Course Outline
Foundations, Social Engineering, and the Workplace Environment
Module 1: Cybersecurity Fundamentals for Staff
-
Overview of threats: Defining cybersecurity and explaining why every employee plays a vital role.
-
Digital hygiene and password strategy: Crafting strong passwords, leveraging password managers, and adhering to the "unique password for each service" principle.
-
Clear desk and screen protocols: Ensuring physical information security within the office space.
Module 2: Phishing and Social Engineering – Identifying Risks
-
The psychology behind attacks: Understanding social engineering and why cybercriminals exploit urgency, fear, or perceived authority (such as CEO Fraud or BEC).
-
Dissecting phishing: Analyzing message headers, concealed links, and harmful attachments (using exercises based on real-world examples).
-
Alternative attack vectors: Exploring Vishing (voice phishing) and Smishing (SMS phishing).
Module 3: Safe Remote and Mobile Operations
-
Network security: Explaining the risks of public Wi-Fi (in cafes, trains) and demonstrating the correct use of a VPN.
-
Device safeguarding: Implementing disk encryption, screen locks, and avoiding the use of unrecognized USB drives.
-
Bring Your Own Device (BYOD) policies: Guidelines for using personal smartphones for business and maintaining data segregation.
Tools, Regulations, and Incident Management
Module 4: Cybersecurity within the Microsoft 365 Ecosystem
-
Authentication and verification: Practical use of Multi-Factor Authentication (MFA/2FA) for account security.
-
Secure data exchange: Managing permissions for files and folders in OneDrive and SharePoint (preventing uncontrolled "anyone with the link" access).
-
Secure communication and collaboration: Best practices for using Microsoft Teams, including managing external guest invitations and shared files.
Module 5: Personal Data Protection and GDPR Application
-
Data classification: Distinguishing between public, confidential, sensitive, and personal data.
-
GDPR in daily operations: Addressing common errors that lead to data breaches (e.g., emailing the wrong recipient, neglecting to use BCC).
-
Data handling and disposal: Protocols for securely transferring information to third parties and permanently removing documents.
Module 6: Managing Security Incidents
-
Recognizing incidents: Defining what constitutes a breach (e.g., losing a phone, ransomware infection, clicking a phishing link).
-
Reporting mechanisms: Identifying the correct contacts and response timeframes (the roles of the IT Helpdesk, Security Officer, and Data Protection Officer).
-
Best response practices: Isolating the device from the network, maintaining composure, and strictly avoiding self-attempts to "fix" the issue or delete evidence.
Requirements
-
Foundational proficiency in using computers and web browsers.
-
Regular engagement with a standard office setup, including email, messaging platforms, and document management.
-
No specialized IT background is necessary – all technical concepts are contextualized through business relevance and daily operational processes.
Target Audience
- All office and administrative staff, as well as mid-level management, across all departments.
- Especially recommended for employees working in hybrid or fully remote configurations.
- Regular users of the Microsoft 365 ecosystem.
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
get to understand more about the product and some key differences between RHDS and open source OpenLDAP.
Jackie Xie - Westpac Banking Corporation
Course - 389 Directory Server for Administrators
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions