Skip to content
Getting Digital

Cybersecurity

Security awareness for everyone

This is the one page in the silo written for people who want no security career and still carry security risk every working day. A handful of habits (a password manager, a second factor, prompt updates, backups that have been tested, a pause before acting on an urgent message) head off a large share of the incidents that reach small businesses and freelancers. None of them needs technical knowledge; each needs a decision to actually do it.

Why this topic exists: Most incidents start with a person, not a port: what every employee and freelancer must know about phishing, passwords, MFA, backups and updates (NICE Oversight and Governance; the management side of every blueprint).

Security awareness is the part of the field aimed at everyone who is not a security professional: the accountant, the designer, the freelancer running a business from a laptop. It asks for a short list of habits rather than technical knowledge, and each habit closes a door that attackers try routinely. The list below is deliberately brief, because a person who adopts five things does more good than one who is told fifty and adopts none.

  • A password manager, so that every account gets its own long, random password and a breach at one site does not open the others.
  • A second factor on important accounts. Multi-factor authentication means a stolen password alone is no longer enough; prefer an app, a hardware key or a passkey over codes sent by text message.
  • Updates installed promptly on phones, computers and routers, since many attacks rely on weaknesses that already have a fix.
  • Backups that have been restored at least once, kept where a ransomware infection on your main machine cannot reach them.
  • A pause before acting on urgency. Phishing works by rushing people; a request to pay, share a code or open a file under time pressure deserves a check through a channel you already trust.

Awareness as an organisational duty

For employers, awareness is more than a poster campaign. The NICE Workforce Framework lists work roles for developing awareness and training content and for delivering it, both under its Oversight and Governance category, which says where the subject belongs: with leadership and policy, not only with the IT desk. Security+ examines it in the same spirit, inside its programme management and oversight domain, where one objective covers running phishing campaigns, handling messages staff report as suspicious, recognising risky or unexpected behaviour, and guidance for hybrid and remote work. Useful programmes are short, frequent and tied to the tools people use every day. They also make reporting easy and free of blame, because the employee who clicks a bad link and reports it within a minute has helped more than one who never reports anything.

Two free or low-cost starting points

Cisco's free Introduction to Cybersecurity takes about six hours and covers personal and organisational security for beginners. Google's Cybersecurity certificate is a longer programme for people weighing a career change, and it starts from the same ground.

The usual mistake, for individuals and small firms alike, is to assume they are too small to interest anyone. Automated campaigns do not select victims by size; they reach thousands of inboxes at once and succeed wherever a habit is missing. A one-person business holds bank access, client data and a reputation, which is reason enough. Readers who want to understand the lures in more depth can continue with threats and attacks, and anyone responsible for accounts across a team with identity and access management.

Next to this topic

Concepts to know

Glossary entries with the reason each one matters here.

  • Phishing

    What every employee must recognise.

  • MFA

    The one habit that stops most account takeovers.

  • Ransomware

    Why backups and updates are everybody's job.

Certifications that test it

Vendor exams and free certificates; facts, cost and the preparation path are on each page, and the certifications hub has them all.

Frequently asked

Is a password manager safe when every password sits in one place?
It is far safer than the alternative most people use, which is repeating a few passwords everywhere. Protect the manager itself with a strong passphrase and a second factor, and the single point you have created becomes the single point you defend.
Are text-message codes still worth using?
Yes, where nothing stronger is offered. They are weaker than a code-generating app or a physical security key, because messages can be intercepted or a number moved to another SIM, but any second factor is a large step up from none.
What should I do if I clicked a phishing link?
Report it at once to whoever handles IT. If you work alone, change the password of any account you typed into the page and check its recent sign-ins. Speed matters more than embarrassment; a quick report often turns an incident into a non-event.

Courses in the directory

9 courses are filed here; the top 6 by our ranking, details and the provider link on each course page.

Browse the directory shelf

Last reviewed 26 September 2026 · Getting Digital