A comprehensive course providing detailed insights, realistic scenarios, and practical tools to enhance cyber security awareness in financial services. Covers the threat landscape, hacker tactics, data protection under GDPR and DORA, authentication and password management, practical workplace scenarios, incident reporting responsibilities, and the Luxembourg/CSSF regulatory framework including DORA implementation, ICT third-party risk, TIBER-LU testing, and major ICT incident reporting.
Suitable for financial services professionals at all levels, from entry-level employees to senior executives; staff in banking, insurance, investment, and payments who handle sensitive client information or have access to internal systems.
Learning Objectives:
By the end of this course, the learner will be able to:
- Explain why cyber security is critical to financial services and outline the regulatory environment (GDPR, DORA) within which the firm operates.
- Recognise the most common cyber threats facing financial institutions, including phishing, ransomware, malware, and insider threats.
- Identify red flags and indicators of compromise in everyday workplace situations and report them through the correct channels.
- Describe the psychology, motivations, and methods of cyber criminals, including social engineering techniques such as pretexting, baiting, and impersonation.
- Apply data protection principles when handling sensitive personal and client information, including classification, secure transfer, and disposal.
- Create strong passwords, use approved password manager tools, and configure multi-factor authentication on workplace systems.
- Respond effectively to suspected cyber incidents — reporting, containment, and escalation — and meet obligations under GDPR and DORA.
- Apply cyber security best practices consistently across daily workplace tasks, from email handling to remote working.
- Identify the CSSF and the other Luxembourg authorities involved in cyber security supervision (BCL, CAA, CNPD, CIRCL) and describe each authority’s role.
- Distinguish between DORA and non-DORA entities under CSSF supervision and identify which framework of CSSF circulars applies to the firm.
- Describe DORA’s five pillars and the key ICT risk management, third-party risk, and resilience-testing obligations, including the TIBER-LU framework.
- Apply the major ICT-related incident classification criteria and meet the CSSF reporting timelines (4 hours / 24 hours / 72 hours / 1 month) under DORA.
- Recognise emerging cyber threats and the importance of continuous awareness, training, and learning.
Sections & Modules:
Module A — Recognising Cyber Threats and Hacker Tactics
Section 1: Introduction to Cyber Security for Financial Services
1.1 Welcome and Course Overview
1.2 Why Cyber Security Matters in Financial Services
1.3 Types of Data Targeted by Cyber Criminals
1.4 Recent High-Profile Cyber Incidents in Finance
1.5 The Impact of Cyber Breaches: Financial, Legal, and Reputational
1.6 Learning Objectives and Course Structure
Section 2: Recognising Cyber Threats
2.1 Overview of Common Threats
2.2 Deep Dive into Phishing Attacks
2.3 Case Study: Santander Phishing Incident (2022)
2.4 Recognising Phishing Emails
2.5 Indicators of Compromise
2.6 Insider Threats
2.7 Ransomware Explained
2.8 Malware Threats
2.9 Best Practices for Identifying Threats
2.10 Reporting Cyber Threats
2.11 Preventive Measures
2.12 Interactive: Spot the Phishing Email
Section 3: Understanding Hacker Tactics
3.1 Psychology and Motivations of Hackers
3.2 Common Attack Vectors
3.3 Methods Hackers Use to Exploit Vulnerabilities
3.4 How Cyber Criminals Monetise Stolen Data
3.5 Case Study: Deutsche Bank Malware Incident (2023)
3.6 Social Engineering Explained
3.7 Real-World Social Engineering Example
3.8 Prevention Through Awareness
3.9 The Importance of Regular Software Updates
3.10 Practical Advice and Action Steps
Module B — Protection, Authentication & Your Responsibilities
Section 4: Protecting Personal & Private Information
4.1 Principles of Data Protection and Privacy
4.2 Strategies for Securing Confidential Information
4.3 Secure Data Handling Protocols
4.4 Encryption and Secure Communication Methods
4.5 Common Data Protection Mistakes to Avoid
4.6 Case Study: HSBC Data Leak Incident (2022)
4.7 Employee Responsibilities in Data Protection
4.8 How to Respond to Data Breaches
4.9 Practical Tips for Everyday Security
4.10 Interactive Scenario: Data Protection Decisions
Section 5: Creating Strong Passwords & Authentication
5.1 The Critical Role of Strong Authentication
5.2 Anatomy of a Strong Password
5.3 Password Manager Tools and Best Practices
5.4 Multi-Factor Authentication (MFA)
5.5 Common Authentication Pitfalls and How to Avoid Them
5.6 Interactive: Identify the Weak Passwords
Section 6: Practical Scenarios & Best Practices
6.1 Interactive Scenarios Overview
6.2 Scenario 1 — Phishing Email Detection
6.3 Scenario 2 — Responding to Ransomware
6.4 Scenario 3 — Social Engineering Attempts
6.5 Step-by-Step Response Plans
6.6 Preventative Strategies
6.7 Contingency Planning
6.8 Regular Security Audits and Assessments
6.9 Employee Roles in Cyber Security
6.10 Practical Exercise: Incident Response Drill
6.11 Best Practices Checklist
6.12 Continuous Learning Recommendations
Module C — CSSF-Specific Requirements for Luxembourg Financial Entities
Section 7: The Luxembourg Regulatory Landscape
7.1 Welcome to Module C: Why Luxembourg-Specific Cyber Rules Matter
7.2 The CSSF: Role and Mandate
7.3 DORA Entities vs Non-DORA Entities: Which Rules Apply to You
7.4 The CSSF Cyber Rulebook at a Glance
7.5 Other Luxembourg Authorities You Need to Know
7.6 Where the CSSF Sits in the EU Architecture
Section 8: DORA and ICT Risk Management Obligations
8.1 Introduction to DORA: Regulation (EU) 2022/2554
8.2 The Five Pillars of DORA
8.3 ICT Risk Management Framework: Board and Senior Management Accountability
8.4 ICT Third-Party Risk and Circular CSSF 25/882
8.5 Subcontracting of Critical ICT Services
8.6 Digital Operational Resilience Testing
8.7 Threat-Led Penetration Testing (TLPT) and TIBER-LU
Section 9: Incident Reporting to the CSSF
9.1 The Post-DORA Incident Reporting Procedure
9.2 When Is an Incident “Major”? The Classification Criteria
9.3 The Automatic Trigger: Malicious Unauthorised Access
9.4 The Three-Stage Reporting Timeline
9.5 Significant Cyber Threats: Voluntary Notification
9.6 Interactive Scenario: A Phishing-Triggered Incident
Knowledge Check:
There is a 10 question knowledge check at the end of the course with a standard pass mark of 80% and unlimited attempts. The 10 questions are drawn randomly from a larger bank of questions. Each attempt will draw a different mix of questions.
Course Length:
90 minutes + 10 minutes of questions.
Certificate:
The user will receive a certificate in pdf format upon successful completion of the course and knowledge check.
Licence Information:
Each purchase is for a licence for a single user. The user has access to all the course material for 6 (six) months via our web based elearning platform.
Reporting:
For volume purchasers (offline only), your nominated administrator will be able to download:
- A set of detailed reports in Excel format showing course completion data for all of your users; and
- Copies of all certificates.
Compliance Officer Reviews:
Our courses have been reviewed and approved by over 100 Compliance Officers and deemed appropriate for use by all of their employees. We regularly update the course material as regulations evolve.
Our Feedback (from our range of courses):
“It was a great experience to participate in a professional e-learning course.”
“Good presentation, interactive implementation makes education process more interesting.”
“Very clear and well structured. The examples are excellent!”
Course Customisation (optional):
We can customise this course for your organisation. Customisation can include:
- Branded website and course
- Branded certificates
- Additional material covering your organisation and its AML policy and procedures

Cyber Security Awareness – The Human Firewall (Cayman Islands Version) 
















