Course Outline
Core Concepts, Social Engineering, and the Operational Environment
Module 1: Cybersecurity Fundamentals for Staff
-
Threat overview: Understanding what cybersecurity entails and why every employee plays a critical role.
-
Digital hygiene and credential management: Crafting robust passwords, leveraging password managers, and adhering to the unique-password-per-service rule.
-
Clear desk and clear screen protocols: Ensuring physical information security within office spaces.
Module 2: Phishing and Social Engineering – Threat Recognition
-
The psychology of attacks: Exploring social engineering and why cybercriminals exploit urgency, fear, or authority (such as in CEO Fraud and BEC).
-
Dissecting phishing: Analyzing message headers, obscured links, and harmful attachments through exercises based on real-world examples.
-
Additional attack vectors: Examining vishing (voice-based phishing) and smishing (SMS-based phishing).
Module 3: Secure Remote and Mobile Operations
-
Network security: The risks of public Wi-Fi networks (e.g., in cafes or transit) and the correct use of VPNs.
-
Device protection: Implementing disk encryption, enforcing screen locks, and avoiding unauthorized USB drives.
-
Bring Your Own Device (BYOD) policies: Guidelines for using personal smartphones for business and maintaining data separation.
Tools, Regulatory Compliance, and Incident Management
Module 4: Cybersecurity within the Microsoft 365 Ecosystem
-
Authentication and verification: Practical application of Multi-Factor Authentication (MFA/2FA) for secure account access.
-
Secure data exchange: Managing permissions for files and folders in OneDrive and SharePoint to avoid public link access.
-
Collaborative communication: Secure utilization of Microsoft Teams, including managing external guests and shared files.
Module 5: Personal Data Protection and GDPR Application
-
Data classification: Distinguishing between public, confidential, sensitive, and personal data types.
-
GDPR in daily operations: Identifying common errors that lead to data leaks, such as incorrect email recipients or improper use of BCC.
-
Data handling and disposal: Protocols for securely transferring information to third parties and permanently deleting documents.
Module 6: Managing Security Incidents
-
Incident recognition: Defining what constitutes a breach, including lost devices, ransomware attacks, or phishing link clicks.
-
Reporting workflows: Identifying the correct contacts and timelines, including the roles of IT Helpdesk, Security Plenipotentiary, and Data Protection Officer.
-
Immediate response protocols: Disconnecting devices from the network, maintaining composure, and strictly avoiding unauthorized repairs or evidence removal.
Requirements
-
Essential proficiency with computers and web browsers.
-
Regular use of standard office tools, including e-mail, messaging applications, and document processing software.
-
No specialized IT background is necessary, as all technical concepts are presented through the perspective of business value and routine operational processes.
Target Audience
- Office and administrative staff, along with mid-level managers, from any department.
- Strongly recommended for employees engaged in hybrid or fully remote work arrangements.
- Regular users of the Microsoft 365 ecosystem.
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
get to understand more about the product and some key differences between RHDS and open source OpenLDAP.
Jackie Xie - Westpac Banking Corporation
Course - 389 Directory Server for Administrators
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions