Cybersecurity Awareness for Employees

For all employees and volunteers: recognize cyber threats, protect accounts and data, verify suspicious requests and report incidents fast.

For: All employees and volunteers in any US workplace, including non-technical staff, front-line workers, office teams and volunteers who use email, phones or shared computers

  • 2 contact hours
  • 8 modules
  • 8 interactives
  • 4 job aids
  • Updated October 7, 2026

What you will be able to do

  • Recognize common cyber threats (phishing, smishing, vishing, malware, ransomware, business email compromise, social engineering and insider risk) and their warning signs in messages, calls and everyday events.
  • Apply the CISA Secure Our World basics (long, random, unique passwords; a password manager; multifactor authentication; prompt updates) to protect your accounts and devices.
  • Verify any request involving money, credentials, sensitive data or access through an independent, known channel before acting.
  • Protect customer and company data and devices at work, while browsing, with removable media and when working away from the office or on public Wi-Fi.
  • Identify a possible security incident and report it promptly through the correct internal and external routes, preserving evidence and documenting the facts.

Learn to recognize today's most common cyber threats, including phishing, smishing, malware, ransomware, business email compromise and insider risk, and practice a simple routine for verifying suspicious requests before you act. You will lock down your accounts with the four Secure Our World basics, keep devices and data safe in the office and on the road, and know exactly how to report an incident.

This course is written for everyone, not for IT. It suits front-desk staff, warehouse and field workers, office teams, finance and payroll staff, managers and volunteers at businesses, nonprofits and public agencies. No technical background is needed.

Cybercrime reported to the FBI reached more than one million complaints and about $20.9 billion in losses in 2025, and most attacks still depend on a person clicking, paying or sharing. Built on CISA Secure Our World, the NIST Cybersecurity Framework 2.0 and NIST SP 800-63B-4, the course uses realistic US workplace scenarios, a branching payment-fraud simulation, decision tools and printable job aids you will keep using.

What you’ll be able to do Monday morning

  1. Check any link's real domain and spot the red flags in a suspicious email, text or call in under a minute.
  2. Confirm payment, bank-detail or password requests by calling a number you already have, never one in the message.
  3. Turn on MFA for your work email, replace any reused password, and deny sign-in prompts you did not start.
  4. Install pending updates, lock your screen when you step away, and hand found USB drives to IT unplugged.
  5. Keep customer data in approved systems and use your hotspot or the company VPN instead of open public Wi-Fi.
  6. Report a click, odd prompt, lost device or misdirected email within minutes using a ready-to-use incident report template.

Curriculum

8 modules · 32 lessons · about 2 contact hours

01Why does cybersecurity depend on everyone, not just IT?Free preview11 min
  1. How big is the problem, really?
  2. Why are people, not just technology, at the center of most breaches?
  3. Why would anyone target a small organization like ours?
  4. What do national frameworks and laws expect from you?

Diagram · In practice checklist · 2-question knowledge check

02What do today's cyberattacks actually look like?12 min
  1. What is social engineering, and why does it work?
  2. Phishing, smishing and vishing: what's the difference?
  3. What are malware and ransomware?
  4. What are business email compromise and insider risk?
  • Sort activity: Which attack is this?

Diagram · In practice checklist · 3-question knowledge check

03How do you spot and verify a suspicious message or request?14 min
  1. What are the red flags in a message?
  2. What does a phishing email look like up close?
  3. How do you verify a request safely?
  4. What about texts, calls and fake support pop-ups?
  • Spot the issue: Spot the phish: the 'shared document' email
  • Decision tree: Should I verify this request?

Diagram · In practice checklist · 2-question knowledge check

04How do you lock down your accounts with passwords and MFA?13 min
  1. What makes a password strong in 2026?
  2. How does a password manager help?
  3. What is MFA, and which kind is strongest?
  4. How do attackers try to get around MFA?
  • Matching activity: Account security terms

Diagram · In practice checklist · 3-question knowledge check

05How do you keep devices, software and browsing safe?12 min
  1. Why do software updates matter so much?
  2. How do you browse and download safely?
  3. What should you do with USB drives, chargers and other devices?
  4. How do you protect a device in daily use?
  • Spot the issue: Spot the risks: front-desk walk-through

Diagram · In practice checklist · 2-question knowledge check

06How do you protect customer and company data, in the office and on the go?12 min
  1. What data needs protecting, and why?
  2. What are the everyday rules for handling data?
  3. Is public Wi-Fi safe for work?
  4. How do you work safely away from the office?
  • Ethics dilemma: Can I borrow your login?

In practice checklist · 2-question knowledge check

07What counts as a security incident, and how do you report it?14 min
  1. What is a security incident?
  2. What should you do in the first minutes?
  3. Who else should receive a report?
  4. Why does a no-blame reporting culture matter?
  • Branching scenario: The invoice that changed banks

Diagram · In practice checklist · 3-question knowledge check

08What does a secure workday look like from start to finish?12 min
  1. How should the day start?
  2. How do the habits hold up under pressure?
  3. How do you handle data and devices through the day?
  4. How do you keep your skills current, at work and at home?
  • Self-assessment: How strong are my security habits?

Diagram · In practice checklist · 2-question knowledge check

Final assessment: 23 questions, 70% to pass, then your certificate

Try it now, no account needed

The invoice that changed banks

A branching scenario from this course. Your choices are not saved.

Free sample activity

The invoice that changed banks

You are the accounts payable clerk at a 60-person heating and cooling contractor. On Thursday morning you are preparing the weekly vendor payments, including $26,750 to your main equipment supplier.

Inside the course

Practice activities

  • Sort activity1
  • Spot the issue2
  • Decision tree1
  • Matching activity1
  • Ethics dilemma1
  • Self-assessment1
  • Branching scenario1

Job aids you keep

  • Phishing and Suspicious Request ChecklistChecklist
  • Security Incident Report TemplateTemplate
  • Account and Device Security ChecklistChecklist
  • Verify Before You Act Pocket CardPocket card

Credit and approval status

Certificate of completion

This course earns a certificate of completion for 2 contact hours of instruction. It is not currently approved or accredited by any licensing board, state agency, IACET, NASBA or other accreditor, and it does not award continuing education units. Many employers use awareness courses like this one to support their own training programs, including programs that respond to the FTC Safeguards Rule or the NIST Cybersecurity Framework, but whether this course fits your requirement is your employer's decision. Check with your employer, compliance team or board before relying on it for a specific requirement.

Pathways we may pursue in the future include IACET continuing education units and, if approved, NASBA continuing professional education for accounting professionals. Until an approval is granted and shown on this page, the course provides a general certificate of completion only.

Our full approvals list

Questions about this course

Who is this cybersecurity awareness course for?

It is for all employees and volunteers, not IT specialists. It suits front-desk, office, warehouse, field, finance and payroll staff, managers and volunteers at businesses, nonprofits and public agencies across the United States. No technical knowledge is needed. If your job involves email, a phone, a shared computer or customer information, the habits in this course apply to you.

How long does the course take?

The course is 2 contact hours. That includes eight short modules with realistic workplace scenarios, interactive exercises such as a branching payment-fraud simulation and spot-the-phish activities, knowledge checks, and a final assessment of 23 questions with a 70% pass mark. You can stop and resume at any point, and your progress is saved.

Will I earn continuing education units?

No. You receive a certificate of completion for 2 contact hours of instruction. The course is not currently approved or accredited by IACET, NASBA or any licensing board or state agency, so it does not award continuing education units. If you need training for a specific requirement, check with your employer, compliance team or board whether they accept this course.

Does this course satisfy the FTC Safeguards Rule or other training requirements?

The FTC Safeguards Rule requires covered financial businesses to provide security awareness training, and many frameworks expect it. This course covers core awareness topics those programs build on, but only your organization can decide whether it fits its written information security program and risk assessment. We do not claim it satisfies any specific legal requirement.

Is the content different by state?

Very little. Cybersecurity awareness habits are the same nationwide, and the course follows federal guidance from CISA, NIST, the FBI and the FTC. Some states have their own breach notification laws or require cybersecurity training for certain public employees; ask your employer which state rules apply to your role.

Does the course teach hacking techniques?

No. The course focuses on prevention, recognition and reporting. Example messages and links are defanged so nothing is clickable, and no offensive or hacking instructions are included. Our separate courses go deeper into phishing, passwords and MFA, remote work security and AI-driven scams.

This course is general cybersecurity education and training awareness from CE Courses Hub. It is not legal, technical or professional advice and does not replace your employer's policies, your IT or security team's instructions, or advice from a qualified professional. Completing it earns a certificate of completion for the stated contact hours; it is not approved or accredited by any licensing board, state agency or accreditor unless an approval is shown on the course page. Check with your board, employer or state agency whether this course meets your specific requirement.