SECURITY FUNDAMENTALS FOR EVERYONE
Cybersecurity Basics in the Age of AI
Starts with a real fraud in which an employee verified a suspicious request, received convincing confirmation, and still lost 25 million dollars. No prior security background needed, and every module ends with something you can apply the same day.
- 6 modules
- 18 lessons
- 7 quizzes
- 80 questions
- About 9 hours
Free — no enrolment needed
Course syllabus
Six modules build in order: what AI changed and what it did not, the foundations that still hold, identity as the new perimeter, social engineering after fluent generated text, attacks on AI systems themselves, and everyday practice including the first hour of an incident. Each module ends with a quiz, and a final assessment covers all six. Every lesson and every quiz is free.
1. What AI Changed, and What It Did Not
A real deepfake fraud that cost 25 million dollars, the four attack moves that have not changed in thirty years, and an honest account of which parts of the threat landscape AI genuinely rewrote. Separates the shift that matters from the marketing noise around it.
- The Twenty Five Million Dollar Video CallFree lesson
- The Four Moves Behind Every AttackFree lesson
- What Actually ChangedFree lesson
- What AI Changed, and What It Did Not: QuizFree · 10 questions
2. The Foundations That Still Hold
The three properties every security control protects, the single highest value habit in the field, and the reason no defence should ever be asked to work alone. A small mental toolkit that applies to technologies invented after this course was written.
- The Three Properties Worth ProtectingFree lesson
- Least Privilege, the Highest Value HabitFree lesson
- Defence in Depth, and Why Nothing Works AloneFree lesson
- The Foundations That Still Hold: QuizFree · 10 questions
3. Identity Is the New Perimeter
Attackers mostly do not break in, they log in. Why the office network stopped being the boundary, how real time phishing defeats the multi factor authentication most people use, and the specific configuration that makes the whole attack class stop working.
- Why Attackers Log In Rather Than Break InFree lesson
- The Authentication LadderFree lesson
- Passwords, Managers, and What to Do This WeekFree lesson
- Identity Is the New Perimeter: QuizFree · 10 questions
4. Social Engineering, Upgraded
Why hunting for typos stopped working, the four part structure underneath every manipulation attempt regardless of how polished it is, and a mechanical verification procedure designed to work under pressure when judgement will not.
- Why Spotting Flaws Stopped WorkingFree lesson
- The Four Part SkeletonFree lesson
- The Verification RitualFree lesson
- Social Engineering, Upgraded: QuizFree · 10 questions
5. When the AI Itself Is the Target
Prompt injection explained from first principles, why it is a design constraint rather than a bug awaiting a patch, the OWASP Top 10 risks for language model applications in plain language, and the two failures that most often turn a manipulation into a real incident.
- Prompt Injection, From First PrinciplesFree lesson
- The OWASP Top Ten in Plain LanguageFree lesson
- Excessive Agency and Untrusted OutputFree lesson
- When the AI Itself Is the Target: QuizFree · 10 questions
6. Everyday Practice and the First Hour
The risk you create yourself by pasting company data into AI tools, an honest account of where AI genuinely helps defenders and where it will fail you, and exactly what to do in the hour after you realise something has gone wrong.
- Shadow AI and the Paste TestFree lesson
- Defending With AI, HonestlyFree lesson
- The First HourFree lesson
- Everyday Practice and the First Hour: QuizFree · 10 questions
- Final AssessmentFree · 20 questions
Source and attribution
Independently written by Srileo Technologies, and vendor-neutral. The real-world cases it discusses are cited to their published sources so you can read the originals: the 2024 Arup deepfake fraud as reported in the trade press and catalogued in the AI Incident Database, the OWASP Top 10 for Large Language Model Applications, Anthropic's published threat reports on AI-assisted intrusion and extortion, and the 2023 Samsung chatbot data leak. Prevalence figures for deepfake and voice-cloning fraud move quickly and originate largely with security vendors; where a number is soft the lesson says so and states the base rate rather than a headline percentage.