Online professional certificate
Professional Certificate in Cybersecurity Essentials for Non-Technical Professionals
Build calm, practical cybersecurity judgment for ordinary work — from suspicious messages and account protection to data handling, vendor risk, incident reporting and team cyber hygiene.
- Format
- Online, self-paced
- Study time
- Up to 1 month
- Curriculum
- 20 applied lessons
- Language
- English
Practical capability
Make safer workplace decisions without needing to become a technical specialist.
Fresh employer evidence shows that cybersecurity responsibility extends beyond IT. The course turns that responsibility into practical methods for identity, accounts, data, suppliers, incidents and everyday work.
Recognize phishing and impersonation signals, pause consequential actions and verify through trusted channels.
Use password managers, MFA and passkeys safely and respond correctly to unexpected sign-in activity.
Classify, share, store, retain and dispose of business information with minimum-necessary discipline.
Collect decision-ready supplier facts and review third-party access before renewal or removal.
Preserve useful evidence, separate facts from unknowns and route concise handoffs to authorized responders.
Build repeatable routines for devices, remote work, verification, data care, reporting and improvement.
Who this course is for
Cybersecurity essentials for people who run the business, not the security stack.
Designed for employees and leaders who use workplace accounts, communicate with colleagues and suppliers, handle business information, approve work or guide a team.
The response cycle
Move from an uncertain warning sign to a safe, useful handoff.
Work through the connected fictional Harborlight Services case and practise the sequence from pause and verification to protection, escalation and improvement.
Curriculum
Four modules. Twenty applied lessons.
Recognize and Verify Suspicious Requests
Build calm judgment for suspicious messages, identity checks, high-consequence requests and fast factual reporting across email, text, calls and workplace chat.
01The Human Side of Workplace Cybersecurity
Map the cyber responsibilities, limits and escalation routes that belong to an ordinary business role.
Five practical steps
- Map daily work
- Identify information and systems
- Name common pressure points
- Set role boundaries
- Record escalation routes
Primary deliverable: Personal Cyber Responsibility Map.
02Recognizing Phishing Across Email, Text, Calls and Chat
Assess suspicious requests through a repeatable signal-and-context method without treating one clue as proof.
Five practical steps
- Pause the requested action
- Inspect sender and channel
- Assess language and context
- Separate facts from uncertainty
- Choose the safe next step
Primary deliverable: Suspicious Message Triage Card.
03Verifying Requests Through Trusted Channels
Confirm identity and intent using contact routes that do not come from the request being checked.
Five practical steps
- State what must be verified
- Select an independent channel
- Authenticate the contact
- Record the result
- Escalate unresolved risk
Primary deliverable: Independent Verification Plan.
04Handling Executive, Payment and Vendor Impersonation
Apply additional controls when urgency, authority, money or supplier changes raise the consequence of error.
Five practical steps
- Recognize pressure and authority cues
- Pause the transaction
- Check the approved record
- Route the required approval
- Document the decision
Primary deliverable: High-Consequence Request Check.
05Reporting Suspicious Activity Without Delay
Report concise observations through the approved route while preserving useful evidence and avoiding unauthorized investigation.
Five practical steps
- Record what happened
- Preserve safe evidence
- Name actions already taken
- Identify affected work
- Send the first report
Primary deliverable: First Report Note.
Protect Accounts, Devices and Daily Work
Strengthen password, authentication, device, connection and remote-work habits with practical routines that remain usable under pressure.
06Building Strong Password and Password-Manager Habits
Create a realistic protection plan for unique passwords, approved password managers, recovery and shared-account exceptions.
Five practical steps
- Inventory account types
- Separate password use
- Choose approved storage
- Protect recovery routes
- Plan exception handling
Primary deliverable: Account Protection Plan.
07Using MFA and Passkeys Safely
Understand stronger authentication and configure it through approved devices, recovery routes and ownership rules.
Five practical steps
- Identify account risk
- Choose the supported factor
- Register safely
- Protect recovery
- Test the support route
Primary deliverable: Authentication Setup Checklist.
08Detecting MFA Fatigue and Sign-In Manipulation
Respond safely to unexpected approval prompts, recovery messages and sign-in pressure.
Five practical steps
- Reject unrequested prompts
- Record time and channel
- Use the approved report route
- Follow support guidance
- Review recent activity when authorized
Primary deliverable: Unexpected Sign-In Decision Guide.
09Keeping Devices, Software and Connections Safer
Turn updates, locking, storage, networks and physical care into one sustainable work-device routine.
Five practical steps
- Confirm device ownership
- Keep updates current
- Protect screen and storage
- Use approved connections
- Report loss or abnormal behavior
Primary deliverable: Work Device Hygiene Routine.
10Working Securely in Remote and Shared Environments
Plan safer work in homes, travel, coworking spaces and shared rooms without copying data into uncontrolled places.
Five practical steps
- Assess the environment
- Protect conversations and screens
- Use approved access
- Store and transfer safely
- Close the session cleanly
Primary deliverable: Remote Work Safety Plan.
Handle Business Data with Care
Make proportionate decisions about sensitivity, sharing, storage, retention, collaboration tools and possible exposure while respecting specialist authority.
11Identifying Sensitive Business Information
Recognize how content, purpose, people, scale and combinations affect information sensitivity.
Five practical steps
- Describe the information
- State its purpose
- Identify affected parties
- Check combination and scale
- Apply the local handling rule
Primary deliverable: Data Sensitivity Decision Map.
12Sharing Data with the Right People and Scope
Choose recipients, channels, permissions and duration using minimum-necessary thinking.
Five practical steps
- Confirm the purpose
- Check recipient authority
- Reduce the data
- Set channel and access
- Record the decision
Primary deliverable: Safe Sharing Decision Record.
13Storing, Retaining and Disposing of Information
Connect approved locations, retention triggers, ownership and disposal into a usable lifecycle routine.
Five practical steps
- Name the record
- Choose approved storage
- Assign ownership
- Find the retention trigger
- Use approved disposal
Primary deliverable: Data Lifecycle Checklist.
14Using Collaboration and AI Tools Without Oversharing
Evaluate whether information and a proposed tool are approved for the task before uploading or pasting content.
Five practical steps
- Define the task
- Classify the information
- Check tool approval
- Minimize the input
- Record restrictions and review
Primary deliverable: Approved Tool and Data Use Note.
15Responding to Misdirected, Exposed or Lost Data
Take safe first actions, preserve evidence and report uncertainty without making a legal or technical conclusion.
Five practical steps
- Stop further sharing
- Record observed facts
- Protect evidence
- Use the reporting route
- Request the next decision
Primary deliverable: Data Exposure First-Response Note.
Manage Vendors, Incidents and Team Cyber Hygiene
Collect useful vendor-risk facts, review third-party access, hand incidents to the right owners and lead routines that make secure work easier.
16Screening Vendor Cyber Risk Before Access
Collect purpose, data, access, assurance, ownership, incident and exit information for specialist review.
Five practical steps
- Define business need
- Map data and access
- Collect supplier facts
- Assign review owners
- Record unknowns and triggers
Primary deliverable: Vendor Security Intake Checklist.
17Reviewing and Removing Third-Party Access
Decide whether existing supplier access remains needed, correctly scoped, owned and ready for renewal or removal.
Five practical steps
- Confirm the relationship
- Inventory access
- Compare access with need
- Route the decision
- Verify removal or renewal
Primary deliverable: Vendor Access Review Record.
18Escalating Incidents with Useful Facts
Create a structured handoff that helps authorized responders act without unnecessary data or unsupported conclusions.
Five practical steps
- Build the timeline
- Separate facts and unknowns
- Record actions and evidence
- Name decision owners
- Set the next update
Primary deliverable: Incident Handoff Brief.
19Leading Team Cyber Hygiene and Safe Workflows
Design practical team routines for verification, access, data handling, reporting and review.
Five practical steps
- Select high-frequency behaviors
- Make the safe route easy
- Assign owners
- Set reminders and checks
- Improve from feedback
Primary deliverable: Team Cyber Hygiene Routine.
20Practising and Improving the Response
Run a bounded tabletop exercise and convert observations into owned improvements.
Five practical steps
- Define the scenario
- Observe decisions and handoffs
- Record strengths and gaps
- Prioritize improvements
- Assign owners and review dates
Primary deliverable: Tabletop Debrief and Improvement Plan.
Applied capstone
Prepare a decision-ready cyber incident handoff.
Use the methods that fit the situation and produce one concise brief that an authorized response owner can act on.
The situation
At fictional Harborlight Services, an urgent supplier bank-change request, unexpected authentication prompts and a broadly shared client-workbook link appear close together. The team must protect payment, account and data decisions without guessing at the technical cause.
Your task
Build a timed chronology, distinguish facts from indicators and unknowns, record safe actions and evidence locations, identify the required Finance, Security, Privacy and business decisions, and set the next update.
The people behind MTF
Meet MTF faculty and the learner community.
Explore the professional backgrounds of MTF faculty and learn more about the international community studying with the Institute.
Enrollment
Enroll in Professional Certificate in Cybersecurity Essentials for Non-Technical Professionals
One-time course price: €10, including applicable taxes. Payment is processed securely by Stripe. No card details are stored on the MTF Institute website.
You will receive an email with access to the course. If you have any difficulties, please write to welcome@gtf.pt.
Questions and details
Frequently asked questions
Open the sections that matter to you, including delivery format, AI-supported practice and the evidence used to design the curriculum.
Who is this cybersecurity essentials course for?
This program is designed for non-technical employees, supervisors, managers, executives and small-business owners who use workplace accounts, communications, business information and suppliers. It applies across functions such as operations, finance, HR, administration, client service, sales and procurement.
Do I need technical cybersecurity experience?
No. The course uses vendor-neutral decision guides, checklists, records and handoff briefs. Technical investigation, security administration, legal interpretation and external incident communication remain with the authorized specialists.
Does the course cover both employee and manager responsibilities?
Yes. Employees practise safe first actions, verification, data handling and reporting. Leaders also practise team routines, vendor-access review, decision ownership and clear coordination with security, privacy, finance, legal and IT specialists.
How is AI used in the practical work?
Every lesson combines theory with AI Practice. A focused prompt may organize fictional or authorized inputs into a workplace artifact; a separate critic prompt challenges omissions and weak reasoning; and the learner verifies the result before use. Every task also has a no-AI route.
What evidence supports the curriculum?
The curriculum is grounded in an MTF Institute analysis of 100 current U.S.-scoped vacancies from 92 employers and an independent review of 23 current and stable sources. The evidence is available through two MTF Insights publications and an open Zenodo record.
Will this course make me a technical security specialist?
No. It develops practical cybersecurity judgment inside non-technical roles. It does not qualify a learner to investigate systems, administer security tools, make legal determinations or promise that an incident will be prevented.
What certificate and access will I receive?
After successful enrollment, you receive access to the MTF learning platform. Completing the required lessons, applied capstone and certificate activity provides the MTF Institute course-completion certificate for Professional Certificate in Cybersecurity Essentials for Non-Technical Professionals.