Course Outline
Foundations, Social Engineering, and the Work Environment
Module 1: Cybersecurity Basics for Employees
-
Introduction to threats: Understanding cybersecurity and the critical role of every employee.
-
Digital hygiene and password management: Crafting strong passwords, utilizing password managers, and adhering to the "unique password per service" principle.
-
Clear desk and clear screen policies: Ensuring physical information security within office spaces.
Module 2: Phishing and Social Engineering – How to Recognize Threats
-
The psychology of attacks: Defining social engineering and understanding why cybercriminals exploit urgency, fear, or authority (e.g., CEO Fraud, BEC).
-
Anatomy of phishing: Techniques for analyzing message headers, hidden links, and malicious attachments, supported by exercises based on real-world examples.
-
Additional attack vectors: Overview of vishing (voice phishing) and smishing (SMS phishing).
Module 3: Secure Remote and Mobile Work
-
Network security: The risks of public Wi-Fi networks (such as those in cafes or on trains) and the correct usage of VPNs.
-
Device protection: Implementing disk encryption, screen locks, and protocols for avoiding unknown USB drives.
-
Bring Your Own Device (BYOD) policy: Guidelines for using personal smartphones for business and ensuring data separation.
Tools, Law, and Incident Response
Module 4: Cybersecurity in the Microsoft 365 Environment
-
Authentication and verification: Practical application of Multi-Factor Authentication (MFA/2FA) for secure account access.
-
Secure data sharing: Managing file and folder permissions in OneDrive and SharePoint to avoid unsecured "anyone with the link" access.
-
Communication and collaboration: Best practices for secure use of Microsoft Teams, including inviting external guests and controlling shared files.
Module 5: Personal Data Protection and GDPR in Practice
-
Information classification: Distinguishing between public, confidential, sensitive, and personal data.
-
GDPR in daily workflows: Identifying common errors that lead to personal data breaches, such as emailing the wrong recipient or failing to use BCC.
-
Sharing and destroying data: Protocols for secure information transfer to third parties and permanent document deletion.
Module 6: Responding to Security Incidents
-
Incident identification: Recognizing breaches, such as lost devices, ransomware infections, or accidental clicks on phishing links.
-
Reporting procedures: Determining who to notify and the required timeframe, highlighting the roles of the IT Helpdesk, Security Plenipotentiary, and Data Protection Officer.
-
Golden rules of response: Isolating the device from the network, maintaining composure, and strictly avoiding DIY fixes or the deletion of evidence.
Requirements
-
Familiarity with basic computer operations and web browsing.
-
Regular use of standard office tools, including email, messaging applications, and document processing software.
-
No prior specialized IT knowledge is necessary, as all technical concepts are explained through the perspective of business value and everyday workflows.
Target Audience
- Office staff, administrative personnel, and mid-level management across all departments.
- Strongly recommended for employees working in hybrid or fully remote environments.
- Regular users of the Microsoft 365 ecosystem.
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
get to understand more about the product and some key differences between RHDS and open source OpenLDAP.
Jackie Xie - Westpac Banking Corporation
Course - 389 Directory Server for Administrators
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions