All courses

Cyber Security Awareness

Phishing defense, password Management & MFA, Clear Desk, Incident response, Secure Browsing, social media, Locking Devices, Suspicious events

EnglishIS Security30 AED

Price per attendee · VAT added at payment

About this course

1. Phishing Defense

Phishing is a cyberattack where attackers impersonate trusted organizations or individuals to trick users into revealing sensitive information such as passwords, financial details, or personal data. These attacks are commonly delivered through email, SMS (smishing), phone calls (vishing), or fake websites.

Phishing messages often create urgency or fear, such as claiming account suspension, unauthorized transactions, or security alerts. They may contain links to fake login pages or attachments carrying malware.

Effective phishing defense relies on awareness and caution. Users should always verify the sender’s identity before clicking links or opening attachments. Hovering over links to inspect URLs can help detect suspicious destinations. Legitimate organizations rarely ask for sensitive information via email or message.

Security tools such as spam filters, email authentication systems, and web filters provide an additional layer of protection, but human vigilance remains critical.

Key practices:

  • Do not click unknown or suspicious links

  • Verify sender email addresses carefully

  • Report suspicious emails immediately

  • Avoid downloading unexpected attachments

  • Use official websites instead of email links

A strong phishing defense culture significantly reduces the risk of data breaches and malware infections.


2. Password Management & MFA

Password management is the practice of creating, storing, and using strong passwords securely. Weak or reused passwords are one of the most common causes of security breaches.

Strong passwords should be long, complex, and unique for each account. Password managers help users securely store and generate strong passwords, reducing the need to remember multiple credentials.

Multi-Factor Authentication (MFA) adds an extra layer of security by requiring additional verification beyond a password, such as:

  • OTP (One-Time Password)

  • Mobile authentication app approval

  • Biometric verification (fingerprint or face recognition)

Even if a password is compromised, MFA helps prevent unauthorized access.

Key practices:

  • Use unique passwords for every account

  • Enable MFA wherever possible

  • Never share passwords with others

  • Avoid writing passwords on paper or storing them insecurely

  • Change passwords immediately if compromise is suspected

Together, password management and MFA significantly strengthen account security.

  • ADHICS v2 Password Requirements

    • Minimum 12 characters (current best practice).

    • At least:

      • 1 Uppercase letter (A-Z)

      • 1 Lowercase letter (a-z)

      • 1 Number (0-9)

      • 1 Special Character (!,@,#,$,%, etc.)

    • Passwords must not contain:

      • User names

      • Family names

      • Birth dates

      • Easily guessable words or patterns.

    • Reuse of the last 3 passwords should not be allowed.

    • Passwords should be changed every 90 days based on organizational policy and risk requirements.

    • Accounts should be locked after multiple failed login attempts (commonly 5 attempts).

    • Multi-Factor Authentication (MFA) should be enabled wherever possible.

    Awareness Message

    Create Strong Passwords
    Use a password with a minimum of 12 characters containing uppercase letters, lowercase letters, numbers, and special characters.

    Example:

    • Weak Password: Ahmed123

    • Strong Password: H3alth@Care#2026

    Remember:

    • Never share your password.

    • Never write passwords on paper or sticky notes.

    • Enable MFA whenever available.

    • Report any suspected credential compromise immediately.


3. Clear Desk Policy

A clear desk policy ensures that all sensitive information is securely stored when not in use. This includes documents, laptops, USB drives, and any confidential materials.

Leaving sensitive information unattended increases the risk of data breaches, theft, or unauthorized access, especially in shared or public environments.

At the end of the workday or when leaving the desk, employees should ensure all documents are filed or locked away and devices are secured or logged out.

Key practices:

  • Store confidential papers in locked drawers

  • Lock computers when stepping away

  • Remove sensitive documents from desks

  • Dispose of documents using secure shredding methods

  • Do not leave removable media exposed

A clear desk policy promotes confidentiality, professionalism, and regulatory compliance.


4. Incident Response

Incident response refers to the structured approach used to detect, manage, and recover from security incidents such as cyberattacks, data breaches, or system failures.

The goal is to minimize damage, reduce recovery time, and prevent future occurrences.

A typical incident response process includes:

  1. Identification – Detecting and reporting the incident

  2. Containment – Limiting the spread or impact

  3. Eradication – Removing the cause (malware, vulnerabilities)

  4. Recovery – Restoring systems and services

  5. Lessons Learned – Reviewing and improving defenses

Clear communication is essential during an incident. Employees should know how and where to report suspicious activity immediately.

Key practices:

  • Report incidents quickly

  • Do not attempt unauthorized fixes

  • Follow IT/security instructions

  • Preserve evidence where possible

  • Participate in post-incident reviews

A well-prepared incident response plan reduces business disruption and financial loss.


5. Secure Browsing

Secure browsing involves using the internet safely to avoid malware, phishing sites, and data theft. Cybercriminals often create fake websites that look legitimate to steal credentials or install malicious software.

Secure browsing requires awareness of website authenticity, secure connections (HTTPS), and safe download practices.

Key practices:

  • Always check for HTTPS in URLs

  • Avoid clicking suspicious pop-ups or ads

  • Download software only from trusted sources

  • Keep browsers and plugins updated

  • Use security extensions or filters when available

Users should also avoid entering sensitive information on unfamiliar websites.

Safe browsing habits protect both personal and organizational data from cyber threats.


6. Social Media Security

Social media platforms are widely used but can expose users and organizations to security risks such as data leakage, impersonation, and social engineering attacks.

Attackers often gather personal or organizational information from social media to craft targeted attacks.

Key risks include oversharing personal details, accepting unknown connection requests, and clicking malicious links shared via messages or posts.

Key practices:

  • Avoid sharing sensitive work-related information

  • Use strong privacy settings

  • Verify connection requests before accepting

  • Be cautious with links and messages

  • Do not disclose passwords or internal information

Employees should also be aware of organizational social media policies.

Responsible social media use helps protect both personal identity and company security.


7. Device Locking

Device locking ensures that computers, laptops, and mobile devices are protected when not in use. Unlocked devices are a major security risk, allowing unauthorized access to sensitive data and systems.

Locking devices is a simple but highly effective security measure in both office and remote environments.

Key practices:

  • Lock screens whenever stepping away (Windows + L / Ctrl + Alt + Del)

  • Use automatic screen lock settings

  • Enable password/PIN/biometric authentication

  • Do not leave devices unattended in public spaces

  • Log out of systems when work is complete

Device locking prevents unauthorized access, data theft, and misuse of corporate systems.


8. Suspicious Events Reporting

Suspicious events refer to unusual activities that may indicate a security threat, such as unauthorized access attempts, unexpected system behavior, or unknown devices on the network.

Early reporting is critical to preventing potential security incidents from escalating.

Examples include:

  • Unexpected password reset requests

  • Unknown login notifications

  • Strange emails from internal accounts

  • System slowdowns or crashes without reason

  • Unknown USB devices or software installations

Key practices:

  • Report suspicious activity immediately to IT/security team

  • Do not ignore unusual system behavior

  • Avoid interacting further with suspicious content

  • Preserve evidence (screenshots, emails, logs)

  • Follow escalation procedures

A strong reporting culture helps organizations detect threats early and respond effectively.

What you'll learn

  1. 1

    Phishing Defense

    Phishing is the most popular technique hackers use to target their victims by sending emails pretending to be someone else.

  2. 2

    Password Management

    Password managers secure your online accounts by safely storing your passwords in a virtual vault.

  3. 3

    Multi Factor

    Multi-Factor protects your online accounts by requiring more than one authentication method to verify your identity.

  4. 4

    Incident response

    An organized approach to dealing with the impact of a cyber security incident.

  5. 5

    Secure Browsing

    The Internet contains a wide range of threats and knowing how to navigate it safely is critical.

  6. 6

    Storing Passwords

    Strong passwords are the first line of defense for your online accounts. However, even a strong password is only as secure as the place where it’s stored.

  7. 7

    Locking Devices

    When leaving any of your devices unattended, it’s crucial to make sure that you have locked or logged out of them.

  8. 8

    Multifactor-Episode 2

    Multi-Factor protects your online accounts by requiring more than one authentication method to verify your identity.

Need the full ADHICS compliance lifecycle — governance, risk, audit and training at enterprise scale? Explore GRSCIA