Office Awareness with Phishing Training
How email attacks work, how to recognise them and what to do when it matters.
The lessons
-
1
Why?
Why cyberattacks happen at all: who attacks, what they are after and why, despite all the technology, it ultimately comes down to each individual person.
-
2
Is my organisation affected?
How high the chances of a successful attack really are, and how much your resilience can improve through training and practice.
-
3
Phishing attacks exploit psychology · View free preview
Phishing plays on psychology: curiosity, fear, time pressure, trust, helpfulness and the underestimated “autopilot mode” when we read inattentively. Explained with real examples.
-
4
How do phishing attacks by email work?
What exactly phishing is and how an attack unfolds step by step, from the fake website to the hidden link you should check before clicking.
-
5
Ground rules at work – and how email works
How email technically travels across several servers and why this route is not secure by design, the basis for understanding the protective measures that follow.
-
6
The sender – whom can you trust? · View free preview
Why the sender of an email proves nothing: a live demo shows how any sender can be faked with just a few commands.
-
7
Part 2: How to protect yourself
The second part of the course: from here on it is about concrete options for action, what you yourself can do to protect yourself.
-
8
Protection: software updates
The first line of self-defence is updates: why up-to-date software on computers and smartphones closes known security gaps that attackers would otherwise exploit.
-
9
Passwords and two-factor authentication
Why a stolen password on its own must not be enough: password managers, long passphrases and the second factor.
-
10
Opening emails safely: HTML emails and remotely loaded images
Why automatically loading images in emails is a “gift” to the attacker, and how to switch it off in your email program.
-
11
Watch out, smartphones: phishing and malware on your phone
Smartphones catch malware too and are a gateway into the network. When it comes to phishing, the same applies on your phone as on your computer.
-
12
Good to know about email communication – encryption
Why emails in everyday office life are practically never truly encrypted, and the important principle of never sending passwords or secret data by email.
-
13
Malware: viruses, worms, Trojans, ransomware
An overview of the types of malware, from viruses, worms and Trojans to ransomware, and how it gets onto a device.
-
14
Good to know about email communication – responding to spam
How to respond correctly to unsolicited emails and spam, instead of inviting more mail or more risk.
-
15
Recognising phishing: the warning signs
The most important lesson: how to recognise a fraudulent email. With the BSI’s warning signs and the 3-second rule. Sender, subject, attachments.
-
16
The call-back rule: CEO fraud, invoice fraud, changed bank details
When someone wants money, data or a change of bank details: check through a second, known channel before you act.
-
17
Vishing and smishing: fraud by phone and text message
The same scam without email: calls from supposed support staff, texts from the parcel service, faked video calls. And why AI voice clones and deepfakes make the call-back rule more important than ever.
-
18
Report incidents!
What to do if you have fallen for it after all: act immediately, change your login details, report the incident. Reporting early prevents worse.
-
19
You have reached the end of the online course
The end of the course and the transition to practical phishing training in your own inbox.