Phishing and Social Engineering Awareness
Help staff recognise manipulation tactics, suspicious messages, fake login pages, and the common attack patterns behind most breaches.
Course overview
Most security incidents start with a person, not a system. This course gives every member of your team the instincts to spot phishing, social engineering, and impersonation attempts before they cause harm — using realistic, up-to-date examples.
What learners will be able to do
- Recognise the hallmarks of phishing and spear-phishing emails
- Spot fake login pages, spoofed domains, and malicious attachments
- Identify social-engineering tactics over email, phone, and messaging
- Respond safely to urgent, unexpected, or authority-based requests
- Understand why these attacks succeed and how attackers research targets
- Know exactly how and when to report a suspicious message
What the course covers
Module 1: How modern attacks really work
The anatomy of a phishing campaign and the psychology behind it.
Module 2: Spotting suspicious messages
Red flags in senders, links, attachments, and tone.
Module 3: Fake pages and credential theft
Recognising spoofed login screens and protecting your passwords.
Module 4: Beyond email
Phone, SMS, and messaging-based social engineering.
Module 5: Reporting and response
What to do in the first five minutes after a suspicious message.
Interested in this course for your team?
Tell us your team size, preferred format, and goals — we'll recommend the best delivery option.