Cybersecurity Awareness Pack
All employees
Phishing and scams, passwords and MFA, remote work security and AI-enabled fraud.
By profession
For all employees, especially finance, HR and admin staff: spot phishing in every channel, verify before you pay, and report fast.
For: All employees, with extra depth for finance, accounts payable, payroll, HR, executive assistants and office administrators
Learn how phishing and social engineering really work, from spear phishing and whaling to smishing, vishing, callback scams, QR-code phishing and MFA push bombing. You will practice reading suspicious emails, texts and calls with a repeatable inspection routine, verify payment and data requests out of band, and walk through what to do in the first hour after a click.
This course is built for every employee, with extra depth for the people attackers target most: accounts payable, payroll, HR, executive assistants and office managers. Supervisors will also find guidance on responding to reports and running fair phishing simulations.
Phishing is the doorway to most costly fraud. In 2025, the FBI's Internet Crime Complaint Center (IC3) logged more than one million complaints and about $20.9 billion in reported losses, including about $3.05 billion from business email compromise. This course uses only defanged examples, current CISA, FTC, FBI and NIST guidance, and practical tools you can use on Monday: a phishing checklist, an incident report template, an account security checklist and a callback script.
What you’ll be able to do Monday morning
7 modules · 26 lessons · about 2 contact hours
Diagram · In practice checklist · 2-question knowledge check
Diagram · In practice checklist · 3-question knowledge check
Diagram · In practice checklist · 2-question knowledge check
Diagram · In practice checklist · 2-question knowledge check
Diagram · In practice checklist · 3-question knowledge check
Diagram · In practice checklist · 2-question knowledge check
Diagram · In practice checklist · 2-question knowledge check
Try it now, no account needed
A branching scenario from this course. Your choices are not saved.
Practice activities
Job aids you keep
This course awards a certificate of completion for 2 contact hours of instruction. It has not been approved or accredited by IACET, NASBA, any state board of accountancy, any licensing board or any other accreditor, and it is not a government training program. It is general awareness training aligned with public guidance from CISA, the FBI's IC3, the FTC and NIST. Check with your employer, licensing board or professional body whether this course can count toward your security-awareness training records or continuing education.
Pathways we are pursuing or may pursue include IACET accreditation of our course development process and, where eligible, registration as a NASBA continuing professional education (CPE) sponsor. No approval exists today; we will show any approval on this page only after it is granted.
Our full approvals listIt is for all employees, with extra depth for people who handle money, data or access: accounts payable, payroll, HR, executive assistants, office managers and front-desk staff. Supervisors will find guidance on responding to reports and supporting phishing simulations. No technical background is needed, and the course uses only defanged, non-clickable examples.
You receive a certificate of completion for 2 contact hours of instruction. The course is not currently approved or accredited by IACET, NASBA, a state board or any other accreditor. Check with your employer, board or professional body whether it can count toward your training or continuing education records.
That depends on your employer's policy, contracts and any industry rules that apply to them. Many employers accept outside awareness courses, but some require their own training. Ask your manager, IT or compliance team before enrolling, and share the course outline and objectives with them if helpful.
Plan on about 2 hours, including seven short modules, interactive practice activities, knowledge checks and a 23-question final assessment with a 70% pass mark. You can pause and return at any time, and your progress is saved.
The skills taught here follow federal guidance from CISA, the FBI, the FTC and NIST, and apply nationwide. Related rules, such as data breach notification laws, vary by state; your organization's privacy or legal team decides how those apply after an incident.
No. The course covers prevention, recognition, verification and reporting only. All example links are defanged so they cannot be clicked, and simulated phishing is discussed only from the point of view of employees and the organizations that run fair, announced programs.
This course is general education and cybersecurity awareness training from CE Courses Hub. It is not legal, financial or professional advice and does not replace your employer's security policies, your licensing board's rules, or advice from a qualified professional. Completing it earns a certificate of completion for the stated contact hours; it is not approved or accredited by any licensing board, state agency or accreditor unless an approval is shown on the course page. Check with your board, employer or state agency whether this course meets your specific requirement.