
Cyber Security Awareness

ΠΕΡΙΓΡΑΦΗ
In today’s fast evolving digital landscape, cybersecurity has become a critical pillar for safeguarding organizations’ data, information, assets and reputation. This training program is designed to empower organizations by elevating security awareness across all employee levels, including upper management, and equipping them with practical, hands-on experiences to ensure a holistic grasp of cybersecurity principles.
Build a strong foundation in information security, understanding the essentials of cybersecurity and the rapidly evolving threat landscape.
Engage in hands-on experiences and live demonstrations that reveal how cyber-attacks such as phishing, malware, and unauthorized access unfold in real-world scenarios
Discover the critical role of human behavior in preventing breaches.
Join us to strengthen your organization’s security and ensure your teams are prepared to recognize, respond to, and mitigate cyber risks. This program provides live demonstrations of cyber-attack techniques, enabling attendees to witness how threats unfold in real-world scenarios. Don’t miss the opportunity to enhance your organization’s resilience.
ΣΚΟΠΟΣ ΣΕΜΙΝΑΡΙΟΥ
By the end of the training, participants will be able to:
Clearly articulate core cybersecurity principles and concepts.
Recognize and categorize a wide range of potential threats facing organizations today.
Apply the knowledge gained during training to analyze and identify real-world cyber incidents, correlating theory with practical scenarios.
Strengthen critical thinking abilities in the context of cybersecurity, enabling informed decisionmaking and risk assessment.
Demonstrate adherence to fundamental cybersecurity standards and practices in daily operations
Actively contribute to the development and maintenance of a robust security culture within their organization.
Consistently implement cybersecurity best practices to protect both personal and organizational data, fostering a proactive approach to safeguarding information assets.
ΣΕ ΠΟΙΟΥΣ ΑΠΕΥΘΥΝΕΤΑΙ
This training is addressed to:
All types of employees (including upper management) have access to data and information, either in electronic or physical form. This training program is designed for all types of employees— including upper management—who have access to organizational data and information, whether in electronic or physical form. It is particularly relevant for staff in Small and Medium-sized Enterprises (SMEs), where resources dedicated to cybersecurity may be limited, but the need for robust awareness and protection is critical.
Ideal candidates include:
Employees at all levels who handle or access sensitive information.
Managers and decision-makers responsible for information security policies.
Teams from IT, HR, Finance, and other departments are involved in data management.
SME staff are seeking to strengthen both personal and organizational resilience against cyber threats.
All participants should be currently employed.
ΠΕΡΙΣΣΟΤΕΡΕΣ ΠΛΗΡΟΦΟΡΙΕΣ
Agenda
1. Introduction (25 min)
- Information Security Objectives
- Confidentiality, Integrity, and Availability (The C.I.A)
- What is Information Security?
- Key Principles
2. Cyber and Information Security Threats (40 min)
- Terms & Definitions
- Why our organization Awareness with ENISA’s AR-in-a-Box (Building awareness with ENISA’s AR-in-a-box program without needing large budgets or dedicated security teams). AR-in-a-Box is a comprehensive solution for cybersecurity awareness activities.
- Threat Landscape
- Threat and Risk Assessment (Threat level * vulnerabilities * Impact/ Security + Awareness program + Pen testing + etc Implementation of cybersecurity awareness programs using AR-in-a-Box especially for SMEs is essential to reduce risk and build resilience.
- Measuring Security Performance (KPIs and Metrics) – ex. Phishing detection rates, patching times, incident response speed. Phishing is the fraudulent practice of sending emails or other messages purporting to be from reputable companies to induce individuals to reveal personal information, such as passwords and credit card numbers.
- Threat Actors
- Malware
- Information Leakage
- Mobile Devices threats.
3. Real life cyber security incidents (45 min)
- Presentation of recent cyber security incidents (2-3 cases) and a brief description of:
- The type of Attack
- The damage caused
- Highlight the Human errors that contributed (Lack of Awareness)
- How could the attacks be avoided
4.Unauthorized Access (Physical & Logical)- Risk and Controls (15 min)
- Unauthorized Access Overview
- Unauthorized Physical Access
- Unauthorized Logical Access
5. Social Engineering (1 h & 30 min)
- Social Engineering Overview-Social Engineering is the use of deception to manipulate individuals into divulging confidential or personal information that may be used for fraudulent purposes.
- What do the attackers think
- Anatomy of a Phishing Email
- Phishing Attack Demonstration / Simulation
- Vishing. Vishing is the fraudulent practice of making phone calls or leaving voice messages purporting to be from reputable companies to induce individuals to reveal personal information, such as bank details and credit card numbers.
- Smishing
6. Cyber Crisis Communication (20 min)
- What is Cyber Crisis Communication?
- How can SMEs communicate effectively during a cyber incident
- How to minimize impact (Reputational, Financial and Operational)
7. Basic Principles (15 min)
- Phases of an Effective Cyber Crisis
- Essential Principles (Do’s & Don’ts)
8. Three Phases of the Plan (15 min)
- Plan-Execute-Monitor & Evaluate (Giving details about each step how it can be approached from different points of view)
- Real Life Examples
9. Real Cyber Incidents (45 min)
- Present 2-3 Real Cyber Crisis Communication cases and a brief description:
- How the organization communicated during this incident
- The strategies used to manage public perception and maintain trust
- Challenges faced internal and external communication
- How effective communication could reduce reputational and operational impact
10. Cyber Awareness Game (1 h & 30 min)
- Phase 1 (Execution of an email-based phishing simulation)
- Phase 2 (Analysis of a phone and SMS attack scenario)
- Phase 3 (Investigation of unauthorized internal activity)
- Phase 4 (Performance of a ransomware decryption challenge)
**This initiative fully supports ENISA’s AR-in-a-Box cyber awareness objectives by transforming common cyber threats into dynamic, hands-on learning experiences. Through realistic simulations from phishing and fakeencryption to voice scams and ransomware participants will see, feel, and respond to how real attacks unfold. Each interactive scenario empowers SME employees to make smart, confident decisions that directly protect the Confidentiality, Integrity, and Availability of their organization. Rather thanlearning through static theory, participants actively engage in decision-making that highlights the real-world impact of everyday behaviour, turning awareness into action and knowledge into resilience.**
11. Strengthening Security Through Awareness and Controls (30 min)
- Presentation of Control Categories and sample of controls per category that can be established a clear and transparent communication plan for responding to cyber incidents.
- Build continuous cyber awareness in SMEs though ENISA’s AR-in-a-Box to strengthen employee behavior and organizational resilience
Services
Our services include:
- Handouts, including notes and important slides from the presentation, examples, case studies, exercises, and additional notes if applicable.
- Stationery, such as pads, pens, and files.
- Drinks (coffee, tea, etc.), snacks and a buffet lunch.
- A fully equipped training room with WiFi access.
- Certificate of completion.
Trainer
Sandra Zreik
Assistant Manager, Technology Consulting, KPMG in Cyprus
Sandra is an Assistant Manager in Technology Consulting at KPMG in Cyprus, holding an MSc in Computer and Communications Engineering with emphasis in Mechatronics Engineering and bringing over five years of experience in information security, IT assurance, and cybersecurity governance. With a strong foundation in IT assurance and security advisory, she specializes in ISO 27001 and ISO 42001 implementations and certifications, IT risk assessments, regulatory compliance (including DORA and the GDPR), and cybersecurity control evaluations.
She has extensive strong experience in designing and enhancing information security and AI governance frameworks, policies, and governance structures to support organizational resilience and compliance. Sandra has led initiatives to strengthen security practices, overseen ISMS governance, and implement programs across AI governance, business continuity, and security awareness.
Her experience also includes managing audits, regulatory requirements, third-party risk, and the continuous improvement of control environments. She combines technical expertise with leadership skills to manage teams and coordinate projects, delivering high-quality, compliant, and scalable solutions aligned with both business and regulatory expectations.
Αναλυτικό Κόστος Σεμιναρίου
Για Δικαιούχους ΑνΑΔ
- € 270.00
- € 120.00
- € 0.00
- € 150.00
- € 150.00
Για μη-Δικαιούχους ΑνΑΔ
- € 270.00
- € 0.00
- € 51.30
- € 270.00
- € 321.30
ΠΡΟΓΡΑΜΜΑ ΣΕΜΙΝΑΡΙΟΥ
Δευτέρα - 22 Ιουν 2026
Ώρα
09:00 - 16:20
Τοποθεσία:
KPMG (Λευκωσία)
Ελληνικά
English

