Practical Cyber DACTA
Practical Cyber × DACTA · Group: HR · Finance · Ops

Cyber Awareness — Deck & Hands-On Drills

The slide deck plus seven hands-on drills for the full-day class. P.S. Cafe was breached through phishing, and group functions handle the money and the data — so these put you in the seat: spot the phish, clean up the risky files, see how attacks work, watch ransomware lock the business, run a live incident, play the quick-fire rounds, and commit to your own plan. Everything runs in your browser. No real systems, no real data.

🎓 HR · Finance · Operations 📊 Deck with live quizzes 🎯 7 hands-on drills 🔒 Sandboxed training
📊
START HERE

Slide Deck

The full awareness session as navigable slides — tailored to HR/Finance/Ops — with a quick-check quiz after every topic that scores as you go.

Fits: the morning teaching block (7 topics + knowledge checks)
Open deck →
✉️
DRILL 01

Phishing Inbox

A real-looking Outlook inbox with 5 F&B phishing emails hidden among genuine mail. Read each one, then Report Phishing. Get the Domain-Analysis breakdown and a scored debrief.

Fits: Afternoon Exercise 1 · morning “Spot the Phish”
Launch inbox →
🖥️
DRILL 02

Spot the Risky File

A back-office desktop scattered with files — a .pdf.exe in disguise, plaintext passwords, loose customer & staff data. Inspect each and flag what shouldn’t be there.

Fits: morning Malware/Data topics · Exercise 3 (data & device security)
Launch desktop →
DRILL 03

Threat Simulator

See attacks from the other side: brute-forcing a weak password (and how MFA stops it), a SQL-injection login bypass, and a phishing clone with live URL analysis.

Fits: morning “why passwords fail” · mechanism-level demo
Launch simulator →
🚨
DRILL 04

Incident Drill

You’re in the seat when a finance BEC unfolds into an account compromise and a data exposure. Make the call at each step; your decisions are scored against the real incident-response playbook.

Fits: Afternoon Exercise 4 (incident response), hands-on
Run the drill →
🎯
DRILL 05

My 3-Action Plan

The capstone: choose the 3 things you’ll actually do this week — one must be a phishing/verification habit — and get a printable commitment card to keep.

Fits: the closing 3-Action Challenge
Build my plan →
DRILL 06

Quick-Fire Games

Three fast rounds: Domain Detective (SAFE/PHISH links), WiFi or Why-Not? (safe/risky networks), and “Is This OK?” (PDPA data calls). Scored, with an instant why.

Fits: the morning mini-games (Domain Detective, WiFi or Why-Not?, "Is This OK?")
Play →
🔒
DRILL 07

Ransomware Simulator

Open the booby-trapped invoice and watch the business's files get locked — then choose: pay, restore from backup, or report. Learn why backups beat the ransom.

Fits: morning Malware & Ransomware topic
Run the sim →
Trainer note. A slide deck + four hands-on drills, tailored for P.S. Cafe group functions (HR · Finance · Ops). All content is fictional and self-contained — open directly in any browser or host as static files (see README.md). Pair with the facilitator run-of-show and the afternoon exercise guides.
Practical Cyber DACTA