office and administrative staff, along with mid-level management, across all departments.
- Highly recommended for hybrid or fully remote workforce members.
- Routine users of the Microsoft 365 ecosystem.
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
get to understand more about the product and some key differences between RHDS and open source OpenLDAP.
Jackie Xie - Westpac Banking Corporation
Course - 389 Directory Server for Administrators
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions