Cybersecurity Awareness for Users – Recognizing and Countering Social Engineering Attacks CS-8530 Training Plan: Detailed Modules
Module 1: Understanding Targeted Social Engineering Attacks
- The user’s role in the security chain
- Why cybercriminals target employees
- The psychological principles used by attackers
- Urgency, authority, fear, curiosity, and trust
- Information gathering before an attack
- The different stages of a social engineering attack
Module 2: Modern Forms of Phishing
- Targeted phishing
- Impersonating an executive or colleague
- Compromising work email
- Impersonating a supplier or partner
- Fraudulent requests for payment or bank account changes
- Fake IT department requests
- Fake cloud login pages
Module 3: Multichannel Attacks
- Email, phone, and text message attacks
- QR code phishing
- Text message phishing
- Voice phishing and calls
- Fraudulent Identity spoofing in Microsoft Teams and collaboration platforms
- Multi-factor authentication (MFA) fatigue
- The use of voice, video, and artificial intelligence to deceive users
Module 4: Recognizing the signs of a sophisticated attack
- An unusual or unexpected request
- A sense of urgency or pressure
- An unusual request for confidentiality
- A request for a password, MFA code, or sensitive information
- A change in procedure or bank details
- A sudden change in the means of communication
- A slightly different address, link, or domain
- A request that prevents or discourages independent verification
Module 5: Verifying a request securely
- The “Stop – Verify – Report” method
- Do not click, reply, pay, or approve immediately
- Verify a request through an independent and trusted channel
- Do not use contact information provided in the suspicious message
- Confirm financial or confidential requests according to an established procedure
- Verify the identity of a colleague, a Manager, supplier, or technician
- Report an attempted attack, even if no information has been disclosed
Module 6: Scenario Application and Analysis
- Analysis of a targeted phishing email
- Analysis of a fake request from a manager
- Analysis of an urgent request from a supplier
- Analysis of an MFA approval request from a fake technician
- Identifying the manipulation techniques used
- Choosing the safest response
- Exercises in verifying and reporting suspicious requests
Recommended prerequisite knowledge
To ensure your success in this course, participants must have completed the Cybersecurity Awareness for Users (CS8525) (Part 1) course.
In addition, the following are recommended:
- Basic computer skills: A basic understanding of computer operation, internet browsing, email, and collaboration tools (such as Microsoft Teams).
- Familiarity with organizational policies: A basic understanding of internal IT policies, data security, and incident reporting procedures.
- Willingness to learn: A critical mindset and a willingness to exercise caution when faced with unusual or urgent requests.
- No advanced technical security expertise is required, as this course is designed to guide users of all skill levels in recognizing and countering social engineering attacks.
Eccentrix Corner Articles: Cybersecurity Awareness Resources for CS8530 Users
Explore our technical articles on cybersecurity awareness and social engineering attack prevention (CS8530) published on Eccentrix Corner. These resources delve deeper into key concepts, share best practices for recognizing targeted phishing, and provide practical guides to maximize your learning. Our experts share real-world insights to help you master the “Stop-Verify-Report” method and thwart manipulation attempts on a daily basis.
Cybersecurity and Social Engineering Training
The Cybersecurity Awareness for Users – Recognizing and Countering Social Engineering Attacks (CS8530) course is designed to enhance employees’ skills in recognizing, preventing, and neutralizing the most sophisticated forms of digital manipulation. In a context of increasing targeted and multi-channel cyberattacks, this course enables participants to analyze modern deception methods and adopt systematic verification practices in their daily work.
Suitable for participants who have completed Level 1, this interactive course focuses on detecting targeted phishing, identity theft, and applying the “Stop-Verify-Report” methodology to effectively protect sensitive organizational information.
Why choose the Cybersecurity Awareness for Users – Recognizing and Countering Social Engineering Attacks (CS8530) training ?
Most cyberattacks now exploit psychological manipulation and human error. Therefore, a thorough awareness of social engineering attacks is crucial for strengthening any organization’s overall security posture. This training provides employees with the practical skills and reflexes needed to identify warning signs, thwart identity theft, and independently validate suspicious requests.
By preparing your teams to face multichannel threats (targeted phishing emails, fraudulent calls, text messages, and MFA fatigue), you actively reduce the risk of compromise and help protect your organization against major data breaches.
Main objectives of the CS8530 training
Identify targeted social engineering attacks
Understand the psychological mechanisms (urgency, authority, fear, curiosity) and the steps used by cybercriminals to manipulate employees.Thwart modern, multi-channel phishing
Learn to recognize sophisticated traps spread via email (BEC), phone (vishing), text message (smishing), QR codes, fake IT technicians, and collaboration platforms like Microsoft Teams.Detect warning signs of sophisticated attacks
Quickly identify anomalies such as changes to bank details, MFA prompt fatigue, or slight alterations to domains and addresses.Apply the “Stop – Verify – Report” method
Master independent verification procedures through trusted channels before clicking, responding, or confirming a confidential or financial transaction.Analyze real-life scenarios and react safely
Develop your reflexes through practical case studies (executive impersonation, fake supplier emergency) and learn how to effectively report any suspicious activity.
An interactive and engaging training program
This training is delivered live in a virtual classroom by cybersecurity experts who use real-world scenarios and concrete case studies. Through guided analysis of fake executive emails, fraudulent MFA approval requests, and multi-channel scams, the interactive modules and practical exercises promote grounded learning and the lasting retention of security best practices.
Who is this training for?
- Employees at all levels who want to strengthen their ability to identify sophisticated traps and manipulation attempts
- Operational and administrative teams (human resources, finance, procurement) exposed to targeted requests for wire transfers or changes to bank details
- Managers, supervisors, and executives targeted by identity theft or wishing to instill a culture of caution within their teams
- Anyone who has completed Level 1 (CS8525) and is looking to master the “Stop – Check – Report” method for responding to multi-channel attacks (email, phone, text, Teams, MFA)
Protect your business with increased awareness of social engineering attacks
The Cybersecurity Awareness for Users – Recognizing and Countering Social Engineering Attacks (CS8530) course strengthens your organization’s first line of defense: its employees. Register today to embed the “Stop – Check – Report” methodology, build a culture of proactive vigilance, and sustainably reduce the risks of impersonation and targeted cyberattacks.
Frequently Asked Questions - CS8530 Cybersecurity Awareness Training (FAQ)
What topics are covered in the training?
The training covers understanding targeted social engineering attacks, modern forms of phishing (identity theft, email compromise), multi-channel attacks (email, phone, text, QR codes, Microsoft Teams, MFA fatigue), detecting warning signs, the “Stop – Check – Report” method, and analyzing practical scenarios.
Is this training intended for non-technical users?
Yes, this course is specifically designed for users of all levels. No prior technical skills are required, provided you have completed the first level of awareness training (CS8525).
How does this training help prevent cyberattacks?
It develops employees’ vigilance and reflexes in the face of psychological manipulation (urgency, authority, fear). By teaching them to systematically verify suspicious requests through independent channels, it significantly reduces the risk of human error and identity theft.
What tools or resources are provided during the training?
Participants receive learning materials in the form of downloadable PDF files in French. At the end of the training, delivered in an interactive virtual classroom on Microsoft Teams, a badge of achievement and a digital certificate are also awarded.



