Phishing, Malware and Online Security eLearning
Online security awareness training that shows staff what a phishing email actually looks like now, and why the old advice about spelling mistakes stopped working years ago.
Who it is for
Who this online security course is for
Almost every serious data breach starts with a person rather than a system: a clicked link, a plausible invoice, a password reused somewhere it should not have been. That makes every member of staff part of your security perimeter.
- All staff, as part of induction or annual refresher training
- Finance teams handling invoices and payments
- Anyone with access to customer or employee data
- Remote and hybrid workers
- Managers who authorise payments or access
- Small businesses without an IT department
Course content
What the online security course covers
Six short modules on the attacks that actually work, and the handful of habits that stop most of them.
How attacks start
Phishing, spear phishing, smishing and vishing, and why targeted attacks succeed.
Spotting a phish
Sender, links, urgency and context: and why bad spelling is no longer the tell.
Malware and ransomware
How infection happens, what ransomware does, and why backups are the real defence.
Passwords and access
Strong unique passwords, password managers and multi-factor authentication.
Safe working habits
Public wi-fi, devices, removable media, screen locking and working in public places.
Reporting an incident
Recognising that something has gone wrong, and reporting fast without fear of blame.
Outcomes
What you will be able to do afterwards
- Recognise a phishing attempt in email, text or a phone call
- Check a link or a sender before acting on a message
- Explain how ransomware gets in and what limits the damage
- Use strong unique passwords and multi-factor authentication
- Work safely on public networks and shared devices
- Report a suspected incident immediately and without hesitation
Your legal duty
The law behind security awareness training
There is no regulation requiring security awareness training by name. The nearest duty sits in data protection law: the UK GDPR requires appropriate technical and organisational measures to keep personal data secure, and staff awareness is one of the organisational measures regulators expect to see.
In practice the driver is commercial as much as legal: cyber insurance, client due diligence and certification schemes routinely ask whether staff receive security awareness training, and when they last had it.
- UK GDPR - appropriate technical and organisational security measures
- Data Protection Act 2018
- Regulated by the Information Commissioner's Office (ICO)
- No statute names security awareness training; insurers and clients increasingly ask for it
Practicalities
How the course works
For employers
Security awareness across a workforce
Attackers target whole organisations, so partial coverage is the weakness. An account lets you cover everybody and prove when you did.
- One invoice instead of a card payment per person
- Licences allocated as people join, so induction is covered
- Completion and expiry reporting for your records
- Renewal reminders before certificates lapse
- Bespoke versions built around your own procedures
Where your own procedures, equipment and reporting lines need to be in the training, we can build that version for you. Talk to us about a bespoke version →
Phishing, Malware and Online Security eLearning: common questions
Not by name. Data protection law requires appropriate organisational measures to keep personal data secure, and staff awareness is one of those. Insurers and clients also increasingly ask for evidence of it.
That advice is out of date and the course says so. Modern phishing is well written, well branded and often references real events, which is why the checks that still work are sender, link and context.
Report it immediately. The course is built around removing the fear of blame, because the damage from a phishing click is largely determined by how fast it gets reported.
Yes: how infection happens, what it does, and why tested backups and fast reporting matter more than any single control.
About 30 minutes, with no time limit: start it, pause it, and come back whenever suits. The certificate is issued the moment you finish.
Yes. It runs in a browser on any modern phone, tablet or computer, with nothing to install.
Yes. Open a business account and we invoice you for the licences, which you allocate as people need them, with completion reporting included.
Related