We accept Apple Pay Google Pay & 3 interest-free instalments via Klarna · 0330 124 2165
eLearning · start today

Phishing, Malware and Online Security eLearning

Online security awareness training that shows staff what a phishing email actually looks like now, and why the old advice about spelling mistakes stopped working years ago.

Price£15 + VAT
How longApproximately 30 to 45 minutes
Valid for1 year
WhereOnline, on any device
Laptop and smartphone on a desk showing a login screen with a hand at the keyboard

Who it is for

Who this online security course is for

Almost every serious data breach starts with a person rather than a system: a clicked link, a plausible invoice, a password reused somewhere it should not have been. That makes every member of staff part of your security perimeter.

  • All staff, as part of induction or annual refresher training
  • Finance teams handling invoices and payments
  • Anyone with access to customer or employee data
  • Remote and hybrid workers
  • Managers who authorise payments or access
  • Small businesses without an IT department

Course content

What the online security course covers

Five short lessons covering how attacks start, spotting a phish, malware and ransomware, passwords and safe habits, and reporting an incident, then a 12-question assessment.

1

How attacks start

Phishing, smishing, vishing, business email compromise and AI-written messages, and how common they are.

2

Spotting a phish

Checking the sender, the link, the urgency and the request, including in convincing messages.

3

Malware and ransomware

How malware gets in, what ransomware does, what limits the damage, and what to do if you click.

4

Passwords, MFA and safe habits

Three random words, password managers, multi-factor authentication, public wifi and shared devices.

5

Reporting an incident

Why reporting fast matters, how to report, and a no-blame culture.

Outcomes

What you will be able to do afterwards

  • Recognise how attacks start, including phishing, smishing and vishing
  • Spot the signs of a phishing message, even a convincing one
  • Explain how malware and ransomware get in and what limits the damage
  • Use strong passwords, MFA and safe working habits
  • Report incidents straight away through the right route

Your legal duty

The law behind security awareness training

There is no regulation requiring security awareness training by name. The nearest duty sits in data protection law: the UK GDPR requires appropriate technical and organisational measures to keep personal data secure, and staff awareness is one of the organisational measures regulators expect to see.

In practice the driver is commercial as much as legal: cyber insurance, client due diligence and certification schemes routinely ask whether staff receive security awareness training, and when they last had it.

  • UK GDPR - appropriate technical and organisational security measures
  • Data Protection Act 2018
  • Regulated by the Information Commissioner's Office (ICO)
  • No statute names security awareness training; insurers and clients increasingly ask for it

Practicalities

How the course works

WhereOnline, in a browser: phone, tablet or computer
WhenStart straight after payment; pause and resume any time
How longAround 30 to 45 minutes, with no time limit on completion
AssessmentKnowledge checks in every lesson, then a 12-question assessment. Pass mark 70% (9 of 12), retake as often as you need
CertificateIssued when you pass the assessment, downloadable as a PDF
RefresherCommonly annual; certificate valid 1 year

Would you rather have a tutor?

Where your own procedures, equipment and reporting lines need to be in the training, we can build that version for you.

Talk to us about a bespoke version

For employers

Security awareness across a workforce

Attackers target whole organisations, so partial coverage is the weakness. An account lets you cover everybody and prove when you did.

  • One invoice instead of a card payment per person
  • Licences allocated as people join, so induction is covered
  • Completion and expiry reporting for your records
  • Renewal reminders before certificates lapse
  • Bespoke versions built around your own procedures

Phishing, Malware and Online Security eLearning: common questions

Not by name. Data protection law requires appropriate organisational measures to keep personal data secure, and staff awareness is one of those. Insurers and clients also increasingly ask for evidence of it.

That advice is out of date and the course says so. Modern phishing is well written, well branded and often references real events, which is why the checks that still work are sender, link and context.

Report it immediately. The course is built around removing the fear of blame, because the damage from a phishing click is largely determined by how fast it gets reported.

Yes: how infection happens, what it does, and why tested backups and fast reporting matter more than any single control.

About 30 to 45 minutes, with no time limit: start it, pause it, and come back whenever suits. The certificate is issued as soon as you pass the end assessment.

Yes. It runs in a browser on any modern phone, tablet or computer, with nothing to install.

Yes. Open a business account and we invoice you for the licences, which you allocate as people need them, with completion reporting included.

Skip to main content