MDS IT Support Services Cyber Awareness Training

Episode 1 · Foundations

The Day Everything Stopped

Help Sarah spot hidden threats before the working day stops.

12 min Beginner Threat Spotter 100 XP
S I
Sarah cartoon characterSarah
IT Mike cartoon characterIT Mike
Everyday Cyber Threats interactive training artwork
20% episode progress
Watch Investigate Decide Play Complete
Everyday Cyber Threats scenario artwork

Scenario overview

A Normal Day, Four Hidden Threats

Sarah opens her laptop at the start of the day. Her screen fills with a phishing email, a...

Most cyber attacks do not begin with a dramatic hack. They begin inside ordinary work: an email, a...

Interactive staff exercise

Practise it like the NCSC Top Tips course

Short visual challenge, one realistic staff decision, instant feedback, and a downloadable reminder.

Everyday Cyber Threats visual exercise
Choose a card to get instant feedback.
S Sarah Office Manager
Sarah

The Day Everything Stopped begins now.

IT Mike

Pause, inspect, then choose.

Sarah

I will check the sender, timing, and request.

IT Mike

Good. Safe staff verify outside suspicious messages.

Sarah

If unsure, I report it before acting.

Decision game

Sarah sees four alerts at once. What should she do...

0 safe moves
Pick a move. Feedback appears instantly.

Mini game

Morning threat sweep

0 risks found
Inbox game
Find the risky items. Safe items turn green.

30-second explainer

Three things to remember

Threats hide in normal work
Pause before clicking
Report patterns early

Case story

A Small Business Lost a Working Day

Download PDF
1

Several small warning signs appeared together.

2

One rushed click opened a fake login page.

3

The account was used to send more messages.

4

Fast reporting would have contained it earlier.

Everyday Cyber Threats infographicVisual recap
Threat Spotter100 XP reward

Quick challenge

Three taps to finish practice

3 questions

Why do attackers try several routes into the same company?

Tap an answer.

What should staff do when several suspicious events happen close together?

Tap an answer.

Which everyday item can be a cyber threat?

Tap an answer.

Animated intro

Mission M001: Everyday Cyber Threats

A short animated workplace scene introduces the risk before the lesson.

Character story

S

Sarah

Office Manager

Sarah notices unusual supplier emails, repeated MFA prompts and a new file-sharing request in the same morning.

What should the character do next?

Everyday Cyber Threats briefing

Spot how normal work messages can hide cyber threats.

Open video lesson

Everyday Cyber Threats workplace decision

Sarah notices unusual supplier emails, repeated MFA prompts and a new file-sharing request in the same morning.

Open scenario

Cyber Threats Overview PDF

A one-page guide showing the most common routes attackers use against small businesses.

Download resource

Threat Spotter

Awarded for spotting hidden threats across normal workplace activity.

100 XP reward

Foundations · Beginner

Lesson content

12 min
Recognise common cyber threats that appear during normal office work.Understand why attackers try several routes into the same business.Identify when an email, message, attachment or password request should be reported.Build the habit of reporting suspicious patterns early.

Why Businesses Are Targeted

Cyber criminals often target businesses of all sizes because company systems hold valuable information such as customer records, payment details, staff data and supplier information.

Common Attack Routes

The most common routes include phishing emails, weak passwords, infected attachments, unsafe downloads, stolen credentials and exposed remote access systems.

A fake Microsoft 365 login page asking staff to re-enter their password.

An email pretending to be from a supplier asking for urgent payment.

Do

Report anything suspicious quickly.

Use strong passwords and MFA.

Check unusual payment or login requests.

Do not

Ignore warning signs.

Reuse passwords across work systems.

Open unexpected attachments without checking.

Guided workshop

What you will be able to do

Practical outcome

Learning outcomes

Recognise common cyber threats that appear during normal office work.

Understand why attackers try several routes into the same business.

Identify when an email, message, attachment or password request should be reported.

Practice activity

Why Businesses Are Targeted: Cyber criminals often target businesses of all sizes because company systems hold valuable information such as customer records, payment details, staff data and supplier information.

Common Attack Routes: The most common routes include phishing emails, weak passwords, infected attachments, unsafe downloads, stolen credentials and exposed remote access systems.

Common mistakes to avoid

Skipping verification

Using unapproved routes

Delaying reports

Evidence for the business

A completed checklist showing the safe behaviour expected from staff.

Advanced training boosters

Extra topics covered in this episode

2 practical points

Security culture snapshot

Know when a small clue should become a team report instead of a private worry.

Role-based risk

Finance, HR, managers, and remote workers see different attack routes and need different examples.

Why Businesses Are Targeted: Cyber criminals often target businesses of all sizes because company systems hold valuable information such as customer records, payment details, staff data and supplier information.

Common Attack Routes: The most common routes include phishing emails, weak passwords, infected attachments, unsafe downloads, stolen credentials and exposed remote access systems.

Course notes

Practical security habits

Read and apply

Why Businesses Are Targeted: Cyber criminals often target businesses of all sizes because company systems hold valuable information such as customer records, payment details, staff data and supplier information.

Common Attack Routes: The most common routes include phishing emails, weak passwords, infected attachments, unsafe downloads, stolen credentials and exposed remote access systems.

Case study

A fake Microsoft 365 login page asking staff to re-enter their password.

Pause, verify through an approved route, and report uncertainty early.

Use approved processes and ask for help early.
What is the risk?What is the approved route?Who should be told?
Habit Pause and verify
Control Use approved systems
Escalation Report early

Awareness video

Watch and apply

1 video

MDS local training video

Everyday Cyber Threats

Short lesson video explaining why small businesses are targeted and how attacks usually begin.

Open video file

Personal action plan

Choose three behaviours to apply this week

This turns training into a usable work habit. Select the actions you can apply immediately.

Select up to three actions to build your plan.

Practice checklist

0/4 complete

Scenario

A fake Microsoft 365 login page asking staff to re-enter their password.

Show recommended response

Pause, verify through an approved route, and report uncertainty early.

Knowledge check preview

Which event should be reported?
What does a suspicious attachment create?
Why is a pattern of suspicious events important?
What is the safest first behaviour?
Who should staff contact?

Quiz scoring, certificates, and progress tracking unlock after trial or subscription activation.