Cybersecurity
Cybersecurity Awareness for Employees
For: All employees
By profession
Cybersecurity
Spot phishing and impersonation, lock down accounts, work safely from anywhere and report fast. Built for people who are not in IT, with real-looking (and defanged) examples.

Cybersecurity
For: All employees
Cybersecurity
For: HR & recruiters, Managers & supervisors and 2 more roles
Try removing a filter or searching for a broader term.
Clear all filtersMost attacks that reach staff need a person to click, approve, pay or share. These courses train those moments: checking a sender, slowing down when a message pushes urgency, verifying a payment change on a known phone number, refusing an unexpected login prompt and reporting quickly so IT can contain the damage.
They never teach offensive techniques. Every example email, text and web page is defanged, and each course ends with what to do in the first ten minutes after a mistake.
Reporting fast matters more than being right. A course scenario where someone reports a message that turns out to be harmless is scored as a success.
| Habit | Course | What you practice |
|---|---|---|
| The basics for everyone | Cybersecurity Awareness for Employees | Common threats, updates, safe browsing, protecting customer data |
| Spotting the lure | Phishing, Social Engineering and Scams | Email, text, voice and QR-code phishing; business email compromise; what to do if you clicked |
| Locking the door | Password, MFA and Account Security | Long passphrases, password managers, multi-factor authentication, passkeys, MFA fatigue |
| Working anywhere | Cybersecurity for Remote and Hybrid Workers | Home Wi-Fi, public networks, travel, shared devices, lost laptops |
| Fakes that sound real | Deepfakes, Online Fraud and AI-Enabled Scams | Voice cloning, executive impersonation, call-back checks and code words |
| AI without leaks | Secure Use of Generative AI Tools | Data leakage, prompt injection, unapproved “shadow” AI, permissions for AI agents |
When personal information is exposed, state law decides how fast people must be told. Deadlines differ, and several are now fixed numbers of days. Examples from statutes we have verified:
| State | Notice to residents | Notice to the attorney general |
|---|---|---|
| California | Within 30 calendar days of discovery (from January 1, 2026) | Sample copy if more than 500 residents, within 15 calendar days |
| Colorado | Within 30 days after determining a breach occurred | If 500 or more residents, within 30 days |
| Florida | No later than 30 days (15-day extension for good cause) | If 500 or more residents |
| Alabama | No later than 45 days | If more than 1,000 residents, within 45 days |
| Connecticut | No later than 60 days after discovery | No later than notice to residents |
An employee who reports a suspicious login on day one gives the response team the whole window to investigate. Look up more states in the Breach Notification Lookup.
Courses on this topic
Many people think a breach means card numbers or Social Security numbers. Several state laws, including those of Arizona, California, Colorado, Delaware, Florida and New York, also count a username or email address together with the password or security answer that unlocks the account. That is why the account security course treats a reused password as a business risk, not a personal habit.
Training only works if people feel safe admitting a mistake. Staff who fear blame wait, delete the message or try to fix things quietly, and the response team loses hours it needs. The courses model a different habit: report what you saw, what you clicked and what you entered, as soon as you notice, even if you are not sure it was an attack.
Managers can use the remote work and deepfake courses to set the verification rules their teams follow.
Team seats show who has finished, and a CSV export gives you a record for audits and insurers.
About credit
Every course earns a certificate of completion for its stated contact hours. A course is approved by a licensing board or accreditor only when the approval and its number are shown on the course page. Check with your board, employer or state agency whether a course meets your requirement. See our approvals list.
No. They are awareness training for non-technical employees and volunteers. They do not teach hacking or system administration, and they do not prepare you for a security certification exam.
The phishing course includes practice messages you inspect and sort inside the course. It does not send live test emails to your staff; if you run a simulation program, use the course as the training that follows it.
Disconnect if told to, change the password from a different device if credentials were entered, and report to IT or a manager straight away with the message still available. Every course in this topic ends with that first-ten-minutes checklist.
Most are 2 contact hours, and the password and account security course is 1.5. Progress saves automatically, so staff can complete a course in short sessions between other work.
Requirements differ by insurer, contract and industry. Each course earns a certificate of completion with a date and verification ID; check whether your insurer, client or regulator accepts it and what topics it expects.
Preview the first module of any course free. Pay only when it is the right fit.