Course track
Ransomware Readiness for Staff
How ransomware really gets in, your role in the first 60 minutes, VPN/remote-desktop hygiene, backups that actually save you, and whether paying the ransom ever makes sense.
Who takes this: All staff, especially those with remote or VPN access
ISONISTSOC2FTCCBNNDPA
| Module | Length | What staff learn | Maps to |
|---|---|---|---|
| How Ransomware Really Gets In | 5 min | Connect everyday habits (passwords, phishing reports, updates) to ransomware prevention. | ISO, NIST |
| Your Role in the First 60 Minutes | 5 min | Disconnect safely and report immediately without trying to fix a suspected ransomware attack. | ISO, SOC2, NIST |
| VPN and Remote Desktop Hygiene for Everyday Staff | 4 min | Use only approved remote access tools with unique credentials. | ISO, NIST |
| Spotting Ransomware Before It Spreads | 5 min | Identify the early warning signs of a ransomware infection on your device or network before it causes widespread damage. | ISO, NIST |
| Backups That Actually Save You | 5 min | Explain what makes a backup reliable for ransomware recovery and describe the habits that keep backups safe and usable. | ISO, NIST, SOC2 |
| Phishing and Malicious Attachments: The Human Door | 5 min | Recognise the social engineering tactics attackers use in emails and messages to trick staff into launching ransomware. | ISO, NIST, FTC |
| Ransomware on Mobile and Personal Devices | 5 min | Describe the specific risks that mobile phones and personal devices bring to the workplace and apply safe habits to reduce those risks. | ISO, NIST |
| Paying the Ransom: What You Need to Know | 5 min | Explain why paying a ransom is not a reliable recovery strategy and describe the organisational, legal, and ethical factors involved in that decision. | CBN, FTC, NIST |
| Protecting Sensitive Data Before an Attack Happens | 5 min | Apply data minimisation and access control habits that reduce the amount of sensitive information at risk if ransomware strikes. | NDPA, ISO, SOC2 |
| Building a Ransomware-Resilient Mindset | 5 min | Describe how a security-aware culture reduces ransomware risk and commit to specific daily habits that make the whole organisation harder to attack. | ISO, NIST, SOC2 |
Compliance codes show which frameworks each module supports; they describe what the training content covers, not a guarantee of legal compliance. Confirm specific clause wording with your own compliance advisor before citing it to a regulator or auditor.