Learn to recognize cyber threats like phishing and social engineering, protect sensitive data, and follow security best practices to keep yourself and your organization safe.
In today's digital world, every employee plays a critical role in protecting information and systems from cyber threats. This course provides a practical, non-technical introduction to information security, equipping learners with the awareness and habits needed to recognize risks and respond appropriately — no technical background required. Learners begin by understanding the current threat landscape, including common attack types such as phishing, social engineering, malware, and ransomware. The course explains how attackers exploit human behavior rather than just technical weaknesses, and why every individual is a critical line of defense in an organization's security posture. A major focus of the course is phishing and social engineering awareness. Learners will study real-world examples of suspicious emails, messages, and phone calls, learning to spot red flags such as urgency, unfamiliar senders, suspicious links, and requests for sensitive information. Practical guidance is provided on how to verify requests, report suspicious activity, and avoid falling victim to manipulation tactics. The course also covers password security and authentication best practices, including creating strong passwords, using password managers, and the importance of multi-factor authentication. Learners will explore safe data-handling practices — how to classify, store, share, and dispose of sensitive information securely, both in the office and while working remotely. Device and network security are addressed as well, covering safe use of company devices, risks of public Wi-Fi, safe browsing habits, and the importance of keeping software updated. The course also introduces physical security practices, such as securing workstations and safeguarding access badges, and explains why these everyday habits matter just as much as digital precautions.