Cyber course

Cyber course

First hour decides. Phishing, accounts, data and incident procedure for management and operation.

Lecturer and participants with laptops for training — cyber course for the team

Division Director GBH Cyber

Adam Schinzel

Your cybersecurity is not driven by a marketer, but by an engineer.

He built secure systems for IBM and Trezor. Now they are building them for your organization.

Adam Schinzel, Division Director GBH Cyber
NIS2 specialist NÚKIB IBM Vault (SatoshiLabs)

1 day

practical team course

10-25

management, IT, operation

NIS2

comprehensible for management

First hour

what to do in an incident

Data, traffic and roles. One procedure for the first hour

Lecturer and participants with laptops for training — cyber course for the team Team course

Practical impact

People need to know who to call, what to disconnect and what to let run.

The course doesn't matter cyber security by layers. Accounts, dates, physical operation and human roles will be put together in such a way that no one improvises in the incident.

  1. 01

    Data

    Accounts, backups and critical data. Do you know who holds them and how to recover them?

  2. 02

    Traffic

    The network, cameras and building mode run 24/7. The course links them with data into one procedure.

  3. 03

    Role

    Management, IT and reception. Everyone knows what they are doing in the first hour of an incident.

Less fear of cyber. More concrete decisions

We build the course for people who incident they really pick up the phone, open the door or make traffic decisions.

A laptop with a fraudulent email and a hand on the mouse — phishing

01

Phishing and social engineering

The team recognizes the risk and knows who to pass the incident on to.

Hand with phone and verification code at keyboard — accounts and access

02

Accounts, access and roles

Accounts, cameras and administration have an owner.

Modern server room in blue light — backups and data recovery

03

Data and backups

Critical data has clear recovery.

Security camera on the building guarding the outdoor area

04

Cameras and physical mode

Cyber ​​sits on the building, cameras and entrances.

Smaller computer security team — incident response

05

Incident in the first hour

First phone call, decision and isolation.

Two female experts go through documents — NIS2 duties and NÚKIB

06

NIS2 / NÚKIB no chaos

We translate duties into steps for management.

The team leaves the course with progress, not just an impression

We do not deal with cybernetics in isolation. We will connect dates, people, building and management decision making.

  1. 01

    Quick screening

    Accounts, data, cameras, suppliers, crisis contacts.

  2. 02

    Real scenarios

    Phishing, lost device, data leak, camera outage.

  3. 03

    Division of roles

    Management, IT, reception, operation and communication in one procedure.

  4. 04

    Action plan

    What to change now, what to plan and what belongs to the audit.

A course for organizations where a cyber incident stops the normal day

The school building as an operation that must run even during the incident

01

School directors and founders

You protect student data, teacher accounts and cameras. In the course, you will receive a clear procedure, not another directive in a drawer.

Lecturer and executives at laptops for training

02

Company management and operational directors

When cyber stops production or billing, you decide. You will learn what to do in the first hour and who to call.

Detail of a network switch with cables — network operation and accounts

03

IT administrators without their own security team

You keep the network, accounts and backups yourself. You'll leave with a process you can handle even without a SOC behind you.

A laptop with a fraudulent email and a hand on the mouse — phishing at the reception desk

04

Reception, administration and data access people

The attack starts with one click on the reception desk. You can recognize phishing before you open the attachment and know who to forward it to.

Two female experts go through documents — NIS2 duties and NÚKIB

05

Organization dealing with NIS2 / NÚKIB

We will translate the obligations into steps that you can defend in front of management and the regulator. No legal chaos.

A smaller computer security team — a clear incident procedure

06

Teams that need a clear incident procedure

Instead of improvising, you leave with a plan: who isolates, who communicates, and who decides on traffic.

GBH Cyber

When an incident comes, it can't just stay with IT.

The course connects employees, account managers, reception and management. We train for the first hour: recognizing an attack, who to pass it on to, what to limit and how to maintain traffic.

Know the attack

Submit an incident

Restrict access

Keep running

Ask for a course
Analytical workplace GBH Cyber

The first hour of the incident

Who's calling What to turn off. To whom to pass.

A technical problem quickly becomes an operational crisis. The course gives people a concrete procedure, not another presentation.

Security operational supervision of incidents
SOC
Detail of network cable in server infrastructure
Network
Verification of physical entry to the object
Entrance

Most of these attacks started in humans. That's why we train people

Publicly documented Czech incidents that were triggered by one click or an open attachment. The course trains exactly that moment — how phishing know who incident to pass and what to do in the first lesson.

The historic building of the Rudolf and Stefanie Benešov Hospital (Máchova 400) — the target of the 2019 ransomware attack Logo of Czech Television / ČT24

December 2019 Ryuk ransomware

Benešov Hospital

On December 11, 2019, ransomware crippled hospital systems. Full operation did not resume until December 30, the damage exceeded 59 million crowns.

What we do with it: It started with email and poorly protected accounts. Cyber ​​audit examines exactly these entry points.

Source: Czech Television (ČT24)
Campus of the Faculty Hospital Brno-Bohunice Aktuálně.cz logo

March 2020 · ransomware, the day after the state of emergency was declared

University Hospital Brno

On March 13, 2020, a day after the state of emergency was declared, an attack encrypted the systems of the country's second largest hospital. Postponed operations, provisional damage of 150 million crowns.

What we do with it: One open attachment stopped the operation. That is why in the course we train phishing recognition and the procedure of the first hour.

Source: Aktuálně.cz

268

of cyber security incidents recorded by NÚKIB in 2024 — the most so far, most often in the public sector

Source: NÚKIB, Report on the state of cyber security of the Czech Republic (2024)

Cybersecurity is no longer voluntary.

NIS2 and the new Cyber Security Act shift responsibility to management. An audit and a prepared team will cost less than a fine, downtime and data loss.

up to €10 million

or 2% of turnover — fines according to NIS2

Management is responsible

personal responsibility for the measures taken

24 / 72 h

statutory deadlines for reporting an incident

Suppliers

you are also responsible for the supply chain

Training that sticks to practice

Phishing, traffic analysis i risks on mobile — a day with the team, shot by shot.

Demonstration of a phishing attack on the screen
Phishing
Cyber security analyst at workplace with monitors
Traffic analysis
Security Operations Center GBH Cyber
Operations Center
Students work with artificial intelligence tools
Working in a group
Student on mobile phone
Risks in mobile
Is the course technical?

It is practical. Management, operations and IT get a common language: what is the risk, who has what role and what to do in the first minutes of an incident.

Does it follow up on a cyber audit?

Yes. The course can stand alone, but it makes the most sense after auditing accounts, data, cameras and suppliers. The audit will find weaknesses, the course will teach the team to react.

Is it suitable for schools?

Yes. Schools deal with student data, staff accounts, cameras, suppliers and crisis communications. The course translates cyber risks into normal school operations.

Cyber course

Let's prepare the team for an incident that must not be driven by improvisation

Just describe the organization, the number of people and the current problem. We will return the recommended rate range.

A cyber course for your team

Write whether you are dealing with a school, company or institution, the number of participants and the main concern. We will propose a specific course.