Core Training Modules
Reduction in Credential Attacks with MFA
Compliance Frameworks Mapped
On-Demand Access
Core Cybersecurity Awareness Curriculum
Each module is self-paced, takes under 15 minutes, and includes a knowledge check. Complete all ten to earn the STM Cybersecurity Essentials Certificate.
MODULE 01 · FOUNDATIONAL
Phishing & Business Email Compromise
Learn to identify phishing emails, SMS smishing, and AI-generated voice scams. Covers the latest BEC tactics targeting finance and executive teams.
MODULE 02 · FOUNDATIONAL
Password Hygiene & MFA
Strong password creation, password manager adoption, and multi-factor authentication enrollment. Understand why MFA blocks over 90% of credential-based attacks.
MODULE 03 · FOUNDATIONAL
Social Engineering Defense
Recognize vishing, smishing, tailgating, and pretexting using OSINT data. Includes real-world scenarios of AI-generated voice cloning and deepfake video impersonation.
MODULE 04 · COMPLIANCE
Data Handling & Classification
Identify data categories — PII, PHI, PCI, CUI — and apply secure storage, sharing, encryption, and disposal practices. Covers shadow-IT risks and data exfiltration prevention.
MODULE 05 · CRITICAL
Incident Reporting & Response
Know exactly when and how to report suspicious activity. Learn reporting channels, escalation timelines, and why prompt reporting is the fastest path to containment.
MODULE 06 · FOUNDATIONAL
Acceptable Use & Secure Browsing
Policies for internet, cloud services, SaaS apps, personal devices, and generative-AI tool usage. Understand the risks of unsanctioned tools and data leakage through AI platforms.
MODULE 07 · OPERATIONAL
Physical Security & Clean Desk
Tailgating prevention, device locking, screen privacy filters, and secure disposal of printed materials. A required control for ISO 27001 and NIST SP 800-50 compliance.
MODULE 08 · OPERATIONAL
Mobile & Remote Work Security
Secure Wi-Fi practices, VPN usage, BYOD policies, device encryption, and home-network hygiene. Built for the 30%+ of your workforce that operates remotely.
MODULE 09 · EMERGING
AI-Era Threat Awareness
AI-generated spear-phishing, deepfake video impersonation, AI-voice cloning for vishing, and OSINT-driven pretexting. Learn how AI is lowering the cost and raising the quality of attacks.
MODULE 10 · ROLE-BASED
Role-Based Security Practices
Tailored content for executives, finance, IT, and HR teams. Meets ISO 27001 Clause 7.2, CMMC AT.L2-3.2.1, and HIPAA role-specific awareness requirements.
Your Training Journey, Step by Step
Follow this structured path to build cybersecurity competency from the ground up. Each phase builds on the last.
Onboarding Baseline
Complete Modules 1–3 within your first 30 days. Establish baseline knowledge of phishing, passwords, and social engineering before you encounter real threats in the wild.
Days 1–30 · ~36 min total
Core Compliance
Complete Modules 4–6 to cover data handling, incident reporting, and acceptable use. This phase satisfies annual compliance refresher requirements for most frameworks.
Days 31–60 · ~34 min total
Operational Security
Complete Modules 7–8 to address physical security, clean-desk practices, and remote-work hygiene. Essential for teams with field, hybrid, or remote personnel.
Days 61–90 · ~20 min total
Advanced & Role-Based
Complete Modules 9–10 to understand AI-era threats and role-specific security practices. Earn your STM Cybersecurity Essentials Certificate upon completion.
Ongoing · ~29 min total
Downloadable Guides & Quick References
Supplement your training with these printable one-pagers, checklists, and policy templates. Free for all registered visitors.
Phishing Identification Checklist
A one-page reference for spotting phishing emails, SMS messages, and voice scams. Print and post at every workstation.
PDF · 1 page
Password Best Practices Guide
Step-by-step instructions for creating strong passwords, setting up a password manager, and enrolling in MFA.
PDF · 2 pages
Incident Response Quick Card
Who to call, what to document, and what not to do in the first 15 minutes of a suspected security incident.
PDF · 1 page
Remote Work Security Checklist
Secure your home network, configure VPN, encrypt devices, and follow BYOD best practices.
PDF · 2 pages
Data Classification Policy Template
A starter template for classifying data as PII, PHI, PCI, or CUI — with handling, storage, and disposal rules.
Word · Template
AI Tool Usage Guidelines
Policy language for governing employee use of generative-AI tools — what data can and cannot be entered.
PDF · 3 pages
How Our Training Maps to Your Frameworks
Every module is mapped to the regulatory and industry frameworks your organization must satisfy. Use this table for audit-ready evidence of your awareness training program.
Ready to Build a Security-First Culture?
Register your team for the full STM Cybersecurity Essentials Training program. Get progress tracking, completion certificates, and audit-ready reporting.