Module 1: Why Immediate Reporting Matters
Incident reporting is a business-critical behavior, not an optional courtesy to IT. The first minutes after a suspicious click, malware event, or account anomaly can affect containment, recovery, and business damage.
Module 2: Recognizing the Signs of a Possible Compromise
This module teaches employees to notice signs that something may be wrong, including suspicious links, pop-ups, abnormal logins, missing files, unexpected MFA prompts, and unusual system behavior.
Module 3: What To Do After a Bad Link or Suspicious Attachment
This module gives employees a clear first-response sequence for incidents triggered by phishing and malicious content. It emphasizes speed, calm action, and policy-based escalation rather than panic or improvisation.
Module 4: Ransomware, Malware, and Signs of Active Infection
This module helps employees recognize when a device may be actively compromised. It covers ransomware warnings, encryption-like behavior, locked files, system slowdown, suspicious processes, and why speed is critical to help prevent lateral movement.
Module 5: How To Report an Incident Correctly
This module teaches the information employees should provide when reporting a suspected incident and the approved channels they should use. It reinforces consistency, clarity, and speed so IT or security teams can respond effectively.
Module 6: What Not To Do During a Suspected Incident
This module addresses mistakes that can worsen damage or complicate investigation: delaying, deleting evidence, continuing to use a compromised system, using unapproved channels, or attempting to solve the issue alone.
Module 7: Helping Limit Lateral Movement and Wider Business Impact
This module explains how quick reporting helps stop threats from spreading to additional users, devices, accounts, or systems. It connects employee speed with organizational containment, recovery, and business continuity.
Module 8: Final Review, Scenario Practice, and Employee Commitments
This final module reinforces the course’s core response behaviors and ties them to annual compliance documentation. It includes scenario-based knowledge checks and employee acknowledgment that can be stored in the LMS as evidence of completion.