Sofia has run red team engagements against banks, hospitals and one national rail operator. She teaches security to people who build software rather than to specialists, on the grounds that this is where the leverage is. Her threat modelling exercises are the most-completed practical assessments on the platform.
Information Security Essentials
Forty minutes that might actually change what someone clicks.
- Completion rate
- 94%
- Free previews
- 1
- Total time
- 1h 55m
- 1h 55m, lifetime access
- Learn on desktop, tablet and phone
- Verifiable certificate on completion
- AI tutor with full course context
Training a team?
Volume pricing from five seats, with assignment, reminders and completion reporting included.
See team plans →What you will be able to do
- Recognise the phishing patterns currently in use
- Handle credentials and MFA correctly
- Know exactly what to do in the first five minutes of a suspected incident
- Understand your obligations for handling personal data
Skills this course develops
Each maps to the same taxonomy your organization’s roles are defined in, so progress here moves your skill profile.
About this course
Annual security awareness training, rebuilt. Short, scenario-driven and specific to the attacks that actually reach employees. Designed to be assigned organisation-wide, with reporting that satisfies audit.
Requirements
- None
Curriculum
3 modules · 10 lessons · 1h 55m
Current, specific and scenario-based.
- Phishing in 2026: what it looks like nowVideoPreview12m
- Business email compromiseVideo10m
- Scenario: five emails, which are real?Interactive15m
Your instructors
James Ashworth
Compliance & Risk Lead, Harbourline Financial
James is responsible for making sure four thousand people complete training they would rather not do, and for proving it to a regulator afterwards. He teaches compliance design as a genuine craft problem: how do you make mandatory learning that people do not resent? His answer involves considerably less clip art than the industry standard.
What learners say
3,947 reviews
- Yuki NakamuraData ScientistRated 5.0 out of 511 months ago
The instructor is honest about what does not work, which is rarer than it should be. There is a whole lesson on a failed approach and why it failed. I learned more from that than from most successful case studies.
- Nathan ColeOperations DirectorRated 5.0 out of 51 month ago
Watched it over three weeks of commutes. The transcripts are accurate enough that I could read on the train and watch the demos later. That is a small thing that made the whole course possible for me.
- Rafael OrtizProduct ManagerRated 4.0 out of 52 months ago
Genuinely good, with one caveat: the first module moves slowly if you already know the basics. Skip to module two if you do — the rest is excellent and the case studies are specific rather than generic.
Learners who took this also took
Responsible AI in Practice
Governance that engineers will actually follow, written by someone who has shipped.
Dr. Amara Okonkwo · James Ashworth
21.5K
Application Security for Builders
Security for the people writing the code, not for a specialist team.
Sofia Novak
38.9K
Compliance Training People Actually Complete
Mandatory does not have to mean resented.
James Ashworth · Nia Adeyemi
19.3K
