Information Security Awareness
Comprehensive training modules, (ADHICS, Clear Desk & Clear Screen, Password Manage, Cyber Crime and Information Security)
Price per attendee · VAT added at payment
About this course
1. Password Management
Password Management
Passwords are the first line of defense in protecting an organization's information and digital assets. Every employee is responsible for creating and maintaining strong passwords that prevent unauthorized access to company systems, applications, and sensitive information. Weak or reused passwords are among the most common causes of cybersecurity incidents, including data breaches, identity theft, and unauthorized access.
A strong password should be at least 12–16 characters long and contain a combination of uppercase letters, lowercase letters, numbers, and special characters. Avoid using easily guessed information such as names, birthdays, phone numbers, company names, or common dictionary words. Each business application or service should have a unique password to prevent attackers from gaining access to multiple systems if one password is compromised.
Employees should never share their passwords with colleagues, supervisors, vendors, or anyone else. Passwords should not be written on paper, stored in unsecured files, or saved in web browsers without organizational approval. Instead, use an approved password manager to securely generate and store complex passwords.
Organizations should also implement Multi-Factor Authentication (MFA) wherever possible. MFA provides an additional layer of security by requiring users to verify their identity using a second authentication factor such as a mobile application, biometric verification, or hardware token.
If there is any suspicion that a password has been compromised, employees must change it immediately and report the incident to the IT or Information Security team. Regular password updates should follow the organization's password policy and applicable compliance requirements.
Best Practices
Use strong, unique passwords for every account.
Enable Multi-Factor Authentication (MFA).
Never share passwords.
Use an approved password manager.
Change compromised passwords immediately.
Lock your device whenever you leave your workstation.
Remember: A strong password protects not only your account but also your organization's reputation, customer information, and business operations.
2. Economics in Cyber Crime
Economics in Cyber Crime
Cybercrime has evolved into a highly profitable global industry. Modern cybercriminals operate like legitimate businesses, investing in tools, infrastructure, and skilled individuals to maximize financial returns while minimizing their own risk. Understanding the economics behind cybercrime helps organizations appreciate why cyberattacks continue to increase.
Cybercriminals carefully evaluate the cost, effort, potential profit, and likelihood of success before launching attacks. Low-cost attacks such as phishing emails or credential theft can generate significant financial rewards with minimal investment. Ransomware groups, for example, encrypt an organization's data and demand payment for its recovery, often targeting organizations that are likely to pay quickly to restore critical services.
A thriving underground economy supports cybercrime by providing services such as Malware-as-a-Service (MaaS), Ransomware-as-a-Service (RaaS), stolen credentials, exploit kits, fake identities, and illegal marketplaces. This ecosystem allows individuals with limited technical knowledge to launch sophisticated cyberattacks.
Organizations can reduce their attractiveness as targets by increasing the cost and difficulty of successful attacks. Implementing strong security controls such as employee awareness training, Multi-Factor Authentication, vulnerability management, regular patching, encryption, and continuous monitoring significantly reduces cybercriminals' chances of success.
Every employee contributes to cybersecurity by following security policies, reporting suspicious activities, protecting sensitive information, and remaining alert against phishing and social engineering attacks.
Key Takeaways
Cybercrime is financially motivated.
Attackers choose easy and profitable targets.
Human error is one of the biggest attack opportunities.
Strong security controls increase the attacker's cost.
Security awareness reduces organizational risk.
Remember: Every secure action you take makes your organization a less attractive target for cybercriminals.
3. Clean Desk & Clear Screen
Clean Desk & Clear Screen Policy
A Clean Desk and Clear Screen Policy helps protect confidential information from unauthorized access, accidental disclosure, and theft. Sensitive information left unattended on desks, printers, meeting rooms, or computer screens can easily be viewed, copied, photographed, or stolen.
Employees should maintain a clean and organized workspace by removing confidential documents from desks when not in use. Important papers should be stored in locked cabinets or secure storage locations. Printed documents containing confidential or personal information should never be left unattended on printers or photocopiers.
When leaving a workstation—even for a short period—employees must lock their computer using the approved screen lock function. At the end of the working day, all confidential documents, portable storage devices, laptops, ID cards, and company equipment should be secured properly.
Whiteboards used during meetings should be erased after discussions, especially if they contain confidential information. USB drives, backup media, access cards, and portable devices should never be left unattended in meeting rooms or public areas.
Organizations handling healthcare information, financial data, or personal information must ensure compliance with privacy regulations by minimizing unnecessary exposure of sensitive information in the workplace.
Best Practices
Lock your computer whenever leaving your desk.
Store confidential documents securely.
Clear desks before leaving the office.
Collect printed documents immediately.
Dispose of sensitive documents using approved shredding methods.
Remove confidential information from meeting rooms after use.
Remember: A clean desk and locked screen reduce the risk of unauthorized access and help protect confidential business information.
4. Information Security
Information Security
Information Security is the practice of protecting information and information systems against unauthorized access, disclosure, modification, destruction, or disruption. The objective is to ensure that information remains Confidential, Accurate, and Available whenever it is needed. These three principles are known as the CIA Triad:
Confidentiality: Information is accessible only to authorized individuals.
Integrity: Information remains accurate, complete, and protected from unauthorized changes.
Availability: Information and systems are available to authorized users whenever required.
Information security is not solely the responsibility of the IT department; every employee plays an important role in protecting organizational information. Sensitive information may exist in electronic files, emails, cloud services, printed documents, mobile devices, conversations, or removable media.
Common threats to information security include phishing attacks, malware, ransomware, social engineering, insider threats, weak passwords, unauthorized access, accidental disclosure, and system failures.
Employees should always follow organizational policies when handling information, classify information appropriately, use approved systems, report security incidents immediately, and avoid sharing confidential information unless properly authorized.
Organizations implement technical, administrative, and physical controls such as access management, encryption, security awareness training, firewalls, endpoint protection, backups, monitoring, and incident response procedures to protect their information assets.
Employee Responsibilities
Follow all information security policies.
Protect passwords and company credentials.
Report suspicious emails or incidents immediately.
Use only authorized software and devices.
Handle confidential information responsibly.
Keep systems updated and follow IT guidance.
Remember: Information security is everyone's responsibility. Every employee contributes to protecting the organization's data, customers, reputation, and business continuity by following good security practices every day.
What you'll learn
- 1
Password Management
- 2
Economics in Cyber Crime
- 3
ADHICS- General Awareness
- 4
Clean Desk & Clear Screen
- 5
Information Security
Need the full ADHICS compliance lifecycle — governance, risk, audit and training at enterprise scale? Explore GRSCIA →