01
Target Package
The Human Perimeter: Security Culture and Individual Accountability
How an adversary researches a person before first contact, illustrated through an open-source reconnaissance demonstration. Establishes the five individual responsibilities and the anticipation standard the series builds on.
02
The Approach
Phishing and Social Engineering: Recognition and Response
The setup phase of every social engineering operation: email, spear phishing, smishing, vishing, and QR lures, including AI-written variants that defeat grammar-based instincts. Teaches the STOP check as the standing habit.
03
Watch a Password Fall
Strong Passwords and Passphrases
A recorded cracking demonstration shows why short, predictable passwords are vulnerable and how long, unique passphrases improve resistance to guessing. Length over complexity per current NIST guidance, no arbitrary periodic password changes (with required changes when compromise is suspected or confirmed), and an approved password manager wherever passwords remain necessary.
04
Beating the Second Lock
MFA and MFA Fatigue
How attackers defeat weak second factors: push-bombing, adversary-in-the-middle pages, and stolen session cookies, demonstrated from the attacker's console. Ranks factors from phishable to phishing-resistant.
05
The Voice on the Line
AI Threats and Deepfakes
How little source material a synthetic voice or video needs, and why the defense is a process rather than a better eye. Out-of-band callback to a directory number, a pre-shared challenge phrase, and dual authorization, executed regardless of who appears to be asking.
06
Know Where Data Lives
Handling Data the Right Way
Four-tier classification and the handling rules that follow from it, with a demonstration of what a compromised endpoint can expose: the passwords file, the cookie store, autofill, and a system fingerprint.
07
Hostile Ground
Safe Browsing and Device Security
Untrusted networks and devices treated as an operating environment. Evil twin access points, external exposure, and the device and identity controls that can limit whether a compromised browser becomes a compromised network.
08
Left in Plain Sight
Acceptable Use, Physical Security, and Clean Desk
What systematic observation of a workspace yields, demonstrated through badge cloning and keystroke injection. A dropped drive is a report to file, not a mystery to solve.
09
The Recruitment Pitch
Insider Threat Awareness: Behavioral Indicators and Reporting
Indicators of negligent, compromised, coerced, recruited, malicious, and third-party insider risk. Framed protectively, never as peer monitoring.
10
Observe and Report
Incident Recognition and Reporting Without Fear
What qualifies as reportable, the quantified cost of delay, and the no-blame standard. Includes the ransomware economy of brokers, affiliates, and leak sites.
11
Standing Posture
Security Commitment: Recap, Assessment, and Attestation
Program recap, final knowledge assessment, and the signed acknowledgment that generates the completion certificate.