
Explore cybersecurity fundamentals, including malware, firewalls, ids, ips, security policy, physical security, vulnerabilities, and patch management. See how these concepts protect confidentiality, integrity, and availability of information systems.
Define cyber threats and attacks as malicious activities targeting computer systems and assets, including malware, phishing, ransomware, data breaches, and network disruption. Highlight security software, firewalls, authentication, training, and updates.
Explore cyber security factors that protect digital assets, including risk management, security policies, access control, authentication and authorization, encryption, security awareness and training, network and endpoint security, and audits.
Develop cybersecurity awareness by understanding threat awareness, security practices, and incident response. Build a resilient culture through training, organizational awareness, and crisis management.
Explore what malware is, including viruses, worms, trojans, spyware, adware, ransomware, and botnets, and learn how antivirus software and safe internet use mitigate its harm.
Viruses are malicious software that damage devices, exfiltrate data, steal information, and disrupt system performance. They spread by infecting files and running when opened, via email, downloads, and USB drives.
Understand how worm malware replicates and spreads by exploiting vulnerabilities, impacts system performance and network traffic, and learn protections like updates, firewall use, strong passwords, backups, and user education.
Understand how spyware secretly monitors activities and personal information for advertising or profiling, and learn protections like anti-spyware software, regular scans, updates, and cybersecurity awareness.
Identify adware as a malware type bundled with free software that displays ads and can affect device performance. Protect yourself by downloading from trusted sources and enabling advanced installation options.
Learn how Trojan malware stealthily infiltrates systems to steal information or damage data, disguising itself as harmless content. Protect yourself with antivirus, scans, cautious emails and downloads, and up-to-date patches.
Explore how botnets form when malware infects devices to create a control network used for attacks like DDoS, spam, and phishing, and learn protective measures.
Learn how ransomware encrypts files and demands payment, how attacks spread via email, links, and downloads, and how backups, updates, antivirus scans, and user education protect organizations.
Learn how penetration testing simulates cyber attacks to identify vulnerabilities and improve security posture. Follow the steps of information gathering, vulnerability analysis, exploitation, post-exploitation, and reporting by ethical hackers.
Identify hacker types and groups, including white hat, black hat, grey hat, hacktivists, organized cybercrime, nation-state units, advanced persistent threats, and insider threats, to understand risks and cybersecurity measures.
Protect information by balancing confidentiality, integrity, and availability, preventing unauthorized access and changes while ensuring authorized access and continuity of systems through unplanned outages.
Understand vulnerability in cyber security, how design, implementation, or configuration errors create exploitable flaws, and how issues like buffer overflow, outdated software, weak passwords, and unencrypted networks enable breaches.
Explore how the GDPR protects personal data across the EU, detailing consent, rights such as access and erasure, privacy by design, breach notification within 72 hours, and fines.
Explore how denial-of-service attacks overwhelm a network or service, and how distributed denial-of-service attacks use botnets to flood a site from many sources, causing outages during Christmas shopping period.
Explore application-based attacks on web apps, including sql injection, cross-site scripting, and csrf. Defend with input validation, parameterized queries, headers, and tokens to mitigate command injection and file inclusion risks.
A man-in-the-middle attack places an attacker between two communicating parties to observe, alter, or manipulate traffic, especially on open networks, with https and ssl/tls encryption protecting passwords and usernames.
Identify social engineering as a manipulation technique that exploits human psychology to deceive and gain information. Avoid sharing sensitive data, verify identities, and participate in security awareness training.
Phishing attacks use convincing messages to steal personal and financial information by directing users to fake websites. Avoid untrusted links and verify suspicious messages to block these attempts.
Spear phishing targets a specific person or group with personalized messages crafted from victim information. Attackers use fake content with names, titles, or internal details to prompt action.
Explore common social engineering attacks such as baiting, impersonation, tailgating, phishing, and smishing, and learn practical defenses like verification, strong passwords, two factor authentication, and security policies.
Examine anonymity in cyber security, its privacy and protection benefits, and ethical and legal drawbacks, with tools like VPNs and the Tor browser to balance security and access.
Describe the cyber kill chain model from reconnaissance to actions on objectives, developed by Lockheed Martin, and show how each stage enables detection, prevention, and attacker progression to ransomware.
Explore password attacks, including brute force and dictionary methods, how attackers crack passwords, and how strong, unique passwords resist these techniques.
Enforce a strong password policy with unique, complex passwords of at least 12 characters using uppercase, lowercase, numbers, and symbols. Enable two-factor authentication and conduct regular audits while educating users.
Explore email threats like phishing and social engineering, where deceptive messages lure users into clicking links or opening attachments and sharing data, while attackers forge headers to spread malware.
Explore email security by using spam filters, antivirus software, and encryption, implement two-factor authentication, keep systems updated, conduct regular audits, monitor traffic, and use dMarc to prevent spoofing.
Learn practical system security measures to protect computers and networks, including updates, strong passwords, MFA, firewalls, backups, full disk encryption, least privilege, secure protocols, and audits.
Http transmits text-based data over tcp without encryption. Https encrypts with ssl/tls, using port 443 and certificates to prevent eavesdropping and man-in-the-middle threats.
Enable strong passwords or biometrics and encrypt data on mobile devices; keep the operating system and apps updated. Review permissions, download apps from official stores, and back up data securely.
Protect your personal and professional information on social media by using strong unique passwords, enabling two-factor authentication, and monitoring account activity to prevent unauthorized access and privacy breaches.
Firewall controls traffic between internal networks and outside world, filtering by IP address, port, or protocol to block malware and unauthorized access, log activity, and support VPN traffic for compliance.
Compare intrusion detection and intrusion prevention systems, showing how IDS monitors and alerts while IPS blocks traffic and isolates systems to strengthen network security.
A web application firewall sits in front of web applications, filters http traffic to block attacks (SQL injection, XSS, CSRF), logs traffic, and helps enforce security policies.
Understand how network access control enforces security policies by authenticating devices, assessing endpoint security, quarantining noncompliant devices, and downgrading sessions or routing to the guest network after suspicious activity.
Explore how security information event management collects, normalizes, and analyzes logs from numerous sources to detect incidents using rules and correlations tied to attacker techniques, tactics, and procedures.
Soar stands for security, orchestration, automation and response to accelerate and improve cyber security operations. Orchestration coordinates workflows and harmonizes tools and tasks for a unified, standardized incident response.
Backups protect data, enable quick recovery after loss or ransomware, and support business continuity, data integrity, regulatory compliance, and customer trust in cybersecurity.
Cyber security is of vital importance in today's rapidly digitalizing world. The "Cyber Security Awareness and Information Security" course aims to raise participants' awareness of digital threats, increase security, and enable them to understand strategies to protect information systems.
Individuals working in personal data protection, system management, network, and information security need to have information about cyber attacks, both individually and corporately. This training content covers cyber attacks and logical and hardware security solutions that can be applied to protect against cyber attacks.
Every individual working in institutions should have a good degree of awareness of cyber security and information security. 80% of successful attacks against companies occur from within. In other words, every individual should have cyber security awareness to be protected from attacks caused by the mistakes of company personnel. The content in this training has been prepared completely accordingly.
This comprehensive course provides a framework that will empower participants in information security and improve their ability to defend against a variety of cyber threats that may be encountered. In addition to explaining basic cybersecurity principles, the course content offers participants a broad perspective by focusing on topics such as social engineering, malware, data security, and network security.