
CYBER SECURITY BUILDING HUMAN FIREWALL
OVERVIEW
Cybersecurity threats continue to grow in frequency and sophistication, with many successful attacks targeting people rather than technology. Employees are often the first line of defence against phishing, social engineering, ransomware, data breaches and other cyber risks.
This two-day programme is designed to build a strong Human Firewall within the organisation by increasing cybersecurity awareness, promoting secure digital behaviour, and equipping participants with practical skills to identify, prevent and respond to cyber threats. Through interactive discussions, case studies, simulations and hands-on exercises, participants will gain the knowledge and confidence required to protect organisational information assets and contribute to a stronger cybersecurity culture.
LEARNING OUTCOMES
Upon completion of this programme, participants will be able to:
- Understand fundamental cybersecurity concepts and current cyber threat trends.
- Identify common cyber attacks, including phishing, malware, ransomware, and social engineering.
- Recognise suspicious emails, websites, links, and online activities.
- Apply cybersecurity best practices when handling organisational information and digital assets.
- Strengthen password management and authentication practices.
- Protect sensitive and confidential data from unauthorised access and disclosure.
- Respond appropriately to cybersecurity incidents and security breaches.
- Contribute to building a cyber-aware and security-conscious workplace culture.
COURSE OUTLINE
- DAY 1: Cybersecurity Awareness & Threat Identification Module 1: Introduction to Cybersecurity
- a) Understanding cybersecurity fundamentals
- b) The importance of human factors in security
- c) Current cyber threat landscape
- d) Cybersecurity trends and organisational risks
- e) Consequences of cyber incidents and breaches Module 2: Understanding Common Cyber
Threats
- a) Malware, viruses, worms and trojans
- b) Ransomware attacks and business disruption
- c) Business Email Compromise (BEC)
- d) Insider threats and accidental exposure
- e) Data breaches and information theft
Module 3: Social Engineering Attacks
- a) What social engineering means in daily work
- b) Psychological manipulation techniques used by attackers
- c) Phishing, spear phishing and whaling
- d) Vishing (voice phishing) and smishing (SMS phishing)
- e) Real-world attack case studies and lessons learned
Module 4: Phishing Detection Workshop
- a) Identifying phishing emails and suspicious attachments
- b) Recognising fake websites and login pages
- c) URL inspection and link verification techniques
- d) Safe browsing practices for work and personal devices
- e) Practical phishing simulation exercises
Module 5: Cybersecurity Best Practices
- a) Safe internet usage and digital hygiene
- b) Email security guidelines
- c) Secure use of social media and messaging platforms
- d) Mobile device security
- e) Remote working security practices
DAY 2: Data Protection, Incident Response & Human Firewall Culture Module 6: Password Security & Access Control
- a) Common password vulnerabilities and risky habits
- b) Creating strong and memorable passwords
- c) Using password managers securely
- d) Multi-factor authentication (MFA)
- e) Access control principles and least privilege
Module 7: Data Protection & Information Security
- a) Understanding sensitive and confidential information
- b) Data classification and proper handling
- c) Personal Data Protection Act (PDPA) awareness
- d) Secure file sharing, storage and disposal
- e) Data loss prevention practices
Module 8: Incident Response for Employees
- a) Recognising security incidents and warning signs
- b) Reporting procedures and communication channels
- c) Immediate response actions for employees
- d) Escalation process and evidence preservation
- e) Lessons learned from cyber incidents
Module 9: Building a Human Firewall Culture
- a) Security awareness responsibilities
- b) Creating a cyber-aware workplace
- c) Security habits and behaviour at work
- d) Managing cyber risks in daily operations
- e) Leadership and employee roles in cybersecurity
Module 10: Cybersecurity Simulation & Action Planning
- a) Cyber attack scenario exercise
- b) Team-based threat response activities
- c) Knowledge assessment and review
- d) Personal cybersecurity action plan development
- e) Course review, discussion and commitment to action
METHODOLOGY
- Interactive Lectures (30%): facilitator-led presentations, group discussions and knowledge sharing sessions
- Case Studies (20%): analysis of real cyber incidents, lessons learned and best practice discussions
- Practical Exercises (20%): phishing detection activities, password security exercises and cyber risk identification
- Simulations & Role Plays (20%): social engineering simulations, incident response scenarios and team-based challenges
- Assessment & Reflection (10%): knowledge quizzes, group presentations and individual action planning