Course Outline
Foundations, Social Engineering, and Work Environment
Module 1: Cybersecurity Fundamentals for Employees
-
Threat overview: Understanding cybersecurity and the critical role of every employee.
-
Digital hygiene and password strategy: Developing robust passwords, leveraging password managers, and adhering to the "unique password per service" principle.
-
Clear desk and clear screen protocols: Managing physical information security within office spaces.
Module 2: Phishing and Social Engineering – Identifying Threats
-
Attack psychology: Explaining social engineering and why cybercriminals exploit urgency, fear, or authority (CEO Fraud, BEC).
-
Phishing dissection: Analyzing message headers, concealed links, and malicious attachments (using exercises derived from real-world examples).
-
Additional attack channels: Vishing (voice-based phishing) and Smishing (SMS-based phishing).
Module 3: Securing Remote and Mobile Operations
-
Network safety: Understanding the risks of public Wi-Fi (cafes, transit) and the correct implementation of VPNs.
-
Device security: Applying disk encryption, screen locks, and avoiding unknown USB peripherals.
-
Bring Your Own Device (BYOD) governance: Guidelines for using personal smartphones for business and ensuring data segregation.
Tools, Regulations, and Incident Handling
Module 4: Cybersecurity within the Microsoft 365 Ecosystem
-
Authentication and verification: Implementing Multi-Factor Authentication (MFA/2FA) for secure account access.
-
Safe data exchange: Controlling file and folder permissions in OneDrive and SharePoint (preventing "anyone with the link" exposure).
-
Collaboration security: Safely utilizing Microsoft Teams (managing external guests and shared file controls).
Module 5: Personal Data Protection and GDPR Application
-
Data classification: Distinguishing between public, confidential, sensitive, and personal data.
-
GDPR in daily operations: Avoiding common errors that lead to personal data leaks (e.g., incorrect email recipients, misuse of BCC).
-
Data lifecycle management: Protocols for secure third-party data transfer and permanent document deletion.
Module 6: Handling Security Incidents
-
Breach identification: Recognizing incidents such as lost devices, ransomware infections, or accidental phishing clicks.
-
Escalation procedures: Determining the correct reporting chain and timelines (involving IT Helpdesk, Security Plenipotentiary, and Data Protection Officer).
-
Critical response guidelines: Isolating the device from the network, maintaining composure, and strictly avoiding unauthorized repairs or evidence deletion.
Requirements
-
Foundational proficiency with computers and web browsers.
-
Routine engagement with standard office tools (e-mail, messaging applications, document management).
-
No specialized IT expertise is necessary; all technical topics are framed through business impact and daily workflows.
Target Audience
- Office and administrative staff, as well as mid-level managers, across all departments.
- Especially recommended for hybrid or fully remote personnel
- Regular users of the Microsoft 365 ecosystem.
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
get to understand more about the product and some key differences between RHDS and open source OpenLDAP.
Jackie Xie - Westpac Banking Corporation
Course - 389 Directory Server for Administrators
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions