Cybersecurity
-
20 Minutes
-
For all staff
-
Global
This 20-minute global course covers how to recognise cybersecurity risks, where they typically originate, how to counter them, and the support arrangements available when an incident occurs. Staff learn to identify threats, act appropriately in specific situations, and find the sources of information and help the organisation provides.
Attackers probe an international group for its weakest point, and inconsistent awareness between locations gives them one. Time zones also mean an incident often starts where nobody senior is awake. Delivering the same standard everywhere shortens the time between something looking wrong and someone reporting it, which is the variable that determines how much damage an intrusion causes.
What you’ll learn in
this course
- Recognise cybersecurity threats and where they come from
- Act appropriately in given situations to combat cybersecurity threats
- Identify sources of information and support
Hear from our customers
Being able to personalise our own training has been a game-changer! Excellent training was provided on how to use the CMS and the support team have been so helpful, patient and quick to reply when I've got stuck.
Feefo Customer Rating ★★★★★ 4.9/5
Ready to try this course?
Start your free trial of this course and get instant access today.
Want to explore more courses?
Browse all courses and search by topic to find what matters most to you.
Operational Resilience
Resilience regulation shifted the question from whether a firm can prevent disruption to whether it can keep serving customers during one. That needs more than the business continuity plan already sitting on the shared drive. Training staff on impact tolerances and service mapping is what turns a board-level commitment into something your operational teams can actually execute under pressure.
Explore the course
Operational Risk
Operational risk frameworks usually fail at the reporting layer, not the design layer, because staff never learned what counts as a risk event worth escalating. A shared way of describing cause and consequence fixes more of that than another policy revision will. This course gives every function the same language, which is what makes aggregated risk data mean something to a board.
Explore the course
Business Continuity Management
Continuity plans are written by a small group and executed by everyone, usually at short notice and under stress. If staff first encounter the plan during an incident, it will not work as designed. Training the wider workforce is what converts documentation into capability, and it supports the resilience expectations that now apply across financial services and beyond.
Explore the course
Information Security Compliance Training Course
Attackers target people because people are reachable, and most incidents begin with an ordinary action rather than a technical failure. For firms in scope of DORA or facing supplier security assessments, evidence of staff-level security training is now requested directly. Delivering it across the workforce gives you both the practical control and the documentation.
Explore the course
Digital Operational Resilience Act (DORA)
DORA reaches beyond EU-domiciled firms, catching group entities and technology providers that serve in-scope financial institutions wherever they are based. Non-EU organisations frequently discover their obligations through a client contract rather than a regulator. Training staff across technology, procurement and operations gives an international group one standard rather than a patchwork assembled entity by entity.
Explore the course
Electronic Communications
Business communications are disclosable in litigation and reviewable by regulators, and the informal register people use in chat tools does not read well years later out of context. Recording and retention obligations also extend to channels many staff assume are private. Setting the expectation clearly protects individuals from a message written quickly and protects the firm from having to explain it.
Explore the course
Digital Operational Resilience Act (DORA)
DORA is prescriptive in a way earlier resilience guidance was not, with defined requirements for incident reporting, testing and third party oversight, and supervisory consequences for gaps. The obligations reach beyond the technology function into procurement, operations and governance. Training staff across those areas is what allows a firm to demonstrate compliance rather than describe an intention to comply.
Explore the course
Cybersecurity
Attackers probe an international group for its weakest point, and inconsistent awareness between locations gives them one. Time zones also mean an incident often starts where nobody senior is awake. Delivering the same standard everywhere shortens the time between something looking wrong and someone reporting it, which is the variable that determines how much damage an intrusion causes.
Explore the course
Records Management
Records are held too long as often as they are destroyed too early, and both create exposure: one under data protection law, the other during litigation or a regulatory request. Retention decisions are made by individuals every day without much thought. Giving the workforce a clear framework means your retention schedule describes what actually happens rather than what was intended.
Explore the course
Information Security
Security behaviour degrades between annual courses, and attackers rely on that. A short refresher keeps classification habits and email caution current without repeating the full course, which makes it practical to run more than once a year. For firms subject to DORA or regular client security assessments, a documented refresher cycle is increasingly what evidence of ongoing awareness actually means.
Explore the course
Cybersecurity Compliance Training Course
Attackers target people because people are reachable and predictable under time pressure. The short format matters here: cyber awareness works best delivered frequently rather than thoroughly once a year, since the techniques change faster than annual training cycles. Running this across the whole workforce gives you a control that scales, and satisfies the staff awareness expectations that appear in client and supplier security assessments.
Explore the course
Phishing
Phishing is how most breaches begin, and the messages have improved enormously with better tooling behind them. The decisive factor is rarely whether someone clicked but how quickly they said so. Training that removes the embarrassment around reporting shortens that gap, and short modules can be repeated often enough to keep pace with techniques that change every few months.
Explore the course
Think Before You Click
Clicking on malicious links or attachments is one of the most common ways cybercriminals infect IT systems with malware. This training helps employees recognise suspicious emails, understand the dangers of phishing and ransomware and apply best practices to protect company data.
Guide to Secure Remote Working
Remote work provides flexibility but also introduces cybersecurity risks that can compromise company data and systems. This training helps employees understand the security challenges of working from home and apply best practices to protect sensitive information.
CEO Fraud
CEO fraud is a type of Business Email Compromise where cybercriminals impersonate executives to trick employees into making payments or sharing confidential information. This training helps employees recognise CEO fraud attempts, understand spoofing tactics and follow verification steps to prevent financial and data loss.
Advising Customers on Cybersecurity
Cybersecurity is everyone's responsibility, including guiding customers to protect themselves from online threats. This training helps employees understand common cyber risks customers face and how to provide clear, helpful security advice to build trust and prevent fraud.
Using Wi-Fi safely
Wi-Fi connectivity offers convenience but also exposes devices and data to security risks if not properly managed. This training helps employees understand Wi-Fi security threats and apply best practices to protect sensitive information when working from home, in the office and on the move.
Transferring Information Securely
Securely transferring information is essential to protect sensitive data from breaches, legal risks and business disruptions. This training helps employees understand best practices for secure communication, including encryption, password protection and using secure transfer protocols.
Supply Chain Cybersecurity
A company’s cybersecurity is only as strong as its weakest link and supply chain vulnerabilities can expose businesses to major breaches. This training helps employees understand the risks posed by third-party access, the importance of supply chain security and best practices to prevent cyberattacks.
Secure Web Browsing
Practicing safe web browsing helps to reduce security risks and protect sensitive information. This training explains how to browse the internet securely and avoid common cyber threats.
Tailgating and Piggybacking
Cybersecurity is not just about digital protection but also involves securing physical access to critical systems. This training helps employees recognise security risks like tailgating and piggybacking, understand their consequences and take steps to prevent unauthorised access.
Information Security on the Move
Handling company information securely, especially when working remotely or traveling, is essential to prevent data breaches and security risks. This training helps employees understand how to protect sensitive information, secure devices and minimise exposure to cyber and physical threats.
Information Classification
This training helps employees understand different levels of information classification, their restrictions and how to handle data securely.
Reacting to Password Breaches
Password breaches can lead to unauthorised access, fraud and data theft, often resulting from weak passwords, phishing or insecure networks. This training helps employees recognise the warning signs of compromised credentials, understand the risks and apply best practices to prevent breaches.
Multi-factor Authentication
Multi-factor authentication (MFA) enhances security by requiring users to verify their identity through multiple authentication methods. This training helps employees understand the importance of MFA, how it protects company data and when it should be used.
Creating Strong Passwords
Strong password protection is essential to safeguarding company systems from cyber threats such as brute force attacks and password guessing. This training helps employees understand the importance of creating strong passwords, following security policies and preventing unauthorised access.
Vishing
Vishing is a social engineering attack where cybercriminals use phone calls to trick individuals into revealing sensitive information. This training helps employees recognise vishing attempts, understand manipulation tactics and apply best practices to verify callers and protect confidential data.
Video Conferencing
Video conferencing is a vital business tool, but it also presents security and privacy risks if not used correctly. This training helps employees understand best practices for secure video meetings, from using approved software to protecting confidential information.
Spear Phishing
Spear phishing targets specific individuals with convincing emails designed to deceive them. This training demonstrates how to recognise and handle these targeted phishing attempts.
Smishing
Smishing is a targeted phishing scam that uses deceptive text messages to gain sensitive information. This training highlights how to recognise and avoid falling victim to smishing attacks.
Ransomware
Ransomware is a type of malware that encrypts files and demands payment for their release, often causing severe financial and operational damage. This training helps employees recognise ransomware threats, understand how attacks occur and take preventive measures to protect company systems.
Malware
Malware is malicious software designed to harm or exploit computer systems, ranging from viruses and ransomware to spyware and botnets. This training helps employees recognise different types of malware, understand how they spread and take proactive steps to prevent infections.
Device Hygiene
Device hygiene is the practice of keeping digital devices secure and free from cyber threats to protect company data and networks. This training helps employees understand the importance of device hygiene and apply best practices to prevent malware infections, data breaches and unauthorised access.
Bring Your Own Device Security
Bring Your Own Device (BYOD) policies offer convenience and flexibility but also introduce cybersecurity risks. This training helps employees understand the precautions necessary to secure personal devices and protect company data from threats like theft, hacking and data breaches.
Zero Trust Cybersecurity
The zero trust cybersecurity model ensures IT systems remain inaccessible by default, requiring strict verification before granting access. This training helps employees understand how zero trust works, including authentication measures, restricted access and continuous security monitoring.
Common Cyber Threats
Cyber threats such as phishing, malware, ransomware and unsecured networks pose significant risks to businesses. This training helps employees recognise common cyber threats, understand their impact and apply best practices to prevent security breaches.
Understanding Information Security
Information security is essential to protect sensitive business and customer data from unauthorised access, breaches and cyber threats. This training helps employees understand their role in safeguarding information, following security policies and identifying potential risks.
Deepfake Awareness
Deepfakes use artificial intelligence to create fake images, audio or videos that can deceive individuals and organisations. This training helps employees recognise deepfake scams, understand their risks and apply verification steps to prevent fraud and cybercrime.
Business Email Compromise
Business Email Compromise (BEC) is a targeted cyberattack where criminals impersonate executives or hack accounts to steal money or sensitive information. This training helps employees recognise different types of BEC scams, understand the risks and apply verification steps to prevent fraud.
Spot a Phishing Attempt
Phishing emails are fraudulent attempts by cybercriminals to trick individuals into revealing sensitive information. This training helps employees recognise phishing attempts, identify red flags in emails and take steps to protect personal and company data from cyber threats.
Your questions, answered
DORA