Course
Cybersecurity
Everyday online-safety habits: strong passwords and MFA, spotting phishing and social engineering, and staying safe against AI-powered scams.
What this course promises
Reviewed- For
- Beginners, students, families and professionals who use phones, email or online accounts.
- Prerequisites
- No technical experience required · Comfort using a browser and email
- Expected effort
- About 6 to 8 hours plus a 25-minute final drill
- Tools and materials
- A modern browser · Paper or notes for the final drill
- Final capability
- Complete a talk-through incident drill and defend the actions you would take first.
By the end, you should be able to
- Recognise common digital threats and explain the risk they create
- Use practical protections such as MFA, updates and tested backups
- Verify suspicious requests through a separate, trusted channel
- Prioritise risks and talk through a realistic incident response
Content status: evolving · reviewed 2026-08-21
№ 01 · Why This Matters
- What is information security?6 min read
- The CIA and DAD triads7 min read
- Threats, vulnerabilities, and risk8 min read
- What a cyber incident costs6 min read
- Who the attackers are7 min read
Module checkpoint: produce evidence
You should be able to
- • Separate threat, vulnerability and risk
- • Explain why consequences and likelihood both matter
Choose one digital service you use. Name one threat, one vulnerability and the resulting risk without using the terms interchangeably.
Evidence: A three-part explanation in your own words.
Need a hint?
A threat can act; a vulnerability is a weakness; risk combines what could happen with how likely it is.
№ 02 · Everyday Security Basics
- Passwords and MFA7 min read
- Updates and patching6 min read
- Backups that actually work6 min read
- How an attack unfolds6 min read
- Reporting an incident6 min read
Module checkpoint: produce evidence
You should be able to
- • Choose practical protections for ordinary accounts and devices
- • Describe a useful first response to an incident
Audit one account or device. Identify the most useful improvement you can make today and explain why it comes first.
Evidence: One completed change or a concrete, ordered action plan.
№ 03 · The Vocabulary
№ 04 · Social Engineering & the Human Factor
- Hacking the human6 min read
- Weaponised bias7 min read
- Phishing, smishing, and vishingEducator-ready · learner + educator + workshop + print7 min read
- Business email compromise6 min read
- Physical tactics6 min read
- Password managers and MFA7 min read
Module checkpoint: produce evidence
You should be able to
- • Recognise pressure and impersonation tactics
- • Verify a request without trusting the channel that delivered it
Rewrite a suspicious request as a verification plan: what will you pause, what will you check, and which separate, trusted channel will you use?
Evidence: A short verification script you could follow under pressure.
№ 05 · How AI Actually Works
№ 06 · AI-Powered Scams
- AI-written phishing6 min read
- Deepfake video7 min read
- Voice cloning6 min read
- Synthetic identities6 min read
- The verification playbook7 min read
Module checkpoint: produce evidence
You should be able to
- • Identify what synthetic media changes and what it does not
- • Use evidence and trusted contact details to verify identity
- • Keep verifying when the trusted channel is slow, unavailable or already compromised
- • Separate a legitimate request from the suspicious change attached to it, and grant one while refusing the other
- • Write a process rule that does not depend on anyone being alert on the day
Design a verification rule for your family or team that still works when a voice, image or message looks convincing.
Evidence: A rule with a trigger, a trusted channel and a stop condition.
№ 07 · Using AI Safely
№ 08 · Prioritising Risk
- Impact × likelihood in practice6 min read
- The critical few6 min read
- Where weak spots cluster6 min read
Module checkpoint: produce evidence
You should be able to
- • Compare risks by impact and likelihood
- • Defend why one action should come before another
Place three real risks on a simple impact and likelihood grid. Choose the first action and defend the tradeoff.
Evidence: A completed grid plus a two-sentence decision.
№ 09 · Capstone Talk-through Drill
Module checkpoint: produce evidence
You should be able to
- • Apply the whole course under uncertainty
- • Explain priorities, tradeoffs and communication choices
Run the final talk-through drill alone or with a group. Record each decision before reading the next inject, then revise your plan at the end.
Evidence: A decision log and a short reflection on what changed.
Risk priorities
Every key risk in the course, ranked by priority (Impact × Likelihood) and grouped into tiers, so the most consequential habits come first.
Critical16
- Weak or reused passwords, and skipping the extra login step20
- Being tricked into helping an attacker20
- Fake emails that push you to click, open, or share20
- Scam messages written by AI that look flawless20
- Pressure to act fast because a 'boss' says so20
- Not checking whether a message or request is really from who it claims to be20
- Ignoring small warning signs early in an attack15
- Having no backup copy of important files15
- Handling sensitive data as carelessly as public data15
- Sharing private or sensitive information with AI chatbots15
- Scam phone calls and text messages15
- Someone pretending to be a person you would trust15
- Fake video or voice that imitates someone real15
- Fake business emails asking for payments or data15
- Staying silent instead of reporting a problem15
- Not recognising which data must be protected15
High14
- Thinking cybersecurity isn't your problem12
- Putting off software updates12
- Assuming that signing in means access to everything12
- Giving people more access than they need12
- Trusting AI answers as always correct12
- Believing confident AI answers that are made up12
- Using AI apps your workplace hasn't approved12
- Fake people made with AI photos and profiles12
- Turning off or ignoring security logs10
- Hidden instructions that trick an AI tool10
- Forgetting that the AI tools themselves can be attacked10
- Trusting AI coding helpers without reviewing their output10
- Letting AI make the decisions during a security incident10
- Not protecting the data that feeds AI systems10
Medium6
- Assuming scrambled data is always safe8
- Feeding private data into AI tools to 'train' them8
- Relying on AI security tools without human checks8
- Following someone through a secure door, or peeking at screens8
- Attackers using AI to research your company8
- Assuming AI decisions are always fair8
Everyday habits
The tip sheet in one screen: six habits that stop most of the trouble before it starts.
- Use a password manager for strong, unique passwords, and turn on multi-factor authentication (MFA) everywhere it is offered.
- Install updates promptly, and restart when asked, because updates close the holes attackers use.
- Keep your work in backed-up places, and check now and then that a backup actually restores.
- Slow down on unexpected links and messages, preview the link and check the sender before you act.
- Before you trust or pay, verify the request through a separate, trusted channel.
- Use only approved AI tools, and never paste passwords, secrets or private data into a chatbot.
Practice exercises
Two guided talk-through drills you can run on your own, about 30 minutes each.
The story
Practical online-safety awareness for everyone.
The cybersecurity program builds simple, everyday defensive habits: strong passwords and multi-factor authentication, spotting phishing and social engineering, and staying safe against a new wave of AI-powered scams.
The material is organised into modules that move from security basics through the technical vocabulary, the human factor, and how AI actually works, up to a hands-on group tabletop exercise that puts it all to the test.
Everything is open, bilingual and free for anyone, with no sign-up and no access code.
Continue learning: 0 of 40 lessons are marked complete. The required suspicious-message practice is not yet complete. A page mark alone is not evidence of learning. Practice completion records participation; certificate requests are reviewed by a person.
Your progress is saved on this device only. On iPhone it can be cleared if you don't visit for about a week, so export it to keep it safe.