Course Outline
Basics, Social Engineering, and the Operational Environment
Module 1: Core Cybersecurity Principles for Staff
-
Overview of threats: Understanding cybersecurity and the critical role every employee plays.
-
Digital hygiene and credential management: Developing robust passwords, leveraging password managers, and adhering to the unique password per service principle.
-
Clear desk and clear screen protocols: Ensuring physical information security within office premises.
Module 2: Phishing and Social Engineering – Threat Recognition
-
The psychology behind attacks: Defining social engineering and understanding why cybercriminals exploit urgency, fear, or authority (such as in CEO Fraud or BEC).
-
Deconstructing phishing: Techniques for analyzing message headers, concealed links, and malicious attachments, supported by exercises using real-world examples.
-
Additional attack channels: Exploring vishing (voice phishing) and smishing (SMS phishing).
Module 3: Securing Remote and Mobile Operations
-
Network security: Understanding the risks of public Wi-Fi networks (in venues like cafes or transit) and the proper utilization of VPNs.
-
Device safeguarding: Implementing disk encryption, screen locks, and avoiding the use of unidentified USB drives.
-
BYOD policies: Guidelines for using personal smartphones for business activities and maintaining data segregation.
Tools, Regulations, and Incident Management
Module 4: Cybersecurity within the Microsoft 365 Ecosystem
-
Authentication and verification: Practical implementation of Multi-Factor Authentication (MFA/2FA) for secure account access.
-
Secure data distribution: Managing file and folder permissions in OneDrive and SharePoint, specifically avoiding unrestricted 'anyone with the link' access.
-
Communication and collaboration: Secure practices for Microsoft Teams, including inviting external guests and managing shared file access.
Module 5: Data Privacy and GDPR Application
-
Data classification: Differentiating between public information, confidential data, sensitive records, and personal data.
-
GDPR in everyday workflows: Preventing common errors that lead to personal data leaks, such as incorrect email recipients or failure to use BCC.
-
Data lifecycle management: Protocols for securely transferring information to third parties and permanently disposing of documents.
Module 6: Managing Security Incidents
-
Identifying incidents: Defining breaches, including lost devices, ransomware infections, or accidental phishing link clicks.
-
Reporting workflows: Determining whom to notify and the required timelines, involving the IT Helpdesk, Security Representative, and Data Protection Officer.
-
Key reaction principles: Isolating devices from the network, maintaining composure, and strictly prohibiting unauthorized troubleshooting or deletion of evidence.
Requirements
-
Fundamental proficiency with computers and web browsers.
-
Routine engagement with standard office workflows, including email, messaging platforms, and document management.
-
No specialized IT expertise is necessary; all technical concepts are presented through the perspective of business utility and everyday operational processes.
Target Audience
- Office personnel and administrative staff, along with mid-level management across all departments.
- Highly recommended for professionals engaged in hybrid or fully remote work arrangements.
- Regular users operating within the Microsoft 365 ecosystem.
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
get to understand more about the product and some key differences between RHDS and open source OpenLDAP.
Jackie Xie - Westpac Banking Corporation
Course - 389 Directory Server for Administrators
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions