Information Security eLearning
Online information security awareness: classifying information, handling it safely, and the everyday habits that keep data where it should be.
Who it is for
Who this information security course is for
Information security is not only a technical discipline. Most losses involve ordinary handling: an email to the wrong address, a document left on a printer, a USB stick in a coat pocket, an account still active months after someone left.
- All staff, as part of induction or refresher training
- Anyone handling customer or employee data
- Finance, HR and administrative teams
- Remote and hybrid workers
- Managers responsible for access rights
- Businesses answering security questions in tenders
Course content
What the information security course covers
Eight short modules covering how information is classified, handled, shared, stored and disposed of, and what to do when something goes wrong.
What information security means
Confidentiality, integrity and availability, in practical terms.
Classifying information
Recognising what is sensitive, and handling it accordingly.
Access and authentication
Passwords, multi-factor authentication and why access should be limited to need.
Handling and sharing
Email, attachments, file sharing, and checking the recipient before sending.
Physical security
Clear desk, printers, visitors, screens, documents and portable devices.
Removable media and devices
USB sticks, laptops and phones, and what happens when one goes missing.
Retention and disposal
Keeping information only as long as needed, and destroying it properly.
Incidents
Recognising a security incident and reporting it immediately
Outcomes
What you will be able to do afterwards
- Explain what information security protects and why
- Recognise sensitive information and handle it appropriately
- Use strong authentication and appropriate access
- Share information safely and check recipients
- Apply clear desk and physical security habits
- Handle removable media and mobile devices safely
- Recognise and report a security incident without delay
Your legal duty
The law behind information security training
The most direct legal driver is data protection. The UK GDPR requires appropriate technical and organisational measures to keep personal data secure, and the Data Protection Act 2018 sits alongside it, with the Information Commissioner's Office as regulator. Staff awareness is one of the organisational measures regulators expect to see.
Beyond personal data, the drivers are contractual and commercial: client due diligence, tender requirements and certification schemes routinely ask what security awareness training staff receive and when they last had it.
- UK GDPR - appropriate technical and organisational measures
- Data Protection Act 2018
- Regulated by the Information Commissioner's Office (ICO)
- Contractual and certification requirements often drive the training in practice
Practicalities
How the course works
For employers
Information Security training for a team
Information security is only as strong as the least-trained person with access. Partial coverage is the weakness.
- One invoice instead of a card payment per person
- Licences allocated as people join, so induction is covered
- Completion and expiry reporting for your records
- Renewal reminders before certificates lapse
- Bespoke versions built around your own procedures
Attack-specific awareness, phishing, malware and ransomware, is covered there. See the Phishing and Online Security course →
Information Security eLearning: common questions
This one covers how information is classified, handled, stored, shared and destroyed. The phishing course covers the attacks themselves. Most organisations run both.
Not by that name. Data protection law requires appropriate organisational measures to protect personal data, and staff awareness is one of them. Clients and certification schemes often require it explicitly.
Yes: clear desk, printers, visitors, screens and portable devices. A large share of losses are physical rather than technical.
Report it immediately. The course is built around removing the delay, because the window between loss and reporting is when the damage happens.
Yes. Screens on trains, calls in cafés and public wi-fi are all covered as everyday handling risks.
About 30 minutes, with no time limit: start it, pause it, and come back whenever suits. The certificate is issued the moment you finish.
Yes. It runs in a browser on any modern phone, tablet or computer, with nothing to install.
Yes. Open a business account and we invoice you for the licences, which you allocate as people need them, with completion reporting included.
Related