Course Outline
Core Concepts, Social Engineering, and Workplace Security
Module 1: Fundamental Cybersecurity for Employees
-
Understanding threats: The definition of cybersecurity and the critical role of every employee.
-
Digital hygiene and credential management: Crafting robust passwords, utilizing password managers, and adhering to the "unique password per service" principle.
-
Clear desk and clear screen policies: Ensuring physical information security within the office.
Module 2: Phishing and Social Engineering – Identifying Threats
-
The psychology behind attacks: Understanding social engineering and why cybercriminals exploit urgency, fear, or authority (e.g., CEO Fraud, BEC).
-
Dissecting phishing: How to scrutinize message headers, concealed links, and malicious attachments (using exercises based on real-world examples).
-
Alternative attack vectors: Vishing (voice-based phishing) and Smishing (SMS-based phishing).
Module 3: Securing Remote and Mobile Operations
-
Network security: The risks associated with public Wi-Fi networks (such as those in cafes or transit) and the correct usage of VPNs.
-
Device security: Implementing disk encryption, screen locks, and avoiding unverified USB drives.
-
Bring Your Own Device (BYOD) policy: Guidelines for using personal smartphones for business and maintaining data separation.
Tools, Regulations, and Incident Response
Module 4: Cybersecurity within the Microsoft 365 Ecosystem
-
Authentication and verification: Practical application of Multi-Factor Authentication (MFA/2FA) for account security.
-
Secure data sharing: Managing permissions for files and folders in OneDrive and SharePoint (preventing accidental "anyone with the link" access).
-
Secure communication and collaboration: Best practices for using Microsoft Teams, including inviting external guests and managing shared files.
Module 5: Personal Data Protection and GDPR Application
-
Data classification: Distinguishing between public, confidential, sensitive, and personal data.
-
GDPR in daily operations: Common errors that lead to data breaches (e.g., misdirected emails, failure to use BCC).
-
Data sharing and disposal: Protocols for securely transferring information to third parties and permanently deleting documents.
Module 6: Managing Security Incidents
-
Identifying incidents: Defining what constitutes a breach (lost devices, ransomware infections, or clicking phishing links).
-
Reporting workflows: Identifying key contacts and timeframes for reporting (involving the IT Helpdesk, Security Representative, and Data Protection Officer).
-
Immediate response principles: Disconnecting affected devices, maintaining composure, and strictly avoiding unauthorized "fixes" or evidence destruction.
Requirements
-
Fundamental proficiency with computers and web browsers.
-
Regular engagement with standard office tools (email, messaging applications, document editing software).
-
No specialized IT expertise is necessary – all technical concepts are contextualized through business value and routine operational processes.
Target Audience
- Office staff, administrative personnel, and mid-level management across all departments.
- Strongly recommended for hybrid or fully remote professionals.
- Regular users of the Microsoft 365 ecosystem.
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
get to understand more about the product and some key differences between RHDS and open source OpenLDAP.
Jackie Xie - Westpac Banking Corporation
Course - 389 Directory Server for Administrators
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions