Course Outline
Core Concepts, Social Engineering, and Workplace Security
Module 1: Employee Cybersecurity Fundamentals
-
Threat landscape introduction: Defining cybersecurity and the critical role of every employee.
-
Digital hygiene and password management: Crafting robust passwords, leveraging password managers, and adhering to the "unique password per service" standard.
-
Physical security protocols: Implementing clear desk and clear screen policies in office spaces.
Module 2: Phishing and Social Engineering – Threat Identification
-
The psychology of attacks: Understanding social engineering and why cybercriminals exploit urgency, fear, or authority (e.g., CEO Fraud, BEC).
-
Deconstructing phishing: Analyzing message headers, concealed links, and malicious attachments through authentic examples.
-
Alternative attack vectors: Examining Vishing (voice-based phishing) and Smishing (SMS-based phishing).
Module 3: Securing Remote and Mobile Operations
-
Network security: Assessing risks of public Wi-Fi networks (cafes, transit) and proper VPN utilization.
-
Device safeguards: Implementing disk encryption, screen locks, and avoiding unknown USB drives.
-
BYOD policies: Guidelines for using personal smartphones for business and ensuring data separation.
Tools, Regulatory Compliance, and Incident Management
Module 4: Cybersecurity within Microsoft 365
-
Authentication practices: Applying Multi-Factor Authentication (MFA/2FA) for secure account access.
-
Secure data exchange: Managing permissions in OneDrive and SharePoint to avoid insecure "anyone with the link" access.
-
Collaborative security: Safely using Microsoft Teams, including managing external guests and controlling shared files.
Module 5: Data Protection and Practical GDPR Compliance
-
Data classification: Distinguishing between public, confidential, sensitive, and personal data.
-
GDPR in daily workflows: Preventing common errors that lead to data breaches (e.g., incorrect recipients, failure to use BCC).
-
Data lifecycle management: Protocols for securely transferring information to third parties and permanently deleting documents.
Module 6: Security Incident Response
-
Recognizing incidents: Identifying breaches such as lost devices, ransomware infections, or accidental phishing clicks.
-
Reporting workflows: Understanding notification timelines and the roles of the IT Helpdesk, Security Officer, and Data Protection Officer.
-
Response best practices: Disconnecting affected devices, maintaining composure, and avoiding unauthorized "fixes" or evidence deletion.
Requirements
-
Familiarity with basic computer operations and web browsing.
-
Regular use of standard office tools, including email, messaging applications, and document processing software.
-
No specialized IT expertise is necessary; all technical concepts are contextualized through business value and everyday workflows.
Target Audience
- Office and administrative staff, as well as mid-level managers, across all departments.
- Strongly recommended for hybrid or fully remote personnel.
- Users who regularly interact with the Microsoft 365 ecosystem.
Testimonials (3)
One-on-one interaction for individual tracking during the training. Focus on the direct interests of the participant.
Guillaume FROGER - NOOUS pour Atos/Eviden
Course - 389 Directory Server for Administrators
Machine Translated
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions