Course Outline
Core Concepts, Social Engineering, and Workplace Context
Module 1: Cybersecurity Essentials for Staff
-
Understanding threats: Defining cybersecurity and explaining the critical role of every employee.
-
Digital hygiene and credential management: Crafting robust passwords, utilizing password managers, and adhering to unique password rules per service.
-
Clear desk and screen policies: Ensuring physical information security within office spaces.
Module 2: Phishing and Social Engineering – Identifying Threats
-
The psychology behind attacks: Explaining social engineering and why attackers exploit urgency, fear, or authority (e.g., CEO Fraud, BEC).
-
Dissecting phishing messages: Analyzing headers, concealed links, and malicious attachments (using authentic case studies).
-
Additional attack vectors: Exploring vishing (voice-based) and smishing (SMS-based) tactics.
Module 3: Securing Remote and Mobile Operations
-
Network security: Highlighting the risks of public Wi-Fi (in venues like cafes or transit) and demonstrating proper VPN usage.
-
Device safeguards: Implementing disk encryption, screen locks, and avoiding unverified USB storage.
-
BYOD protocols: Guidelines for using personal smartphones for work and ensuring data separation.
Tools, Regulatory Compliance, and Incident Management
Module 4: Security within the Microsoft 365 Ecosystem
-
Access and verification: Practical implementation of Multi-Factor Authentication (MFA/2FA) for secure logins.
-
Safe data collaboration: Managing permissions in OneDrive and SharePoint to prevent accidental public access via links.
-
Secure communication: Best practices for using Microsoft Teams, including managing external guests and shared content.
Module 5: Practical Application of GDPR and Data Protection
-
Data classification: Distinguishing between public, confidential, sensitive, and personal information.
-
GDPR in daily workflows: Avoiding common errors that lead to data breaches, such as incorrect recipients or neglecting BCC.
-
Data lifecycle management: Protocols for securely transferring information to third parties and permanently disposing of documents.
Module 6: Managing Security Incidents
-
Recognizing breaches: Identifying events such as lost devices, ransomware infections, or clicks on malicious links.
-
Escalation procedures: Determining the correct contacts (IT Helpdesk, Security Plenipotentiary, DPO) and reporting deadlines.
-
Immediate response principles: Isolating affected devices, maintaining composure, and avoiding unauthorized repairs or evidence destruction.
Requirements
-
Foundational proficiency with computers and web browsers.
-
Routine engagement with standard office tools, including email, messaging applications, and document processing software.
-
No specialized IT background is necessary; all technical concepts are presented through the perspective of business impact and daily workflows.
Intended Audience
- Office and administrative staff, along with middle management, across all departments.
- Strongly advised for hybrid or fully remote personnel.
- Regular users of the Microsoft 365 ecosystem.
Custom Corporate Training
Training solutions designed exclusively for businesses.
- Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
- Flexible Schedule: Dates and times adapted to your team's agenda.
- Format: Online (live), In-company (at your offices), or Hybrid.
Price per private group, online live training, starting from 2600 € + VAT*
Contact us for an exact quote and to hear our latest promotions
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
get to understand more about the product and some key differences between RHDS and open source OpenLDAP.
Jackie Xie - Westpac Banking Corporation
Course - 389 Directory Server for Administrators
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions