Course track
Ransomware Readiness for Staff
How ransomware really gets in, your role in the first 60 minutes, VPN/remote-desktop hygiene, backups that actually save you, and whether paying the ransom ever makes sense.
Who takes this: All staff, especially those with remote or VPN access
ISONISTSOC2FTCCBNNDPA
| Module | Length | What staff learn | Maps to |
|---|---|---|---|
| How Ransomware Really Gets In | 5 min | Connect everyday habits (passwords, phishing reports, updates) to ransomware prevention. | ISO, NIST |
| Your Role in the First 60 Minutes | 5 min | Disconnect safely and report immediately without trying to fix a suspected ransomware attack. | ISO, SOC2, NIST |
| VPN and Remote Desktop Hygiene for Everyday Staff | 4 min | Use only approved remote access tools with unique credentials. | ISO, NIST |
| Spotting Ransomware Before It Spreads | 5 min | Identify the early warning signs of a ransomware infection on your device or network before it causes widespread damage. | ISO, NIST |
| Backups That Actually Save You | 5 min | Explain what makes a backup reliable for ransomware recovery and describe the habits that keep backups safe and usable. | ISO, NIST, SOC2 |
| Phishing and Malicious Attachments: The Human Door | 5 min | Recognise the social engineering tactics attackers use in emails and messages to trick staff into launching ransomware. | ISO, NIST, FTC |
| Ransomware on Mobile and Personal Devices | 5 min | Describe the specific risks that mobile phones and personal devices bring to the workplace and apply safe habits to reduce those risks. | ISO, NIST |
| Paying the Ransom: What You Need to Know | 5 min | Explain why paying a ransom is not a reliable recovery strategy and describe the organisational, legal, and ethical factors involved in that decision. | CBN, FTC, NIST |
| Protecting Sensitive Data Before an Attack Happens | 5 min | Apply data minimisation and access control habits that reduce the amount of sensitive information at risk if ransomware strikes. | NDPA, ISO, SOC2 |
| Building a Ransomware-Resilient Mindset | 5 min | Describe how a security-aware culture reduces ransomware risk and commit to specific daily habits that make the whole organisation harder to attack. | ISO, NIST, SOC2 |
Compliance codes show which frameworks each module supports. Some clauses are marked "verify" in our source review, meaning we phrase the claim cautiously rather than cite an exact, unconfirmed section number. See the glossary for term definitions.