Foundations
Recognize a phishing attempt
Learn a repeatable way to assess a suspicious message without opening its links or trusting its urgency.
FREE FOUNDATIONS
Forty concise lessons, including 20 micro-lessons. Build understanding before moving into deeper professional practice.
AVAILABLE NOW
Foundations
Learn a repeatable way to assess a suspicious message without opening its links or trusting its urgency.
Identity
Build account resilience with unique credentials, a password manager and a recovery plan.
Identity
Understand what MFA protects, where it can fail, and how to avoid approving an attacker’s sign-in.
Incident response
Respond calmly, preserve useful evidence and get the right people involved.
Foundations
Reduce common endpoint risks through updates, sensible installation choices and protected storage.
Foundations
Protect workspaces, documents and devices without making everyday work unnecessarily difficult.
Foundations
Understand how attackers exploit normal helpful behaviour and how a consistent process reduces that pressure.
Privacy
Understand what you share, who can access it and what happens when a device or account is lost.
Foundations
Use a short review to find preventable gaps before adding more security products.
Foundations
Set up remote work around protected devices, approved services and clear reporting.
AVAILABLE NOW
Incident response
Connect prevention, containment and recovery into a practical ransomware response sequence.
Cloud security
Secure collaboration services by controlling identity, application permissions, sharing and administrative activity.
Cloud security
Move from spotting suspicious wording to understanding account compromise, OAuth abuse and payment-process risk.
Endpoint security
Define appropriate controls for personally owned and organisation-owned devices without assuming they have identical needs.
Identity
Reduce account takeover and excessive privilege with strong authentication and deliberate access design.
Incident response
Move from “we have backups” to evidence that important services can be restored within an acceptable window.
Network security
Limit unnecessary communication and make access decisions explicit across identities, devices and services.
AVAILABLE NOW
Security+ preparation
Build the vocabulary needed to reason about security scenarios without reducing them to memorised acronyms.
Security+ preparation
Connect threats to weaknesses and consequences, then choose a proportionate response.
Security+ preparation
Understand how architecture shapes failure, trust and recovery before selecting individual products.
AVAILABLE NOW
Identity
MFA combines independent kinds of proof. It reduces many password-only risks, but users still need to recognise unexpected prompts and protect recovery access.
Foundations
Focus on the action requested, not only spelling or visual design. A familiar sender can be compromised, and a professional message can still ask you to bypass a sensible process.
Identity
Use a long, unique credential for each service. A password manager can generate unpredictable passwords so one compromised service does not expose a reused credential elsewhere.
Incident response
Ransomware incidents can involve encryption, data theft and operational disruption. Prepared response contacts and tested recovery reduce confusion when a warning appears.
Foundations
Social engineering uses pressure, authority or helpfulness to influence a decision. A consistent verification process makes it easier to refuse an unsafe exception without personal conflict.
Privacy
Public profiles can reveal roles, suppliers, travel and working patterns. This can make deceptive messages more convincing. Review what your posts disclose without assuming that obscurity alone provides security.
Endpoint security
Unknown removable media may contain unwanted software or present other device risks. Use approved transfer methods and let the responsible team handle found media.
Foundations
An unexpected call or browser message may pretend to be support. Do not install remote-access software, share codes or pay a fee because an unsolicited message demands it.
Network security
Use supported router software, a unique administrator credential and an appropriate wireless security configuration. Keep guest and work access separated where supported and review connected devices.
Incident response
A breach notice needs context: what information was involved, which account is affected and what protective actions are recommended. Use the service’s known address to verify the notice.
Identity
A password manager helps maintain unique credentials, but its own access and recovery need protection. Understand vault locking, MFA, device security and the risk of unprotected exports.
Career awareness
Check the employer, recruitment channel and requested action. Requests for upfront payment, sensitive documents too early or installing unusual software deserve independent verification.
Foundations
A QR code is another way to carry a link. A sticker can replace a legitimate code. Check the destination and avoid entering credentials or payment details into an unexpected page.
Privacy
Review which applications can access location and when. Public posts, shared maps and account access can also disclose whereabouts. Use permissions that match a real need.
Identity
A phone number can be an account-recovery channel. Protect mobile-provider account access and prefer stronger supported authentication for important services. Unexpected loss of service deserves prompt investigation.
Identity
Turning on 2FA is the beginning, not the end. Know which method is enrolled, how prompts appear and how to recover after losing the device. Keep recovery information secure.
Endpoint security
Extensions can have broad access to web pages. Review the publisher, purpose and requested permissions. Remove extensions you no longer need and use organisational approvals at work.
Foundations
Verify the merchant and the destination before entering payment information. Use known services and review unusual urgency, payment methods or changed bank details. HTTPS protects a connection, not the honesty of the seller.
Endpoint security
A browser page claiming to have scanned your whole device may be misleading. Do not install software or pay because a pop-up pressures you. Use your known security application or support team.
Network security
An intermediary may try to observe or alter communication. Correctly validated encrypted connections help protect against some forms of interception. Do not ignore certificate warnings or assume a familiar network name proves trust.