Cybersecurity Awareness Pack
All employees
Phishing and scams, passwords and MFA, remote work security and AI-enabled fraud.
By profession
For all employees and volunteers: recognize cyber threats, protect accounts and data, verify suspicious requests and report incidents fast.
For: All employees and volunteers in any US workplace, including non-technical staff, front-line workers, office teams and volunteers who use email, phones or shared computers
Learn to recognize today's most common cyber threats, including phishing, smishing, malware, ransomware, business email compromise and insider risk, and practice a simple routine for verifying suspicious requests before you act. You will lock down your accounts with the four Secure Our World basics, keep devices and data safe in the office and on the road, and know exactly how to report an incident.
This course is written for everyone, not for IT. It suits front-desk staff, warehouse and field workers, office teams, finance and payroll staff, managers and volunteers at businesses, nonprofits and public agencies. No technical background is needed.
Cybercrime reported to the FBI reached more than one million complaints and about $20.9 billion in losses in 2025, and most attacks still depend on a person clicking, paying or sharing. Built on CISA Secure Our World, the NIST Cybersecurity Framework 2.0 and NIST SP 800-63B-4, the course uses realistic US workplace scenarios, a branching payment-fraud simulation, decision tools and printable job aids you will keep using.
What you’ll be able to do Monday morning
8 modules · 32 lessons · about 2 contact hours
Diagram · In practice checklist · 2-question knowledge check
Diagram · In practice checklist · 3-question knowledge check
Diagram · In practice checklist · 2-question knowledge check
Diagram · In practice checklist · 3-question knowledge check
Diagram · In practice checklist · 2-question knowledge check
In practice checklist · 2-question knowledge check
Diagram · In practice checklist · 3-question knowledge check
Diagram · In practice checklist · 2-question knowledge check
Try it now, no account needed
A branching scenario from this course. Your choices are not saved.
Practice activities
Job aids you keep
This course earns a certificate of completion for 2 contact hours of instruction. It is not currently approved or accredited by any licensing board, state agency, IACET, NASBA or other accreditor, and it does not award continuing education units. Many employers use awareness courses like this one to support their own training programs, including programs that respond to the FTC Safeguards Rule or the NIST Cybersecurity Framework, but whether this course fits your requirement is your employer's decision. Check with your employer, compliance team or board before relying on it for a specific requirement.
Pathways we may pursue in the future include IACET continuing education units and, if approved, NASBA continuing professional education for accounting professionals. Until an approval is granted and shown on this page, the course provides a general certificate of completion only.
Our full approvals listIt is for all employees and volunteers, not IT specialists. It suits front-desk, office, warehouse, field, finance and payroll staff, managers and volunteers at businesses, nonprofits and public agencies across the United States. No technical knowledge is needed. If your job involves email, a phone, a shared computer or customer information, the habits in this course apply to you.
The course is 2 contact hours. That includes eight short modules with realistic workplace scenarios, interactive exercises such as a branching payment-fraud simulation and spot-the-phish activities, knowledge checks, and a final assessment of 23 questions with a 70% pass mark. You can stop and resume at any point, and your progress is saved.
No. You receive a certificate of completion for 2 contact hours of instruction. The course is not currently approved or accredited by IACET, NASBA or any licensing board or state agency, so it does not award continuing education units. If you need training for a specific requirement, check with your employer, compliance team or board whether they accept this course.
The FTC Safeguards Rule requires covered financial businesses to provide security awareness training, and many frameworks expect it. This course covers core awareness topics those programs build on, but only your organization can decide whether it fits its written information security program and risk assessment. We do not claim it satisfies any specific legal requirement.
Very little. Cybersecurity awareness habits are the same nationwide, and the course follows federal guidance from CISA, NIST, the FBI and the FTC. Some states have their own breach notification laws or require cybersecurity training for certain public employees; ask your employer which state rules apply to your role.
No. The course focuses on prevention, recognition and reporting. Example messages and links are defanged so nothing is clickable, and no offensive or hacking instructions are included. Our separate courses go deeper into phishing, passwords and MFA, remote work security and AI-driven scams.
This course is general cybersecurity education and training awareness from CE Courses Hub. It is not legal, technical or professional advice and does not replace your employer's policies, your IT or security team's instructions, or advice from a qualified professional. Completing it earns a certificate of completion for the stated contact hours; it is not approved or accredited by any licensing board, state agency or accreditor unless an approval is shown on the course page. Check with your board, employer or state agency whether this course meets your specific requirement.