Course Outline
Core Concepts, Social Engineering, and the Workplace
Module 1: Employee-Focused Cybersecurity Fundamentals
-
Understanding threats: Defining cybersecurity and highlighting the critical role of every employee.
-
Digital hygiene and password management: Constructing robust passwords, leveraging password managers, and adhering to the "unique password per service" principle.
-
Clear desk and screen policies: Maintaining physical information security within office spaces.
Module 2: Detecting Phishing and Social Engineering Threats
-
The psychology behind attacks: Exploring social engineering and why cybercriminals exploit urgency, fear, or perceived authority (e.g., CEO Fraud, BEC).
-
Deconstructing phishing: Analyzing message headers, concealed links, and malicious attachments through exercises based on real-world examples.
-
Additional attack vectors: Covering vishing (voice-based phishing) and smishing (SMS-based phishing).
Module 3: Securing Remote and Mobile Workflows
-
Network security: Explaining the risks of public Wi-Fi networks (such as those in cafes or transit) and demonstrating proper VPN usage.
-
Device protection: Implementing disk encryption, enforcing screen locks, and avoiding untrusted USB drives.
-
Bring Your Own Device (BYOD) policy: Establishing guidelines for using personal smartphones for business and ensuring data separation.
Tools, Compliance, and Incident Handling
Module 4: Cybersecurity within the Microsoft 365 Ecosystem
-
Authentication and verification: Practical application of Multi-Factor Authentication (MFA/2FA) for securing account access.
-
Secure data sharing: Managing file and folder permissions in OneDrive and SharePoint to prevent unauthorized "anyone with the link" access.
-
Communication and collaboration: Secure practices in Microsoft Teams, including inviting external guests and managing shared file controls.
Module 5: Practical GDPR and Personal Data Protection
-
Information classification: Differentiating between public, confidential, sensitive, and personal data.
-
GDPR in daily operations: Addressing common errors that lead to data breaches, such as emailing the wrong recipient or neglecting to use BCC.
-
Data sharing and disposal: Following rules for secure third-party transfers and the permanent deletion of documents.
Module 6: Handling Security Incidents
-
Incident recognition: Identifying breaches, such as lost devices, ransomware infections, or accidental clicks on phishing links.
-
Reporting workflows: Determining who to notify and the required timeframes, including the roles of the IT Helpdesk, Security Officer, and Data Protection Officer.
-
Response best practices: Disconnecting devices from the network, maintaining composure, and strictly avoiding unauthorized "fixes" or destruction of evidence.
Requirements
-
Proficiency with basic computer operations and web browsers.
-
Routine engagement with standard office tools, such as email clients, messaging applications, and document processing software.
-
No prior specialized IT expertise is needed, as all technical concepts are contextualized through business value and daily workflows.
Target Audience
- Office and administrative staff across all departments, as well as mid-level management.
- Professionals working in hybrid or fully remote settings, for whom this training is especially recommended.
- Regular users of the Microsoft 365 ecosystem.
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
get to understand more about the product and some key differences between RHDS and open source OpenLDAP.
Jackie Xie - Westpac Banking Corporation
Course - 389 Directory Server for Administrators
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions