Cybersecurity

Cybersecurity awareness training for every employee

Spot phishing and impersonation, lock down accounts, work safely from anywhere and report fast. Built for people who are not in IT, with real-looking (and defanged) examples.

  • 2courses
  • 4contact hours in total
  • $19starting price
Laptop screen showing a security lock icon

Filters

Profession
Profession
Courses with rules for this state
Contact hours
Contact hours
Price
Price
CE pathway
CE pathway

Topic fit for these credentials. Approval status is shown on each course.

Level
Level
Clear all

2 courses

Prevention, recognition and reporting

Most attacks that reach staff need a person to click, approve, pay or share. These courses train those moments: checking a sender, slowing down when a message pushes urgency, verifying a payment change on a known phone number, refusing an unexpected login prompt and reporting quickly so IT can contain the damage.

They never teach offensive techniques. Every example email, text and web page is defanged, and each course ends with what to do in the first ten minutes after a mistake.

Reporting fast matters more than being right. A course scenario where someone reports a message that turns out to be harmless is scored as a success.

A course for each habit

HabitCourseWhat you practice
The basics for everyoneCybersecurity Awareness for EmployeesCommon threats, updates, safe browsing, protecting customer data
Spotting the lurePhishing, Social Engineering and ScamsEmail, text, voice and QR-code phishing; business email compromise; what to do if you clicked
Locking the doorPassword, MFA and Account SecurityLong passphrases, password managers, multi-factor authentication, passkeys, MFA fatigue
Working anywhereCybersecurity for Remote and Hybrid WorkersHome Wi-Fi, public networks, travel, shared devices, lost laptops
Fakes that sound realDeepfakes, Online Fraud and AI-Enabled ScamsVoice cloning, executive impersonation, call-back checks and code words
AI without leaksSecure Use of Generative AI ToolsData leakage, prompt injection, unapproved “shadow” AI, permissions for AI agents

Why minutes count: the breach notice clock

When personal information is exposed, state law decides how fast people must be told. Deadlines differ, and several are now fixed numbers of days. Examples from statutes we have verified:

StateNotice to residentsNotice to the attorney general
CaliforniaWithin 30 calendar days of discovery (from January 1, 2026)Sample copy if more than 500 residents, within 15 calendar days
ColoradoWithin 30 days after determining a breach occurredIf 500 or more residents, within 30 days
FloridaNo later than 30 days (15-day extension for good cause)If 500 or more residents
AlabamaNo later than 45 daysIf more than 1,000 residents, within 45 days
ConnecticutNo later than 60 days after discoveryNo later than notice to residents

An employee who reports a suspicious login on day one gives the response team the whole window to investigate. Look up more states in the Breach Notification Lookup.

Courses on this topic

Stolen logins are personal information too

Many people think a breach means card numbers or Social Security numbers. Several state laws, including those of Arizona, California, Colorado, Delaware, Florida and New York, also count a username or email address together with the password or security answer that unlocks the account. That is why the account security course treats a reused password as a business risk, not a personal habit.

Build a culture where people report

Training only works if people feel safe admitting a mistake. Staff who fear blame wait, delete the message or try to fix things quietly, and the response team loses hours it needs. The courses model a different habit: report what you saw, what you clicked and what you entered, as soon as you notice, even if you are not sure it was an attack.

  • Give staff one obvious way to report, such as a report button or a single mailbox
  • Thank people who report, including false alarms
  • Share short, anonymous stories of attacks that were caught early
  • Verify payment and bank detail changes through a known phone number, every time

Managers can use the remote work and deepfake courses to set the verification rules their teams follow.

Rolling it out across a company

  1. Give everyone the awareness course in their first week.
  2. Add the phishing course for finance, HR and admin staff, who are targeted most for payment and data requests.
  3. Add the remote work course for anyone who works away from the office.
  4. Repeat a short course each year and after any incident, and keep the certificates with your training records.

Team seats show who has finished, and a CSV export gives you a record for audits and insurers.

About credit

Every course earns a certificate of completion for its stated contact hours. A course is approved by a licensing board or accreditor only when the approval and its number are shown on the course page. Check with your board, employer or state agency whether a course meets your requirement. See our approvals list.

Frequently asked questions

Are these courses for IT professionals?

No. They are awareness training for non-technical employees and volunteers. They do not teach hacking or system administration, and they do not prepare you for a security certification exam.

Do the courses include simulated phishing?

The phishing course includes practice messages you inspect and sort inside the course. It does not send live test emails to your staff; if you run a simulation program, use the course as the training that follows it.

What should an employee do right after clicking a bad link?

Disconnect if told to, change the password from a different device if credentials were entered, and report to IT or a manager straight away with the message still available. Every course in this topic ends with that first-ten-minutes checklist.

How long does each cybersecurity course take?

Most are 2 contact hours, and the password and account security course is 1.5. Progress saves automatically, so staff can complete a course in short sessions between other work.

Will cybersecurity training satisfy my insurer or a regulator?

Requirements differ by insurer, contract and industry. Each course earns a certificate of completion with a date and verification ID; check whether your insurer, client or regulator accepts it and what topics it expects.

Find the course you need

Preview the first module of any course free. Pay only when it is the right fit.