Course Outline
Foundations, Social Engineering, and the Work Environment
Module 1: Cybersecurity Basics for Employees
-
Introduction to threats: What cybersecurity is and why every employee matters.
-
Digital hygiene and password management: Creating strong passwords, using password managers, and the "one password per service" rule.
-
Clear desk and clear screen policies: Physical information security in the office space.
Module 2: Phishing and Social Engineering – How to Recognize Threats
-
The psychology of an attack: What social engineering is and why cybercriminals rely on urgency, fear, or authority (CEO Fraud, BEC).
-
The anatomy of phishing: How to analyze message headers, hidden links, and malicious attachments (exercises based on authentic examples).
-
Other attack vectors: Vishing (voice phishing) and Smishing (SMS phishing).
Module 3: Secure Remote and Mobile Work
-
Network security: Why public Wi-Fi networks (in cafes, trains) are dangerous and how to properly use a VPN.
-
Device protection: Disk encryption, screen locks, and avoiding unknown USB drives.
-
Bring Your Own Device (BYOD) policy: Rules for using private smartphones for business purposes and data separation.
Tools, Law, and Incident Response
Module 4: Cybersecurity in the Microsoft 365 Environment
-
Logging in and verification: Practical application of Multi-Factor Authentication (MFA/2FA) for account access.
-
Secure data sharing: Managing file and folder permissions in OneDrive and SharePoint (avoiding "anyone with the link" access).
-
Communication and collaboration: Secure use of Microsoft Teams (inviting external guests, controlling shared files).
Module 5: Personal Data Protection and GDPR in Practice
-
Information classification: How to distinguish public data from confidential, sensitive, and personal data.
-
GDPR in daily work: Common mistakes leading to personal data breaches (e.g., sending emails to the wrong recipient, failing to use BCC).
-
Sharing and destroying data: Rules for securely transferring information to third parties and permanently deleting documents.
Module 6: Responding to Security Incidents
-
Incident identification: What constitutes a breach (losing a phone, ransomware locking a computer, clicking a phishing link).
-
Reporting procedures: Who to inform and within what timeframe (the role of IT Helpdesk, Security Plenipotentiary, and Data Protection Officer).
-
Golden rules of reaction: Disconnecting the device from the network, avoiding panic, and strictly prohibiting DIY "fixes" or deleting evidence.
Requirements
-
Basic computer and web browser skills.
-
Daily interaction with a standard office environment (e-mail, messaging apps, document processing).
-
No specialized IT knowledge is required – all technical concepts are explained through the lens of business value and everyday processes.
Audience
- All office and administrative employees, as well as mid-level management, regardless of their department.
- This training is particularly highly recommended for hybrid or fully remote workers
- Everyday users of the Microsoft 365 ecosystem.
Custom Corporate Training
Training solutions designed exclusively for businesses.
- Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
- Flexible Schedule: Dates and times adapted to your team's agenda.
- Format: Online (live), In-company (at your offices), or Hybrid.
Price per private group, online live training, starting from 3200 € + VAT*
Contact us for an exact quote and to hear our latest promotions
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
get to understand more about the product and some key differences between RHDS and open source OpenLDAP.
Jackie Xie - Westpac Banking Corporation
Course - 389 Directory Server for Administrators
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions