More in Cybersecurity: Cybersecurity Awareness Fundamentals · Data Privacy & GDPR/CCPA Basics · Remote Work Security · Generative AI Acceptable Use & Data Privacy · Incident Reporting Protocols · Data Backup Hygiene & Ransomware Readiness · Lifecycle Patch & Vulnerability Management

Cybersecurity 30m

Social Engineering & Business Email Compromise (BEC) & Deepfake Defense

This compliance-focused, role-based security-awareness course is for Finance, HR, and executive teams. It turns social engineering, impersonation, wire fraud, and business email compromise into a documented, SCORM-ready annual training asset focused on compliance, fraud prevention, and defensible risk management.

Social Engineering & Business Email Compromise (BEC) & Deepfake Defense

What this course covers

  • How social engineering, BEC, impersonation, and emerging deepfake tactics target employees with authority over payments, payroll, hiring, benefits, or sensitive decisions.
  • Why Finance, HR, and executives are high-value targets for requests involving urgent approvals, account access, employee records, or vendor payment changes.
  • Strict out-of-band verification before releasing funds, changing banking instructions, or acting on high-risk requests.
  • Red flags in email, text, voice, video, and collaboration-tool communications.
  • How to escalate suspicious requests, preserve evidence, and use approved incident-reporting channels.
  • How documented annual training supports audit readiness, internal controls, and fraud-prevention programs.

Modules

Module 1: Why Finance, HR, and Executives Are Prime Targets

This module explains why these functions are disproportionately targeted by attackers. Authority, urgency, and access to money or sensitive records make their workflows especially attractive for fraud.

Module 2: Social Engineering Tactics Used Against High-Trust Roles

This module explains urgency, authority pressure, secrecy, pretexting, and manipulation of normal business routines. Strong attacks often look plausible because they are tailored to real roles and responsibilities.

Module 3: Business Email Compromise and Wire-Fraud Patterns

This module covers BEC schemes targeting money movement and account changes, including fake vendor updates, urgent wire requests, payroll diversion, and executive impersonation. Learners identify process-level red flags before a fraudulent transfer or record change occurs.

Module 4: Executive Impersonation, HR Fraud, and Deepfake-Enabled Requests

This module covers AI-generated voice or video deepfakes layered on top of classic executive and HR impersonation. Familiar names, recognizable voices, and convincing video are not sufficient proof of authenticity.

Module 5: Out-of-Band Verification Procedures That Must Happen Every Time

This operational core module teaches a strict, repeatable verification process for wires, payroll or benefits changes, tax forms, new vendors, account updates, and sensitive approvals.

Module 6: Approval Workflows, Separation of Duties, and Exception Handling

This module teaches that fraud prevention depends on workflow design as well as individual vigilance. It reinforces approval chains, separation of duties, exception management, and documentation practices that make risky requests easier to stop.

Module 7: Reporting Suspicious Requests and Potential Fraud Immediately

This module teaches what to do after receiving a suspicious request or suspecting that action was already taken. It emphasizes speed, escalation, evidence preservation, and appropriate coordination with finance, IT, HR, legal, or leadership.

Module 8: Final Review, Scenario Check, and Employee Commitments

This final module reinforces role-specific fraud-prevention behaviors and ties them to annual compliance documentation. It supports LMS tracking and provides a defensible record that high-risk teams were trained on verification, escalation, and payment-control expectations.

Course features

SCORM 1.2 or 2004 Audio Narration Captions Transcript Knowledge Checks Locked Navigation Post-Assessment Certificate
Frequently asked questions

Who should take Social Engineering & Business Email Compromise (BEC) & Deepfake Defense?

This compliance-focused, role-based security-awareness course is for Finance, HR, and executive teams.

How long does the course take?

About 30 minutes, delivered across 8 modules with knowledge checks.

What does the course cover?

How social engineering, BEC, impersonation, and emerging deepfake tactics target employees with authority over payments, payroll, hiring, benefits, or sensitive decisions; Why Finance, HR, and executives are high-value targets for requests involving urgent approvals, account access, employee records, or vendor payment changes; Strict out-of-band verification before releasing funds, changing banking instructions, or acting on high-risk requests; Red flags in email, text, voice, video, and collaboration-tool communications; How to escalate suspicious requests, preserve evidence, and use approved incident-reporting channels; How documented annual training supports audit readiness, internal controls, and fraud-prevention programs.

Do learners receive a certificate?

Yes. The course issues a certificate on completion. It ships SCORM 1.2 or 2004 with audio narration, captions, transcript, and runs on the Provisant learning platform.

How much does it cost?

$5 per user per course per year. Annual billing saves 20%. Any course in the catalog can be added to a plan.