TRAINING · INFORMATION SECURITY

Cybersecurity
Awareness Training

A complete guide to protecting yourself and your company against digital threats.

By Yosef Alberti · 443sec · X2 Nova Labs

Scroll down
TRAINING · INFORMATION SECURITY

Cybersecurity Awareness Training

A complete guide to protecting yourself and your company against digital threats — phishing, passwords, social engineering, and best practices.

Employee Onboarding · 443sec · X2 Nova Labs

Why This Matters

Most attacks start with human error. A click on a malicious link, a weak password, or information shared with the wrong person. Technology protects systems, but training protects people.

90%
of attacks start
with phishing
$4.5M
average cost
of a breach
43%
target small
businesses
95%
involve human
error
01

What is Information Security

Information Security is the set of practices to protect information against unauthorized access, misuse, disclosure, destruction, or modification. It is based on three pillars:

02

Phishing — how to identify scams

Phishing is an attempt to obtain confidential information (passwords, banking data) by pretending to be a trustworthy entity through emails, messages, or fake websites.

WARNING SIGNS

Golden rule: When in doubt, DON'T CLICK. Contact the company directly through an official channel to confirm if the message is legitimate.

03

Strong passwords and 2FA

STRONG PASSWORD What makes a good password

Never use: 123456, password, qwerty, abc123, admin, your name, date of birth

2FA Two-Factor Authentication

An extra layer of security. Even if someone discovers your password, they'll still need an additional code.

Tip: Use a password manager like Bitwarden, 1Password, or LastPass. You only need to remember ONE master password.

04

Social Engineering

Manipulation techniques used to deceive people into revealing information or taking harmful actions. The attacker exploits trust, fear, or urgency.

Pretexting

"I'm from IT, I need your password for a system update"

Baiting

"Lost" USB drive in the parking lot with a virus

Vishing

Phishing by phone — "Call from the bank"

Tailgating

Following an authorized employee to enter a restricted area

No legitimate institution will ask for your password over the phone. When in doubt, hang up and call the official number yourself.

05

Computer and phone security

COMPUTER
  • Keep system and apps updated
  • Use antivirus and keep it active
  • Lock your screen when away (Win + L)
  • Don't install unauthorized programs
  • Back up regularly
  • Be careful with unknown USB drives
PHONE
  • Always use password/biometrics
  • Apps only from official stores
  • Review app permissions
  • Enable "Find my device"
  • Be careful with links in messages
  • Keep system updated
06

Public Wi-Fi — the dangers

Networks in cafes, airports, and hotels can be monitored by attackers. They can see everything you do online if the connection is not encrypted.

NEVER do this on public Wi-Fi: Access banking, shop online, enter important passwords, access company systems without VPN

PROTECTION
07

Sensitive data and privacy regulations

Privacy regulations (like GDPR, CCPA, LGPD) protect personal data. Violations can result in fines of up to 4% of annual revenue or millions of dollars.

WHAT IS SENSITIVE DATA

Best practices: Don't send sensitive data via email without encryption. Don't leave documents at the printer. Shred papers with data. Lock your screen when away.

08

What to do in case of an incident

SIGNS OF TROUBLE

IMMEDIATE STEPS:
1. DON'T panic
2. Disconnect from the network (if possible)
3. DON'T turn off the computer (may erase evidence)
4. Notify IT/Security IMMEDIATELY
5. Document what happened (screenshots, times)
6. Change passwords on another device

Remember: Reporting an incident is NOT grounds for punishment. It's better to report a false alarm than to ignore a real threat.

Golden Rules

SECURITY CHECKLIST