Get in Touch
 Duration 14 hours

Course Outline

Foundations, Social Engineering, and the Work Environment

Module 1: Cybersecurity Basics for Employees

  • Introduction to threats: Understanding cybersecurity and why every employee plays a crucial role.

  • Digital hygiene and password management: Creating robust passwords, using password managers, and the "one password per service" rule.

  • Clear desk and clear screen policies: Physical information security within the office space.

Module 2: Phishing and Social Engineering – How to Recognise Threats

  • The psychology of an attack: Understanding social engineering and why cybercriminals rely on urgency, fear, or authority (CEO Fraud, BEC).

  • The anatomy of phishing: How to analyse message headers, hidden links, and malicious attachments (exercises based on authentic examples).

  • Other attack vectors: Vishing (voice phishing) and Smishing (SMS phishing).

Module 3: Secure Remote and Mobile Work

  • Network security: Why public Wi-Fi networks (in cafes, trains) pose risks and how to properly use a VPN.

  • Device protection: Disk encryption, screen locks, and avoiding unknown USB drives.

  • Bring Your Own Device (BYOD) policy: Rules for using personal smartphones for business purposes and maintaining data separation.


Tools, Law, and Incident Response

Module 4: Cybersecurity in the Microsoft 365 Environment

  • Logging in and verification: Practical application of Multi-Factor Authentication (MFA/2FA) for account access.

  • Secure data sharing: Managing file and folder permissions in OneDrive and SharePoint (avoiding "anyone with the link" access).

  • Communication and collaboration: Secure use of Microsoft Teams (inviting external guests, controlling shared files).

Module 5: Personal Data Protection and GDPR in Practice

  • Information classification: How to distinguish public data from confidential, sensitive, and personal data.

  • GDPR in daily work: Common mistakes leading to personal data breaches (e.g., sending emails to the wrong recipient, failing to use BCC).

  • Sharing and destroying data: Rules for securely transferring information to third parties and permanently deleting documents.

Module 6: Responding to Security Incidents

  • Incident identification: What constitutes a breach (losing a phone, ransomware locking a computer, clicking a phishing link).

  • Reporting procedures: Who to inform and within what timeframe (the role of IT Helpdesk, Security Plenipotentiary, and Data Protection Officer).

  • Golden rules of reaction: Disconnecting the device from the network, avoiding panic, and strictly prohibiting DIY "fixes" or deleting evidence.

Requirements

  • Basic proficiency with computers and web browsers.

  • Routine interaction with a standard office environment (email, messaging apps, document processing).

  • No specialist IT knowledge is required – all technical concepts are explained through the lens of business value and everyday workflows.

Target Audience

  • All office and administrative staff, as well as mid-level management, regardless of their department.
  • This training is particularly highly recommended for hybrid or fully remote workers.
  • Regular users of the Microsoft 365 ecosystem.

Number of participants


Price per participant

Testimonials (3)

Provisional Upcoming Courses (Require 5+ participants)

Related Categories