All coursesTechnology

TECHNOLOGY · 2 HOURS

Security Decisions for Non-Technical Teams

Security Decisions for Non-Technical Teams teaches team leaders and office managers to see how their team really shares accounts, files and devices, and which of those habits could cause serious harm. You finish with an exposure list for your own team and three changes to make this week, each with an owner and a date.

About this course

Team leaders and office managers decide every day how people share logins, files and devices, usually without a security specialist to ask. Most harm to small teams does not come from sophisticated hacking but from ordinary routes: a convincing email that asks for a password, a request to change a supplier's bank details, a reused password, or access that was never removed when someone left. This course teaches people with no technical background to see where their own team is exposed and to act on the items that matter most.

You walk through how your team really gets into its systems, sort each shared item by the worst realistic outcome, learn the habit of checking any request by a route you already trust, and choose changes that can be finished in days rather than months. The course draws on the National Cyber Security Centre's Small Business Guide and Cyber Aware advice, and you finish with a signed exposure list for your own team with at least three changes for this week, each with one owner and a date.

What you will take away

  • You will be able to list how your team really shares access, by walking the work and reading user lists, and label each item as named access or shared access.
  • You will be able to sort shared access by the worst realistic outcome into serious harm or nuisance, including the harm of being locked out when only one person knows a password.
  • You will be able to recognise phishing, payment diversion, reused passwords and unrevoked access in workplace examples, and respond by checking the request through a contact you already held.
  • You will be able to tell a change for this week, such as turning on two-step verification or changing a password a leaver knew, from a project for later.
  • You will leave with a signed exposure list that records, for each serious harm, what is shared, who can get in, the worst realistic outcome, the change, and the owner with a date.

Who this course is for

  • Office managers in small and medium-sized organisations who look after shared logins, the bank portal and the office devices without an in-house security team.
  • Team leaders inside larger organisations who decide how access is handed to new starters, temporary staff and suppliers.
  • Managers who suspect that former staff or contractors can still get into a mailbox, folder or system and want a practical way to find out.
  • Staff who approve payments or handle supplier details and need a dependable habit against payment diversion and phishing.

What you will do

Each lesson teaches one part of the method, works through a realistic example, and ends with a check on a case you have not seen. The course closes with an assessment and then the piece of work you sign.

  • 5lessons with a worked example and a check
  • 8scenario questions in the course assessment
  • Signedthe exposure list, with a record anyone can verify
  • 2 hoursat your own pace, with progress saved
  1. 01

    Lesson

    What you actually share

    This lesson explains what access means in practice and the difference between named access and shared access, which is common for good reasons. You walk through a normal week of work and mark items such as shared logins and open links as named or shared.

    • Access is how people get in
    • Named access and shared access
    • What shared access is not
    • The mistake people usually make

    You mark 4 statements from a realistic case and receive an explanation for each one.

  2. 02

    Lesson

    What would hurt

    This lesson teaches you to sort shared access by the worst realistic outcome, rather than by how visible or embarrassing a problem would be. You mark items as serious harm or nuisance, including the risk of being locked out of an account.

    • Ask what the worst realistic outcome would be
    • Serious harm and nuisance
    • What this sort is not
    • The mistake people usually make

    You mark 4 statements from a realistic case and receive an explanation for each one.

  3. 03

    Lesson

    How it usually goes wrong

    This lesson describes the four ordinary routes by which small teams are harmed and the habit of checking a request by another route you already trust. You choose between responses to suspicious requests and learn how to report a phishing email.

    • Four ordinary routes
    • Checks by another route and trusts the message
    • Why spotting fakes is not the defence
    • Reporting what you find

    You compare two versions of the same piece of work, choose the stronger one, and see the reasoning behind the answer.

  4. 04

    Lesson

    Three changes this week

    This lesson gives you three tests for a good change: it reduces a serious harm, it can be done now, and it has one owner and a date. You mark proposals as a change for this week or a project for later.

    • Three tests for a good change
    • A change for this week and a project for later
    • The changes that usually pass
    • The mistake people usually make

    You mark 4 statements from a realistic case and receive an explanation for each one.

  5. 05

    Lesson

    Repair an exposure list

    This lesson sets out the five parts of an exposure list row and the parts most often missing, which are who can get in and a real owner. You repair a weak row about a bank portal so that someone else could check and act on it.

    • The five parts of a row
    • What an exposure list is not
    • The parts most often missing
    • How to repair a row

    You repair a flawed draft so it meets the standard the lesson sets, and your revision is checked against it.

  6. 06

    Course assessment

    Test your judgement on new cases

    This course assessment recaps the five moves of the method and shows where careful professionals usually slip. You apply the method to eight new situations, reading each one for who holds the access, what could be lost and where the request came from.

    • The method in full
    • Where people slip in the assessment
    • How the assessment is marked

    You judge 8 new workplace situations, with feedback on every option, and need 6 correct to pass.

  7. 07

    Final work and signed record

    Your exposure list

    In this final lesson you write the exposure list for your own team, with a numbered line for each serious harm and a note of nuisances and projects for later. You check each line is ready to act on and then sign it for your record.

    • What your list covers
    • How to write the fields
    • Ready to act on and someone would have to ask
    • What the list must not contain or claim

    You write the exposure list for your own work, part by part, and sign it as your record.

Colleagues around a table, working through a problem together.GOOD WORK.
THE EXPOSURE LIST, SIGNED.

WHAT CHANGES

What the course changes for you and your organisation.

  1. 01

    Changes made this week

    The course directs your effort to small changes that reduce a serious harm and can be finished now, each with one named owner and a date. The organisation removes real exposure in days instead of waiting for a larger project to be approved.

  2. 02

    Protection against payment diversion

    You learn to confirm any request for money, passwords or changed details by a route you already had before the message arrived. This habit works whether or not the message looks genuine, so it does not rely on spotting a fake.

  3. 03

    A list others can act on

    Your exposure list is written so that a manager or IT provider can act on each row without calling you and can check on the due date whether the change was made. It describes access without containing passwords, account numbers or personal data.

  4. 04

    Everyday habits drive cyber risk

    The government's Cyber Security Breaches Survey 2025 found that 43% of UK businesses experienced a breach or attack in the previous year, with phishing the most common type. Team leaders who can see how their people share accounts, files and devices can close common gaps before they cause harm.

QUESTIONS

Questions about Security Decisions for Non-Technical Teams

What is Security Decisions for Non-Technical Teams about?
Team leaders and office managers decide every day how people share logins, files and devices, usually without a security specialist to ask. Most harm to small teams does not come from sophisticated hacking but from ordinary routes: a convincing email that asks for a password, a request to change a supplier's bank details, a reused password, or access that was never removed when someone left. This course teaches people with no technical background to see where their own team is exposed and to act on the items that matter most. You walk through how your team really gets into its systems, sort each shared item by the worst realistic outcome, learn the habit of checking any request by a route you already trust, and choose changes that can be finished in days rather than months. The course draws on the National Cyber Security Centre's Small Business Guide and Cyber Aware advice, and you finish with a signed exposure list for your own team with at least three changes for this week, each with one owner and a date.
Who is Security Decisions for Non-Technical Teams for?
Office managers in small and medium-sized organisations who look after shared logins, the bank portal and the office devices without an in-house security team. Team leaders inside larger organisations who decide how access is handed to new starters, temporary staff and suppliers. Managers who suspect that former staff or contractors can still get into a mailbox, folder or system and want a practical way to find out. Staff who approve payments or handle supplier details and need a dependable habit against payment diversion and phishing. No specialist background is assumed, and every term is explained before it is used.
What will I be able to do after Security Decisions for Non-Technical Teams?
You will be able to list how your team really shares access, by walking the work and reading user lists, and label each item as named access or shared access. You will be able to sort shared access by the worst realistic outcome into serious harm or nuisance, including the harm of being locked out when only one person knows a password. You will be able to recognise phishing, payment diversion, reused passwords and unrevoked access in workplace examples, and respond by checking the request through a contact you already held. You will be able to tell a change for this week, such as turning on two-step verification or changing a password a leaver knew, from a project for later. You will leave with a signed exposure list that records, for each serious harm, what is shared, who can get in, the worst realistic outcome, the change, and the owner with a date.
How long does the course take, and how is it taught?
The course takes about 2 hours and is studied online at your own pace. It has 5 lessons, each with a worked example, a practice exercise, and a check on a new case, followed by a course assessment of 8 scenario questions in which you need 6 correct to pass. Your progress is saved to your account.
Do I get a certificate?
Yes. When you pass, you sign a record that names you, the course, and the exposure list. Anyone you share it with can verify it online and download it as a PDF. The record confirms what you completed and does not claim compliance with any regulation.
How much does it cost, and when can I start?
The course costs £99, paid once by card through Stripe. Access begins as soon as payment is confirmed, and you can save a sign-in to return to the course from any device.
Can my organisation train a whole team?
Yes. Individuals can buy any self-paced course online, and organisations can book trainer-led courses for teams, in person or online, through the Experrt Academy.

More technology courses are listed on the self-paced technology courses for non-technical teams page.

THERE IS A NEXT CHAPTER.

Start today, and finish with
the exposure list your organisation can use.

Checkout takes an email address and a card, and access begins as soon as payment is confirmed. When you finish, you sign a record that names you and the exposure list, which anyone you choose can verify online. The record confirms what you completed and does not claim compliance with any regulation.