Free course 21 minutes Certificate По-русски

Security Awareness for Employees

Most breaches don't start with clever code. They start with an ordinary-looking email, a phone call that already knows your name, or a password reused from a forum you joined years ago. This is a free 21-minute course on the three of them — five short lessons, a quiz after each, and a certificate at the end.

Start the course Free · no signup to start · email only if you want the certificate

Already clicked? Start here

If you entered your details somewhere you shouldn't have, or read a code out loud over the phone, the next few minutes matter more than anything else. Almost everything can be stopped early. Almost nothing can be stopped the next day.

  1. Disconnect from the network — don't power off. Pull the cable or turn off Wi-Fi. Shutting down wipes the memory, and with it the traces of what happened.
  2. Tell someone now. At work, whoever handles this. At home, your family — especially if money is involved. This is the step people put off, and it's the one that decides how things end.
  3. Change your passwords, email first. Every other account is recovered through email. While someone else has it, changing anything else is pointless.
  4. Call your bank if you entered card details or read out a code — through the app or the number on your card, never a link from the message.
  5. Try to stop the payment. Transfers can sometimes be reversed, but the window is minutes or hours.
  6. Delete nothing. The message, the link, your browser history — all of it is needed to work out what happened and warn everyone else.

What the problem actually looks like

Security advice usually pictures an attacker breaking through something. In practice, nothing gets broken. Someone is asked politely, in a hurry, to do something ordinary — and they do it, because it looked like work.

The email that hurries you

A fake email rarely looks fake. Familiar sender name, the usual layout, a reasonable request. What gives it away is almost never a spelling mistake — it's the deadline. "Your account will be locked in 24 hours." A real bank doesn't set you a deadline by email; it stops the transaction and waits for you to call. A deadline exists so you don't have time to think or ask a colleague.

The one rule worth taking away right now

An address is read right to left. Look at it up to the first slash, then take the last two parts — that's who owns the page. Everything to the left of that, the owner made up.

AddressOwner
your-bank.example.comexample.comnot the bank
login.your-bank.exampleyour-bank.examplethe bank
your-bank-example.comyour-bank-example.comnot the bank — a hyphen, not a dot

That third line is the most common trick there is. A hyphen looks almost like a dot, but a dot separates owners and a hyphen is just another character in a name.

The call that already knows you

The number on your screen is not proof — the phone network carries it like any other piece of data, and it can be set to anything, including the real number printed on your card. Neither is what the caller knows about you: your name, your employer, the last four digits of your card. That's either in a leak already or a few minutes of searching. Knowing things about you isn't evidence. It's a tool for stopping your doubts.

The password that leaked years ago

Passwords are almost never guessed. They're taken ready-made from a site that leaked, then tried everywhere else. Which is why the rule isn't "make it strong" — it's "never use it twice". A strong password used on two sites leaks exactly like a weak one.

What you'll be able to do afterward

What's inside

Lesson 1 · 5 min

The email that asks you to hurry

How a fake email is built, and the right-to-left rule for reading an address.

Lesson 2 · 4 min

Passwords, codes, and a second lock

Why reuse is the real problem, and which second factor to choose.

Lesson 3 · 4 min

The call that knows your name

Spoofed numbers, borrowed facts, and the only check that actually works.

Lesson 4 · 4 min

Untrusted networks and oversharing

Mixing work and personal, open Wi-Fi, and what never gets sent to anyone.

Lesson 5 · 4 min

The first fifteen minutes

What to do after a mistake — and why silence, not the click, does the damage.

Each lesson is followed by a quiz. Questions are drawn from a larger pool, so a retake isn't the same set again. The pass mark is 70%.

Questions people ask

Do I need an account?
No. You can go through the whole course without signing up. An email address is asked for only at the end, and only if you want the certificate sent to you.
Is it really free?
Yes, for anyone taking it. Cletica makes money from organizations that run courses for their own staff and need the records — not from learners.
What is the certificate worth?
It confirms that you completed this course, carries a number, and has a public page where anyone can check that it's genuine. It is not an accredited qualification, and the course doesn't claim to satisfy any specific regulation.
Can I run this for my team?
Yes. You can send the course to a list of people, see who finished and who didn't, how long each person actually spent on the material, and their quiz scores — and every learner gets their own certificate.
How long does it really take?
About 21 minutes of reading across five lessons, plus the quizzes. It's built to be done in one sitting or a few short ones — progress is saved.

Running this for a team?

The same course can be assigned to a list of people, with per-person progress, quiz scores, time spent on each lesson, and a certificate for everyone who passes. Built on Cletica, which is also where you can build your own courses, surveys and tests.