Security Awareness Training
SECURITY AWARENESS PROGRAM
Employee Training — Rev. 2026.1

Security starts with you.

Most breaches don't begin with clever code. They begin with a click, a shared password, or a moment of trust.

Read time ~8 min Modules 5 Assessment 10 questions

Five things every account holder should know

Read each module before taking the assessment. The test questions map directly to the practices below.

MODULE 01 / PHISHING & SOCIAL ENGINEERING

Attackers target people, not just systems

Phishing is a message designed to make you act before you think — usually by clicking a link, opening an attachment, or handing over credentials. It works because it borrows real logos, real names, and real urgency. Social engineering is the same trick over the phone or in person: someone impersonates authority to pressure you into helping them.

Red flags to watch for
  • Urgency or threats — "your account closes in 1 hour," "act now or lose access."
  • A sender address that doesn't match the display name, or a look‑alike domain.
  • Requests for passwords, codes, or payment that "must" happen right now.
  • Unexpected attachments or links, even from a name you recognize.

Do this: slow down, verify through a channel you already trust (not the one in the message), and report anything suspicious to IT or Security.

MODULE 02 / PASSWORDS & MFA

Length beats complexity — and MFA covers the rest

A long, unpredictable passphrase (four or more random words) is far harder to crack than a short password stuffed with symbols. Never reuse a work password anywhere else, and use the company password manager instead of memorizing or writing them down.

Multi‑factor authentication (MFA) adds a second proof of identity, so a stolen password alone isn't enough to get in. If you ever receive an MFA prompt you didn't trigger, that means someone has your password and is trying to log in as you.

  • Use a unique passphrase per account, stored in the password manager.
  • Turn on MFA everywhere it's offered.
  • Deny any MFA request you didn't start, then change your password and report it.
MODULE 03 / HANDLING DATA

Right information, right people, right place

Treat data on a need‑to‑know basis. Information marked Confidential or Restricted should only be shared with people who require it for their work, and only through approved systems. Moving company data to personal email, personal cloud storage, or an unmanaged USB drive removes it from the organization's protections — even if your intent is just a backup.

  • Share on a least‑privilege basis: only those who need it.
  • Keep company data in approved, managed systems.
  • Never copy sensitive data to personal accounts or unknown devices.
MODULE 04 / DEVICES & PHYSICAL SECURITY

Your unlocked screen is an open door

Lock your screen every time you step away — even for a coffee. Walk‑up access and "tailgating" (following someone through a secure door) are common ways attackers get in without touching a keyboard remotely. Unknown USB drives are another classic trap: a device "found" in a parking lot may be bait designed to run malware the moment it's plugged in.

  • Lock your screen whenever you leave your desk (Win + L, or Ctrl + Cmd + Q on Mac).
  • Don't hold secure doors open for people you can't vouch for.
  • Never plug in a USB drive you didn't buy or receive through a trusted channel.
MODULE 05 / REPORTING INCIDENTS

Report early — even when you're not sure

If you think you clicked something you shouldn't have, entered a password on a suspicious page, or lost a device, report it immediately. Fast reporting is what limits the damage. Security teams would far rather investigate a false alarm than discover a real breach days later. You will not be blamed for reporting a genuine mistake.

  • Report suspected phishing, clicks, or lost devices right away.
  • Use your organization's Security/IT reporting channel, not a guess.
  • When unsure, report anyway — speed matters more than certainty.

Knowledge check

Answer all ten questions, then submit to see your score. Each question is marked with the correct answer and a short explanation. You need 80% (8 of 10) to pass.

> All questions must be answered before grading.
0 / 10 correct
0%Pass mark: 80%100%

SECURITY AWARENESS PROGRAM · This briefing is training material. Report real incidents through your organization's Security or IT channel.

Security Awareness Training