Episode 1 · Foundations
The Day Everything Stopped
Help Sarah spot hidden threats before the working day stops.
Scenario overview
A Normal Day, Four Hidden Threats
Sarah opens her laptop at the start of the day. Her screen fills with a phishing email, a...
Most cyber attacks do not begin with a dramatic hack. They begin inside ordinary work: an email, a...
Training video included
Everyday Cyber Threats briefing
Watch the supplied MDS video here, then complete the decision game and checkpoints.
Interactive staff exercise
Practise it like the NCSC Top Tips course
Short visual challenge, one realistic staff decision, instant feedback, and a downloadable reminder.
The Day Everything Stopped begins now.
Pause, inspect, then choose.
I will check the sender, timing, and request.
Good. Safe staff verify outside suspicious messages.
If unsure, I report it before acting.
Decision game
Sarah sees four alerts at once. What should she do...
Mini game
Morning threat sweep
30-second explainer
Three things to remember
Case story
A Small Business Lost a Working Day
Several small warning signs appeared together.
One rushed click opened a fake login page.
The account was used to send more messages.
Fast reporting would have contained it earlier.
Quick challenge
Three taps to finish practice
Why do attackers try several routes into the same company?
Tap an answer.
What should staff do when several suspicious events happen close together?
Tap an answer.
Which everyday item can be a cyber threat?
Tap an answer.
Animated intro
Mission M001: Everyday Cyber Threats
A short animated workplace scene introduces the risk before the lesson.
Character story
Sarah
Office Manager
Sarah notices unusual supplier emails, repeated MFA prompts and a new file-sharing request in the same morning.
What should the character do next?Everyday Cyber Threats briefing
Spot how normal work messages can hide cyber threats.
Open video lessonEveryday Cyber Threats workplace decision
Sarah notices unusual supplier emails, repeated MFA prompts and a new file-sharing request in the same morning.
Open scenarioCyber Threats Overview PDF
A one-page guide showing the most common routes attackers use against small businesses.
Download resourceThreat Spotter
Awarded for spotting hidden threats across normal workplace activity.
100 XP rewardFoundations · Beginner
Lesson content
Why Businesses Are Targeted
Cyber criminals often target businesses of all sizes because company systems hold valuable information such as customer records, payment details, staff data and supplier information.
Common Attack Routes
The most common routes include phishing emails, weak passwords, infected attachments, unsafe downloads, stolen credentials and exposed remote access systems.
A fake Microsoft 365 login page asking staff to re-enter their password.
An email pretending to be from a supplier asking for urgent payment.
Do
Report anything suspicious quickly.
Use strong passwords and MFA.
Check unusual payment or login requests.
Do not
Ignore warning signs.
Reuse passwords across work systems.
Open unexpected attachments without checking.
Guided workshop
What you will be able to do
Learning outcomes
Recognise common cyber threats that appear during normal office work.
Understand why attackers try several routes into the same business.
Identify when an email, message, attachment or password request should be reported.
Practice activity
Why Businesses Are Targeted: Cyber criminals often target businesses of all sizes because company systems hold valuable information such as customer records, payment details, staff data and supplier information.
Common Attack Routes: The most common routes include phishing emails, weak passwords, infected attachments, unsafe downloads, stolen credentials and exposed remote access systems.
Common mistakes to avoid
Skipping verification
Using unapproved routes
Delaying reports
Evidence for the business
A completed checklist showing the safe behaviour expected from staff.
Advanced training boosters
Extra topics covered in this episode
Security culture snapshot
Know when a small clue should become a team report instead of a private worry.
Role-based risk
Finance, HR, managers, and remote workers see different attack routes and need different examples.
Why Businesses Are Targeted: Cyber criminals often target businesses of all sizes because company systems hold valuable information such as customer records, payment details, staff data and supplier information.
Common Attack Routes: The most common routes include phishing emails, weak passwords, infected attachments, unsafe downloads, stolen credentials and exposed remote access systems.
Course notes
Practical security habits
Why Businesses Are Targeted: Cyber criminals often target businesses of all sizes because company systems hold valuable information such as customer records, payment details, staff data and supplier information.
Common Attack Routes: The most common routes include phishing emails, weak passwords, infected attachments, unsafe downloads, stolen credentials and exposed remote access systems.
Case study
A fake Microsoft 365 login page asking staff to re-enter their password.
Pause, verify through an approved route, and report uncertainty early.
Use approved processes and ask for help early.Awareness video
Watch and apply
MDS local training video
Everyday Cyber Threats
Short lesson video explaining why small businesses are targeted and how attacks usually begin.
Open video filePersonal action plan
Choose three behaviours to apply this week
This turns training into a usable work habit. Select the actions you can apply immediately.
Practice checklist
0/4 completeScenario
A fake Microsoft 365 login page asking staff to re-enter their password.
Show recommended response
Pause, verify through an approved route, and report uncertainty early.
Knowledge check preview
Quiz scoring, certificates, and progress tracking unlock after trial or subscription activation.