Camp Fire Academy
Learning path
Complete UI/UX Masterclass UI/UX Design Foundations UI/UX Design Intermediate Advanced UX Strategy
Specialisations
Fintech & Banking UI/UX UI/UX with AI Training UX for Leaders Design Thinking Figma Training
Most requested
AI for Workplace Productivity Excel for Business Power BI & Business Intelligence Cybersecurity Awareness PDPA Compliance Data Protection Officer Browse the full catalogue →
For teams
Corporate & In-House Training LMS & Self-Paced Learning Events
Company
About Contact Verify Certificate WhatsApp

Ransomware & BEC Awareness Training

Two attacks account for most of the money Malaysian companies lose to cybercrime, and neither of them needs a sophisticated hacker. Ransomware arrives through an attachment, a stolen password or an unpatched remote access service. Business email compromise arrives through a convincing message asking someone in finance to change a bank account. This programme takes both apart in front of the people most likely to meet them, then rehearses the response until it becomes reflex rather than panic.

Programme Agenda

How Ransomware Actually Gets In

The four routes that account for almost every case: phishing attachments, credential reuse, exposed remote desktop, and an unpatched internet-facing device. Real Malaysian and regional incidents traced from first click to encrypted file server.

The Hour After the Screen Changes

Who disconnects what, who calls whom, and the decisions that quietly destroy evidence. Isolation without powering down, preserving logs, and why the ransom note is not the first thing to read.

Backups That Survive the Attack

Why the backup is usually encrypted too. Offline and immutable copies, restore testing, and the uncomfortable question of how long a full restore actually takes for your systems.

Business Email Compromise: the Long Con

Mailbox compromise, thread hijacking and lookalike domains. How an attacker sits inside a conversation for weeks before sending the message that matters, and the small tells that give it away.

Invoice Redirection and Bank Change Fraud

The single control that stops most losses: verifying a bank detail change out of band, against a number you already held. Building it into the payment process so it cannot be skipped under pressure.

Executive Impersonation and Urgency Pressure

Why a message from the managing director asking for a quiet, urgent transfer works. Authority, secrecy and time pressure as attack tools, and giving staff explicit permission to slow down.

Reporting: Internally, and to the Authorities

Escalation inside the company, the PDPA notification clock where personal data is involved, reporting to the bank in time to attempt a recall, and lodging with the police and the National Scam Response Centre.

Tabletop: Friday Afternoon, Encrypted Servers

A facilitated scenario run against your own environment. Participants make the calls in sequence and the group reviews where the plan held and where it did not.

Learning Outcomes:
Recognise the common delivery routes for ransomware before the payload runs
Take the right first three actions when a device shows signs of encryption
Judge whether a backup strategy would actually survive a ransomware event
Spot thread hijacking, lookalike domains and mailbox compromise in day-to-day email
Apply out-of-band verification to every bank detail change without exception
Resist urgency and authority pressure in payment requests
Escalate and report an incident within the internal, banking and regulatory deadlines

Duration: 1 Day (8 Hours)
Training Hours: 9:00 AM to 5:00 PM
Level: Beginner
Training Mode: Physical, Online, or Hybrid
HRD Corp SBL-KHAS Claimable
Certificate of Completion included

Frequently Asked Questions

Finance and accounts payable staff, executive assistants, procurement, HR, and anyone who can move money or change a supplier record. IT teams attend to run the technical half of the tabletop, but the material is written for non-technical staff.

No. General awareness covers passwords, phishing and device hygiene across the board. This programme goes deep on the two attack types that cause the largest financial losses, and spends most of the day on payment controls and response rather than on prevention theory.

None. Every technical concept is introduced through the decision a non-technical employee has to make. The tabletop exercise is run in business terms.

Yes. For in-house sessions we build the scenario around your actual approval chain, banking arrangements and escalation contacts, so the rehearsal matches what people would really do.

Yes, this programme is HRD Corp SBL-KHAS claimable. Our team can assist your HR department with the documentation required for the grant application.

Yes. Any programme can be booked as a team day. Everyone works the same brief together, so your people come away having built something and knowing each other better.

If you are claiming under HRD Corp, the session has to fall at least 14 days after your HRD Corp approval. If you are not claiming, the date is flexible and we work around your calendar.

Put them on the self-paced e-learning instead. Your team works through the modules on our LMS in their own time, sits the assessment, and earns the same certificate, so nobody has to clear a full day together.

More in Cybersecurity