Cyber Safety: Empowering Employees in Digital Defence
Hands-on cyber-hygiene and awareness training that turns everyday employees into a security-aware first line of defence.
What your team will gain
Most breaches start with a person, not a firewall. This workshop turns everyday employees into a confident first line of defence. Your people learn to recognise phishing and social engineering, handle data safely, use strong authentication, and respond calmly when something looks wrong. The session is hands-on and grounded in real incidents, not slideware.
Built for Singapore organisations
We reference the regulatory context your people actually work in, including PDPA, MAS and CSA guidance where relevant, so the training is specific rather than generic. Content is scoped to your sector and, where useful, to examples from your own business.
How we teach
The workshop is interactive from start to finish. We use real scenarios and a live, simulated phishing exercise so the lessons stick, then debrief as a group so the habits carry back to the desk. Sessions can be run as a half day or a full day, on site or online, and are tailored to your team’s starting point.
Take it further
Awareness is the foundation. If you want to build deeper technical capability — a security-aware workforce plus the specialists who hold the line — we can scope a pathway from this workshop into our technical courses. Book a consultation and we will design the right programme for your organisation.
What you will cover
Module 01 Business and cyber fundamentals
- Core business operations and where cyber risk sits
- IT asset management
- Industry-specific regulations and obligations
- Business resilience planning
- The financial impact of a cyber incident
Module 02 Everyday cyber hygiene
- Corporate cyber hygiene habits
- Password security and strong authentication
- Email cybersecurity and safe handling of attachments and links
- Safe handling of company and personal data
Module 03 How attackers think
- Open-source intelligence (OSINT) and what attackers can find
- An introduction to the tools and techniques attackers use
- The MITRE ATT&CK framework, in plain language
- The CIA triad: confidentiality, integrity and availability
Module 04 Respond and practise
- A simple cyber response playbook for your team
- Real-world simulated phishing exercise
- A guided, hands-on threat scenario
- Where to go for help and how to report
How AirAsia strengthened cyber safety across departments
“CFCI's awareness training was highly engaging and informative. The workshop improved our organisation's cybersecurity posture by building strong foundational knowledge across all our departments. I highly recommend the cyber awareness workshop for its relevant content and excellent delivery.”
“We have worked with CFCI over the last few years to continuously train and update our team's cybersecurity awareness and capabilities. Over the years, we have seen a 70% reduction in phishing incidents due to the increased vigilance brought about through yearly workshops.”
Organisations who trust us to keep them safe
Frequently asked questions
Who is this for?
Any organisation that wants to reduce human-factor risk: phishing, weak passwords, social engineering and unsafe handling of data. It suits whole teams, from frontline staff to management.
Can it be tailored to our organisation?
Yes. We scope the content to your sector and regulatory context, including PDPA, MAS and CSA guidance where relevant, and can build in examples specific to your business.
Is the training delivered on site or online?
Either. We can run the workshop on site at your premises or deliver it online, whichever works best for your team.
What is the minimum group size?
A minimum of 20 participants is required for a dedicated session.
Is any funding available?
For Malaysian companies, this cyber awareness training is HRDF claimable. For Singapore organisations, we can discuss the available enterprise training support during a consultation.
What do participants get out of it?
Practical habits they use the same day: spotting phishing and social-engineering attempts, handling data safely, using strong authentication, and knowing how to report and respond when something looks wrong.
Ready to secure your workforce?
Book a 30-minute consultation to scope the right training for your team and your regulatory context.