
EdTech Company – Employee Security Awareness
- Home
- Projects
Project Overview
An EdTech company providing virtual classrooms needed to address increasing phishing attempts and internal security negligence. We were engaged to roll out a lightweight but effective employee awareness and training program.
Challenges
- Frequent phishing attacks targeting non-technical staff.
- No prior cybersecurity training or formal onboarding.
- Use of weak and repeated passwords across platforms.
- Staff unaware of basic reporting protocols for incidents.
- Shadow IT and unvetted third-party tool usage.
Solutions
- Conducted interactive phishing simulations with employees.
- Designed an internal cybersecurity awareness program.
- Rolled out a password manager and MFA policy company-wide.
- Created an easy-to-understand incident reporting framework.
- Audited all active tools and implemented app approval policies.