Skip to content
CyberSafe logoCyberSafe
For Business

CyberSafe for Business: staff training

A 6-academic-hour cyber-safety course for your office staff, held at your office or a venue we agree on.

CyberSafe for Business is a private cyber-safety awareness course for groups of up to 20 employees. Over 6 academic hours we cover the threats hitting companies in Estonia in 2026: CEO fraud (the 'CEO' urgently asks for a transfer), invoice fraud (a fake supplier sends an invoice with different bank details), email account takeover, ransomware, and staff awareness in line with GDPR. The longer format leaves time for exercises for each department. On the day we also set up a pilot phishing simulation and walk the whole team through your incident-response plan. We come to your office, or we agree on a separate training room.

Who it's for

What you'll know after the course

Syllabus

  1. Introduction: how companies in Estonia are being attacked in 2026

    • Real scam cases from Estonian companies, 2024–2026
    • What costs the most right now: CEO fraud, ransomware or invoice fraud
    • How a scam usually reaches your company
  2. CEO fraud and invoice fraud (core module)

    • The 'CEO' urgently asks for €24,700 to be transferred
    • A fake supplier sends an invoice with a changed account number
    • AI-cloned voices and deepfake video calls
    • The four-eyes principle: how to make it work in practice
  3. Protecting email and accounts

    • Signs of a phishing email: DKIM, SPF, spoofed sender names
    • Security settings in Microsoft 365 and Google Workspace
    • Two-factor authentication for the whole team
    • What to do when an account has been taken over
  4. Customer data and GDPR

    • How to handle requests about customer data
    • What counts as a personal data breach and when to notify AKI
    • Employees' obligations under GDPR
  5. Practical exercise: role play

    • 'The CEO needs an urgent transfer': finance practises
    • 'A customer asks for a password': customer service practises
    • 'A contractor has sent an invoice': accounting practises
    • Each department gets its own scenario
  6. An incident-response plan for your company

    • Checklist for the first 60 minutes after an incident
    • Internal escalation: who calls whom
    • Templates for messages to customers and partners
    • The AKI notification form and deadlines
    • Reviewing the incident afterwards and learning from it
  7. Phishing-simulation pilot and audit trail

    • How to choose your first phishing-simulation tool (KnowBe4, Hoxhunt, free options)
    • Setting up the first campaign on site
    • Reading the results: when there is a problem and when there is not
    • Audit trail: which documents to show in an ISO 27001 or GDPR audit
    • How often to repeat the training: quarterly or yearly

What's included

Other CyberSafe courses

Ready to submit a request?

Send us a request and we'll reply within 24 hours with a quote and payment details.