We accept Apple Pay Google Pay & 3 interest-free instalments via Klarna · 0330 124 2165
eLearning · start today

Phishing, Malware and Online Security eLearning

Online security awareness training that shows staff what a phishing email actually looks like now, and why the old advice about spelling mistakes stopped working years ago.

Price£15 +VAT
How longApproximately 30 minutes
Valid for3 years
WhereOnline, on any device
Laptop and smartphone on a desk showing a login screen with a hand at the keyboard

Who it is for

Who this online security course is for

Almost every serious data breach starts with a person rather than a system: a clicked link, a plausible invoice, a password reused somewhere it should not have been. That makes every member of staff part of your security perimeter.

  • All staff, as part of induction or annual refresher training
  • Finance teams handling invoices and payments
  • Anyone with access to customer or employee data
  • Remote and hybrid workers
  • Managers who authorise payments or access
  • Small businesses without an IT department

Course content

What the online security course covers

Six short modules on the attacks that actually work, and the handful of habits that stop most of them.

1

How attacks start

Phishing, spear phishing, smishing and vishing, and why targeted attacks succeed.

2

Spotting a phish

Sender, links, urgency and context: and why bad spelling is no longer the tell.

3

Malware and ransomware

How infection happens, what ransomware does, and why backups are the real defence.

4

Passwords and access

Strong unique passwords, password managers and multi-factor authentication.

5

Safe working habits

Public wi-fi, devices, removable media, screen locking and working in public places.

6

Reporting an incident

Recognising that something has gone wrong, and reporting fast without fear of blame.

Outcomes

What you will be able to do afterwards

  • Recognise a phishing attempt in email, text or a phone call
  • Check a link or a sender before acting on a message
  • Explain how ransomware gets in and what limits the damage
  • Use strong unique passwords and multi-factor authentication
  • Work safely on public networks and shared devices
  • Report a suspected incident immediately and without hesitation

Your legal duty

The law behind security awareness training

There is no regulation requiring security awareness training by name. The nearest duty sits in data protection law: the UK GDPR requires appropriate technical and organisational measures to keep personal data secure, and staff awareness is one of the organisational measures regulators expect to see.

In practice the driver is commercial as much as legal: cyber insurance, client due diligence and certification schemes routinely ask whether staff receive security awareness training, and when they last had it.

  • UK GDPR - appropriate technical and organisational security measures
  • Data Protection Act 2018
  • Regulated by the Information Commissioner's Office (ICO)
  • No statute names security awareness training; insurers and clients increasingly ask for it

Practicalities

How the course works

WhereOnline, in a browser: phone, tablet or computer
WhenStart straight after payment; pause and resume any time
How longAround 30 minutes, with no time limit on completion
AssessmentQuestions throughout, retaken as often as you need
CertificateIssued on completion, downloadable as a PDF
RefresherCommonly annual; certificate valid 3 years

For employers

Security awareness across a workforce

Attackers target whole organisations, so partial coverage is the weakness. An account lets you cover everybody and prove when you did.

  • One invoice instead of a card payment per person
  • Licences allocated as people join, so induction is covered
  • Completion and expiry reporting for your records
  • Renewal reminders before certificates lapse
  • Bespoke versions built around your own procedures

Where your own procedures, equipment and reporting lines need to be in the training, we can build that version for you. Talk to us about a bespoke version →

Phishing, Malware and Online Security eLearning: common questions

Not by name. Data protection law requires appropriate organisational measures to keep personal data secure, and staff awareness is one of those. Insurers and clients also increasingly ask for evidence of it.

That advice is out of date and the course says so. Modern phishing is well written, well branded and often references real events, which is why the checks that still work are sender, link and context.

Report it immediately. The course is built around removing the fear of blame, because the damage from a phishing click is largely determined by how fast it gets reported.

Yes: how infection happens, what it does, and why tested backups and fast reporting matter more than any single control.

About 30 minutes, with no time limit: start it, pause it, and come back whenever suits. The certificate is issued the moment you finish.

Yes. It runs in a browser on any modern phone, tablet or computer, with nothing to install.

Yes. Open a business account and we invoice you for the licences, which you allocate as people need them, with completion reporting included.

Skip to main content