icon icon

Cyber awareness in practice – real-life situations, mistakes and good security practices

icon

Training process

Training needs analysis

If you have specific requirements regarding the training programme, we will carry out a training needs analysis for you. This will guide us on which aspects of the programme should receive greater emphasis, so that the training programme meets your specific needs.

What will you gain?

icon

Spot risks earlier - You will learn to notice common warning signs in everyday work, so you can identify risky situations faster and reduce the chance of making an expensive security mistake.

icon

Assess suspicious messages - You will learn how to check emails and messages for phishing, fake links and impersonation attempts, so you can respond safely instead of acting under pressure.

icon

Protect your accounts better - You will gain practical habits for passwords, password managers and MFA, helping you secure access to both company and personal services more effectively.

icon

Work remotely more safely - You will learn how to protect data outside the office, use Wi-Fi more safely and secure your laptop and phone, so sensitive information is less exposed to loss or leaks.

icon

Resist manipulation more easily - You will recognize social engineering tactics based on urgency, authority and emotions, making it easier to pause, verify a request and avoid rushed decisions.

icon

Share information more securely - You will learn to identify confidential and sensitive data and handle file sharing by email and cloud tools properly, reducing the risk of accidental exposure.

icon

Use AI tools more wisely - You will learn how to use AI without exposing company or confidential data, which mistakes users make most often and how to apply safe prompting practices at work.

icon

Respond to incidents faster - You will follow a clear response path after spotting a threat: what to check first, what to avoid and who to notify, so you can limit damage and act with confidence.

Training programme

1. Cybersecurity in everyday work

  • the most common sources of security incidents,
  • the role of the employee as the first line of defense,
  • errors, haste and routine as sources of threats,
  • basic concepts: phishing, malware, ransomware and social engineering,
  • the consequences of incidents for the employee and the organization.

2. Phishing and other forms of digital fraud

  • phishing, spear-phishing, smishing and vishing,
  • spoofing and impersonating trusted senders,
  • fake emails, SMS messages and communications,
  • CEO fraud, „invoice”, „courier” and „technical support” scams,
  • malicious links, attachments and QR codes,
  • red flags that make it possible to recognize an attack attempt,
  • safe response to suspicious communication.

3. Social Engineering and the Psychology of Manipulation

  • the use of time pressure, authority, emotions and fear,
  • obtaining information and access data by deception,
  • manipulation by phone and during direct contact,
  • the principle of limited trust,
  • ways of verifying unusual requests,
  • analysis of sample attack scenarios.

4. Passwords, MFA and account security

  • the most common password-related mistakes,
  • rules for creating strong and unique passwords,
  • secure storage of access credentials,
  • password managers,
  • multi-factor authentication – MFA,
  • account takeovers and attacks on the login process,
  • fake requests to approve login,
  • actions to take in case of suspected account takeover.

5. Secure electronic communication

  • security of email and messengers,
  • verification of the sender, domain, links and attachments,
  • secure transfer of information and documents,
  • calls and videoconferences,
  • screen sharing and presenting documents,
  • protection of information when using Microsoft Teams and other messengers,
  • the most common user mistakes.

6. Safe work in the cloud and Microsoft 365

  • rules for secure logging in,
  • safe use of OneDrive, SharePoint and Teams,
  • sharing documents with people inside and outside the organization,
  • granting and controlling permissions,
  • risks related to public links,
  • data protection during file sharing,
  • threats related to incorrect access configuration.

7. Protection of company devices

  • security of computers, phones and tablets,
  • system and application updates,
  • antivirus software and firewalls,
  • encryption of devices and data,
  • screen locking and protection of the device against access by third parties,
  • installation of applications and use of external media,
  • procedures in the event of loss or theft of a device.

8. Safe remote and mobile work

  • threats related to working outside the office,
  • using public and home Wi-Fi networks,
  • working in hotels, on trains, at airports and in public spaces,
  • securing documents and conversations from unauthorized persons,
  • safe use of private devices,
  • good practices for hybrid work.

9. Protection of data and company information

  • personal, confidential, sensitive, financial and commercial data,
  • classification of information,
  • the principle of minimum access to data,
  • secure storage, transmission and destruction of documents,
  • incorrect recipients and accidental disclosure of information,
  • data protection in messages, documents and the cloud,
  • clean desk and clean screen policy rules,
  • prevention of data leaks.

10. Safe use of AI tools

  • the most important risks associated with generative artificial intelligence,
  • data that should not be provided to AI tools,
  • protection of company, personal, financial, and customer data,
  • differences between public tools and corporate AI environments,
  • the risk of storing and further processing the entered information,
  • safe preparation of prompts,
  • anonymization and limiting the scope of data,
  • AI hallucinations and the need to verify responses,
  • malicious content and manipulation of instructions,
  • deepfakes, fake recordings, and content generated by AI,
  • principles of responsible use of ChatGPT, Copilot, and other AI tools.

11. Malware and ransomware in practice

  • the most common ways devices are infected,
  • malicious files, applications, links and websites,
  • recognizing unusual device behavior,
  • basic rules for reducing the risk of infection,
  • how ransomware works,
  • what not to do after detecting a threat,
  • first actions after suspecting an infection.

12. Responding to security incidents

  • how to recognize an incident or a suspicious situation,
  • first actions after detecting a threat,
  • securing information and the device,
  • reporting incidents in accordance with the organization's procedures,
  • cooperation with the IT department or security team,
  • what should not be done after an incident,
  • response after clicking a suspicious link or disclosing a password,
  • response to the incorrect sending or sharing of data.

13. Practical workshops

  • analysis of suspicious e-mail and SMS messages,
  • recognition of phishing attempts and social engineering,
  • assessment of password security and login methods,
  • analysis of methods of sharing documents,
  • recognition of content generated or manipulated by AI,
  • assessment of example prompts in terms of data security,
  • simulation of a security incident,
  • decision scenarios: „What to do in this situation?”.

14. Summary and good security habits

  • the most important principles of safe work,
  • user safety checklist,
  • the most common mistakes and ways to avoid them,
  • principles of safe use of AI,
  • questions and answers.

What are the prerequisites for participating in the training?

icon

Basic computer skills - You should be comfortable using a computer, email and a web browser, so you can focus on security practices instead of learning the basics of the tools themselves.

icon

Everyday online work - You should have experience using accounts, messengers, documents or cloud tools in daily work, because the training is built around realistic digital work scenarios.

icon

Basic understanding of passwords - You should understand what a login, password and extra access verification are, so it will be easier for you to apply secure sign-in and account protection practices.

icon

Willingness to apply rules - You should be ready to review examples, ask questions and relate the content to your own work, because the training is practical and based on everyday situations.