Online professional certificate

Professional Certificate in Cybersecurity Essentials for Non-Technical Professionals

Build calm, practical cybersecurity judgment for ordinary work — from suspicious messages and account protection to data handling, vendor risk, incident reporting and team cyber hygiene.

Format
Online, self-paced
Study time
Up to 1 month
Curriculum
20 applied lessons
Language
English

Practical capability

Make safer workplace decisions without needing to become a technical specialist.

Fresh employer evidence shows that cybersecurity responsibility extends beyond IT. The course turns that responsibility into practical methods for identity, accounts, data, suppliers, incidents and everyday work.

01Suspicious-request judgment

Recognize phishing and impersonation signals, pause consequential actions and verify through trusted channels.

02Account protection

Use password managers, MFA and passkeys safely and respond correctly to unexpected sign-in activity.

03Data handling

Classify, share, store, retain and dispose of business information with minimum-necessary discipline.

04Vendor risk

Collect decision-ready supplier facts and review third-party access before renewal or removal.

05Incident reporting

Preserve useful evidence, separate facts from unknowns and route concise handoffs to authorized responders.

06Team cyber hygiene

Build repeatable routines for devices, remote work, verification, data care, reporting and improvement.

Who this course is for

Cybersecurity essentials for people who run the business, not the security stack.

Designed for employees and leaders who use workplace accounts, communicate with colleagues and suppliers, handle business information, approve work or guide a team.

EPEmployees across business functions
MLManagers and team leaders
BOBusiness owners and executives
OPOperations, finance, HR and procurement professionals
CSClient service, sales and marketing professionals

The response cycle

Move from an uncertain warning sign to a safe, useful handoff.

Work through the connected fictional Harborlight Services case and practise the sequence from pause and verification to protection, escalation and improvement.

Step 1Pause the risky action
Step 2Observe facts
Step 3Verify independently
Step 4Protect accounts and data
Step 5Report through the approved route
Step 6Route owner decisions
Step 7Review and improve

Curriculum

Four modules. Twenty applied lessons.

Module 1

Recognize and Verify Suspicious Requests

Build calm judgment for suspicious messages, identity checks, high-consequence requests and fast factual reporting across email, text, calls and workplace chat.

01The Human Side of Workplace Cybersecurity

Map the cyber responsibilities, limits and escalation routes that belong to an ordinary business role.

Five practical steps

  1. Map daily work
  2. Identify information and systems
  3. Name common pressure points
  4. Set role boundaries
  5. Record escalation routes

Primary deliverable: Personal Cyber Responsibility Map.

02Recognizing Phishing Across Email, Text, Calls and Chat

Assess suspicious requests through a repeatable signal-and-context method without treating one clue as proof.

Five practical steps

  1. Pause the requested action
  2. Inspect sender and channel
  3. Assess language and context
  4. Separate facts from uncertainty
  5. Choose the safe next step

Primary deliverable: Suspicious Message Triage Card.

03Verifying Requests Through Trusted Channels

Confirm identity and intent using contact routes that do not come from the request being checked.

Five practical steps

  1. State what must be verified
  2. Select an independent channel
  3. Authenticate the contact
  4. Record the result
  5. Escalate unresolved risk

Primary deliverable: Independent Verification Plan.

04Handling Executive, Payment and Vendor Impersonation

Apply additional controls when urgency, authority, money or supplier changes raise the consequence of error.

Five practical steps

  1. Recognize pressure and authority cues
  2. Pause the transaction
  3. Check the approved record
  4. Route the required approval
  5. Document the decision

Primary deliverable: High-Consequence Request Check.

05Reporting Suspicious Activity Without Delay

Report concise observations through the approved route while preserving useful evidence and avoiding unauthorized investigation.

Five practical steps

  1. Record what happened
  2. Preserve safe evidence
  3. Name actions already taken
  4. Identify affected work
  5. Send the first report

Primary deliverable: First Report Note.

Module 2

Protect Accounts, Devices and Daily Work

Strengthen password, authentication, device, connection and remote-work habits with practical routines that remain usable under pressure.

06Building Strong Password and Password-Manager Habits

Create a realistic protection plan for unique passwords, approved password managers, recovery and shared-account exceptions.

Five practical steps

  1. Inventory account types
  2. Separate password use
  3. Choose approved storage
  4. Protect recovery routes
  5. Plan exception handling

Primary deliverable: Account Protection Plan.

07Using MFA and Passkeys Safely

Understand stronger authentication and configure it through approved devices, recovery routes and ownership rules.

Five practical steps

  1. Identify account risk
  2. Choose the supported factor
  3. Register safely
  4. Protect recovery
  5. Test the support route

Primary deliverable: Authentication Setup Checklist.

08Detecting MFA Fatigue and Sign-In Manipulation

Respond safely to unexpected approval prompts, recovery messages and sign-in pressure.

Five practical steps

  1. Reject unrequested prompts
  2. Record time and channel
  3. Use the approved report route
  4. Follow support guidance
  5. Review recent activity when authorized

Primary deliverable: Unexpected Sign-In Decision Guide.

09Keeping Devices, Software and Connections Safer

Turn updates, locking, storage, networks and physical care into one sustainable work-device routine.

Five practical steps

  1. Confirm device ownership
  2. Keep updates current
  3. Protect screen and storage
  4. Use approved connections
  5. Report loss or abnormal behavior

Primary deliverable: Work Device Hygiene Routine.

10Working Securely in Remote and Shared Environments

Plan safer work in homes, travel, coworking spaces and shared rooms without copying data into uncontrolled places.

Five practical steps

  1. Assess the environment
  2. Protect conversations and screens
  3. Use approved access
  4. Store and transfer safely
  5. Close the session cleanly

Primary deliverable: Remote Work Safety Plan.

Module 3

Handle Business Data with Care

Make proportionate decisions about sensitivity, sharing, storage, retention, collaboration tools and possible exposure while respecting specialist authority.

11Identifying Sensitive Business Information

Recognize how content, purpose, people, scale and combinations affect information sensitivity.

Five practical steps

  1. Describe the information
  2. State its purpose
  3. Identify affected parties
  4. Check combination and scale
  5. Apply the local handling rule

Primary deliverable: Data Sensitivity Decision Map.

12Sharing Data with the Right People and Scope

Choose recipients, channels, permissions and duration using minimum-necessary thinking.

Five practical steps

  1. Confirm the purpose
  2. Check recipient authority
  3. Reduce the data
  4. Set channel and access
  5. Record the decision

Primary deliverable: Safe Sharing Decision Record.

13Storing, Retaining and Disposing of Information

Connect approved locations, retention triggers, ownership and disposal into a usable lifecycle routine.

Five practical steps

  1. Name the record
  2. Choose approved storage
  3. Assign ownership
  4. Find the retention trigger
  5. Use approved disposal

Primary deliverable: Data Lifecycle Checklist.

14Using Collaboration and AI Tools Without Oversharing

Evaluate whether information and a proposed tool are approved for the task before uploading or pasting content.

Five practical steps

  1. Define the task
  2. Classify the information
  3. Check tool approval
  4. Minimize the input
  5. Record restrictions and review

Primary deliverable: Approved Tool and Data Use Note.

15Responding to Misdirected, Exposed or Lost Data

Take safe first actions, preserve evidence and report uncertainty without making a legal or technical conclusion.

Five practical steps

  1. Stop further sharing
  2. Record observed facts
  3. Protect evidence
  4. Use the reporting route
  5. Request the next decision

Primary deliverable: Data Exposure First-Response Note.

Module 4

Manage Vendors, Incidents and Team Cyber Hygiene

Collect useful vendor-risk facts, review third-party access, hand incidents to the right owners and lead routines that make secure work easier.

16Screening Vendor Cyber Risk Before Access

Collect purpose, data, access, assurance, ownership, incident and exit information for specialist review.

Five practical steps

  1. Define business need
  2. Map data and access
  3. Collect supplier facts
  4. Assign review owners
  5. Record unknowns and triggers

Primary deliverable: Vendor Security Intake Checklist.

17Reviewing and Removing Third-Party Access

Decide whether existing supplier access remains needed, correctly scoped, owned and ready for renewal or removal.

Five practical steps

  1. Confirm the relationship
  2. Inventory access
  3. Compare access with need
  4. Route the decision
  5. Verify removal or renewal

Primary deliverable: Vendor Access Review Record.

18Escalating Incidents with Useful Facts

Create a structured handoff that helps authorized responders act without unnecessary data or unsupported conclusions.

Five practical steps

  1. Build the timeline
  2. Separate facts and unknowns
  3. Record actions and evidence
  4. Name decision owners
  5. Set the next update

Primary deliverable: Incident Handoff Brief.

19Leading Team Cyber Hygiene and Safe Workflows

Design practical team routines for verification, access, data handling, reporting and review.

Five practical steps

  1. Select high-frequency behaviors
  2. Make the safe route easy
  3. Assign owners
  4. Set reminders and checks
  5. Improve from feedback

Primary deliverable: Team Cyber Hygiene Routine.

20Practising and Improving the Response

Run a bounded tabletop exercise and convert observations into owned improvements.

Five practical steps

  1. Define the scenario
  2. Observe decisions and handoffs
  3. Record strengths and gaps
  4. Prioritize improvements
  5. Assign owners and review dates

Primary deliverable: Tabletop Debrief and Improvement Plan.

Applied capstone

Prepare a decision-ready cyber incident handoff.

Use the methods that fit the situation and produce one concise brief that an authorized response owner can act on.

The situation

At fictional Harborlight Services, an urgent supplier bank-change request, unexpected authentication prompts and a broadly shared client-workbook link appear close together. The team must protect payment, account and data decisions without guessing at the technical cause.

Your task

Build a timed chronology, distinguish facts from indicators and unknowns, record safe actions and evidence locations, identify the required Finance, Security, Privacy and business decisions, and set the next update.

Cyber Incident Decision and Handoff BriefOne principal deliverable connecting message triage, independent verification, authentication response, data protection, vendor workflow, incident reporting and leadership coordination.

The people behind MTF

Meet MTF faculty and the learner community.

Explore the professional backgrounds of MTF faculty and learn more about the international community studying with the Institute.

Enrollment

Enroll in Professional Certificate in Cybersecurity Essentials for Non-Technical Professionals

One-time course price: €10, including applicable taxes. Payment is processed securely by Stripe. No card details are stored on the MTF Institute website.

You will receive an email with access to the course. If you have any difficulties, please write to welcome@gtf.pt.

Secure payment on this page

Enter your enrollment email to continue in Stripe's encrypted form.

Cards, Apple Pay, Google Pay and other eligible methods

Questions and details

Frequently asked questions

Open the sections that matter to you, including delivery format, AI-supported practice and the evidence used to design the curriculum.

Who is this cybersecurity essentials course for?

This program is designed for non-technical employees, supervisors, managers, executives and small-business owners who use workplace accounts, communications, business information and suppliers. It applies across functions such as operations, finance, HR, administration, client service, sales and procurement.

Do I need technical cybersecurity experience?

No. The course uses vendor-neutral decision guides, checklists, records and handoff briefs. Technical investigation, security administration, legal interpretation and external incident communication remain with the authorized specialists.

Does the course cover both employee and manager responsibilities?

Yes. Employees practise safe first actions, verification, data handling and reporting. Leaders also practise team routines, vendor-access review, decision ownership and clear coordination with security, privacy, finance, legal and IT specialists.

How is AI used in the practical work?

Every lesson combines theory with AI Practice. A focused prompt may organize fictional or authorized inputs into a workplace artifact; a separate critic prompt challenges omissions and weak reasoning; and the learner verifies the result before use. Every task also has a no-AI route.

What evidence supports the curriculum?

The curriculum is grounded in an MTF Institute analysis of 100 current U.S.-scoped vacancies from 92 employers and an independent review of 23 current and stable sources. The evidence is available through two MTF Insights publications and an open Zenodo record.

Will this course make me a technical security specialist?

No. It develops practical cybersecurity judgment inside non-technical roles. It does not qualify a learner to investigate systems, administer security tools, make legal determinations or promise that an incident will be prevented.

What certificate and access will I receive?

After successful enrollment, you receive access to the MTF learning platform. Completing the required lessons, applied capstone and certificate activity provides the MTF Institute course-completion certificate for Professional Certificate in Cybersecurity Essentials for Non-Technical Professionals.