Cybersecurity
Cybersecurity Awareness for Employees
For: All employees
By profession
For all employees and individuals: replace old password rules with current NIST guidance, choose phishing-resistant MFA and passkeys, and recover fast when an account is compromised.
For: All employees and individuals who sign in to work or personal accounts, including office managers, payroll and finance staff, small business owners and IT administrators
Learn how accounts really get broken into, from credential stuffing and password spraying to push bombing and SIM swaps, and the specific defense that stops each one. You will apply NIST SP 800-63B-4 password guidance, set up a password manager, choose the strongest MFA an account offers, understand passkeys, lock down email recovery settings and handle shared and admin accounts safely.
This deep-dive course is for anyone who signs in to anything: staff at every level, small business owners who set their office's password rules, and administrators who manage shared or privileged accounts. It is short enough to finish in one sitting and practical enough to change your habits that day.
Old rules such as forced 90-day changes and mandatory symbols are out; length, uniqueness, password managers and phishing-resistant MFA are in. This course explains why, using current NIST and CISA guidance, and gives you an account security checklist, a phishing pocket card and an incident report template for when something goes wrong.
What you’ll be able to do Monday morning
5 modules · 20 lessons · about 1.5 contact hours
Diagram · In practice checklist · 3-question knowledge check
Diagram · In practice checklist · 2-question knowledge check
Diagram · In practice checklist · 3-question knowledge check
Diagram · In practice checklist · 2-question knowledge check
Diagram · In practice checklist · 2-question knowledge check
Try it now, no account needed
A branching scenario from this course. Your choices are not saved.
Practice activities
Job aids you keep
This course awards a certificate of completion for 1.5 contact hours of instruction. It has not been approved or accredited by IACET, any licensing board, any state agency or any other accreditor. It is general security awareness training aligned with public guidance from NIST and CISA. Check with your employer, licensing board or professional body whether this course can count toward your security-awareness training records or continuing education.
A pathway we are pursuing or may pursue is IACET accreditation of our course development process. No approval exists today; we will show an approval on this page only after it is granted.
Our full approvals listEveryone who signs in to work or personal accounts. It is especially useful for office managers and small business owners who set password rules, payroll and finance staff whose accounts attract fraud, and IT administrators who manage shared and privileged accounts. No technical background is needed.
You receive a certificate of completion for 1.5 contact hours of instruction. The course is not currently approved or accredited by IACET, a licensing board or any other accreditor. Check with your employer or board whether it can count toward your training or continuing education records.
Yes. NIST SP 800-63B-4, finalized in 2025, says systems should not require scheduled password changes, and should force a change when there is evidence of compromise. Your employer's systems may still use older rules; follow your workplace policy and raise the question with IT.
Plan on about 90 minutes, including five modules, interactive activities, knowledge checks and a 17-question final assessment with an 80% pass mark. You can pause and return at any time.
No installation is required to take the course. The activities and job aids help you set up a password manager, MFA and passkeys afterward, using tools your employer approves for work accounts.
No. It explains attack methods only at the level needed to recognize and prevent them. The focus is prevention, recognition, recovery and reporting.
This course is general education and account security awareness training from CE Courses Hub. It is not legal, technical or professional advice and does not replace your employer's security policies, your licensing board's rules, or advice from a qualified professional. Completing it earns a certificate of completion for the stated contact hours; it is not approved or accredited by any licensing board, state agency or accreditor unless an approval is shown on the course page. Check with your board, employer or state agency whether this course meets your specific requirement.