Safer everyday decisions

Cybersecurity awareness workshop for non-technical staff

The team practices how to pause, verify, protect information, and escalate a suspicious signal without relying on unnecessary technical explanations.

This is an educational awareness activity. It does not replace audits, penetration tests, legal advice, compliance work, or professional incident response.

Non-technical staff identify phishing signals during a guided exercise.

Signals of need

When one click, call, or file can create exposure

The workshop helps build shared language and responses for situations any department may encounter.

Urgent messages

Emails or chats pressure people to open links, provide data, or bypass a process.

Fragile access

Reused passwords, automatic approvals, or open sessions increase exposure.

Overshared data

Staff do not always distinguish which information requires protection or authorization.

No incident path

Someone notices something unusual but does not know what to preserve, report, or avoid.

Practice outcomes

Behaviors that can be rehearsed and reinforced

Awareness reduces uncertainty but does not eliminate risk or replace technical and management controls.

Verification

Questions and alternate channels for checking unusual requests before acting.

Access protection

Practices for passwords, multifactor authentication, and shared sessions.

Data care

Basic criteria for storing, sending, and disposing of work information.

Initial escalation

An agreed path for reporting signals while avoiding actions that destroy evidence.

Adaptable content

Situations that can become practice

Available virtually or in person in Panama; virtual for other countries. Conditions are confirmed in the proposal.

  1. 01 Social engineering, phishing, and verification.
  2. 02 Passwords, MFA, and work devices.
  3. 03 Classification and responsible transfer of data.
  4. 04 Remote work, networks, and updates.
  5. 05 Initial reporting and coordination with internal owners.

Prepare the proposal

Start from the risks staff actually face

Scope is adapted to the sector, work channels, and existing procedures.

Request a proposal and quote
  • Roles and departments participating.
  • Channels and devices used for work.
  • Situations or incidents they want to prevent.
  • Current internal reporting path.

Frequently asked questions

Is technical knowledge required?

No. The workshop is designed for non-technical staff and everyday decisions. A specialized IT scope should be defined separately.

Does it include phishing simulations?

It can include controlled workshop exercises. A live email campaign, individual tracking, or external testing is performed only when expressly authorized and scoped.

Does it meet a standard or guarantee compliance?

No. It can support awareness objectives but does not certify or guarantee legal, regulatory, or standards compliance.

Is it a security audit?

No. It does not assess technical vulnerabilities or replace an audit, penetration test, or professional controls review.

What delivery format is available?

Panama may contract virtual or in-person delivery; outside Panama, delivery is virtual. Duration, group, and exercises are confirmed in the proposal.

Initial response improves when everyone knows how to pause, verify, and report

Share the roles, channels, and priority situations so we can prepare an understandable, responsible workshop.

Crezendo is a registered nonprofit foundation in Panama dedicated to elevating human potential through education. We train individuals, teams, and organizations across Latin America in programming, web development, leadership, emotional intelligence, business skills, and technology repair — because access to quality training should not depend on where you were born or how much money you have. We also accept donations of computers, laptops, consoles, cell phones, and electronics in any condition, which become hands-on learning tools for our tech training programs.