Course track
Passwords, MFA and Account Takeover
Passkeys, OAuth/consent phishing, infostealers and session-cookie theft, SIM swap, and what to do the moment an account takeover happens.
Who takes this: All staff; also useful as a stand-alone refresher course
ISONISTCBNNDPASOC2FTC
| Module | Length | What staff learn | Maps to |
|---|---|---|---|
| Passkeys and Phishing-Resistant Login | 5 min | Set up and use a passkey wherever a company tool supports one. | ISO, NIST |
| "Allow Access?" - OAuth and Consent Phishing | 5 min | Pause and verify before approving any app permission request. | ISO, NIST |
| Infostealers and Session-Cookie Theft | 5 min | Install only approved software and report unusual device behavior immediately. | ISO, NIST |
| SIM Swap and Account-Recovery Hijacking | 5 min | Recognize a SIM swap in progress and reduce reliance on phone-based recovery. | CBN, NDPA |
| Why Weak Passwords Still Win (and How to Stop Them) | 5 min | Explain why simple and reused passwords are dangerous and create strong, unique passwords for every account. | ISO, NIST, SOC2 |
| Password Managers: Your Digital Keychain | 5 min | Set up and use a password manager to store and generate strong, unique passwords safely. | ISO, NIST, SOC2 |
| Multi-Factor Authentication: Your Second Lock on the Door | 5 min | Explain what MFA is, why it matters, and enable it correctly on work and personal accounts. | ISO, NIST, SOC2 |
| Spotting Phishing That Targets Your Login | 5 min | Identify common phishing tactics designed to steal credentials and respond without giving away your password. | ISO, NIST, FTC |
| MFA Fatigue and Prompt Bombing Attacks | 5 min | Recognise an MFA fatigue attack and respond correctly without accidentally approving unauthorised access. | ISO, NIST, SOC2 |
| Responding to an Account Takeover: What to Do When It Happens | 5 min | Follow the correct steps to contain and recover from an account takeover quickly and without making things worse. | NDPA, ISO, SOC2 |
Compliance codes show which frameworks each module supports. Some clauses are marked "verify" in our source review, meaning we phrase the claim cautiously rather than cite an exact, unconfirmed section number. See the glossary for term definitions.