Information security training at Bodhih is a practical awareness program that helps all employees protect company and customer data. It covers phishing and social engineering, passwords and multi-factor authentication, safe device and network use, data privacy, secure use of AI tools and incident reporting. It is customised to each organisation's policies and delivered in person or live virtual.
- Standard duration: 1-day, customisable to your needs
- Delivered in person at your location or as live virtual sessions
- Designed with the ADDIE model and evaluated for behaviour change
- Offered by Bodhih since 2008 to 2,000+ organisations across 7 regions
Where and how: information security training as an in-person workshop in Bengaluru, Mumbai, Delhi NCR, Gurugram, Hyderabad, Chennai, Pune, Kolkata, Ahmedabad and Jaipur; as a live online course; or delivered overseas in Dubai, Singapore and across the Middle East, Asia and Africa.
Data Protection and Data Privacy
Program Overview:
- Securing your Endpoint Devices and Organization Networks
- Data Theft Protection tips for Cellular Devices
- Protecting Your Personal Identity
- Protecting Your Online Transaction and Credit Information
- Protecting Your Data on Social Networking
- Secure While you Surf Data Online
- Countermeasure Data Breach standing the MicroStrategy architecture.
Training Duration:
1-day Instructor Led Training
Target Audience:
This is a common program for all the employees who work in a IT environment and handling customer data is a part of their work profile.
Training Prerequisite:
Basic Computer Knowledge.
Training Outcome:
- Practical Approach
- Hands on training session
- Real time project and case studies
- 24/7 support
Solutions & Services
What participants will be able to do
Recognise phishing and social engineering
Participants spot suspicious emails, messages, calls and QR codes, including AI-generated scams.
Protect accounts
Employees use strong passphrases, password managers and multi-factor authentication correctly.
Secure devices and connections
Participants keep laptops and phones updated, locked and safe on public networks.
Handle personal and customer data responsibly
Employees apply data classification, minimisation and privacy principles in daily work.
Use AI and cloud tools safely
Participants know what information must not be pasted into public tools or shared through unapproved apps.
Report incidents quickly
Employees know what counts as an incident and exactly how to report it.
Who should attend
- All employees who handle customer or company data
- Customer support, sales and operations teams working with personal information
- New joiners as part of induction
- Managers who must reinforce security behaviour in their teams
- Remote and hybrid staff working from home or on the move
Recommended program outline
Recommended design, customised to your context after a short needs analysis.
01Why information security mattersModule 1 · 1 hour+
- The CIA triad: confidentiality, integrity and availability
- How attackers target people rather than systems
- Individual responsibilities under company policy
- Recent attack patterns explained in plain language
02Phishing and social engineeringModule 2 · 1.5 hours+
- Email, SMS, voice and QR code phishing
- Deepfakes and AI-generated impersonation scams
- Hands-on exercise: spot the phish
- What to do after clicking a suspicious link
03Accounts, devices and networksModule 3 · 1.5 hours+
- Passphrases, password managers and multi-factor authentication
- Endpoint and mobile device security
- Safe browsing, public Wi-Fi and VPN use
- Physical security, clean desk and screen locking
04Data protection and privacyModule 4 · 1.5 hours+
- Data classification and handling rules
- Privacy principles and data protection law in overview, such as India's DPDP Act
- Protecting identity, transactions and data on social networks
- Safe use of public AI tools, file sharing and USB drives
05Incidents and everyday habitsModule 5 · 1.5 hours+
- Recognising a data breach or security incident
- Reporting steps and first actions
- Scenario walk-throughs and a personal security checklist
- Quick quiz to confirm key learnings
When to choose this
Frequently asked questions
What is information security awareness training?
Information security awareness training teaches employees how to recognise and avoid common threats, protect accounts and devices, and handle data safely. Because many breaches start with human error or manipulation, it is a core part of any security program. Bodhih's one-day program is practical and scenario-based, and it is customised to your policies.
How often should employees receive security awareness training?
Most organisations run security awareness training at least once a year, with new joiners covered at induction. Short refreshers in between help, because threats such as phishing change quickly. Bodhih can pair the core program with shorter follow-up sessions or e-learning modules through Bodhih.org to keep the key messages fresh.
Does the training cover India's data protection law?
Yes, at an awareness level. The program explains the key ideas behind India's Digital Personal Data Protection Act, such as consent, purpose limitation and handling personal data responsibly. It is not legal advice, and it is aligned with your own policies. Teams in other regions can have examples from their applicable regulations instead.
How do you train employees to recognise phishing?
The most effective approach is practice. Participants examine realistic sample messages, identify warning signs such as urgency, mismatched links and unusual requests, and discuss what to do next. The program also covers phone, SMS, QR code and AI-generated scams. Clear reporting steps ensure people know how to act on a suspicious message.
Is this program suitable for non-technical staff?
Yes. It is designed for all employees, not IT specialists, and uses plain language and everyday examples. The only prerequisite is basic computer knowledge. Technical teams who need deeper security skills, such as secure coding or DevSecOps, can take a separate technical program customised for their roles.
Who is the Information Security program for?
This is a common program for all the employees who work in a IT environment and handling customer data is a part of their work profile.. Bodhih tailors the examples, case studies and depth to your industry, culture and team level.
How long is the Information Security program?
The standard program runs 1-day. Bodhih can shorten or extend it to fit your goals and schedule.
Can Information Security be delivered online?
Yes. Information Security can run in person at your location, as live virtual sessions for distributed or hybrid teams, or as a blended journey that adds self-paced learning on Bodhih.org between sessions.
How is the impact of Information Security measured?
Success measures for Information Security are agreed with you before design, as part of the ADDIE model. Bodhih can add pre- and post-program assessments on AssessAll and manager check-ins to track behaviour change.
