Skip to content
Skip to lesson
American CornersLegal disclaimer

Course

Cybersecurity

Everyday online-safety habits: strong passwords and MFA, spotting phishing and social engineering, and staying safe against AI-powered scams.

Where you are

0 of 40 lessons done.

  1. 01 Why This Matters0/5

  2. 02 Everyday Security Basics0/5

  3. 03 The Vocabulary0/5

  4. 04 Social Engineering & the Human Factor0/6

  5. 05 How AI Actually Works0/5

  6. 06 AI-Powered Scams0/5

  7. 07 Using AI Safely0/5

  8. 08 Prioritising Risk0/3

  9. 09 Capstone Talk-through Drill0/1

Continue: What is information security?

What this course promises

For
Beginners, students, families and professionals who use phones, email or online accounts.
Prerequisites
No technical experience required · Comfort using a browser and email
Expected effort
About 6 to 8 hours plus a 45-minute final drill
Tools and materials
A modern browser · Paper or notes for the final drill
What you will be able to do
Complete a talk-through incident drill and defend the actions you would take first.

By the end, you should be able to

  • Recognise common digital threats and explain the risk they create
  • Use practical protections such as MFA, updates and tested backups
  • Verify suspicious requests through a separate, trusted channel
  • Prioritise risks and talk through a realistic incident response

Last checked: 2026-08-21

  1. 01 · Why This Matters

    Cheat-sheet for this module
    Checkpoint: show what you can do

    You should be able to

    • Name what information must stay private, accurate and available in a situation you know
    • Separate a threat, a vulnerability and the resulting risk
    • Prioritise a likely high-impact weakness before a dramatic but remote one

    Choose one account, device or record you rely on. Name its most important security goal, one realistic threat, the weakness that threat could use, and the smallest action that reduces the risk.

    Evidence: One causal chain from valued information to threat, weakness, risk and action.

  2. 02 · Everyday Security Basics

    Cheat-sheet for this module
    Checkpoint: show what you can do

    You should be able to

    • Strengthen account access with unique passwords and MFA
    • Reduce the time a known software weakness stays open
    • Test a real restore with a safe sample and revise the backup promise from the result
    • Recognise several points where an attack chain can be interrupted and report uncertainty early

    After the restore check, choose one other break in the attack chain you can make this week. Say what it blocks and what observable result will tell you the action is working.

    Evidence: One completed restore observation plus one separate prevention or reporting action with a visible check.

  3. 03 · The Vocabulary

    Cheat-sheet for this module
  4. 04 · Social Engineering & the Human Factor

    Cheat-sheet for this module
    Checkpoint: show what you can do

    You should be able to

    • Recognise pressure and impersonation tactics
    • Verify a request without trusting the channel that delivered it

    Rewrite a suspicious request as a verification plan: what will you pause, what will you check, and which separate, trusted channel will you use?

    Evidence: A short verification script you could follow under pressure.

  5. 05 · How AI Actually Works

    Cheat-sheet for this module
  6. 06 · AI-Powered Scams

    Cheat-sheet for this module
    Checkpoint: show what you can do

    You should be able to

    • Identify what synthetic media changes and what it does not
    • Use evidence and trusted contact details to verify identity
    • Keep verifying when the trusted channel is slow, unavailable or already compromised
    • Separate a legitimate request from the suspicious change attached to it, and grant one while refusing the other
    • Write a process rule that does not depend on anyone being alert on the day

    Design a verification rule for your family or team that still works when a voice, image or message looks convincing.

    Evidence: A rule with a trigger, a trusted channel and a stop condition.

  7. 07 · Using AI Safely

    Cheat-sheet for this module
  8. 08 · Prioritising Risk

    Cheat-sheet for this module
    Checkpoint: show what you can do

    You should be able to

    • Compare risks by impact and likelihood
    • Defend why one action should come before another

    Place three real risks on a simple impact and likelihood grid. Choose the first action and defend the tradeoff.

    Evidence: A completed grid plus a two-sentence decision.

  9. 09 · Capstone Talk-through Drill

    Cheat-sheet for this module
    Checkpoint: show what you can do

    You should be able to

    • Apply the whole course under uncertainty
    • Explain priorities, tradeoffs and communication choices

    Run the final talk-through drill alone or with a group. Record each decision before reading the next inject, then revise your plan at the end.

    Evidence: A decision log and a short reflection on what changed.

Risk priorities

Every key risk in the course, ranked by priority (Impact × Likelihood) and grouped into tiers, so the most consequential habits come first.

Critical16

  • Weak or reused passwords, and skipping the extra login step20
  • Being tricked into helping an attacker20
  • Fake emails that push you to click, open, or share20
  • Scam messages written by AI that look flawless20
  • Pressure to act fast because a 'boss' says so20
  • Not checking whether a message or request is really from who it claims to be20
  • Ignoring small warning signs early in an attack15
  • Having no backup copy of important files15
  • Handling sensitive data as carelessly as public data15
  • Sharing private or sensitive information with AI chatbots15
  • Scam phone calls and text messages15
  • Someone pretending to be a person you would trust15
  • Fake video or voice that imitates someone real15
  • Fake business emails asking for payments or data15
  • Staying silent instead of reporting a problem15
  • Not recognising which data must be protected15

High14

  • Thinking cybersecurity isn't your problem12
  • Putting off software updates12
  • Assuming that signing in means access to everything12
  • Giving people more access than they need12
  • Trusting AI answers as always correct12
  • Believing confident AI answers that are made up12
  • Using AI apps your workplace hasn't approved12
  • Fake people made with AI photos and profiles12
  • Turning off or ignoring security logs10
  • Hidden instructions that trick an AI tool10
  • Forgetting that the AI tools themselves can be attacked10
  • Trusting AI coding helpers without reviewing their output10
  • Letting AI make the decisions during a security incident10
  • Not protecting the data that feeds AI systems10

Medium6

  • Assuming scrambled data is always safe8
  • Feeding private data into AI tools to 'train' them8
  • Relying on AI security tools without human checks8
  • Following someone through a secure door, or peeking at screens8
  • Attackers using AI to research your company8
  • Assuming AI decisions are always fair8

Everyday habits

The tip sheet in one screen: six habits that stop most of the trouble before it starts.

  • Use a password manager for strong, unique passwords, and turn on multi-factor authentication (MFA) everywhere it is offered.
  • Install updates promptly, and restart when asked, because updates close the holes attackers use.
  • Keep your work in backed-up places, and check now and then that a backup actually restores.
  • Slow down on unexpected links and messages, preview the link and check the sender before you act.
  • Before you trust or pay, verify the request through a separate, trusted channel.
  • Use only approved AI tools, and never paste passwords, secrets or private data into a chatbot.

Practice exercises

Two guided talk-through drills you can run on your own, about 30 minutes each.

Download the Tip SheetA printable one-page summary of the everyday security habits (PDF).

The story

Practical online-safety awareness for everyone.

The cybersecurity program builds simple, everyday defensive habits: strong passwords and multi-factor authentication, spotting phishing and social engineering, and staying safe against a new wave of AI-powered scams.

The material is organised into modules that move from security basics through the technical vocabulary, the human factor, and how AI actually works, up to a hands-on group tabletop exercise that puts it all to the test.

Everything is open, bilingual and free for anyone, with no sign-up and no access code.

Continue learning: 0 of 40 lessons are marked complete. The required suspicious-message practice is not yet complete. Finish every lesson and the practice activity, and you can open a certificate.

Your progress is saved on this device only. On iPhone it can be cleared if you don't visit for about a week, so export it to keep it safe. Importing a file replaces the progress currently in this browser.