Course Outline
Core Concepts, Social Engineering, and Workplace Context
Module 1: Cybersecurity Fundamentals for Staff
-
Understanding threats: An introduction to cybersecurity and why every employee plays a crucial role.
-
Digital hygiene and password security: Crafting robust passwords, utilizing password managers, and adhering to the "unique password for each service" principle.
-
Clear desk and clear screen protocols: Ensuring physical information security within office spaces.
Module 2: Phishing and Social Engineering – Identifying Threats
-
The psychological aspects of attacks: Understanding social engineering and why cybercriminals exploit urgency, fear, or authority (such as CEO Fraud and BEC).
-
Analyzing phishing: Techniques for examining message headers, concealed links, and malicious attachments, supported by exercises based on real-world examples.
-
Additional attack methods: Vishing (voice phishing) and Smishing (SMS phishing).
Module 3: Securing Remote and Mobile Work
-
Network security: The risks associated with public Wi-Fi networks (in cafes, on trains) and the proper use of VPNs.
-
Device security: Disk encryption, implementing screen locks, and avoiding unverified USB drives.
-
BYOD policies: Guidelines for using personal smartphones for business and maintaining data separation.
Tools, Regulatory Compliance, and Incident Response
Module 4: Cybersecurity within Microsoft 365
-
Authentication and verification: Practical application of Multi-Factor Authentication (MFA/2FA) for secure account access.
-
Secure data exchange: Managing file and folder permissions in OneDrive and SharePoint to avoid unrestricted "anyone with the link" access.
-
Collaboration and communication: Secure utilization of Microsoft Teams, including managing external guests and controlling shared files.
Module 5: Data Privacy and GDPR in Action
-
Data classification: Distinguishing between public, confidential, sensitive, and personal data.
-
GDPR in daily operations: Common errors that lead to personal data leaks, such as emailing the wrong recipient or neglecting BCC.
-
Data handling and disposal: Protocols for secure information transfer to third parties and the permanent deletion of documents.
Module 6: Handling Security Incidents
-
Recognizing incidents: Defining what constitutes a breach, such as losing a device, ransomware infection, or accidental clicks on phishing links.
-
Reporting mechanisms: Identifying who to notify and the required timeframes, including the roles of the IT Helpdesk, Security Officer, and Data Protection Officer.
-
Essential response rules: Disconnecting devices from the network, maintaining composure, and strictly avoiding DIY fixes or the removal of evidence.
Requirements
-
Fundamental proficiency with computers and web browsers.
-
Regular use of standard office environments, including email, messaging applications, and document processing tools.
-
No prior specialized IT knowledge is necessary; all technical concepts are presented through the perspective of business value and routine processes.
Target Audience
- Office and administrative staff, as well as mid-level managers, across all departments.
- Especially recommended for hybrid or fully remote workforce members.
- Daily users of the Microsoft 365 ecosystem.
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
get to understand more about the product and some key differences between RHDS and open source OpenLDAP.
Jackie Xie - Westpac Banking Corporation
Course - 389 Directory Server for Administrators
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions