Every other Shieldly module watches your infrastructure. This one covers what attackers actually target. Six short modules, each ending in a five-question quiz, with your scores recorded as compliance evidence.
Written for people who don't work in IT. Each one is short enough to finish in a sitting and specific enough to change what someone does on Monday morning.
How phishing emails are built, the signals that give them away, and what to do before you click, reply or pay.
Why password reuse is the single cheapest way in, and how multi-factor authentication closes that door.
The manipulation techniques that bypass every technical control you own — urgency, authority and familiarity.
What personal data actually is, how long you may keep it, and the obligations NDPR places on ordinary staff.
What counts as an incident, who to tell, how fast — and why the first hour decides how bad it gets.
Why the weakest link is often someone else's system, and what to check before granting a supplier access.
Most SMBs either skip awareness training entirely or run it once and lose the record. Auditors don't accept “we told everyone” — they want dated, scored evidence. That is what this produces.
An email from your CEO asks you to urgently buy gift cards and send the codes. The address looks right. What is the strongest signal this is a scam?
Essentials includes phishing, passwords and safe browsing. Professional adds data handling, incident reporting and vendor risk — the three modules auditors ask about most. Start with a free domain audit to see where you stand.