Course Outline
Foundations, Social Engineering, and Work Environments
Module 1: Employee Cybersecurity Essentials
-
Overview of threats: Understanding the scope of cybersecurity and the critical role of every employee.
-
Digital hygiene and credential management: Crafting strong passwords, leveraging password managers, and adhering to the "unique password per service" principle.
-
Clear desk and screen protocols: Implementing physical information security measures within office spaces.
Module 2: Phishing and Social Engineering – Threat Recognition
-
The psychology behind attacks: Explaining social engineering and why cybercriminals exploit urgency, fear, or authority (e.g., CEO Fraud, BEC).
-
Anatomy of a phishing attempt: Analyzing message headers, concealed links, and malicious attachments through exercises based on real-world examples.
-
Additional attack vectors: Recognizing Vishing (voice-based) and Smishing (SMS-based) threats.
Module 3: Secure Remote and Mobile Operations
-
Network security: Understanding the risks of public Wi-Fi networks (in cafes, transit) and the proper use of VPNs.
-
Device safeguarding: Utilizing disk encryption, screen locks, and avoiding unverified USB drives.
-
Bring Your Own Device (BYOD) policies: Guidelines for using personal smartphones for business and maintaining data separation.
Tools, Regulatory Compliance, and Incident Management
Module 4: Security within the Microsoft 365 Ecosystem
-
Access and verification: Practical implementation of Multi-Factor Authentication (MFA/2FA) for account security.
-
Secure data exchange: Managing file and folder permissions in OneDrive and SharePoint (preventing broad "anyone with the link" access).
-
Collaboration and communication: Secure utilization of Microsoft Teams (managing external guests and controlling shared files).
Module 5: Personal Data Protection and Practical GDPR Compliance
-
Data classification: Distinguishing between public, confidential, sensitive, and personal data.
-
GDPR in daily workflows: Identifying common errors that lead to data breaches (e.g., incorrect email recipients, neglecting BCC).
-
Data handling and disposal: Protocols for securely transferring information to third parties and permanently deleting documents.
Module 6: Security Incident Response
-
Incident recognition: Defining what constitutes a breach (lost devices, ransomware infections, or clicking phishing links).
-
Reporting mechanisms: Identifying the correct contacts and timelines (roles of IT Helpdesk, Security Officer, and Data Protection Officer).
-
Core response principles: Isolating the device from the network, maintaining composure, and strictly avoiding unauthorized "fixes" or evidence destruction.
Requirements
-
Fundamental computer and web browser proficiency.
-
Routine interaction with standard office tools (email, messaging platforms, document processing).
-
No specialized IT expertise is necessary – all technical concepts are presented through the perspective of business value and daily operational processes.
Target Audience
- All administrative and office personnel, as well as mid-level managers, across all departments.
- Especially recommended for hybrid or fully remote team members.
- Daily users of the Microsoft 365 ecosystem.
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
get to understand more about the product and some key differences between RHDS and open source OpenLDAP.
Jackie Xie - Westpac Banking Corporation
Course - 389 Directory Server for Administrators
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions