Cybersecurity Crash Course
Cybersecurity Crash Course
Cybersecurity Crash Course
CRASH COURSE
Lesson 1: Cybersecurity Basics
Patch Management
Patching is a very important security control. Start by listing the apps, operating
systems and browsers that you use:
Framework Structure:
Lesson 3: Physical Security
Physical Security
Here are some physical security issues you should take into consideration:
Security Training
Train your employees on physical security issues including:
● Document shredding
● Erasing data correctly
● Promote security in ALL locations
● Know the response plan
Lesson 4: Ransomware
The Start
Here are some of the common ways that attackers are able to deploy
ransomware on your network:
Awareness Training
Training your employees on the risk of cybersecurity threats like ransomware can
drastically improve the security of your organization. We have partnered with
Wizer training to provide completely free security awareness training to your
employees.
training.cyberx.tech
Lesson 5: Phishing
● Email authentication
● Keep security and operating systems up to date
● Policies and procedures around risky activities - money transfers,
changing payment methods, etc
Lesson 7: Tech Support Scams
https://www.vendorsecurityalliance.org/
Lesson 8: Vendor Security
https://www.vendorsecurityalliance.org/
Lesson 9: Cyber Insurance
Forensic services
Payments to consumers
Accounting Costs
Lesson 10: Email Authentication
Mechanisms
Mechanisms are used to describe which hosts are designated outbound mailers
for the domain and can have four qualifiers:
+ Pass
- Fail
~ Softfail
? Neutral
Examples:
“v=spf1 =all”
“v=spf1 a -all”
“v=spf1 a mx -all”
all
This mechanism always matches. It should always be at the end of the SPF
record.
Lesson 10: Email Authentication
ip4:0.0.0.0
ip4:0.0.0.0/24
mx
mx/<prefix-length>
mx:<domain>
mx:<domain>/<prefix-length>
include:<domain>
Lesson 11: Web Security
Use SSL/TLS
Regularly update
Is MFA available
Lesson 12: Secure Remote Access
There is a paid option that includes special items like phishing tests
and gamification, but you can start improving your employees
awareness for free in just 90 seconds.
www.training.cyberx.tech