Cyber Security Awareness
Phishing defense, password Management & MFA, Clear Desk, Incident response, Secure Browsing, social media, Locking Devices, Suspicious events
Price per attendee · VAT added at payment
About this course
1. Phishing Defense
Phishing is a cyberattack where attackers impersonate trusted organizations or individuals to trick users into revealing sensitive information such as passwords, financial details, or personal data. These attacks are commonly delivered through email, SMS (smishing), phone calls (vishing), or fake websites.
Phishing messages often create urgency or fear, such as claiming account suspension, unauthorized transactions, or security alerts. They may contain links to fake login pages or attachments carrying malware.
Effective phishing defense relies on awareness and caution. Users should always verify the sender’s identity before clicking links or opening attachments. Hovering over links to inspect URLs can help detect suspicious destinations. Legitimate organizations rarely ask for sensitive information via email or message.
Security tools such as spam filters, email authentication systems, and web filters provide an additional layer of protection, but human vigilance remains critical.
Key practices:
Do not click unknown or suspicious links
Verify sender email addresses carefully
Report suspicious emails immediately
Avoid downloading unexpected attachments
Use official websites instead of email links
A strong phishing defense culture significantly reduces the risk of data breaches and malware infections.
2. Password Management & MFA
Password management is the practice of creating, storing, and using strong passwords securely. Weak or reused passwords are one of the most common causes of security breaches.
Strong passwords should be long, complex, and unique for each account. Password managers help users securely store and generate strong passwords, reducing the need to remember multiple credentials.
Multi-Factor Authentication (MFA) adds an extra layer of security by requiring additional verification beyond a password, such as:
OTP (One-Time Password)
Mobile authentication app approval
Biometric verification (fingerprint or face recognition)
Even if a password is compromised, MFA helps prevent unauthorized access.
Key practices:
Use unique passwords for every account
Enable MFA wherever possible
Never share passwords with others
Avoid writing passwords on paper or storing them insecurely
Change passwords immediately if compromise is suspected
Together, password management and MFA significantly strengthen account security.
ADHICS v2 Password Requirements
Minimum 12 characters (current best practice).
At least:
1 Uppercase letter (A-Z)
1 Lowercase letter (a-z)
1 Number (0-9)
1 Special Character (!,@,#,$,%, etc.)
Passwords must not contain:
User names
Family names
Birth dates
Easily guessable words or patterns.
Reuse of the last 3 passwords should not be allowed.
Passwords should be changed every 90 days based on organizational policy and risk requirements.
Accounts should be locked after multiple failed login attempts (commonly 5 attempts).
Multi-Factor Authentication (MFA) should be enabled wherever possible.
Awareness Message
Create Strong Passwords
Use a password with a minimum of 12 characters containing uppercase letters, lowercase letters, numbers, and special characters.Example:
Weak Password: Ahmed123
Strong Password: H3alth@Care#2026
Remember:
Never share your password.
Never write passwords on paper or sticky notes.
Enable MFA whenever available.
Report any suspected credential compromise immediately.
3. Clear Desk Policy
A clear desk policy ensures that all sensitive information is securely stored when not in use. This includes documents, laptops, USB drives, and any confidential materials.
Leaving sensitive information unattended increases the risk of data breaches, theft, or unauthorized access, especially in shared or public environments.
At the end of the workday or when leaving the desk, employees should ensure all documents are filed or locked away and devices are secured or logged out.
Key practices:
Store confidential papers in locked drawers
Lock computers when stepping away
Remove sensitive documents from desks
Dispose of documents using secure shredding methods
Do not leave removable media exposed
A clear desk policy promotes confidentiality, professionalism, and regulatory compliance.
4. Incident Response
Incident response refers to the structured approach used to detect, manage, and recover from security incidents such as cyberattacks, data breaches, or system failures.
The goal is to minimize damage, reduce recovery time, and prevent future occurrences.
A typical incident response process includes:
Identification – Detecting and reporting the incident
Containment – Limiting the spread or impact
Eradication – Removing the cause (malware, vulnerabilities)
Recovery – Restoring systems and services
Lessons Learned – Reviewing and improving defenses
Clear communication is essential during an incident. Employees should know how and where to report suspicious activity immediately.
Key practices:
Report incidents quickly
Do not attempt unauthorized fixes
Follow IT/security instructions
Preserve evidence where possible
Participate in post-incident reviews
A well-prepared incident response plan reduces business disruption and financial loss.
5. Secure Browsing
Secure browsing involves using the internet safely to avoid malware, phishing sites, and data theft. Cybercriminals often create fake websites that look legitimate to steal credentials or install malicious software.
Secure browsing requires awareness of website authenticity, secure connections (HTTPS), and safe download practices.
Key practices:
Always check for HTTPS in URLs
Avoid clicking suspicious pop-ups or ads
Download software only from trusted sources
Keep browsers and plugins updated
Use security extensions or filters when available
Users should also avoid entering sensitive information on unfamiliar websites.
Safe browsing habits protect both personal and organizational data from cyber threats.
6. Social Media Security
Social media platforms are widely used but can expose users and organizations to security risks such as data leakage, impersonation, and social engineering attacks.
Attackers often gather personal or organizational information from social media to craft targeted attacks.
Key risks include oversharing personal details, accepting unknown connection requests, and clicking malicious links shared via messages or posts.
Key practices:
Avoid sharing sensitive work-related information
Use strong privacy settings
Verify connection requests before accepting
Be cautious with links and messages
Do not disclose passwords or internal information
Employees should also be aware of organizational social media policies.
Responsible social media use helps protect both personal identity and company security.
7. Device Locking
Device locking ensures that computers, laptops, and mobile devices are protected when not in use. Unlocked devices are a major security risk, allowing unauthorized access to sensitive data and systems.
Locking devices is a simple but highly effective security measure in both office and remote environments.
Key practices:
Lock screens whenever stepping away (Windows + L / Ctrl + Alt + Del)
Use automatic screen lock settings
Enable password/PIN/biometric authentication
Do not leave devices unattended in public spaces
Log out of systems when work is complete
Device locking prevents unauthorized access, data theft, and misuse of corporate systems.
8. Suspicious Events Reporting
Suspicious events refer to unusual activities that may indicate a security threat, such as unauthorized access attempts, unexpected system behavior, or unknown devices on the network.
Early reporting is critical to preventing potential security incidents from escalating.
Examples include:
Unexpected password reset requests
Unknown login notifications
Strange emails from internal accounts
System slowdowns or crashes without reason
Unknown USB devices or software installations
Key practices:
Report suspicious activity immediately to IT/security team
Do not ignore unusual system behavior
Avoid interacting further with suspicious content
Preserve evidence (screenshots, emails, logs)
Follow escalation procedures
A strong reporting culture helps organizations detect threats early and respond effectively.
What you'll learn
- 1
Phishing Defense
Phishing is the most popular technique hackers use to target their victims by sending emails pretending to be someone else.
- 2
Password Management
Password managers secure your online accounts by safely storing your passwords in a virtual vault.
- 3
Multi Factor
Multi-Factor protects your online accounts by requiring more than one authentication method to verify your identity.
- 4
Incident response
An organized approach to dealing with the impact of a cyber security incident.
- 5
Secure Browsing
The Internet contains a wide range of threats and knowing how to navigate it safely is critical.
- 6
Storing Passwords
Strong passwords are the first line of defense for your online accounts. However, even a strong password is only as secure as the place where it’s stored.
- 7
Locking Devices
When leaving any of your devices unattended, it’s crucial to make sure that you have locked or logged out of them.
- 8
Multifactor-Episode 2
Multi-Factor protects your online accounts by requiring more than one authentication method to verify your identity.
Need the full ADHICS compliance lifecycle — governance, risk, audit and training at enterprise scale? Explore GRSCIA →