Get in Touch
 Duration 14 hours

Course Outline

Foundations, Social Engineering, and the Work Environment

Module 1: Employee-Focused Cybersecurity Basics

  • Understanding threats: The definition of cybersecurity and the critical role of every employee.

  • Digital hygiene and password management: Developing strong passwords, leveraging password managers, and adhering to the 'one password per service' principle.

  • Clear desk and clear screen policies: Ensuring physical information security within office spaces.

Module 2: Phishing and Social Engineering – Identifying Threats

  • The psychology of attacks: Understanding social engineering and why cybercriminals exploit urgency, fear, or authority (including CEO Fraud and BEC).

  • Deconstructing phishing: Analyzing message headers, hidden links, and malicious attachments through exercises based on real-world examples.

  • Alternative attack vectors: Vishing (voice phishing) and Smishing (SMS phishing).

Module 3: Secure Remote and Mobile Work

  • Network security: Understanding the risks of public Wi-Fi networks (such as those in cafes or on trains) and the correct use of VPNs.

  • Device protection: Implementing disk encryption, screen locks, and avoiding unknown USB drives.

  • Bring Your Own Device (BYOD) policy: Guidelines for using personal smartphones for business and maintaining data separation.


Tools, Law, and Incident Response

Module 4: Cybersecurity Within the Microsoft 365 Environment

  • Authentication and verification: Practical application of Multi-Factor Authentication (MFA/2FA) for secure account access.

  • Secure data sharing: Managing file and folder permissions in OneDrive and SharePoint, specifically avoiding 'anyone with the link' access.

  • Communication and collaboration: Secure practices in Microsoft Teams, including managing external guests and controlling shared files.

Module 5: Personal Data Protection and GDPR Application

  • Information classification: Distinguishing between public, confidential, sensitive, and personal data.

  • GDPR in daily operations: Common errors leading to personal data breaches, such as emailing the wrong recipient or failing to use BCC.

  • Data sharing and destruction: Protocols for securely transferring information to third parties and permanently deleting documents.

Module 6: Managing Security Incidents

  • Identifying incidents: Recognizing breaches, such as lost devices, ransomware infections, or accidental clicks on phishing links.

  • Reporting procedures: Knowing who to notify and the required timeframes (involving the IT Helpdesk, Security Plenipotentiary, and Data Protection Officer).

  • Key response principles: Disconnecting affected devices from the network, remaining calm, and strictly avoiding unauthorized 'fixes' or deletion of evidence.

Requirements

  • Familiarity with basic computer operations and web browsers.

  • Routine engagement with standard office environments, including e-mail, messaging applications, and document processing tools.

  • No specialized IT expertise is necessary; all technical concepts are presented through the perspective of business value and everyday workflows.

Target Audience

  • All office and administrative staff, as well as mid-level management, across various departments.
  • Highly recommended for hybrid or fully remote workers.
  • Daily users of the Microsoft 365 ecosystem.

Testimonials (3)

Related Categories