← Secured Cyber Security For Non Techies · Lesson 5 of 10

Module Four

📖 Every lesson in this course is free to read right here, no account needed. Create a free account to track your progress, take the exam, and earn your certificate.
1

Course Outline

Secured Cyber Security For Non Techies · Course Outline

Secured Cyber Security For Non Techies

2026 · v2.0
Duration: 3–5 days (24–40 hours)
Modules: 8 core + capstone
Level: Beginner · No IT background required
Format: In-person · virtual · hybrid
Course overview
The Secured Cyber Security For Non Techies program is designed for professionals across all business functions who need to understand cybersecurity as a business risk and strategic imperative, not just an IT concern . Participants will learn to speak the language of security, identify common threats, apply practical controls, and contribute to a culture of digital resilience—all without any technical background .
Detailed syllabus
M1 Cybersecurity Fundamentals & Digital Business Risk 4h
  • Why cybersecurity is everyone's responsibility: moving beyond the IT silo
  • Core principles: Confidentiality, Integrity, Availability (CIA triad)
  • The digital threat surface: how connectivity, automation, and data reliance expand risk
  • Cybersecurity as business value: protecting brand, trust, and innovation
Security mindset Risk vs. threat vs. vulnerability Digital transformation
M2 Common Cyber Threats & Attack Types 5h
  • Social engineering: phishing, spear-phishing, smishing, vishing, and whaling
  • Malware & ransomware: how they spread and why they're so damaging
  • Password & credential attacks: methods used by attackers
  • Insider threats: accidental and malicious risks from within
Business Email Compromise DDoS attacks Man-in-the-middle Fake URLs
M3 Everyday Defences: Practical Security for Non-Techies 5h
  • Password & identity hygiene: creating strong passwords, using password managers, and Multi-Factor Authentication (MFA)
  • Email & device security: spotting red flags, safe browsing, and updating software
  • Secure remote working: VPNs, public Wi-Fi risks, and cloud security
  • Backup & recovery: why it matters and how to do it effectively
Phishing identification Device hygiene Encryption basics Safe AI use
M4 Risk Assessment & Security Posture 4h
  • Understanding cyber risk: threats, vulnerabilities, assets, and controls
  • Top three vulnerable risks: focusing on what matters most
  • Quantifying security posture: how to measure and communicate risk
  • Business impact analysis: connecting security to business outcomes
Risk register Asset inventory Control selection Risk appetite
M5 Incident Response & Crisis Communication 4h
  • Incident response lifecycle: detection, triage, containment, and recovery
  • Communication strategy: preparing stakeholders for incidents
  • Reporting pathways: who to tell and when
  • Crisis management: protecting people, brand, and trust
Incident response plans Communication trees Legal considerations Media handling
M6 Governance, Compliance & Frameworks 4h
  • Key frameworks: NIST Cybersecurity Framework (CSF), ISO 27001, GDPR
  • Regulatory landscape: data protection laws and compliance obligations
  • Security policies: what they are and how to implement them
  • Building a governance structure: roles and responsibilities
NIST CSF PDPA ISO 27001 Policy development
M7 Building a Cybersecurity Culture & Awareness Program 3h
  • Shared responsibility model: everyone plays a role
  • Designing awareness programs: simple, engaging, and effective
  • Changing behaviour: moving from awareness to action
  • Leadership's role: modelling secure behaviours
Security champions Training design Phishing simulations Metrics
M8 Emerging Threats & Future-Proofing 3h
  • AI-powered threats: how attackers use AI and how to defend
  • Post-quantum preparedness: what it means for business systems
  • Internet of Things (IoT) & Cloud security: new risks to understand
  • Staying updated: ongoing education and resources
AI & cybersecurity IoT vulnerabilities Cloud best practices Continuous learning
CAP Capstone: Cybersecurity Action Plan 3h + presentation
  • Practical project: design a cybersecurity awareness plan for a case organisation
  • Risk communication: present findings in business language
  • Integration of all modules: from threats to governance to culture
Case study Action plan Implementation roadmap

Learning methodology

  • Interactive lectures
  • Group workshops
  • Scenario-based discussions
  • Real-world case studies
  • Peer-to-peer exchange
24–40 CPE / CEU credits
Assessment: Quizzes, knowledge checks, capstone project
Certification: Certificate of Completion awarded upon passing assessment
Refresher: Recommended annual update to stay current
2

Module One

Module 1 · Secured Cyber Security For Non Techies | Cybersecurity Fundamentals
MODULE 1 · FOUNDATION

Cybersecurity Fundamentals & Digital Business Risk

4 hours (in‑class + workshop)
Focus: Security mindset · CIA triad · digital threat surface · business value
Delivery: Lecture · case studies · group discussion
Weight: 10% of final grade

Imagine your house has a front door with a lock. You lock it to keep your toys, games, and family safe. Cybersecurity is like locking the doors to your digital house! But instead of one door, there are many—your emails, your phone, your computer, and even your smart TV. Hackers are like people trying to break into your digital house. In this module, we'll learn how to keep those doors locked and spot when someone is trying to get in!

Learning objectives
  • Understand why cybersecurity is everyone's responsibility (not just IT)
  • Learn the CIA triad: Confidentiality, Integrity, Availability
  • Identify how digital connectivity expands our "threat surface"
  • Recognise cybersecurity as a business value driver
Module content
1.1 Why Cybersecurity is Everyone's Responsibility 1h

Think of cybersecurity like keeping your classroom safe. Your teacher can't watch every door and window all by themselves. Everyone in the class needs to help—close the door, don't let strangers in, and tell the teacher if something looks wrong. In a company, cybersecurity works the same way! IT teams are like the teacher, but everyone needs to help protect the digital house.

  • Cybersecurity is a team sport: It's not just the IT department's job
  • Real-world impact: How a single mistake can affect the whole company
  • Shared responsibility model: Everyone has a role to play
  • discussion Share a time you noticed a security risk (digital or physical)

Example: The "One Mistake" Ripple Effect

Scenario: An employee clicks on a fake link in an email.
What happens: Hackers steal passwords → They break into the system → They steal customer data → The company loses trust → Customers leave → The company loses money
The lesson: One click by one person can affect everyone—the company, colleagues, and even customers!

1.2 Core Principles: The CIA Triad 1h

Imagine you have a secret diary with three special rules:
1. Only YOU can read it (Confidentiality). — You keep it hidden under your pillow.
2. Your writing doesn't get scribbled out (Integrity). — No one changes what you wrote.
3. You can read it whenever you want (Availability). — It's always there when you need it.
These three rules are the CIA Triad—the most important ideas in cybersecurity!

  • Confidentiality: Keeping secrets secret. Only the right people can see the information
  • Integrity: Making sure information hasn't been changed or tampered with
  • Availability: Making sure information is there when you need it
  • workshop Identify CIA triad examples in everyday life

Example: CIA Triad in Action

Confidentiality: Your medical records are only shared with your doctor.
Integrity: Your bank statement shows the correct balance (not altered by a hacker).
Availability: You can access your email when you need to check an important message.

All three are important! If any one fails, there's a security problem.

1.3 The Digital Threat Surface 1h

Your "threat surface" is like all the doors and windows of your digital house. Every app you use, every website you visit, and every device you own is a door. The more doors you have, the more ways a bad person could try to get in. As companies grow, they get more doors—more devices, more apps, more places to protect. Cybersecurity is about knowing where all your doors are and making sure they're locked!

  • What is a threat surface? All the places where a hacker could attack
  • Digital connectivity: More connected devices = more risk
  • Automation and data reliance: How technology increases our exposure
  • exercise Map the threat surface of a typical office

Example: Expanding the Threat Surface

10 years ago: A small company had 10 computers and 1 server.
Today: The same company has 100 computers, 50 smartphones, 30 tablets, cloud storage, smart printers, employee wearables, and IoT sensors.

More doors = more risk! Each new device is another way a hacker could try to get in.

1.4 Cybersecurity as Business Value 1h

Why do companies spend money on cybersecurity? It's like why you pay for a good lock on your bicycle. A good lock costs money, but it's cheaper than buying a new bike! Companies invest in cybersecurity to protect their money, their reputation, and their customers' trust. When customers trust a company, they buy more. Security helps build that trust.

  • Security is an investment, not a cost: Protecting the business
  • Brand and trust: How security affects customer loyalty
  • Innovation enablement: Security allows companies to try new things safely
  • case study Companies that lost trust due to a security breach

Example: The Cost of a Breach

A company gets hacked:
- Money lost: $4 million in fines and legal fees
- Trust lost: 40% of customers leave to competitors
- Time lost: 3 months of lost productivity while fixing things
- Reputation lost: 2 years to rebuild trust with customers

Investing in cybersecurity: $500,000 would have prevented it all!

Key takeaway: Cybersecurity is not just an IT problem—it's a business priority that everyone must understand. By thinking about security like locking the doors to your digital house, you can protect your company, your customers, and yourself. CIA · Threat Surface · Responsibility
Resources: CIA Triad worksheet · Threat surface mapping template · Security mindset guide
Pre‑work: watch “Cybersecurity for Beginners” (15 min)
Reading: “Why Security is Everyone's Job” (5 min article)
3

Module Two

Module 2 · Secured Cyber Security For Non Techies | Common Cyber Threats
MODULE 2 · CORE

Common Cyber Threats & Attack Types

5 hours (in‑class + workshop)
Focus: Social engineering · malware · ransomware · password attacks · insider threats
Delivery: Lecture · case studies · phishing simulation
Weight: 15% of final grade

Think of cyber threats like the "tricks" bad guys use to break into your digital house. Some try to fool you into opening the door (social engineering). Others sneak in through a broken window (malware). Some even try to guess your secret password (password attacks). In this module, we'll learn about all the ways hackers try to get in—and how to stop them!

Learning objectives
  • Identify different types of social engineering attacks
  • Understand how malware and ransomware work
  • Recognise password and credential attacks
  • Understand insider threats (accidental and malicious)
  • Spot common red flags and warning signs
Module content
2.1 Social Engineering: Tricks That Fool People 1.5h

Social engineering is like a magician trick—but instead of making you disappear, they make YOUR INFORMATION disappear! Hackers use clever tricks to convince you to give them your password, click a bad link, or send them money. They might pretend to be your boss, your bank, or even your friend. The best defence? Always double-check before you click, call, or send!

  • Phishing: Fake emails that look real, trying to get you to click or share info
  • Spear-phishing: Targeted phishing—hackers know your name and use it!
  • Smishing: Phishing via text messages (SMS)
  • Vishing: Phishing via phone calls—"Hello, this is the bank..."
  • Whaling: Phishing attacks targeting big fish—CEOs and VIPs
  • simulation Spot-the-phishing game: Can you tell which emails are fake?

⚠️ Red Flag: If someone asks for your password, credit card, or personal info—STOP! Legitimate organisations never ask for this via email, text, or phone.

Example: Phishing Attack

You receive an email that looks like it's from your bank:
"Your account has been compromised! Click this link to reset your password NOW."

The truth: The link goes to a fake website that steals your password. Your bank would NEVER send a link like this.
What to do: Always go directly to your bank's website (type the address yourself) or call them using the number on your card.

2.2 Malware & Ransomware: Digital Germs 1.5h

Malware is like a virus for your computer. Just like germs can make you sick, malware can make your computer sick. Ransomware is even scarier—it locks up your computer and demands money to unlock it! Imagine someone locking your diary and saying "Pay me $100 or you'll never read it again." The good news? You can prevent malware by being careful what you click and keeping your software updated.

  • What is malware? Software designed to damage or steal from your device
  • Types of malware: Viruses, worms, trojans, spyware, and adware
  • Ransomware: Holds your files hostage—pay money to get them back
  • How malware spreads: Email attachments, fake downloads, infected websites
  • case study The WannaCry ransomware attack (it affected 150+ countries!)

⚠️ Red Flag: Don't download files from unknown sources. If an email has an attachment you weren't expecting—DON'T OPEN IT!

Example: Ransomware Attack

Scenario: An employee opens an email attachment that looks like an invoice.
What happens: Ransomware encrypts (locks) all files on the company network.
The demand: "Pay $1 million in Bitcoin or lose all your files forever."
The result: The company can't work for a week, loses $5 million in revenue, and pays $500,000 to get their files back.
The lesson: Always verify email attachments before opening!

2.3 Password & Credential Attacks 1h

Passwords are like the secret knock to your treehouse. If someone figures out your knock, they can get in! Hackers use different tricks to guess your password. Some try common passwords like "password123" or "iloveyou." Others use computers to try millions of guesses in seconds! The best defence? Use long, unique passwords for each account—or better yet, use a password manager!

  • Brute force attacks: Computers try millions of passwords per second
  • Dictionary attacks: Using common words and phrases from the dictionary
  • Credential stuffing: Using passwords stolen from one site to break into another
  • Password reuse: The #1 mistake people make!
  • workshop Create a strong password policy for your team

⚠️ Red Flag: If you're using the same password for multiple accounts, you're at HIGH risk. One breach = all accounts compromised!

Example: The Danger of Password Reuse

You use the same password for:
- Your personal email
- Your work email
- Your bank account
- Your social media

One day: A gaming site you joined years ago gets hacked. Hackers steal your password.
Now what? Hackers try that password on your bank, email, and social media—and it WORKS!
Solution: Use unique passwords for every account. A password manager can help remember them all!

2.4 Insider Threats: The Enemy Within 1h

An insider threat is when someone inside the company causes a security problem. Sometimes it's an accident—like leaving your work laptop on the train. Other times, someone might steal information on purpose because they're upset at the company. That's why it's important to treat everyone kindly and have good security policies—even for people you trust!

  • Accidental threats: Mistakes like sending an email to the wrong person
  • Malicious threats: Employees or contractors who deliberately cause harm
  • Negligent threats: Carelessness like using weak passwords
  • Indicators of insider threats: Unusual behaviour, working odd hours, downloading lots of data
  • discussion How would you prevent insider threats in your company?

⚠️ Red Flag: If you notice a colleague acting suspiciously—like downloading files they don't need—report it to your security team. It's better to be safe than sorry!

Example: Insider Threat

Scenario: An employee is leaving the company. On their last day, they download 10,000 customer records to a USB stick.
Why it's a problem: They plan to use those records at their new job.
What happened: The company later finds out that competitors have their customer list.
Prevention: Companies should monitor data downloads and disable USB drives on company computers!

Key takeaway: Cyber threats come in many forms—from clever social engineering tricks to sneaky malware and insider mistakes. By understanding how attackers think and operate, you can spot red flags and protect yourself, your team, and your company. Phishing · Malware · Passwords · Insider
Resources: Phishing identification guide · malware prevention checklist · password policy template
Pre‑work: watch “Spot the Phishing Attack” (15 min)
Reading: “The Psychology of Social Engineering” (10 min article)
4

Module Three

Module 3 · Secured Cyber Security For Non Techies | Everyday Defences
MODULE 3 · CORE

Everyday Defences: Practical Security for Non-Techies

5 hours (in‑class + workshop)
Focus: Password hygiene · MFA · email safety · device security · backup
Delivery: Lecture · hands-on workshops · simulations
Weight: 15% of final grade

Now that we know about all the "bad guys" and their tricks, let's learn how to stop them! This module is all about everyday defences—simple things you can do to protect yourself and your company. Think of it like learning to lock your doors, check who's at the window, and even have a backup plan if something goes wrong. The best part? These defences work for everyone—no tech skills needed!

Learning objectives
  • Create and manage strong passwords (and use a password manager!)
  • Enable Multi-Factor Authentication (MFA) wherever possible
  • Spot phishing emails and unsafe websites
  • Keep devices and software secure and updated
  • Back up important data and work safely from anywhere
Module content
3.1 Password & Identity Hygiene 1.5h

Passwords are like the secret knock to your clubhouse. But if you use the same knock for every clubhouse, anyone who learns it can get into ALL of them! That's why you need long, strong, unique passwords for every account. And if remembering them all is hard? Use a password manager—it's like a safe that remembers all your secret knocks for you!

  • Password rules: Long (12+ characters), unique, with mixed characters
  • What NOT to use: "password123", your name, or common words
  • Password managers: Tools that remember your passwords securely (like LastPass, 1Password)
  • Multi-Factor Authentication (MFA): The "extra lock" on your door—it requires a code from your phone
  • workshop Set up a password manager and enable MFA on your accounts

🛡️ Defence of the day: Use a password manager and turn on Multi-Factor Authentication (MFA) for ALL your accounts. It's the single most effective thing you can do to protect yourself!

Example: Creating a Strong Password

Weak password: "password123" (hackers guess this in 1 second!)
Better password: "BlueElephant#42" (better, but still guessable)
Strong password: "C0rrectH0rseBatteryStaple!" (long and unique)
Best solution: Use a password manager to create and remember passwords like "Qx7@mP9#sL2$vR5&" for every account!

3.2 Email & Device Security 1.5h

Your email inbox is like your front door—bad guys LOVE to knock on it. They send fake emails that look real, hoping you'll click a link or open an attachment. But you can spot them! Look for strange email addresses, spelling mistakes, and urgent demands. And always keep your devices updated—it's like getting a stronger lock on your door every time!

  • How to spot phishing emails: Check the sender, hover over links, look for mistakes
  • Safe browsing: Look for "https://" and the padlock symbol in your browser
  • Software updates: Always install updates (they fix security holes)
  • Device hygiene: Lock your screen when away from your desk
  • simulation Identify phishing emails in a real-world simulation

🛡️ Defence of the day: If you receive an unexpected email asking you to click or download—STOP and CHECK! Call the sender using a phone number you know is real.

Example: Spotting a Phishing Email

You receive this email:
"From: PayPal" (but the email address is "paypal@secure-update.net")
"Subject: Your account has been locked!"
"Click here to unlock: http://paypal-secure-login.com"

What's wrong:
- The sender's email address is NOT from PayPal (it's from a fake domain)
- The link goes to a fake website (not real PayPal)
- They're trying to scare you into clicking quickly

What to do: Delete the email! Never click links from unknown senders.

3.3 Secure Remote Working 1h

Working from home is like building a new clubhouse—you need to make sure it's just as safe as your main one! Public Wi-Fi (like at a coffee shop) is dangerous because anyone can listen in on what you're doing. Use a VPN (a secret tunnel for your internet) to keep your work private. And always make sure you're using secure cloud services to save your files.

  • VPNs (Virtual Private Networks): They create a secure "tunnel" for your internet traffic
  • Public Wi-Fi risks: Hackers can see what you're doing on unsecured networks
  • Cloud security: Use trusted services like Google Drive, OneDrive, or Dropbox
  • Home router security: Change the default password on your home Wi-Fi
  • workshop Set up a VPN and secure your home network

⚠️ Danger zone: Never access sensitive work information (like emails or bank accounts) on public Wi-Fi without a VPN. It's like shouting your secrets in a crowded room!

Example: Public Wi-Fi Attack

Scenario: You're at a coffee shop using their free Wi-Fi.
What happens: A hacker on the same network intercepts your traffic and steals your password.
What should you do? Use a VPN! It encrypts (scrambles) your data so even if a hacker sees it, they can't read it.
Also: Make sure you're connecting to the coffee shop's REAL Wi-Fi, not a fake one with a similar name (like "Free Wi-Fi" instead of "Starbucks Wi-Fi").

3.4 Backup & Recovery 1h

Backing up your data is like having a photocopy of your homework. If your dog eats the original, you still have a copy! In cybersecurity, bad things can happen—your computer could break, ransomware could lock your files, or you might accidentally delete something important. Having a backup means you can always get your work back. Remember: backup like it's 3-2-1—3 copies, 2 different storage types, 1 copy off-site!

  • Why backup matters: Protects against ransomware, hardware failure, and accidents
  • The 3-2-1 rule: 3 copies, 2 different storage types, 1 off-site
  • What to backup: Documents, photos, emails, and any work files
  • Testing backups: Make sure your backups actually work!
  • workshop Create a backup plan for your work and personal files

🛡️ Defence of the day: Test your backups! It's not enough to just save files—make sure you can actually recover them when something goes wrong.

Example: The 3-2-1 Backup Rule

You have important files:
Copy 1: Saved on your computer (original)
Copy 2: Saved on an external hard drive (different storage type)
Copy 3: Saved in the cloud (off-site, like Google Drive or OneDrive)

Why it works:
- If your computer breaks → you still have the external drive and cloud
- If ransomware encrypts your files → you can restore from the cloud
- If your house floods → you still have the cloud copy
It's always smart to have a backup plan!

Key takeaway: Cybersecurity doesn't have to be complicated! Simple daily habits—using strong passwords, enabling MFA, spotting phishing, keeping devices updated, and backing up data—can protect you from 90% of common attacks. Passwords · MFA · Backups · Updates
Resources: Password manager guide · phishing spotter checklist · backup plan template
Pre‑work: watch “How to Never Get Hacked Again” (15 min)
Reading: “The 3-2-1 Backup Rule Explained”
5

Module Four

Module 4 · Secured Cyber Security For Non Techies | Risk Assessment & Security Posture
MODULE 4 · CORE

Risk Assessment & Security Posture

4 hours (in‑class + workshop)
Focus: Cyber risk · vulnerability assessment · security posture · business impact
Delivery: Lecture · case studies · risk assessment workshop
Weight: 15% of final grade

Imagine you're the captain of a ship, and you need to know if there are any holes in the hull, pirates nearby, or storms coming. That's what risk assessment is all about! You look at what could go wrong, how likely it is, and how bad it would be if it happened. Then you can decide what to fix first. In cybersecurity, we do the same thing—we look at our digital ship, find the weak spots, and decide which ones to fix first to stay safe!

Learning objectives
  • Understand the components of cyber risk (threat, vulnerability, asset, control)
  • Identify and prioritise the top three vulnerable risks
  • Measure and communicate security posture using simple metrics
  • Conduct a basic business impact analysis
  • Create a simple risk register to track security issues
Module content
4.1 Understanding Cyber Risk 1h

Cyber risk is like this simple formula: Risk = Threat × Vulnerability × Impact
- A threat is something bad that could happen (like a storm).
- A vulnerability is a weakness that makes you more likely to get hurt (like a broken window).
- Impact is how bad it would be if it happened (like losing all your toys).
By understanding these three things, you can figure out which risks to fix first!

  • Threats: External dangers (hackers, malware, natural disasters)
  • Vulnerabilities: Weaknesses that can be exploited (old software, weak passwords)
  • Assets: What you're trying to protect (data, systems, people)
  • Controls: Measures you put in place to reduce risk (MFA, firewalls)
  • workshop Identify threats, vulnerabilities, and assets in a case scenario

Example: Risk Formula in Action

Scenario: A company has customer data in the cloud.
- Threat: Hackers stealing passwords
- Vulnerability: Employees use weak passwords
- Impact: Customer data stolen, company loses trust and money

Risk level: HIGH (because all three factors are serious)
Solution: Enforce strong passwords and MFA (Multi-Factor Authentication) to reduce the vulnerability.

4.2 Top Three Vulnerable Risks 1h

Not all risks are equal—some are like a tiny leak in a boat, others are like a giant hole! You need to figure out which risks are the most dangerous and fix them first. In cybersecurity, the top three risks are usually:
1. Phishing & Social Engineering (tricks that fool people)
2. Weak Passwords & Identity Theft (easy for hackers to guess)
3. Unpatched Software (old software with known holes)
If you fix these three, you've solved most of your problems!

  • How to identify top risks: Use a risk matrix (likelihood × impact)
  • Risk matrix: High/Medium/Low for both likelihood and impact
  • Focus on "critical" risks: Those with high likelihood AND high impact
  • workshop Create a risk matrix for a case organisation
Low Impact
High Impact
Low Likelihood
Monitor
Plan for
High Likelihood
Plan for
Act NOW!

Example: Prioritising Risks

Risk 1: Phishing emails (High likelihood, High impact) → CRITICAL — Act NOW!
Risk 2: Old computer software (Medium likelihood, High impact) → Plan for
Risk 3: Printer running out of toner (High likelihood, Low impact) → Monitor

Action: The company implements phishing training immediately, plans to update all software next month, and keeps track of printer toner regularly.

4.3 Measuring Security Posture 1h

Security posture is like a health check-up for your company's digital safety. Just like a doctor checks your temperature, blood pressure, and weight, we check things like:
- How many employees completed security training?
- How many computers have the latest updates?
- How long does it take to fix a security problem?
By measuring these things, you can see if your company is getting healthier (more secure) over time!

  • What is security posture? The overall health of your cybersecurity program
  • Key metrics: Training completion, patching compliance, incident response time
  • How to measure: Simple dashboards with red/yellow/green status
  • Communicating security: Speak in business language, not technical jargon
  • workshop Create a simple security dashboard for leadership

Example: Security Posture Dashboard

Security Posture Report — Q3 2026

✅ Training completion: 95% (Target: 90%)
✅ Software patching: 88% (Target: 85%)
⚠️ Phishing simulation: 12% clicked (Target: <10%)
✅ Incident response time: 2.5 hours (Target: 4 hours)

Overall security posture: GOOD — But need to improve phishing awareness!

4.4 Business Impact Analysis 0.5h + workshop

Business Impact Analysis (BIA) is asking: "What would happen if this system stopped working?" Imagine if the school's main computer stopped working—could you still learn? How long could you manage without it? In a company, we figure out which systems are MOST important and how long we can survive without them. This helps us decide which risks to fix first!

  • What is BIA? Understanding the consequences of disruption
  • Key concepts: RTO (Recovery Time Objective) and RPO (Recovery Point Objective)
  • RTO: How quickly you need to recover (in hours/days)
  • RPO: How much data you can afford to lose
  • workshop Conduct a BIA for a case organisation

Example: Business Impact Analysis

Scenario: An online store's website goes down.
- Impact: Customers can't buy anything = lost revenue
- RTO: Must be back online within 2 hours (or lose $50,000/hour)
- RPO: Can only lose 5 minutes of data (or orders get lost)
- Action: Invest in backup systems and faster recovery processes.

Key takeaway: Risk assessment isn't about eliminating all risks—it's about understanding which ones matter most and making smart decisions about what to fix first. By focusing on your top risks, you can protect your business without being overwhelmed. Risk · Posture · BIA · RTO
Resources: Risk assessment template · security posture checklist · BIA worksheet
Pre‑work: watch “Risk Assessment for Beginners” (15 min)
Reading: “The Art of Business Impact Analysis”
6

Module Five

Module 5 · Secured Cyber Security For Non Techies | Incident Response & Crisis Communication
MODULE 5 · CORE

Incident Response & Crisis Communication

4 hours (in‑class + workshop)
Focus: Incident lifecycle · communication · crisis management · reporting
Delivery: Lecture · crisis simulation · role-playing
Weight: 15% of final grade

Imagine your school's fire alarm goes off. What happens next? You don't panic—you follow the plan! You walk outside, the teacher takes attendance, and everyone stays safe. Incident response is the same thing, but for cyber problems. When something goes wrong (like a hack or a virus), we have a plan to: 1️⃣ Stop the problem, 2️⃣ Fix the damage, 3️⃣ Tell the right people, and 4️⃣ Make sure it doesn't happen again. Having a plan means you stay calm and in control!

Learning objectives
  • Understand the incident response lifecycle: detect, triage, contain, recover
  • Create a simple incident communication plan for different stakeholders
  • Practice crisis communication and decision-making under pressure
  • Identify reporting pathways and legal considerations
  • Develop an incident response playbook for your team
Module content
5.1 Incident Response Lifecycle 1.5h

The incident response lifecycle is like a fire drill—but for computers and data! It has 4 steps: 1. Detection — Someone notices something wrong.
2. Triage — Figure out how bad it is.
3. Containment — Stop it from getting worse.
4. Recovery — Fix the damage and get back to normal.
After that, you learn from the experience and make things better for next time!

1️⃣ Detect
2️⃣ Triage
3️⃣ Contain
4️⃣ Recover
  • Detection: How do you know something happened? (Alerts, employee reports)
  • Triage: Is this a minor issue or a major incident?
  • Containment: Stop the spread—disconnect affected systems
  • Recovery: Restore systems from backups and test
  • simulation Walk through a ransomware incident response scenario

🛡️ Defence of the day: The faster you detect and contain an incident, the less damage it causes. Train your team to recognise and report suspicious activity immediately!

Example: Incident Response in Action

Scenario: An employee reports a suspicious email attachment
1. Detect: Employee notices it's from an unknown sender and reports it
2. Triage: IT checks if it's malware—it's ransomware!
3. Contain: IT disconnects the employee's computer from the network to stop the spread
4. Recover: Restore the employee's files from the backup
Learn: The company reviews how the email got through and strengthens its email filters

5.2 Crisis Communication Strategy 1h

When something bad happens, the most important thing is to tell the right people the right way. Imagine if your house was on fire—you'd call the fire department, tell your family, and maybe let your neighbors know. In a cyber incident, you need to tell: - Your team (to keep them safe) - Your boss (to keep them informed) - Your customers (to keep them trusting you) - Sometimes the police or regulators (if required by law) Good communication builds trust and helps everyone stay calm!

  • Who to tell first: Your internal response team and leadership
  • Communication tree: A list of who needs to know and in what order
  • Message templates: Prepared statements for different scenarios
  • When to go public: How to handle media and customer communication
  • role-play Simulate a crisis communication call with stakeholders

⚠️ Golden rule: Never promise something you can't deliver. Be honest, transparent, and tell people what you know—and what you're doing to fix it.

Example: Crisis Communication

Scenario: A company discovers customer data may have been exposed.
Internal message (to employees): "We've detected a potential security incident. The IT team is investigating. Please follow these instructions..."
External message (to customers): "We're investigating a potential data security issue. We take this very seriously and will update you within 24 hours. We recommend changing your password as a precaution."
Regulatory message: "We are notifying the Data Protection Authority as required by law."

5.3 Reporting Pathways & Legal Considerations 0.5h + workshop

Sometimes, when something bad happens, you have to tell the "grown-ups" outside your company. This could be the police, a government agency, or a regulator like the Data Protection Authority. There are laws that say you must report certain types of incidents within a specific time—like if customer data is stolen. It's important to know who to call and when!

  • Legal obligations: Data breach notification laws (GDPR, PDPA, etc.)
  • Reporting timelines: Usually 72 hours for serious breaches
  • What to report: What happened, who's affected, and what you're doing
  • Working with law enforcement: When and how to involve police
  • workshop Create a reporting pathway map for your organisation

Example: Reporting a Breach

Scenario: A company discovers that 5,000 customer records were stolen.
Step 1: Notify the Data Protection Authority within 72 hours
Step 2: Notify affected customers (if the data could cause them harm)
Step 3: Work with law enforcement to investigate
Step 4: Document everything for legal purposes
Step 5: Review and improve security measures

5.4 Crisis Management & Team Roles 0.5h + workshop

In an emergency, everyone needs to know their job—otherwise, it's chaos! Some people fix the problem (IT), some people talk to customers (Communications), some people take notes (Documentation), and one person leads the whole team (Incident Commander). Having clear roles means you can respond faster and better!

  • Incident Commander: The person in charge of the response
  • Technical Team: People who fix the technical problems
  • Communications Team: People who talk to stakeholders
  • Legal Team: People who handle legal and regulatory issues
  • workshop Assign roles in a crisis simulation

Example: Crisis Team Roles

Incident Commander: The CEO or CISO (makes final decisions)
Technical Lead: IT Director (fixes the problem)
Communications Lead: Head of PR (tells customers and media)
Legal Counsel: Company lawyer (advises on legal risks)
Scribe: Someone who takes notes of all decisions and actions
Employee Liaison: Someone who keeps employees informed

Key takeaway: When a cyber incident happens, having a clear plan, knowing your roles, and communicating effectively can make the difference between a minor issue and a major disaster. Practice your response BEFORE you need it! Incident · Communication · Crisis · Roles
Resources: Incident response template · communication plan template · crisis team roles guide
Pre‑work: watch “Crisis Communication in Action” (20 min)
Reading: “The Incident Response Playbook”
7

Module Six

Cybersecurity for Non-Techies – Module 6: Passwords & Authentication
🔑 Module 6

Passwords & Authentication

🧒 Explained for a 10‑year‑old!
Learn how to create super-strong passwords and keep your accounts safe — like a secret agent protecting top-secret files!
⏱️ Time: 20 minutes 📌 Topic: Password Security & MFA 🎯 Level: Beginner — No tech skills needed!
🔑

Hello, future password hero! 🦸

Imagine you have a secret clubhouse with the coolest toys and games inside. You don't want just anyone walking in — you want to keep it safe!

So you put a lock on the door. But what if the lock is flimsy and easy to pick? Or what if you hide the key under the doormat where everyone can find it?

In the online world, your password is like the key to your clubhouse. If your password is weak or you share it, anyone can get in! In this module, we'll learn how to make super-strong passwords that even the smartest cyber thief can't break. Let's go! 🚀

🎯 What you'll learn

  • Why passwords are like keys to your digital house
  • How to create strong, easy-to-remember passwords
  • Why you should use different passwords for different accounts
  • What Multi-Factor Authentication (MFA) is and why it's awesome
  • How to keep your passwords safe from thieves

📚 Topics — Becoming a Password Master

🏠 6.1 Passwords Are Like Keys to Your Digital House The Basics

Passwords are secret words or codes that prove you are who you say you are.

Think of them like keys that open different doors online:

  • Email password: Unlocks your mailbox
  • Social media password: Unlocks your profile
  • Game account password: Unlocks your gaming profile
  • Banking password: Unlocks your money!
🏠 House analogy: Imagine your house has 10 doors, and you use the same key for all of them. If a thief finds that key, they can get into every room! That's why you need different keys (passwords) for different doors (accounts).
😲 Did you know? The first computer password was created in the 1960s at MIT. It was used to protect a time-sharing system. People have been trying to steal passwords ever since!
💪 6.2 How to Create a Super-Strong Password

A strong password is like a lock that's almost impossible to pick. Here's how to make one:

  • Make it LONG: At least 12 characters (more is better!)
  • Use different types: Uppercase letters, lowercase letters, numbers, and symbols
  • Don't use personal info: No birthdays, names, or "password123"
  • Use a passphrase: A sentence that's easy to remember but hard to guess
Weak
Strong
🌟 Example of a strong passphrase:
BluePizzaRidesTheDragon!2024

This is long, has uppercase/lowercase, numbers, and a symbol. And it's easy to remember because it makes a silly picture in your head!
💡 Pro tip: Don't use common phrases like "Iloveyou" or "Password123". Attackers have lists of the most common passwords and try them first!
🚫 6.3 NEVER Reuse Passwords!

Reusing passwords is like using the same key for your house, your car, and your bike lock.

  • Problem: If one account gets hacked, ALL your accounts are at risk
  • What attackers do: They try stolen passwords on other websites
  • This is called: "Credential stuffing" — stuffing stolen passwords into other websites
  • Solution: Use a different password for every account
🎮 Game analogy: Imagine you play a game and a hacker steals your password. If you use the same password for your email and bank account, the hacker can steal everything! Never use the same password twice!

⚠️ Real danger!

In 2016, hackers stole passwords from 500 million Yahoo accounts. Many people used the same passwords on other sites, and hackers broke into those too. Don't be one of those people!

🧠 6.4 How to Remember All Your Passwords

Remembering a different password for every account seems impossible. Here's how to do it:

  • Use a password manager: A special app that stores ALL your passwords safely
  • It creates strong passwords: It can generate long, random passwords for you
  • You only need to remember ONE: The master password to the password manager
  • Popular options: Bitwarden, 1Password, LastPass, and KeePass
🗄️ Safe analogy: Imagine a giant safe with hundreds of tiny compartments inside. Each compartment holds a key to a different door. You only need to remember one key — the key to the giant safe. That's what a password manager does!
💡 Did you know? Password managers can also check if your passwords have been stolen in data breaches. They'll even tell you to change them if they find a problem!
🛡️ 6.5 Multi-Factor Authentication (MFA) — The Extra Lock

Multi-Factor Authentication (MFA) is like having TWO locks on your door instead of one.

Even if someone steals your password, they still can't get in without the second factor.

📱 Text Message A code sent to your phone via SMS
🔢 Authenticator App An app that generates a new code every 30 seconds
🖐️ Biometrics Your fingerprint, face, or voice
💳 Security Key A physical key you plug into your computer
📧 Email Code A code sent to your email address
❓ Security Questions Answering a secret question
🔑 Two-key analogy: Imagine you have a treasure chest that needs two keys to open. You keep one key in your pocket (password) and one key in a secret hiding spot (MFA). If a thief steals the key from your pocket, they still can't open the chest without the second key!
🌟 Pro tip: Turn on MFA for your most important accounts FIRST: Email, bank accounts, social media, and gaming accounts.
🕵️ 6.6 How Hackers Try to Get Your Password

Knowing how hackers try to steal passwords helps you defend against them!

  • Phishing: Fake emails that trick you into typing your password on a fake website
  • Brute force: Guessing millions of passwords very quickly using a computer
  • Dictionary attacks: Trying common words and phrases
  • Keyloggers: Hidden software that records everything you type
  • Data breaches: When a company gets hacked and passwords are stolen
🎣 Phishing example: You get an email that says "Your account has been locked! Click here to reset your password." The link goes to a FAKE website that looks real. If you type your password, the hacker steals it. Always check the website address!

⚠️ Never share your password!

Real companies will NEVER ask for your password in an email, text message, or phone call. If someone asks for your password, it's a scam! 🚨

✅ 6.7 Password Security Checklist

Here's a quick checklist to make sure your passwords are safe:

  • ✅ Use a different password for every account
  • ✅ Make passwords long (12+ characters)
  • ✅ Use a mix of uppercase, lowercase, numbers, and symbols
  • ✅ Use a password manager to store them safely
  • ✅ Turn on Multi-Factor Authentication (MFA) wherever possible
  • ✅ Don't use personal information (birthdays, names, etc.)
  • ✅ Change passwords if you think they might have been stolen
  • ✅ Never share your password with anyone
🏆 Challenge: Go check one of your online accounts right now. Does it have MFA turned on? If not, turn it on! It only takes a few minutes and makes you much safer.

🎓 Password Security — Quick Reference

🔑 Passwords: Keys to your digital accounts
💪 Strong Passwords: Long, mixed characters, and NOT personal
🚫 Never Reuse: Each account needs its own password
🧠 Password Manager: Helps you remember them all
🛡️ MFA: Extra lock for your accounts
🕵️ Beware: Phishing, brute force, and data breaches

💡 Remember: Your password is like the key to your digital life. Make it strong, keep it secret, and never share it with anyone. You're the only one who should have it!

🎮 Activity: Create Your Super Password!

Think of a funny or silly sentence. Turn it into a password by taking the first letter of each word, adding numbers and symbols, and making some letters uppercase. For example:

"My dog eats pizza every Friday at 3!" → MdEpEf@3!

Your turn! Create your own super password using a sentence you'll remember. Share it with a grown-up in your family and ask them to do the same! 🎉

🔐 Cybersecurity for Everyone — Made simple for non-techies and young learners!
8

Module Six

Cybersecurity for Non-Techies – Module 6: Passwords & Authentication
🔑 Module 6

Passwords & Authentication

🧒 Explained for a 10‑year‑old!
Learn how to create super-strong passwords and keep your accounts safe — like a secret agent protecting top-secret files!
⏱️ Time: 20 minutes 📌 Topic: Password Security & MFA 🎯 Level: Beginner — No tech skills needed!
🔑

Hello, future password hero! 🦸

Imagine you have a secret clubhouse with the coolest toys and games inside. You don't want just anyone walking in — you want to keep it safe!

So you put a lock on the door. But what if the lock is flimsy and easy to pick? Or what if you hide the key under the doormat where everyone can find it?

In the online world, your password is like the key to your clubhouse. If your password is weak or you share it, anyone can get in! In this module, we'll learn how to make super-strong passwords that even the smartest cyber thief can't break. Let's go! 🚀

🎯 What you'll learn

  • Why passwords are like keys to your digital house
  • How to create strong, easy-to-remember passwords
  • Why you should use different passwords for different accounts
  • What Multi-Factor Authentication (MFA) is and why it's awesome
  • How to keep your passwords safe from thieves

📚 Topics — Becoming a Password Master

🏠 6.1 Passwords Are Like Keys to Your Digital House The Basics

Passwords are secret words or codes that prove you are who you say you are.

Think of them like keys that open different doors online:

  • Email password: Unlocks your mailbox
  • Social media password: Unlocks your profile
  • Game account password: Unlocks your gaming profile
  • Banking password: Unlocks your money!
🏠 House analogy: Imagine your house has 10 doors, and you use the same key for all of them. If a thief finds that key, they can get into every room! That's why you need different keys (passwords) for different doors (accounts).
😲 Did you know? The first computer password was created in the 1960s at MIT. It was used to protect a time-sharing system. People have been trying to steal passwords ever since!
💪 6.2 How to Create a Super-Strong Password

A strong password is like a lock that's almost impossible to pick. Here's how to make one:

  • Make it LONG: At least 12 characters (more is better!)
  • Use different types: Uppercase letters, lowercase letters, numbers, and symbols
  • Don't use personal info: No birthdays, names, or "password123"
  • Use a passphrase: A sentence that's easy to remember but hard to guess
Weak
Strong
🌟 Example of a strong passphrase:
BluePizzaRidesTheDragon!2024

This is long, has uppercase/lowercase, numbers, and a symbol. And it's easy to remember because it makes a silly picture in your head!
💡 Pro tip: Don't use common phrases like "Iloveyou" or "Password123". Attackers have lists of the most common passwords and try them first!
🚫 6.3 NEVER Reuse Passwords!

Reusing passwords is like using the same key for your house, your car, and your bike lock.

  • Problem: If one account gets hacked, ALL your accounts are at risk
  • What attackers do: They try stolen passwords on other websites
  • This is called: "Credential stuffing" — stuffing stolen passwords into other websites
  • Solution: Use a different password for every account
🎮 Game analogy: Imagine you play a game and a hacker steals your password. If you use the same password for your email and bank account, the hacker can steal everything! Never use the same password twice!

⚠️ Real danger!

In 2016, hackers stole passwords from 500 million Yahoo accounts. Many people used the same passwords on other sites, and hackers broke into those too. Don't be one of those people!

🧠 6.4 How to Remember All Your Passwords

Remembering a different password for every account seems impossible. Here's how to do it:

  • Use a password manager: A special app that stores ALL your passwords safely
  • It creates strong passwords: It can generate long, random passwords for you
  • You only need to remember ONE: The master password to the password manager
  • Popular options: Bitwarden, 1Password, LastPass, and KeePass
🗄️ Safe analogy: Imagine a giant safe with hundreds of tiny compartments inside. Each compartment holds a key to a different door. You only need to remember one key — the key to the giant safe. That's what a password manager does!
💡 Did you know? Password managers can also check if your passwords have been stolen in data breaches. They'll even tell you to change them if they find a problem!
🛡️ 6.5 Multi-Factor Authentication (MFA) — The Extra Lock

Multi-Factor Authentication (MFA) is like having TWO locks on your door instead of one.

Even if someone steals your password, they still can't get in without the second factor.

📱 Text Message A code sent to your phone via SMS
🔢 Authenticator App An app that generates a new code every 30 seconds
🖐️ Biometrics Your fingerprint, face, or voice
💳 Security Key A physical key you plug into your computer
📧 Email Code A code sent to your email address
❓ Security Questions Answering a secret question
🔑 Two-key analogy: Imagine you have a treasure chest that needs two keys to open. You keep one key in your pocket (password) and one key in a secret hiding spot (MFA). If a thief steals the key from your pocket, they still can't open the chest without the second key!
🌟 Pro tip: Turn on MFA for your most important accounts FIRST: Email, bank accounts, social media, and gaming accounts.
🕵️ 6.6 How Hackers Try to Get Your Password

Knowing how hackers try to steal passwords helps you defend against them!

  • Phishing: Fake emails that trick you into typing your password on a fake website
  • Brute force: Guessing millions of passwords very quickly using a computer
  • Dictionary attacks: Trying common words and phrases
  • Keyloggers: Hidden software that records everything you type
  • Data breaches: When a company gets hacked and passwords are stolen
🎣 Phishing example: You get an email that says "Your account has been locked! Click here to reset your password." The link goes to a FAKE website that looks real. If you type your password, the hacker steals it. Always check the website address!

⚠️ Never share your password!

Real companies will NEVER ask for your password in an email, text message, or phone call. If someone asks for your password, it's a scam! 🚨

✅ 6.7 Password Security Checklist

Here's a quick checklist to make sure your passwords are safe:

  • ✅ Use a different password for every account
  • ✅ Make passwords long (12+ characters)
  • ✅ Use a mix of uppercase, lowercase, numbers, and symbols
  • ✅ Use a password manager to store them safely
  • ✅ Turn on Multi-Factor Authentication (MFA) wherever possible
  • ✅ Don't use personal information (birthdays, names, etc.)
  • ✅ Change passwords if you think they might have been stolen
  • ✅ Never share your password with anyone
🏆 Challenge: Go check one of your online accounts right now. Does it have MFA turned on? If not, turn it on! It only takes a few minutes and makes you much safer.

🎓 Password Security — Quick Reference

🔑 Passwords: Keys to your digital accounts
💪 Strong Passwords: Long, mixed characters, and NOT personal
🚫 Never Reuse: Each account needs its own password
🧠 Password Manager: Helps you remember them all
🛡️ MFA: Extra lock for your accounts
🕵️ Beware: Phishing, brute force, and data breaches

💡 Remember: Your password is like the key to your digital life. Make it strong, keep it secret, and never share it with anyone. You're the only one who should have it!

🎮 Activity: Create Your Super Password!

Think of a funny or silly sentence. Turn it into a password by taking the first letter of each word, adding numbers and symbols, and making some letters uppercase. For example:

"My dog eats pizza every Friday at 3!" → MdEpEf@3!

Your turn! Create your own super password using a sentence you'll remember. Share it with a grown-up in your family and ask them to do the same! 🎉

🔐 Cybersecurity for Everyone — Made simple for non-techies and young learners!
9

Module Seven

Cybersecurity for Non-Techies – Module 7: Social Media Safety
📱 Module 7

Social Media Safety

🧒 Explained for a 10‑year‑old!
Learn how to stay safe on social media — like a secret agent protecting their identity online!
⏱️ Time: 20 minutes 📌 Topic: Social Media Privacy & Safety 🎯 Level: Beginner — No tech skills needed!
📱

Hello, social media superstar! 🌟

Imagine you're at a giant party with lots of people you know and lots of people you don't know. You wouldn't tell everyone your secrets, your address, or your plans for the summer, right?

Social media is like that giant party. It's fun to share pictures, chat with friends, and play games. But there are also strangers who might be watching. Some of them might pretend to be someone they're not, or try to trick you into giving them information.

In this module, we'll learn how to enjoy social media safely — like a secret agent who knows exactly what to share and what to keep secret! Let's go! 🕵️

🎯 What you'll learn

  • Why oversharing on social media can be dangerous
  • How to set privacy settings to protect your information
  • How to spot fake profiles and online scams
  • What to do if someone is bothering you online
  • How to be a good digital citizen

📚 Topics — Becoming a Social Media Safety Pro

🤔 7.1 What is Oversharing? The Basics

Oversharing is when you share too much personal information online.

It's like walking around with a sign on your back that tells everyone your secrets!

  • Examples of oversharing: Posting your home address, school name, or your full birthday
  • Why it's dangerous: Strangers can use this information to find you or steal your identity
  • Remember: Once you post something online, it's VERY hard to remove it forever
📸 Photo analogy: Imagine you post a photo of yourself in your school uniform with a sign that says "I go to Sunshine Elementary School." Anyone can now figure out where you are every day. That's dangerous!

⚠️ Important rule!

Before posting anything online, ask yourself: "Would I be okay if a stranger saw this?" If the answer is no, DON'T POST IT!

🔒 7.2 Privacy Settings — Your Secret Shield

Privacy settings are like locks on your social media accounts. They control who can see what.

  • Public: Anyone in the world can see your posts
  • Private: Only people you approve can see your posts
  • Custom: You choose exactly who can see each post
🌍 Public Everyone can see
🔒 Private Only approved friends
⚙️ Custom You choose who sees
🏠 House analogy: Privacy settings are like the locks and windows on your house: - Public = All doors and windows are wide open (anyone can walk in) - Private = The doors are locked and the curtains are drawn (only invited guests can come in) - Custom = You keep the front door locked but invite specific friends through the back door

Always keep your accounts on PRIVATE!
💡 Pro tip: Go check your privacy settings RIGHT NOW on your favorite social media app. Make sure your account is set to PRIVATE. Ask a grown-up to help you if you're not sure!
👤 7.3 Spotting Fake Profiles — The Imposters

Fake profiles are accounts created by people pretending to be someone else.

It's like someone wearing a mask at the party!

  • Red flags: Only one photo, no friends, odd messages, asking for personal information
  • Common tricks: They might pretend to be a famous person, a friend of a friend, or someone in trouble
  • What to do: Don't accept friend requests from people you don't know
🎭 Costume analogy: Imagine someone shows up to your party wearing a costume. They say they're your best friend's cousin. But you've never seen them before. Do you let them into your house? NO! Same thing online — only accept friend requests from people you KNOW in real life!

✅ DO:

  • Check if the person has friends you know
  • Ask them a question only they would know
  • Tell a grown-up if you're unsure

❌ DON'T:

  • Accept requests from strangers
  • Share personal info with someone you just met online
  • Click on links sent by someone you don't know
🕵️ Did you know? Some fake profiles are created by "catfishers" — people who pretend to be someone else to trick others. They might want your personal information, money, or just to mess with you. Always be suspicious!
🎣 7.4 Social Media Scams — The Traps

Scams are tricks designed to steal your money, information, or identity.

  • Common scams: "You've won a free iPhone!" — Click here to claim it! (They want your info)
  • Phishing links: Fake websites that look real but steal your password
  • Quiz scams: "What's your superhero name?" — They're collecting answers to your security questions!
  • Fake giveaway: "Like and share this post to win!" — They're building a list of people to scam
🎁 Fake giveaway analogy: Imagine someone at your school says: "Give me your lunch money, and I'll give you a million dollars!" You know it's a trick, right? Same thing online — if it sounds too good to be true, it IS a trick!

⚠️ Golden rule!

If it sounds too good to be true, it IS too good to be true. No one gives away free iPhones or thousands of dollars for nothing. Report and block these scams!

🚫 7.5 Cyberbullying — When People Are Mean Online

Cyberbullying is when someone uses technology to be mean, hurtful, or threatening.

  • Examples: Mean comments, spreading rumors, excluding people, or sharing embarrassing photos
  • It's NOT your fault: Bullies are usually unhappy themselves and take it out on others
  • What to do: Save the evidence, block the bully, tell a grown-up, and report it
😔 Real talk: Cyberbullying can make you feel sad, scared, or alone. But remember — you are NOT alone! There are people who care about you and want to help. Always tell a parent, teacher, or trusted adult if someone is mean to you online.

✅ DO:

  • Save screenshots of mean messages
  • Block the person who's bullying
  • Report them to the platform (Instagram, TikTok, etc.)
  • Tell a parent or trusted adult

❌ DON'T:

  • Respond to mean messages
  • Delete the messages (you need the evidence)
  • Keep it to yourself — speak up!
  • Blame yourself — it's NOT your fault
🤗 Remember: If someone is mean to you online, it says more about THEM than about YOU. You deserve to be treated with kindness and respect. Don't let anyone tell you otherwise!
🤝 7.6 Being a Good Digital Citizen

Digital citizenship is about being kind, respectful, and safe online.

  • Think before you post: Would you say it to someone's face?
  • Be kind: A nice comment can make someone's day!
  • Don't share other people's photos without permission: Ask first!
  • Report bad behavior: If you see bullying, report it
  • Be a good role model: Show others how to be safe online
🌟 Golden rule: Treat others online the way you want to be treated. If you wouldn't want someone to say it to you, don't say it to them. Simple as that!
💡 Did you know? When you report a mean post, you're helping make the internet a safer place for everyone. You're a cyber hero! 🦸
✅ 7.7 Social Media Safety Checklist

Here's a quick checklist to make sure you're safe on social media:

  • ✅ Your account is set to PRIVATE
  • ✅ You only accept friend requests from people you know in real life
  • ✅ You never share your address, phone number, or school name
  • ✅ You never post your location while you're there
  • ✅ You ask permission before posting photos of other people
  • ✅ You think before you post — would a stranger see this?
  • ✅ You tell a grown-up if someone is mean or suspicious
  • ✅ You report and block suspicious accounts
🏆 Challenge: Pick ONE social media account you use. Go through the checklist with a grown-up. Make sure ALL the items are checked off. You'll be super safe in no time!

🎓 Social Media Safety — Quick Reference

🤔 Oversharing: Don't share personal info online
🔒 Privacy Settings: Keep accounts on PRIVATE
👤 Fake Profiles: Only accept REAL friends
🎣 Scams: If it's too good to be true, it IS
🚫 Cyberbullying: Tell a grown-up, save evidence
🤝 Digital Citizen: Be kind and respectful online

💡 Remember: Social media is fun when you're safe! Just like in real life, you have to be careful who you trust and what you share. Stay safe, have fun, and be kind! 🌟

🎮 Activity: The Privacy Checkup

With a grown-up's help, go through your social media accounts and check:

  • 1️⃣ 🔍 Is your account set to PRIVATE?
  • 2️⃣ 👤 Do you know EVERYONE you're friends with?
  • 3️⃣ 📸 Check your recent posts — would you be okay if a stranger saw them?
  • 4️⃣ 🛡️ Report any suspicious accounts or posts

You're now a social media safety pro! 🎉

🔐 Cybersecurity for Everyone — Made simple for non-techies and young learners!
10

Practice Exercise

Cybersecurity for Non-Techies – Practice Exercise
🌟 Practice Exercise

Cybersecurity Quiz Challenge

🧒 For Young Cyber Heroes!
Test your cybersecurity knowledge with this fun quiz. Can you get a perfect score?
🛡️

📋 Your Mission

You've completed all the modules and learned how to stay safe online. Now it's time to test your skills! Answer these 10 questions about cybersecurity.

🎯 Goal: Get at least 8 out of 10 correct to become a Certified Cyber Hero!

💡 Hint: Think about everything you learned in the modules — passwords, social media safety, scams, and more. You've got this!

0
out of 10 correct
Answer all questions to see your result!
Question 1 of 10
🔑 What is a password?
💡 Remember: A password is like a key to your digital house.
Question 2 of 10
💪 Which of these is a STRONG password?
💡 Remember: A strong password is long, uses different types of characters, and isn't personal info.
Question 3 of 10
🚫 Why is it dangerous to use the same password for multiple accounts?
💡 Remember: Using the same key for all your doors means if someone steals it, they can get into everything.
Question 4 of 10
🛡️ What is Multi-Factor Authentication (MFA)?
💡 Remember: MFA is like having TWO locks on your door instead of one.
Question 5 of 10
🤔 Which of these is an example of OVERSHARING on social media?
💡 Remember: If a stranger could use the information to find or trick you, it's oversharing.
Question 6 of 10
🔒 What should your social media privacy settings be set to?
💡 Remember: You want to control who can see your posts.
Question 7 of 10
🎣 You get a message that says "You've won a free iPhone! Click here to claim it!" What should you do?
💡 Remember: If it sounds too good to be true, it IS too good to be true.
Question 8 of 10
🚫 What should you do if someone is being mean to you online?
💡 Remember: You are NOT alone, and it's NOT your fault.
Question 9 of 10
🤝 What is a digital citizen?
💡 Remember: Being a good digital citizen means being kind and respectful online.
Question 10 of 10
🌟 Which is the BEST way to stay safe online?
💡 Remember: It's about combining all the things you've learned!
💡 Did you know? The skills you just practiced are the same ones that cybersecurity professionals use every day to keep people safe online. You're never too young to start learning how to protect yourself and others!
🔐 Cybersecurity for Everyone — Made simple for non-techies and young learners!

🏆 Get Certified

🔒

Earn this certificate

Every lesson is already free to read. Sign up, pass the exam, and unlock Practice Tools plus a verified certificate with your name on it — ₦4,000/month.

🎓 Sign Up & Unlock for ₦4,000/month
🛠️ Practice Tools
Hands-on simulators & labs - subscription required.
→
🎯 Internship Tasks
Real-world tasks to build your portfolio - try them free for 7 days, no card required.
→