Business & Management

Social Engineering and Phishing Awareness

Assessment type

Training only (attendance)

Minimum duration

30 Minutes

Course delivery

E-learning

Description


The Social Engineering and Phishing Awareness eLearning course provides learners with an understanding of social engineering and phishing threats and how these techniques may be used to obtain information, gain unauthorised access or encourage individuals to take unsafe actions.

The course explores common forms of social engineering, including phishing emails, fraudulent messages, impersonation and deceptive requests. Learners will consider how to recognise warning signs, verify suspicious communications, protect workplace information and respond appropriately to suspected or successful attacks.


Who Should Attend?

  • Employees at all levels.
  • Employees who use workplace email, messaging or online systems.
  • Employees who handle confidential or sensitive information.
  • Customer-facing and administrative personnel.
  • Remote and hybrid workers.
  • Managers and supervisors.
  • New starters requiring information security awareness.
  • Anyone requiring an understanding of social engineering and phishing risks.

What You Will Learn

  • What is meant by social engineering.
  • What is meant by phishing.
  • Understanding why attackers use social engineering techniques.
  • Recognising common methods used to manipulate or deceive individuals.
  • Understanding how attackers may impersonate trusted individuals or organisations.
  • Recognising common characteristics of phishing emails.
  • Identifying suspicious sender addresses and unexpected communications.
  • Recognising misleading or disguised links.
  • Identifying suspicious attachments.
  • Recognising requests designed to create urgency, fear or pressure.
  • Identifying unusual requests for passwords, payment or confidential information.
  • Understanding targeted phishing and impersonation attempts.
  • Awareness of phishing through text messages and messaging platforms.
  • Awareness of telephone-based social engineering.
  • Recognising suspicious requests made through social media or other communication channels.
  • Understanding how publicly available information may be used in social engineering attacks.
  • Maintaining appropriate caution when sharing workplace information.
  • Verifying unusual or unexpected requests independently.
  • Avoiding clicking suspicious links or opening unexpected attachments.
  • Protecting passwords and authentication information.
  • Understanding why authentication codes and credentials should not be disclosed.
  • Recognising suspicious login pages and authentication requests.
  • Understanding the importance of following workplace information security procedures.
  • Reporting suspected phishing or social engineering attempts promptly.
  • Knowing what to do after clicking a suspicious link or opening an attachment.
  • Responding appropriately if login details or information may have been disclosed.
  • Reporting suspected account compromise promptly.
  • Avoiding deleting or concealing suspected security incidents before reporting them.
  • Learning from reported phishing and social engineering attempts.
  • Contributing to a security-aware workplace culture.

Course Delivery

This course is delivered as self-directed eLearning through the ELMO learning platform.

Learners can work through the course at their own pace and can move backwards and forwards through the learning content as required. The course does not need to be completed in one sitting, allowing learners to leave and return to their training where necessary.

Interactive activities may be included throughout the course to reinforce key learning points.


Assessment

Knowledge and understanding are checked through online assessment activities. Depending on the course content, these may include multiple-choice questions, matching exercises, drag-and-drop activities and image-based questions.

A minimum score of 70% is required to successfully complete the course.


Certification

Upon successful completion of the course and assessment requirements, learners will receive a UK Rural Skills (UKRS) Accredited Certificate of Training.

This is an awareness-based eLearning course and should be used alongside the organisation's own information security, acceptable use, incident reporting and data protection policies and procedures.


Course Duration

The course is self-directed and learners can progress through the content at their own pace. Completion time may therefore vary depending on the individual learner.


Share this course:

    

Course calendar


Related courses


Business & Management

Managing Difficult Situations

Business & Management

Understanding Eye Safety at Work

Business & Management

Business Writing Skills

Business & Management

Achieving Through People

Business & Management

Making Decisions