Available courses

M7 is a governance-focused CRA-PAC module designed for managers, security leaders, compliance officers, awareness owners, risk owners and internal auditors. It explains how Moodle LMS evidence can be reviewed and used to support awareness governance, audit readiness and continuous improvement.

The module focuses on course enrolment, role-based cohort assignment, completion reports, quiz scores, acknowledgements, feedback results, weak-topic analysis, corrective actions and management review. Learners practise interpreting dashboard results and deciding when follow-up action is required.

This module supports CRA-PAC by showing how awareness delivery becomes measurable, reviewable and improvable through LMS evidence. It also explains that LMS evidence supports CRA readiness but does not prove full CRA compliance by itself.

M6 is a role-based CRA-PAC module designed for Support, Helpdesk, Service Desk, Customer Support and Operations employees. It focuses on phishing and social-engineering attacks delivered through support tickets, customer requests, unsafe files, malicious links, account-reset abuse, identity-verification bypass and product-security signals.

The module explains how attackers may use support channels to deliver malware, steal credentials, manipulate account recovery, request unsafe troubleshooting actions or hide early signs of product-security incidents. Learners practise safe ticket handling, customer identity verification, file and link handling, and escalation to security or product teams.

This module supports CRA-PAC by linking support-channel phishing awareness to safe ticket handling, account security, product-security escalation, incident readiness, evidence generation and continuous improvement.

M5 is a role-based CRA-PAC module designed for Procurement, Finance, Accounts Payable, Supplier Management and business approval teams. It focuses on supplier impersonation, invoice fraud, payment redirection, fake product updates, malicious supplier files and business-process manipulation.

The module explains how attackers may impersonate suppliers, executives or finance staff to request urgent payments, bank-detail changes, purchase-order changes or unsafe supplier downloads. Learners practise verifying supplier requests through trusted records, applying approval controls and escalating high-risk requests.

This module supports CRA-PAC by linking supplier and finance phishing awareness to verification controls, supplier-risk management, product-update integrity, reporting, escalation, evidence generation and continuous improvement.

M1 is the foundation module of the CRA-PAC awareness programme. It introduces all staff to the Cyber Resilience Act context, phishing threats, social engineering techniques and the importance of employee awareness in supporting cyber-resilience readiness.

The module explains how phishing can affect organisational security, secure product lifecycle processes, incident reporting, vulnerability handling and internal escalation. Learners are introduced to the CRA-PAC behaviour model:

Stop → Verify → Report → Escalate

This module includes basic phishing indicators, practical examples, scenario-based learning, a scored quiz, acknowledgement and feedback. It is assigned to all staff as a core awareness module.

M2 is a core CRA-PAC module focused on internal reporting and escalation behaviour. It teaches all staff how to recognise suspicious activity, verify requests safely, report phishing attempts and escalate security concerns through approved internal channels.

The module explains what should be reported, how to preserve useful evidence and why early reporting supports security triage, incident readiness and cyber-resilience governance. Learners practise the CRA-PAC behaviour model:

Stop → Verify → Report → Escalate

This module includes reporting guidance, approved reporting routes, escalation scenarios, a scored quiz, acknowledgement and feedback. It is assigned to all staff as a core awareness module.

M3 is a role-based CRA-PAC module designed for developers, DevOps engineers, software engineers and technical staff. It focuses on phishing attacks that target source-code repositories, CI/CD pipelines, cloud platforms, secrets, tokens, SSH keys, API keys and developer tooling.

The module explains how developer compromise may affect secure lifecycle processes, product integrity, software builds, deployment workflows and vulnerability handling. Learners practise safe verification of repository alerts, CI/CD messages, OAuth requests, token requests and suspicious code-review activity.

This module supports CRA-PAC by linking developer awareness to secure product lifecycle protection, reporting, escalation and evidence generation. It includes scenario-based lessons, a scored quiz, acknowledgement and feedback.