+34 673 332 457 +34 93 14 15 199 practicas@htlescueladeempresaonline.com

Cybersecurity: online course with internship agreement

The Cybersecurity course teaches you to separate threat, vulnerability and risk, spot AI-enhanced phishing and voice cloning, and set up MFA and passkeys. You will also apply the 3-2-1 backup rule, act correctly in the first hour of an incident, and verify payment requests out-of-band. It is aimed at staff in organisations without a security team. Study 100 % online for 180 days. An internship agreement is included. Price: €200.

  • 180 days of access
  • 100 % online, at your own pace
  • Level: beginner · No prior experience required
  • Assessment: 10 quizzes (50 questions) and a final project
  • Internship agreement included
  • Certificate with a verifiable QR code
  • Languages: Spanish, English, French
  • Price: €200

Who it is for

  • Office staff in small and medium-sized organisations with no in-house IT department
  • People who handle supplier payments, invoices or customer personal data
  • Remote and hybrid workers who use company laptops and cloud tools outside the office
  • Anyone starting out in cybersecurity who wants a practical, non-technical foundation

What do you need to start?

Prior knowledge

  • No prior knowledge of IT or cybersecurity is needed
  • Everyday use of email, a web browser and shared files
  • Basic arithmetic for simple risk and cost estimates

Software and equipment

  • A computer and an internet connection
  • Password managers built into your browser or operating system are covered; they are free and already installed
  • No paid security software or licence is provided or required

What you'll be able to do

  • Distinguish hazard, threat, vulnerability and risk, and estimate the cost of incidents with simple figures
  • Classify suspicious emails, texts, calls and video calls by phishing or social-engineering type
  • Estimate how many phishing emails a company receives monthly and the probability of at least one click
  • Apply the 3-2-1 backup rule and explain why immutable backups defeat ransomware
  • Take the right first actions when encryption is under way: disconnect, escalate and preserve evidence
  • Review cloud and SaaS access under the shared responsibility model and remove access that is no longer needed
  • Determine whether a business falls within NIS2 or the UK Cyber Security and Resilience Bill
  • Verify payment and bank-detail changes out-of-band and report suspected fraud to Report Fraud

Skills you will practise

  • Threat and risk assessment
  • Phishing recognition
  • MFA and passkeys
  • Password managers
  • 3-2-1 backup rule
  • Incident response
  • Shared responsibility model
  • UK GDPR / DPA 2018
  • NIS2
  • Out-of-band verification

Syllabus

  1. Threats, vulnerabilities and risk: the foundational framework — Separates hazard, threat, vulnerability and risk, so you choose the right remedy and estimate incident costs using real, simple numbers. · reading and a 5-question quiz
  2. AI-enhanced phishing and social engineering — Covers phishing, smishing, vishing and deepfake voice and video cloning, and shows which warning signs still work now that AI writes flawless messages. · reading and a 5-question quiz
  3. Passwords, MFA and the shift to passkeys — Explains credential-stuffing attacks, built-in and dedicated password managers, multi-factor authentication and why passkeys are replacing passwords. · reading and a 5-question quiz
  4. Ransomware and backup discipline — Explains Ransomware-as-a-Service, double extortion, the 3-2-1 rule and immutable backups, and compares restore costs with the cost of downtime. · reading and a 5-question quiz
  5. Incident response basics: what to do in the first hour — Sets out what non-specialist staff should do, and avoid doing, in the first minutes after a suspicious attachment or encrypted files appear. · reading and a 5-question quiz
  6. Remote and hybrid work: protecting yourself outside the office — Covers public Wi-Fi, shoulder surfing, shared computers and the limits of company control over the devices staff use. · reading and a 5-question quiz
  7. Cloud and SaaS security basics: shared responsibility — Explains what the provider secures and what you must secure yourself, including scoping and removing access to shared drives. · reading and a 5-question quiz
  8. Data protection basics for employees: UK GDPR/DPA 2018 in practice — Defines personal data, shows what usually goes wrong with it in an ordinary office, and what to do in the first five minutes. · reading and a 5-question quiz
  9. The regulatory horizon: NIS2 and the UK Cyber Security and Resilience Bill — Explains who falls within scope, regulations versus directives, the Bill's status, and how security requirements reach suppliers through contracts. · reading and a 5-question quiz
  10. Recognising and reporting fraud and scams — Covers invoice and mandate fraud and CEO or vendor impersonation, out-of-band verification, and reporting through Report Fraud. · reading and a 5-question quiz

Download the syllabus (PDF)

Internship agreement

An intern with this course could support operations, administration, finance or IT support teams. Typical tasks include reviewing who has access to shared drives and SaaS tools, documenting backups against the 3-2-1 rule and checking that restores work, and helping with phishing-awareness material. You might also help draft out-of-band verification steps for supplier payments, or gather evidence such as MFA coverage and an incident contact for a client's security questionnaire.

The internship can run at the same time as the course, within the 180 days of access.

Frequently asked questions

What kind of role does the Cybersecurity course prepare me for, and what does it not cover?

The Cybersecurity course gives employees and newcomers a practical grounding in everyday security. It covers phishing, passwords and MFA, ransomware and backups, first-hour incident response, cloud access, data protection, fraud and new regulation. It suits support, operations or administration roles in organisations without a security team. The data protection module does not train you as a data protection officer. It teaches what every employee needs to know about handling personal data.

What could I actually do during the internship, and who finds the company?

You find the host company yourself. The school then issues the internship agreement, which the company signs electronically. Tasks you could take on include auditing access to shared drives and SaaS tools, checking backups against the 3-2-1 rule, and drafting procedures for verifying payments. You could also prepare phishing-awareness material or collect evidence for a client's security questionnaire. Suitable departments include operations, finance, administration and IT support.

Which laws, standards and methods does the course cover?

The course covers the UK GDPR and the Data Protection Act 2018 as they apply to employees. It also covers the EU's NIS2 directive and the UK Cyber Security and Resilience Bill, which had not received Royal Assent when the materials were written. Methods include the 3-2-1 backup rule, immutable backups, multi-factor authentication, passkeys, password managers and the cloud shared responsibility model. You will also learn out-of-band verification and how to report fraud through Report Fraud, formerly Action Fraud.

Isn't cybersecurity mostly about installing antivirus and having technical IT skills?

No. The course shows that the remedy has to match the vulnerability. Antivirus does nothing about twelve people sharing one password, and backups do not stop a confidential file being emailed to the wrong person. Most of what keeps data safe relies on habits rather than technical knowledge. Examples include verifying payment requests out-of-band, testing that backups can be restored, removing access that is no longer needed and reporting incidents quickly.

More Technology & AI courses

See all courses

Content updated: 07/10/2026