Cybersecurity
Security awareness for everyone
This is the one page in the silo written for people who want no security career and still carry security risk every working day. A handful of habits (a password manager, a second factor, prompt updates, backups that have been tested, a pause before acting on an urgent message) head off a large share of the incidents that reach small businesses and freelancers. None of them needs technical knowledge; each needs a decision to actually do it.
Why this topic exists: Most incidents start with a person, not a port: what every employee and freelancer must know about phishing, passwords, MFA, backups and updates (NICE Oversight and Governance; the management side of every blueprint).
Security awareness is the part of the field aimed at everyone who is not a security professional: the accountant, the designer, the freelancer running a business from a laptop. It asks for a short list of habits rather than technical knowledge, and each habit closes a door that attackers try routinely. The list below is deliberately brief, because a person who adopts five things does more good than one who is told fifty and adopts none.
- A password manager, so that every account gets its own long, random password and a breach at one site does not open the others.
- A second factor on important accounts. Multi-factor authentication means a stolen password alone is no longer enough; prefer an app, a hardware key or a passkey over codes sent by text message.
- Updates installed promptly on phones, computers and routers, since many attacks rely on weaknesses that already have a fix.
- Backups that have been restored at least once, kept where a ransomware infection on your main machine cannot reach them.
- A pause before acting on urgency. Phishing works by rushing people; a request to pay, share a code or open a file under time pressure deserves a check through a channel you already trust.
Awareness as an organisational duty
For employers, awareness is more than a poster campaign. The NICE Workforce Framework lists work roles for developing awareness and training content and for delivering it, both under its Oversight and Governance category, which says where the subject belongs: with leadership and policy, not only with the IT desk. Security+ examines it in the same spirit, inside its programme management and oversight domain, where one objective covers running phishing campaigns, handling messages staff report as suspicious, recognising risky or unexpected behaviour, and guidance for hybrid and remote work. Useful programmes are short, frequent and tied to the tools people use every day. They also make reporting easy and free of blame, because the employee who clicks a bad link and reports it within a minute has helped more than one who never reports anything.
Two free or low-cost starting points
Cisco's free Introduction to Cybersecurity takes about six hours and covers personal and organisational security for beginners. Google's Cybersecurity certificate is a longer programme for people weighing a career change, and it starts from the same ground.
The usual mistake, for individuals and small firms alike, is to assume they are too small to interest anyone. Automated campaigns do not select victims by size; they reach thousands of inboxes at once and succeed wherever a habit is missing. A one-person business holds bank access, client data and a reputation, which is reason enough. Readers who want to understand the lures in more depth can continue with threats and attacks, and anyone responsible for accounts across a team with identity and access management.
Next to this topic
- Security fundamentalsEvery blueprint opens here: the CIA triad, control types and the threat, vulnerability and risk vocabulary (SY0-701 General Security Concepts, 12 %; CISSP domain 1).
- Network securityFirewalls, segmentation, IDS/IPS, VPNs and zero trust are where most defensive work starts (CISSP Communication and Network Security, 13 %; Network+ and CCNA security domains).
- Identity and access managementWho may do what is its own discipline with its own exam (SC-300) and a full CISSP domain (13 %): authentication, MFA, SSO, directories and least privilege.
- CryptographyEncryption, hashing, keys and PKI underlie every other topic; the exams test them as applied choices, not maths (CISSP Security Architecture and Engineering; SY0-701 domain 1).
- Threats and attacksThe second-largest Security+ domain (Threats, Vulnerabilities and Mitigations, 22 %; only Security Operations weighs more): malware, phishing, social engineering, ransomware and the attack techniques defenders must recognise.
- Security operationsMonitoring, detection and the SOC are the largest Security+ domain (28 %) and the whole of SC-200 and CySA+: SIEM, logging, alert triage, threat hunting.
- Penetration testing and ethical hackingAuthorised attack as a profession: scoping, reconnaissance, exploitation, reporting (PTES; PenTest+ and CEH). Also the most-searched security topic on the course side.
- Governance, risk and compliancePolicies, risk assessment, frameworks (NIST CSF, ISO 27001) and audit are the management half of the field: CISSP domain 1 (16 %), CISM, CISA, Security+ Program Management (20 %).
- Application securityA large share of breaches begins in software: secure design, secure build, security testing and the OWASP Top 10 (OWASP SAMM; CISSP Software Development Security, 10 %).
- Cloud securityShared responsibility, cloud identity and posture management are tested in every cloud exam (SAA-C03 Design Secure Architectures, 30 %) and in SC-900; the cloud silo owns the platforms, this topic owns the defence.
Concepts to know
Glossary entries with the reason each one matters here.
- Phishing
What every employee must recognise.
- MFA
The one habit that stops most account takeovers.
- Ransomware
Why backups and updates are everybody's job.
Certifications that test it
Vendor exams and free certificates; facts, cost and the preparation path are on each page, and the certifications hub has them all.
Frequently asked
- Is a password manager safe when every password sits in one place?
- It is far safer than the alternative most people use, which is repeating a few passwords everywhere. Protect the manager itself with a strong passphrase and a second factor, and the single point you have created becomes the single point you defend.
- Are text-message codes still worth using?
- Yes, where nothing stronger is offered. They are weaker than a code-generating app or a physical security key, because messages can be intercepted or a number moved to another SIM, but any second factor is a large step up from none.
- What should I do if I clicked a phishing link?
- Report it at once to whoever handles IT. If you work alone, change the password of any account you typed into the page and check its recent sign-ins. Speed matters more than embarrassment; a quick report often turns an incident into a non-event.
Courses in the directory
9 courses are filed here; the top 6 by our ranking, details and the provider link on each course page.
Last reviewed 26 September 2026 · Getting Digital
