# Cybersecurity: the fundamentals for protecting your work

URL : https://skillrung.com/en/courses/cybersecurity/cybersecurity-essentials
Topic: Cybersecurity · Duration: 60-85 min · Updated on 2026-09-11

## In brief

Cybersecurity at work comes down to five habits. Check the real sender and the real link before you click. Use a different passphrase for each service, stored in a password manager. Switch on a second factor for your email and your banking access. Install updates without delay and keep one backup unplugged. Finally, if in doubt or after an incident, isolate the device, do not switch it off and raise the alert immediately, never handling the situation alone.

## Programme

- 1. Why cybersecurity concerns you directly : Assess your real exposure and learn the three checks to run before you click
- 2. What you really have to protect : Name your sensitive data and understand who targets it and why
- 3. Spotting a malicious message : Identify the signs of a fraudulent message and verify through another channel
- 4. Passwords and strong authentication : Build resistant passwords and switch on a second factor that actually helps
- 5. Devices, updates and backups : Keep your devices up to date and have a backup you can actually restore
- 6. Responding to an incident : Apply the five emergency reflexes and alert the right people in time
- 7. Your action plan : Turn the course into five dated actions and measure your level

5 content sections, each with its quiz. Three level quizzes: Beginner, Intermediate, Expert.

## Free preview (first 4 slides)

### 1. The first threat arrives by message, not through a security hole

A message imitating your bank or a supplier lands in your inbox. In 2025, phishing was the leading threat reported to Cybermalveillance.gouv.fr, the French government's cyber-assistance service, across every type of victim, up 70%. This is not primarily an IT problem: it is a decision taken in a few seconds, between two tasks, in the everyday routine of your structure. Behind that click: your données personnelles, and that is exactly what this course teaches you to protect.
  - In 2025, phishing was the leading threat reported to Cybermalveillance.gouv.fr, across all audiences, up 70%. (Cybermalveillance.gouv.fr, 2026-03-26, https://www.cybermalveillance.gouv.fr/tous-nos-contenus/actualites/rapport-activite-2025)

### 2. What you will be able to do at the end

- Spot a trap message in under thirty seconds
- Protect your accounts with a passphrase and a second factor
- React and raise the alert after an incident at your structure

### 3. The three checks before you click

Run them on any message that asks you to act, whether it seems to come from your collègues et partenaires or from your logiciel métier.
- The sender's real address, never the name displayed on screen
- The link's real address, revealed by hovering or a long press
- The nature of the request: urgency, money, credentials or an unexpected attachment
- At the slightest doubt, check through another channel you already know

### 4. Where do you stand?

Three questions to place your level: email, passwords and backups at your structure, not theoretical knowledge.
_Self-assessment of 3 questions in the player._

## Access

The first four slides of every course and the Beginner-level quiz are free, with no account. From the fifth slide onwards a subscription is required: €29.99/month incl. VAT, no commitment, cancellable online. skillrung is not a French training body certified under the Qualiopi scheme; its content is not eligible for the French CPF, OPCO or DPC schemes.

## Frequently asked questions

### Do I need technical knowledge to take this course?

No. Everything is explained through everyday actions: reading a message, choosing a password, plugging in a USB stick, calling the right person. No command line, no setting reserved for an IT department. The examples adapt to the job you indicate.

### My organisation is very small: am I really a target?

Yes. The vast majority of attacks target no one in particular: they cast a wide net and exploit whatever opens. A small organisation is often even more exposed, for lack of an IT department and a verified backup. The habits taught here cost nothing and close most of the doors.

### Is a password manager really safer than a notebook?

Yes, for a simple reason: it lets you have a different, long password on every service without having to remember it. The risk with a notebook is not that someone reads it; it is that it pushes you to reuse the same password everywhere, which turns a single leak into a general compromise.

### What should I do if I have already clicked on a suspicious link?

Do not keep the information to yourself. If you entered a password, change it immediately on the service concerned and everywhere it was reused, then switch on a second factor. Then tell your manager or your IT provider, even if nothing seems to have happened.

### Should I pay a ransom to get my files back?

The French authorities recommend not paying. Nothing guarantees that the files will be returned, or that stolen data will not be published, and the payment directly funds further attacks. The right answer is prepared beforehand: a recent, disconnected and tested backup.

### How long does it take to apply what is taught?

The course takes about an hour and a quarter. The final action plan holds five actions, three of which can be done the same day: switching on a second factor on your email, installing pending updates and checking that a recent backup exists and can be restored.

## Sources

- Rapport d'activité et état de la menace 2025 : Cybermalveillance.gouv.fr, 2026-03-26, https://www.cybermalveillance.gouv.fr/tous-nos-contenus/actualites/rapport-activite-2025
- Panorama de la cybermenace 2025 : ANSSI, 2026-03-11, https://cyber.gouv.fr/nous-connaitre/publications/panoramas-de-la-cybermenace/panorama-de-la-cybermenace-2025/
- Mots de passe : une nouvelle recommandation pour maîtriser sa sécurité : CNIL, 2022-10-14, https://www.cnil.fr/fr/mots-de-passe-une-nouvelle-recommandation-pour-maitriser-sa-securite
- Notifier une violation de données personnelles : CNIL, 2018-05-24, https://www.cnil.fr/fr/notifier-une-violation-de-donnees-personnelles
- Les 10 mesures essentielles pour assurer votre cybersécurité : Cybermalveillance.gouv.fr, 2026-05-07, https://www.cybermalveillance.gouv.fr/tous-nos-contenus/bonnes-pratiques/10-mesures-essentielles-assurer-securite-numerique
- Pourquoi et comment bien gérer ses sauvegardes ? : Cybermalveillance.gouv.fr, 2025-08-18, https://www.cybermalveillance.gouv.fr/tous-nos-contenus/bonnes-pratiques/sauvegardes
- Pourquoi et comment bien gérer ses mises à jour ? : Cybermalveillance.gouv.fr, 2022-03-22, https://www.cybermalveillance.gouv.fr/tous-nos-contenus/bonnes-pratiques/mises-a-jour
- Rançongiciel : que faire si votre organisation est victime d'une attaque ? : Cybermalveillance.gouv.fr, 2026-05-07, https://www.cybermalveillance.gouv.fr/tous-nos-contenus/fiches-reflexes/rancongiciels-ransomwares
- Règlement (UE) 2016/679 relatif à la protection des personnes physiques : EUR-Lex, 2016-04-27, https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:32016R0679
- Directive (UE) 2022/2555 sur un niveau élevé commun de cybersécurité : EUR-Lex, 2022-12-14, https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:32022L2555
