Skip to content
American CornersLegal disclaimer

Course

Cybersecurity

Everyday online-safety habits: strong passwords and MFA, spotting phishing and social engineering, and staying safe against AI-powered scams.

What this course promises

Reviewed
For
Beginners, students, families and professionals who use phones, email or online accounts.
Prerequisites
No technical experience required · Comfort using a browser and email
Expected effort
About 6 to 8 hours plus a 25-minute final drill
Tools and materials
A modern browser · Paper or notes for the final drill
Final capability
Complete a talk-through incident drill and defend the actions you would take first.

By the end, you should be able to

  • Recognise common digital threats and explain the risk they create
  • Use practical protections such as MFA, updates and tested backups
  • Verify suspicious requests through a separate, trusted channel
  • Prioritise risks and talk through a realistic incident response

Content status: evolving · reviewed 2026-08-21

  1. 01 · Why This Matters

    Module checkpoint: produce evidence

    You should be able to

    • Separate threat, vulnerability and risk
    • Explain why consequences and likelihood both matter

    Choose one digital service you use. Name one threat, one vulnerability and the resulting risk without using the terms interchangeably.

    Evidence: A three-part explanation in your own words.

    Need a hint?

    A threat can act; a vulnerability is a weakness; risk combines what could happen with how likely it is.

  2. 02 · Everyday Security Basics

    Module checkpoint: produce evidence

    You should be able to

    • Choose practical protections for ordinary accounts and devices
    • Describe a useful first response to an incident

    Audit one account or device. Identify the most useful improvement you can make today and explain why it comes first.

    Evidence: One completed change or a concrete, ordered action plan.

  3. 03 · The Vocabulary

  4. 04 · Social Engineering & the Human Factor

    Module checkpoint: produce evidence

    You should be able to

    • Recognise pressure and impersonation tactics
    • Verify a request without trusting the channel that delivered it

    Rewrite a suspicious request as a verification plan: what will you pause, what will you check, and which separate, trusted channel will you use?

    Evidence: A short verification script you could follow under pressure.

  5. 05 · How AI Actually Works

  6. 06 · AI-Powered Scams

    Module checkpoint: produce evidence

    You should be able to

    • Identify what synthetic media changes and what it does not
    • Use evidence and trusted contact details to verify identity
    • Keep verifying when the trusted channel is slow, unavailable or already compromised
    • Separate a legitimate request from the suspicious change attached to it, and grant one while refusing the other
    • Write a process rule that does not depend on anyone being alert on the day

    Design a verification rule for your family or team that still works when a voice, image or message looks convincing.

    Evidence: A rule with a trigger, a trusted channel and a stop condition.

  7. 07 · Using AI Safely

  8. 08 · Prioritising Risk

    Module checkpoint: produce evidence

    You should be able to

    • Compare risks by impact and likelihood
    • Defend why one action should come before another

    Place three real risks on a simple impact and likelihood grid. Choose the first action and defend the tradeoff.

    Evidence: A completed grid plus a two-sentence decision.

  9. 09 · Capstone Talk-through Drill

    Module checkpoint: produce evidence

    You should be able to

    • Apply the whole course under uncertainty
    • Explain priorities, tradeoffs and communication choices

    Run the final talk-through drill alone or with a group. Record each decision before reading the next inject, then revise your plan at the end.

    Evidence: A decision log and a short reflection on what changed.

Risk priorities

Every key risk in the course, ranked by priority (Impact × Likelihood) and grouped into tiers, so the most consequential habits come first.

Critical16

  • Weak or reused passwords, and skipping the extra login step20
  • Being tricked into helping an attacker20
  • Fake emails that push you to click, open, or share20
  • Scam messages written by AI that look flawless20
  • Pressure to act fast because a 'boss' says so20
  • Not checking whether a message or request is really from who it claims to be20
  • Ignoring small warning signs early in an attack15
  • Having no backup copy of important files15
  • Handling sensitive data as carelessly as public data15
  • Sharing private or sensitive information with AI chatbots15
  • Scam phone calls and text messages15
  • Someone pretending to be a person you would trust15
  • Fake video or voice that imitates someone real15
  • Fake business emails asking for payments or data15
  • Staying silent instead of reporting a problem15
  • Not recognising which data must be protected15

High14

  • Thinking cybersecurity isn't your problem12
  • Putting off software updates12
  • Assuming that signing in means access to everything12
  • Giving people more access than they need12
  • Trusting AI answers as always correct12
  • Believing confident AI answers that are made up12
  • Using AI apps your workplace hasn't approved12
  • Fake people made with AI photos and profiles12
  • Turning off or ignoring security logs10
  • Hidden instructions that trick an AI tool10
  • Forgetting that the AI tools themselves can be attacked10
  • Trusting AI coding helpers without reviewing their output10
  • Letting AI make the decisions during a security incident10
  • Not protecting the data that feeds AI systems10

Medium6

  • Assuming scrambled data is always safe8
  • Feeding private data into AI tools to 'train' them8
  • Relying on AI security tools without human checks8
  • Following someone through a secure door, or peeking at screens8
  • Attackers using AI to research your company8
  • Assuming AI decisions are always fair8

Everyday habits

The tip sheet in one screen: six habits that stop most of the trouble before it starts.

  • Use a password manager for strong, unique passwords, and turn on multi-factor authentication (MFA) everywhere it is offered.
  • Install updates promptly, and restart when asked, because updates close the holes attackers use.
  • Keep your work in backed-up places, and check now and then that a backup actually restores.
  • Slow down on unexpected links and messages, preview the link and check the sender before you act.
  • Before you trust or pay, verify the request through a separate, trusted channel.
  • Use only approved AI tools, and never paste passwords, secrets or private data into a chatbot.

Practice exercises

Two guided talk-through drills you can run on your own, about 30 minutes each.

Download the Tip SheetA printable one-page summary of the everyday security habits (PDF).

The story

Practical online-safety awareness for everyone.

The cybersecurity program builds simple, everyday defensive habits: strong passwords and multi-factor authentication, spotting phishing and social engineering, and staying safe against a new wave of AI-powered scams.

The material is organised into modules that move from security basics through the technical vocabulary, the human factor, and how AI actually works, up to a hands-on group tabletop exercise that puts it all to the test.

Everything is open, bilingual and free for anyone, with no sign-up and no access code.

Continue learning: 0 of 40 lessons are marked complete. The required suspicious-message practice is not yet complete. A page mark alone is not evidence of learning. Practice completion records participation; certificate requests are reviewed by a person.

Your progress is saved on this device only. On iPhone it can be cleared if you don't visit for about a week, so export it to keep it safe.