About this course
When a security incident happens, whether it's a suspicious email that was clicked, a lost laptop, or a system behaving strangely, the actions an ordinary employee takes in the first few minutes can matter as much as anything the security team does afterward. This course focuses narrowly and practically on that employee role: recognizing something is wrong, reporting it quickly and completely, and taking simple containment steps, without stepping into the job of a full incident response team.
The core principle taught throughout this course is report, don't investigate. Employees who try to diagnose or fix a suspected incident themselves, such as restarting a suspicious system, deleting a strange file, or trying to "clean up" after clicking a phishing link, can unintentionally destroy the evidence responders need and can allow an incident to spread further before it's contained. The safer and more effective path is fast, complete reporting to the people trained to handle it.
This matters because most organizations, no matter how strong their security tools are, depend on employees as their earliest detection layer. A phishing email, an unfamiliar login prompt, or a colleague's odd request to transfer funds are all things a human is often better positioned to notice than automated systems, but only if that person knows what to report and feels confident reporting it, including when they're not fully sure something is wrong.
This training is designed for all employees, regardless of technical background. After completing it, learners will be able to recognize common types of security incidents (phishing, malware, lost devices, unauthorized access, suspicious requests), report an incident quickly through the correct internal channel, take basic containment actions such as disconnecting a device from the network, and avoid actions that could destroy evidence or worsen an incident.
Topics covered
- Common categories of security incidents employees may encounter
- Why "report, don't investigate" protects the organization
- What to document while waiting for IT or security to respond
- Basic containment: disconnecting devices, not deleting or restarting
- Escalation paths and who to contact
Want this tailored to your organization's policies? Build your own with AI or book a demo.