Phishing and Email Security
Spot the message that is trying to trick you, and know exactly what to do next
- Duration
- 1.5 hours
- Modules
- 4
- Final exam
- 70% to pass
- Certificate
- No expiry
- Lifetime access to the course and your certificate
- Verifiable Certificate of Completion. Certificate does not expire.
- 3 exam attempts
- Progress saved to your account on every slide
Buying for a team? Volume pricing from 5 seats
| 1 to 4 seats | List price |
| 5 to 10 seats | 15% off |
| 11 to 20 seats | 25% off |
| 21 or more seats | 35% off |
$250.75
5 × $50.15 · save $44.25
Each seat is a single-use code. Send one to each learner; they sign in with their own account and earn their own certificate. Track progress on your Team page.
About this course
Most cyber incidents at defense suppliers start with one person acting on one message. The message might be an email that looks like it came from your prime contractor, a text that looks like it came from your boss, a QR code on a poster, or a push notification asking you to approve a login you did not start. This course teaches you to recognise each of these and to act safely in the few seconds that matter.
You will learn why small and mid-sized suppliers are targeted for controlled unclassified information, federal contract information and payments, how to inspect a sender, a link and an attachment, and what artificial intelligence has changed about the phishing you now receive. You will practise with realistic scenarios drawn from machine shops, purchasing desks and programme offices, each with a decision to make.
The course is written for every employee of a company that holds or is preparing for a DoD contract. It is awareness-level training that supports the awareness and training requirements of NIST SP 800-171 Rev 2 (3.2.1 and 3.2.2) and the CMMC Awareness and Training domain. It explains the DFARS 252.204-7012 rapid reporting obligation so that you understand why your company needs to hear from you within minutes, not days. Always follow your own company's procedures and your security officer's direction.
The course closes with a 10-question examination drawn from a bank of 20. On passing you receive a PlanetISO Certificate of Completion with lifetime access to the course content and your certificate. The certificate does not expire.
What you will be able to do
- Explain why defense suppliers are targeted and what attackers want from a phishing message.
- Distinguish spear phishing, whaling, business email compromise, smishing, vishing, QR code phishing, MFA fatigue and consent phishing.
- Inspect a sender address, a link and an attachment and identify the signs of a lookalike or a lure.
- Apply safe habits for multi-factor authentication, passwords, payment changes and handling controlled information in email.
- Decide the correct action in realistic phishing scenarios, including when to stop and verify by a second channel.
- Describe what to do in the first 10 minutes after clicking a bad link or entering a password on a fake page.
- State the internal reporting path and explain how it supports the company's 72-hour DoD reporting obligation.
Course outline
- 1
What phishing is and why defense suppliers are targeted
What attackers want from a small or mid-sized defense supplier, the forms phishing takes today, and the requirements that make this training part of your contract.
About 20 minutes, then a module quiz
- 2
Spotting a phishing message
How to read a sender, a link and an attachment in 10 seconds, the pressure cues attackers rely on, shared-document lures, fake login pages and what AI-written phishing has changed.
About 20 minutes, then a module quiz
- 3
Safe habits and what to do if you clicked
Multi-factor authentication, password managers, second-channel verification, keeping work data off personal mail, encrypted email for controlled information, and the first 10 minutes after a mistake.
About 20 minutes, then a module quiz
- 4
Scenarios and the reporting path
The DFARS 72-hour clock, your internal reporting path, and 5 realistic situations with a decision to make in each.
About 25 minutes, then a module quiz
Final examination and certificate
10 questions drawn from the course bank. Score 70% or higher to receive your Certificate of Completion.
More CMMC and NIST SP 800-171 training
- CMMC and NIST SP 800-171Short course
CMMC Level 2 and NIST SP 800-171 Overview
What a Level 2 assessment expects, how the 110 requirements are organized and how to build a program that passes
- Duration
- 3 hours
- Level
- Foundation
$99View course - CMMC and NIST SP 800-171Awareness
Insider Threat Awareness
Recognize and report the indicators that protect your colleagues, your company and controlled information
- Duration
- 1.5 hours
- Level
- Foundation
$59View course - CMMC and NIST SP 800-171Awareness
Social Engineering Prevention
Recognize manipulation in person, on the phone and online, and verify before you act
- Duration
- 1.5 hours
- Level
- Foundation
$59View course - CMMC and NIST SP 800-171Awareness
CUI Handling and Marking
Recognize controlled unclassified information, mark it correctly and handle it safely
- Duration
- 1.5 hours
- Level
- Foundation
$59View course - CMMC and NIST SP 800-171Awareness
CMMC Level 1 Overview
The 15 basic safeguards for federal contract information and how the annual self-assessment works
- Duration
- 1.5 hours
- Level
- Foundation
$59View course