Get in Touch
 Duration 14 hours

Course Outline

Foundations, Social Engineering, and the Workplace

Module 1: Cybersecurity Fundamentals for Staff

  • Understanding threats: Defining cybersecurity and explaining why every employee plays a critical role.

  • Digital hygiene and password management: Developing strong passwords, utilizing password managers, and adhering to the “one password per service” principle.

  • Clear desk and clear screen policies: Implementing physical information security within office spaces.

Module 2: Phishing and Social Engineering – Identifying Threats

  • The psychology of attacks: Explaining social engineering and why cybercriminals exploit urgency, fear, or authority (e.g., CEO Fraud, BEC).

  • Deconstructing phishing: Learning to analyze message headers, hidden links, and malicious attachments (using exercises based on real-world examples).

  • Additional attack vectors: Covering Vishing (voice phishing) and Smishing (SMS phishing).

Module 3: Secure Remote and Mobile Work

  • Network security: Discussing the risks of public Wi-Fi networks (in cafes, trains) and the correct use of VPNs.

  • Device protection: Implementing disk encryption, screen locks, and avoiding unknown USB drives.

  • Bring Your Own Device (BYOD) policy: Establishing rules for using personal smartphones for business purposes and ensuring data separation.


Tools, Legal Framework, and Incident Response

Module 4: Cybersecurity within the Microsoft 365 Ecosystem

  • Login and verification: Practicing the application of Multi-Factor Authentication (MFA/2FA) for secure account access.

  • Secure data sharing: Managing file and folder permissions in OneDrive and SharePoint (preventing “anyone with the link” access).

  • Communication and collaboration: Utilizing Microsoft Teams securely (managing external guests and controlling shared files).

Module 5: Personal Data Protection and GDPR in Practice

  • Information classification: Distinguishing between public data and confidential, sensitive, or personal data.

  • GDPR in daily workflows: Identifying common errors that lead to personal data breaches (e.g., emailing the wrong recipient, neglecting to use BCC).

  • Sharing and disposal of data: Following protocols for securely transferring information to third parties and permanently deleting documents.

Module 6: Responding to Security Incidents

  • Incident recognition: Defining what constitutes a breach (e.g., losing a phone, ransomware infection, or clicking a phishing link).

  • Reporting protocols: Determining who to notify and within what timeframe (involving the IT Helpdesk, Security Representative, and Data Protection Officer).

  • Key reaction rules: Disconnecting devices from the network, maintaining composure, and strictly avoiding unauthorized “fixes” or evidence removal.

Requirements

  • Proficiency with basic computer operations and web browsers.

  • Regular use of standard office tools (email, messaging applications, and document processing).

  • No prior specialized IT knowledge is needed – all technical concepts are presented through the perspective of business value and everyday workflows.

Target Audience

  • All office and administrative staff, as well as mid-level management, across all departments.
  • Especially recommended for hybrid or fully remote employees.
  • Regular users of the Microsoft 365 ecosystem.

Number of participants


Price per participant

Testimonials (3)

Upcoming Courses

Related Categories