Information Security eLearning
Online information security awareness: classifying information, handling it safely, and the everyday habits that keep data where it should be.
Who it is for
Who this information security course is for
Information security is not only a technical discipline. Most losses involve ordinary handling: an email to the wrong address, a document left on a printer, a USB stick in a coat pocket, an account still active months after someone left.
- All staff, as part of induction or refresher training
- Anyone handling customer or employee data
- Finance, HR and administrative teams
- Remote and hybrid workers
- Managers responsible for access rights
- Businesses answering security questions in tenders
Course content
What the information security course covers
Five short lessons covering what information security protects and classification, access and authentication, handling and sharing, physical security and devices, and retention, disposal and incidents, then a 12-question assessment.
What information security protects
Confidentiality, integrity and availability, why information security matters, and classifying information.
Access and authentication
Least privilege, strong passwords, multi-factor authentication, and why logins are never shared.
Handling and sharing
Checking recipients and attachments, sharing files securely, and using approved tools.
Physical security, devices and removable media
Clear desk and clear screen, tailgating, devices, USB sticks, and working in public.
Retention, disposal and incidents
Keeping only what is needed, disposing of information securely, and reporting incidents.
Outcomes
What you will be able to do afterwards
- Explain confidentiality, integrity and availability, and classify information
- Control access with strong authentication and least privilege
- Handle and share information safely
- Apply physical security to desks, screens, devices and removable media
- Keep only what is needed, dispose of it securely and report incidents
Your legal duty
The law behind information security training
The most direct legal driver is data protection. The UK GDPR requires appropriate technical and organisational measures to keep personal data secure, and the Data Protection Act 2018 sits alongside it, with the Information Commissioner's Office as regulator. Staff awareness is one of the organisational measures regulators expect to see.
Beyond personal data, the drivers are contractual and commercial: client due diligence, tender requirements and certification schemes routinely ask what security awareness training staff receive and when they last had it.
- UK GDPR - appropriate technical and organisational measures
- Data Protection Act 2018
- Regulated by the Information Commissioner's Office (ICO)
- Contractual and certification requirements often drive the training in practice
Practicalities
How the course works
Would you rather have a tutor?
Attack-specific awareness, phishing, malware and ransomware, is covered there.
For employers
Information Security training for a team
Information security is only as strong as the least-trained person with access. Partial coverage is the weakness.
- One invoice instead of a card payment per person
- Licences allocated as people join, so induction is covered
- Completion and expiry reporting for your records
- Renewal reminders before certificates lapse
- Bespoke versions built around your own procedures
Information Security eLearning: common questions
This one covers how information is classified, handled, stored, shared and destroyed. The phishing course covers the attacks themselves. Most organisations run both.
Not by that name. Data protection law requires appropriate organisational measures to protect personal data, and staff awareness is one of them. Clients and certification schemes often require it explicitly.
Yes: clear desk, printers, visitors, screens and portable devices. A large share of losses are physical rather than technical.
Report it immediately. The course is built around removing the delay, because the window between loss and reporting is when the damage happens.
Yes. Screens on trains, calls in cafés and public wi-fi are all covered as everyday handling risks.
About 30 to 45 minutes, with no time limit: start it, pause it, and come back whenever suits. The certificate is issued as soon as you pass the end assessment.
Yes. It runs in a browser on any modern phone, tablet or computer, with nothing to install.
Yes. Open a business account and we invoice you for the licences, which you allocate as people need them, with completion reporting included.
Related