Get in Touch
 Duration 14 hours

Course Outline

Foundations, Social Engineering, and the Work Environment

Module 1: Core Cybersecurity Concepts for Employees

  • Understanding threats: Defining cybersecurity and explaining the critical role of every employee in maintaining security.

  • Digital hygiene and password management: Strategies for creating strong passwords, utilizing password managers, and adhering to the "unique password per service" principle.

  • Clear desk and screen policies: Ensuring physical information security within office spaces.

Module 2: Phishing and Social Engineering – Identifying Threats

  • The psychology behind attacks: Explaining social engineering and why cybercriminals exploit urgency, fear, or authority (e.g., CEO Fraud, BEC).

  • Analyzing phishing: Techniques for examining message headers, hidden links, and malicious attachments, supported by exercises based on real-world examples.

  • Additional attack vectors: Covering Vishing (voice phishing) and Smishing (SMS phishing).

Module 3: Securing Remote and Mobile Work

  • Network security: Highlighting the risks of public Wi-Fi networks (such as those in cafes or on trains) and demonstrating the correct use of VPNs.

  • Device protection: Implementing disk encryption, screen locks, and avoiding unknown USB drives.

  • Bring Your Own Device (BYOD) policy: Guidelines for using personal smartphones for business and maintaining data separation.


Tools, Regulatory Compliance, and Incident Response

Module 4: Cybersecurity Within the Microsoft 365 Ecosystem

  • Authentication and verification: Practical implementation of Multi-Factor Authentication (MFA/2FA) for secure account access.

  • Secure data sharing: Managing file and folder permissions in OneDrive and SharePoint, specifically avoiding "anyone with the link" access risks.

  • Communication and collaboration: Secure practices for using Microsoft Teams, including managing external guests and controlling shared files.

Module 5: Personal Data Protection and GDPR in Practice

  • Information classification: Distinguishing between public, confidential, sensitive, and personal data.

  • GDPR in daily workflows: Identifying common errors that lead to personal data breaches, such as sending emails to incorrect recipients or failing to use BCC.

  • Data sharing and disposal: Rules for securely transferring information to third parties and permanently deleting documents.

Module 6: Responding to Security Incidents

  • Identifying incidents: Defining what constitutes a breach, including lost devices, ransomware infections, or accidental clicks on phishing links.

  • Reporting protocols: Determining who to notify and the required timeframes, including the roles of the IT Helpdesk, Security Plenipotentiary, and Data Protection Officer.

  • Essential response rules: Disconnecting affected devices from the network, remaining calm, and strictly avoiding DIY "fixes" or deletion of evidence.

Requirements

  • Fundamental proficiency in computer usage and web browsing.

  • Regular engagement with standard office tools, including email, messaging applications, and document management software.

  • No specialized IT background is necessary; all technical concepts are presented through the context of business value and routine processes.

Target Audience

  • Office and administrative staff, along with mid-level managers, across all departments.
  • This training is highly recommended for those working in hybrid or fully remote settings.
  • Regular users of the Microsoft 365 ecosystem.

Testimonials (3)

Related Categories