Cybersecurity & Privacy Basics for Engineers and Technical Professionals
This course can be customized and delivered to your team where and when it's convenient for you.
Online / On-site
OVERVIEW
Description
After participating in this course, you will be able to:
- Build or enhance your cybersecurity and privacy program using international standards for both work and personal environments.
- Understand and address legal and regulatory requirements to ensure organizational compliance.
- Apply controls to prevent incidents, protect privacy, and improve safety across all settings.
- Recognize what qualifies as personal and sensitive data.
- Identify and safeguard personal and sensitive data throughout its lifecycle.
- Recognize common threats like ransomware, social engineering, and supply chain risks—and how to defend against them.
- Access ongoing resources to maintain strong privacy, security, and safety practices.
Description
Cybersecurity & Privacy Basics for Engineers and Technical Professionals is a practical course designed to help technical teams understand and apply essential cybersecurity and privacy principles. Participants will explore current laws, risks, and real-world incidents to grasp the impact of security breaches and privacy violations. The course highlights how strong cybersecurity and privacy practices can enhance both organizational and personal safety, and introduces key controls and program elements that every engineer and technical professional should know.
Through interactive use cases and checklists, learners will gain actionable tips for protecting data and systems in both professional and personal contexts. The course also provides guidance on building effective security and privacy programs, along with curated resources for continued learning. Whether you're new to the topic or looking to strengthen your foundation, this course offers a clear and engaging path to becoming more security-aware and privacy-conscious.
Course Outline
- Current cybersecurity and privacy facts, laws, and risks
- Examples of real-life security incidents and privacy breaches, and the associated harms and penalties
- Using cybersecurity and privacy to improve safety
- Security and privacy controls necessary in organizations
- Security and privacy controls necessary in personal life
- Cybersecurity and privacy program key elements
- Cybersecurity tips and checklists for organizations & individuals
- Privacy tips and checklists for organizations & individuals
- Privacy and security use cases and class participation
- Important parting advice
- Cybersecurity and privacy resources
Who Should Attend
Practitioners that depend upon, or have within their work environment, technologies, including but not limited to:
- Technical personnel
- Facility managers
- IT managers
- Sourcing/Contracting managers
- Design engineers
- Facility engineers
- Electric grid engineers
- Construction engineers
- Engineering consultants
- Transportation engineers
- Material managers
- Facility operators
- Environmental scientists
- Lawyers
- Cybersecurity managers
- Privacy managers
Audience Skill Level
Beginner/Intermediate. No prior experience or prerequisites are needed.
Course Outline
Day 1: 7 hours
- What is social engineering, and related terminology
- The evolution of social engineering techniques throughout history
- The current most commonly used types of social engineering tactics
- Types of social engineering tactics currently being widely used by cybercriminals (use of AI, imposters, spoofing, malicious websites, and more), and the types of individuals they are targeting.
- Type of motives people have for using social engineering tactics, and how they think
- Type of organizations and individuals targeted for social engineering
- How to prevent being a victim of the same types of tactics
- Actions to prevent the organization from falling victim to social engineering attacks
- Types of harms that social engineering exploits have on the associated business, individuals who fell for the tactics, and the people associated with the personal data that was breached
- Real-life social engineering exploits for which other engineers and technical professionals have been victims
Day 2: 7 hours
- Ethics, risks and laws to consider when using social engineering to test your organization
- Determining whether or not to test your organization for the different types of social engineering tactics
- Choosing the best tools to create various types of social engineering campaigns to test your organization
- Investigating phishing and other types of social engineering attacks
- Tools to help block social engineering attacks from being successful in organizations
- Tools to help block social engineering attacks from being successful in personal life
- Use cases for each type of social engineering tactics. Examples include:
- Physical Security Tactics
- Insider threat
- Lobby/entryway
- Tailgating
- USB drops
- RFID cloning
- Snail mail
- Digital trackers
- Compromised security cameras
- Phishing
- Spear Phishing
- Whaling
- Impersonations
- AI and voice spoofing
- Email spoofing
- Cloning Websites
- Vishing
- Smishing
- Caller ID Spoofing
- Tailgating and Physical Access
- Implementing a variety of approaches to create awareness and training programs within your organization to protect against social engineering attacks
- Laws that include requirements that social engineering activities support
- Additional resources to use to maintain ongoing privacy, security, and associated safety protections.