Your first days: security reflexes

Essentials plan

Six short modules for new joiners, to take in your first week: spot a phishing email, deny an MFA prompt you didn't trigger, protect your accounts with a password manager and MFA, recognise personal data, report an incident early and without shame, and know where the security rules are, how you contribute and what happens if they aren't followed.

  • 10 min
  • 6 modules
  • 21-question check
  • English · Français
  • Attestation

You will be able to

  • Recognise the warning signs of a phishing email
  • Recognise an MFA fatigue attack
  • Explain credential stuffing and why one reused password opens every account
  • Recognise personal data, direct or indirect
  • Recognise the first signs of ransomware
  • Know where to find your company's security policy and name one or two rules that apply to your job

Programme

6 modules · 10 min
  1. Phishing: 3 seconds not to click 1 min
    • Recognise the warning signs of a phishing email
    • Apply the 3-second reflex: stop, check, report
    • Know what to do if you have already clicked
  2. MFA fatigue: the attack that counts on you being tired 1 min
    • Recognise an MFA fatigue attack
    • Understand why number matching blocks it
    • Apply the right reflex: deny, report, change the password
  3. One password, every door 2 min
    • Explain credential stuffing and why one reused password opens every account
    • Use one unique password per site with a password manager
    • Prefer passkeys or multi-factor authentication
    • React to a leak: change the password everywhere and tell IT
  4. Personal data, or not? 2 min
    • Recognise personal data, direct or indirect
    • Recognise sensitive data (GDPR Article 9)
    • When in doubt, treat it as personal data and ask the DPO
  5. Report it at 9:02 2 min
    • Recognise the first signs of ransomware
    • Apply the first reflexes: disconnect from the network, don't switch off, call IT, don't pay
    • Report early, even a doubt, without shame
  6. ISO 27001: the auditor's three questions 2 min
    • Know where to find your company's security policy and name one or two rules that apply to your job
    • Describe your own contribution to security through concrete actions
    • Know the consequences of not following it, for the company and for yourself
  7. Knowledge check

    21 questions, pass mark 80 %. Explanations after each answer; you can try again.

  8. Attestation

    One per person, with the date, the score and the frameworks covered — anyone can check it online with its code.

Version 1 · updated October 5, 2026