Course
Cybersecurity
Everyday online-safety habits: strong passwords and MFA, spotting phishing and social engineering, and staying safe against AI-powered scams.
Where you are
0 of 40 lessons done.
01 Why This Matters0/5
02 Everyday Security Basics0/5
03 The Vocabulary0/5
04 Social Engineering & the Human Factor0/6
05 How AI Actually Works0/5
06 AI-Powered Scams0/5
07 Using AI Safely0/5
08 Prioritising Risk0/3
09 Capstone Talk-through Drill0/1
What this course promises
- For
- Beginners, students, families and professionals who use phones, email or online accounts.
- Prerequisites
- No technical experience required · Comfort using a browser and email
- Expected effort
- About 6 to 8 hours plus a 45-minute final drill
- Tools and materials
- A modern browser · Paper or notes for the final drill
- What you will be able to do
- Complete a talk-through incident drill and defend the actions you would take first.
By the end, you should be able to
- Recognise common digital threats and explain the risk they create
- Use practical protections such as MFA, updates and tested backups
- Verify suspicious requests through a separate, trusted channel
- Prioritise risks and talk through a realistic incident response
Last checked: 2026-08-21
№ 01 · Why This Matters
Cheat-sheet for this module- What is information security?6 min read
- The CIA and DAD triads7 min read
- Threats, vulnerabilities, and risk8 min read
- What a cyber incident costs6 min read
- Who the attackers are7 min read
Checkpoint: show what you can do
You should be able to
- • Name what information must stay private, accurate and available in a situation you know
- • Separate a threat, a vulnerability and the resulting risk
- • Prioritise a likely high-impact weakness before a dramatic but remote one
Choose one account, device or record you rely on. Name its most important security goal, one realistic threat, the weakness that threat could use, and the smallest action that reduces the risk.
Evidence: One causal chain from valued information to threat, weakness, risk and action.
№ 02 · Everyday Security Basics
Cheat-sheet for this module- Passwords and MFA7 min read
- Updates and patching6 min read
- Backups that actually work6 min read
- How an attack unfolds6 min read
- Reporting an incident6 min read
Checkpoint: show what you can do
You should be able to
- • Strengthen account access with unique passwords and MFA
- • Reduce the time a known software weakness stays open
- • Test a real restore with a safe sample and revise the backup promise from the result
- • Recognise several points where an attack chain can be interrupted and report uncertainty early
After the restore check, choose one other break in the attack chain you can make this week. Say what it blocks and what observable result will tell you the action is working.
Evidence: One completed restore observation plus one separate prevention or reporting action with a visible check.
№ 03 · The Vocabulary
Cheat-sheet for this module№ 04 · Social Engineering & the Human Factor
Cheat-sheet for this module- Hacking the human6 min read
- Weaponised bias7 min read
- Phishing, smishing, and vishingEducator-ready · learner + educator + workshop + print7 min read
- Business email compromise6 min read
- Physical tactics6 min read
- Password managers and MFA7 min read
Checkpoint: show what you can do
You should be able to
- • Recognise pressure and impersonation tactics
- • Verify a request without trusting the channel that delivered it
Rewrite a suspicious request as a verification plan: what will you pause, what will you check, and which separate, trusted channel will you use?
Evidence: A short verification script you could follow under pressure.
№ 05 · How AI Actually Works
Cheat-sheet for this module№ 06 · AI-Powered Scams
Cheat-sheet for this module- AI-written phishing6 min read
- Deepfake video7 min read
- Voice cloning6 min read
- Synthetic identities6 min read
- The verification playbook7 min read
Checkpoint: show what you can do
You should be able to
- • Identify what synthetic media changes and what it does not
- • Use evidence and trusted contact details to verify identity
- • Keep verifying when the trusted channel is slow, unavailable or already compromised
- • Separate a legitimate request from the suspicious change attached to it, and grant one while refusing the other
- • Write a process rule that does not depend on anyone being alert on the day
Design a verification rule for your family or team that still works when a voice, image or message looks convincing.
Evidence: A rule with a trigger, a trusted channel and a stop condition.
№ 07 · Using AI Safely
Cheat-sheet for this module№ 08 · Prioritising Risk
Cheat-sheet for this module- Impact × likelihood in practice6 min read
- The critical few6 min read
- Where weak spots cluster6 min read
Checkpoint: show what you can do
You should be able to
- • Compare risks by impact and likelihood
- • Defend why one action should come before another
Place three real risks on a simple impact and likelihood grid. Choose the first action and defend the tradeoff.
Evidence: A completed grid plus a two-sentence decision.
№ 09 · Capstone Talk-through Drill
Cheat-sheet for this moduleCheckpoint: show what you can do
You should be able to
- • Apply the whole course under uncertainty
- • Explain priorities, tradeoffs and communication choices
Run the final talk-through drill alone or with a group. Record each decision before reading the next inject, then revise your plan at the end.
Evidence: A decision log and a short reflection on what changed.
Risk priorities
Every key risk in the course, ranked by priority (Impact × Likelihood) and grouped into tiers, so the most consequential habits come first.
Critical16
- Weak or reused passwords, and skipping the extra login step20
- Being tricked into helping an attacker20
- Fake emails that push you to click, open, or share20
- Scam messages written by AI that look flawless20
- Pressure to act fast because a 'boss' says so20
- Not checking whether a message or request is really from who it claims to be20
- Ignoring small warning signs early in an attack15
- Having no backup copy of important files15
- Handling sensitive data as carelessly as public data15
- Sharing private or sensitive information with AI chatbots15
- Scam phone calls and text messages15
- Someone pretending to be a person you would trust15
- Fake video or voice that imitates someone real15
- Fake business emails asking for payments or data15
- Staying silent instead of reporting a problem15
- Not recognising which data must be protected15
High14
- Thinking cybersecurity isn't your problem12
- Putting off software updates12
- Assuming that signing in means access to everything12
- Giving people more access than they need12
- Trusting AI answers as always correct12
- Believing confident AI answers that are made up12
- Using AI apps your workplace hasn't approved12
- Fake people made with AI photos and profiles12
- Turning off or ignoring security logs10
- Hidden instructions that trick an AI tool10
- Forgetting that the AI tools themselves can be attacked10
- Trusting AI coding helpers without reviewing their output10
- Letting AI make the decisions during a security incident10
- Not protecting the data that feeds AI systems10
Medium6
- Assuming scrambled data is always safe8
- Feeding private data into AI tools to 'train' them8
- Relying on AI security tools without human checks8
- Following someone through a secure door, or peeking at screens8
- Attackers using AI to research your company8
- Assuming AI decisions are always fair8
Everyday habits
The tip sheet in one screen: six habits that stop most of the trouble before it starts.
- Use a password manager for strong, unique passwords, and turn on multi-factor authentication (MFA) everywhere it is offered.
- Install updates promptly, and restart when asked, because updates close the holes attackers use.
- Keep your work in backed-up places, and check now and then that a backup actually restores.
- Slow down on unexpected links and messages, preview the link and check the sender before you act.
- Before you trust or pay, verify the request through a separate, trusted channel.
- Use only approved AI tools, and never paste passwords, secrets or private data into a chatbot.
Practice exercises
Two guided talk-through drills you can run on your own, about 30 minutes each.
The story
Practical online-safety awareness for everyone.
The cybersecurity program builds simple, everyday defensive habits: strong passwords and multi-factor authentication, spotting phishing and social engineering, and staying safe against a new wave of AI-powered scams.
The material is organised into modules that move from security basics through the technical vocabulary, the human factor, and how AI actually works, up to a hands-on group tabletop exercise that puts it all to the test.
Everything is open, bilingual and free for anyone, with no sign-up and no access code.
Continue learning: 0 of 40 lessons are marked complete. The required suspicious-message practice is not yet complete. Finish every lesson and the practice activity, and you can open a certificate.
Your progress is saved on this device only. On iPhone it can be cleared if you don't visit for about a week, so export it to keep it safe. Importing a file replaces the progress currently in this browser.