We accept Apple Pay Google Pay & 3 interest-free instalments via Klarna · 0330 124 2165
eLearning · start today

Information Security eLearning

Online information security awareness: classifying information, handling it safely, and the everyday habits that keep data where it should be.

How longApproximately 30 minutes
Valid for3 years
WhereOnline, on any device
Laptop and smartphone on a desk showing a login screen with a hand at the keyboard

Who it is for

Who this information security course is for

Information security is not only a technical discipline. Most losses involve ordinary handling: an email to the wrong address, a document left on a printer, a USB stick in a coat pocket, an account still active months after someone left.

  • All staff, as part of induction or refresher training
  • Anyone handling customer or employee data
  • Finance, HR and administrative teams
  • Remote and hybrid workers
  • Managers responsible for access rights
  • Businesses answering security questions in tenders

Course content

What the information security course covers

Eight short modules covering how information is classified, handled, shared, stored and disposed of, and what to do when something goes wrong.

1

What information security means

Confidentiality, integrity and availability, in practical terms.

2

Classifying information

Recognising what is sensitive, and handling it accordingly.

3

Access and authentication

Passwords, multi-factor authentication and why access should be limited to need.

4

Handling and sharing

Email, attachments, file sharing, and checking the recipient before sending.

5

Physical security

Clear desk, printers, visitors, screens, documents and portable devices.

6

Removable media and devices

USB sticks, laptops and phones, and what happens when one goes missing.

7

Retention and disposal

Keeping information only as long as needed, and destroying it properly.

8

Incidents

Recognising a security incident and reporting it immediately

Outcomes

What you will be able to do afterwards

  • Explain what information security protects and why
  • Recognise sensitive information and handle it appropriately
  • Use strong authentication and appropriate access
  • Share information safely and check recipients
  • Apply clear desk and physical security habits
  • Handle removable media and mobile devices safely
  • Recognise and report a security incident without delay

Your legal duty

The law behind information security training

The most direct legal driver is data protection. The UK GDPR requires appropriate technical and organisational measures to keep personal data secure, and the Data Protection Act 2018 sits alongside it, with the Information Commissioner's Office as regulator. Staff awareness is one of the organisational measures regulators expect to see.

Beyond personal data, the drivers are contractual and commercial: client due diligence, tender requirements and certification schemes routinely ask what security awareness training staff receive and when they last had it.

  • UK GDPR - appropriate technical and organisational measures
  • Data Protection Act 2018
  • Regulated by the Information Commissioner's Office (ICO)
  • Contractual and certification requirements often drive the training in practice

Practicalities

How the course works

WhereOnline, in a browser: phone, tablet or computer
WhenStart straight after payment; pause and resume any time
How longAround 30 minutes, with no time limit on completion
AssessmentQuestions throughout, retaken as often as you need
CertificateIssued on completion, downloadable as a PDF
RefresherCommonly annual; certificate valid 3 years

For employers

Information Security training for a team

Information security is only as strong as the least-trained person with access. Partial coverage is the weakness.

  • One invoice instead of a card payment per person
  • Licences allocated as people join, so induction is covered
  • Completion and expiry reporting for your records
  • Renewal reminders before certificates lapse
  • Bespoke versions built around your own procedures

Attack-specific awareness, phishing, malware and ransomware, is covered there. See the Phishing and Online Security course →

Information Security eLearning: common questions

This one covers how information is classified, handled, stored, shared and destroyed. The phishing course covers the attacks themselves. Most organisations run both.

Not by that name. Data protection law requires appropriate organisational measures to protect personal data, and staff awareness is one of them. Clients and certification schemes often require it explicitly.

Yes: clear desk, printers, visitors, screens and portable devices. A large share of losses are physical rather than technical.

Report it immediately. The course is built around removing the delay, because the window between loss and reporting is when the damage happens.

Yes. Screens on trains, calls in cafés and public wi-fi are all covered as everyday handling risks.

About 30 minutes, with no time limit: start it, pause it, and come back whenever suits. The certificate is issued the moment you finish.

Yes. It runs in a browser on any modern phone, tablet or computer, with nothing to install.

Yes. Open a business account and we invoice you for the licences, which you allocate as people need them, with completion reporting included.

Skip to main content