Phishing messages are designed to look legitimate and to make people act before they have time to think.
For a non-technical employee, knowing that phishing is a threat isn't necessarily enough. They need to recognize the warning signs, pause when something feels suspicious, and know what to do next.
The goal was to create a short cybersecurity awareness experience that would make technical information approachable while giving learners opportunities to practice recognizing and responding to common phishing situations.
By the end of the training, learners will be able to:
Given a sample email, identify common phishing indicators, including a suspicious sender address, urgency language, and potentially unsafe links, with 100% accuracy on the knowledge check.
Select the appropriate reporting action for a suspected phishing attempt.
Apply secure password practices when creating or updating credentials.
I designed a 5-8 minute cybersecurity awareness course for a non-technical workplace audience.
The experience puts learners directly into the problem rather than starting with a list of cybersecurity definitions. Learners examine a simulated phishing email, identify the clues that make it suspicious, explore common phishing indicators, and practice deciding how to respond.
The course also covers secure password practices and reporting behavior through interactive knowledge checks, an accordion interaction, and a short Camtasia video.
Cybersecurity information can become very technical very quickly. I wanted the learning experience to feel relevant to employees who don't think of themselves as "technical" people.
Instead of asking learners to memorize a list of phishing terminology, I started with a situation they could realistically encounter: an email that looks legitimate and creates pressure to act quickly.
The course follows an "explain, show, practice, assess" progression. Learners first see what to look for, then practice identifying warning signs and deciding how to respond.
The goal wasn't simply for learners to recognize the word "phishing." It was to help them slow down, notice the clues, and know what to do next.
Articulate Rise 360, Camtasia, and Canva
Non-technical audience: I avoided unnecessary cybersecurity jargon and focused on observable behaviors learners could recognize in their own inboxes.
Realistic context: The simulated phishing email allows learners to examine the kinds of cues they may encounter in an actual workplace message.
Immediate feedback: Knowledge checks explain why an answer is correct or incorrect so learners can connect the feedback to the warning signs they should watch for.
Short-form learning: The course focuses on a small set of high-value behaviors rather than attempting to cover every aspect of cybersecurity awareness.
Visual clarity: Information is broken into focused sections and supported with visuals to make technical concepts easier to process.
Accessibility: The experience uses clear visual hierarchy, readable text, intentional interaction design, and accessible alternatives for visual content.
This project taught me how much translation is involved in designing technical training for a non-technical audience.
The challenge wasn't simply deciding what cybersecurity information to include. It was figuring out how to turn that information into something people could recognize and act on in the middle of a busy workday.
If this were implemented in a real organization, I would want to evaluate more than whether learners completed the course or passed the knowledge checks. I'd look at behavioral measures such as results from simulated phishing exercises and whether employees are reporting suspicious messages more consistently.
If I expanded the course, I'd add more varied phishing scenarios, including messages that are less obviously suspicious, or give learners additional practice recognizing the subtle cues that can make these attacks difficult to spot.