Phishing, Malware and Online Security eLearning
Online security awareness training that shows staff what a phishing email actually looks like now, and why the old advice about spelling mistakes stopped working years ago.
Who it is for
Who this online security course is for
Almost every serious data breach starts with a person rather than a system: a clicked link, a plausible invoice, a password reused somewhere it should not have been. That makes every member of staff part of your security perimeter.
- All staff, as part of induction or annual refresher training
- Finance teams handling invoices and payments
- Anyone with access to customer or employee data
- Remote and hybrid workers
- Managers who authorise payments or access
- Small businesses without an IT department
Course content
What the online security course covers
Five short lessons covering how attacks start, spotting a phish, malware and ransomware, passwords and safe habits, and reporting an incident, then a 12-question assessment.
How attacks start
Phishing, smishing, vishing, business email compromise and AI-written messages, and how common they are.
Spotting a phish
Checking the sender, the link, the urgency and the request, including in convincing messages.
Malware and ransomware
How malware gets in, what ransomware does, what limits the damage, and what to do if you click.
Passwords, MFA and safe habits
Three random words, password managers, multi-factor authentication, public wifi and shared devices.
Reporting an incident
Why reporting fast matters, how to report, and a no-blame culture.
Outcomes
What you will be able to do afterwards
- Recognise how attacks start, including phishing, smishing and vishing
- Spot the signs of a phishing message, even a convincing one
- Explain how malware and ransomware get in and what limits the damage
- Use strong passwords, MFA and safe working habits
- Report incidents straight away through the right route
Your legal duty
The law behind security awareness training
There is no regulation requiring security awareness training by name. The nearest duty sits in data protection law: the UK GDPR requires appropriate technical and organisational measures to keep personal data secure, and staff awareness is one of the organisational measures regulators expect to see.
In practice the driver is commercial as much as legal: cyber insurance, client due diligence and certification schemes routinely ask whether staff receive security awareness training, and when they last had it.
- UK GDPR - appropriate technical and organisational security measures
- Data Protection Act 2018
- Regulated by the Information Commissioner's Office (ICO)
- No statute names security awareness training; insurers and clients increasingly ask for it
Practicalities
How the course works
Would you rather have a tutor?
Where your own procedures, equipment and reporting lines need to be in the training, we can build that version for you.
For employers
Security awareness across a workforce
Attackers target whole organisations, so partial coverage is the weakness. An account lets you cover everybody and prove when you did.
- One invoice instead of a card payment per person
- Licences allocated as people join, so induction is covered
- Completion and expiry reporting for your records
- Renewal reminders before certificates lapse
- Bespoke versions built around your own procedures
Phishing, Malware and Online Security eLearning: common questions
Not by name. Data protection law requires appropriate organisational measures to keep personal data secure, and staff awareness is one of those. Insurers and clients also increasingly ask for evidence of it.
That advice is out of date and the course says so. Modern phishing is well written, well branded and often references real events, which is why the checks that still work are sender, link and context.
Report it immediately. The course is built around removing the fear of blame, because the damage from a phishing click is largely determined by how fast it gets reported.
Yes: how infection happens, what it does, and why tested backups and fast reporting matter more than any single control.
About 30 to 45 minutes, with no time limit: start it, pause it, and come back whenever suits. The certificate is issued as soon as you pass the end assessment.
Yes. It runs in a browser on any modern phone, tablet or computer, with nothing to install.
Yes. Open a business account and we invoice you for the licences, which you allocate as people need them, with completion reporting included.
Related