Recognise the Threat. Know Your Next Move.
Practical cyber awareness for everyday users, developers, and business teams. Learn how attacks appear in real workflows, what to question, and how to respond.
Current Attack Methods
Awareness Guides
Short, practical guides with warning signs, safer habits, response steps and a quick knowledge check.
Showing 23 of 23 guides
Think Before You Click
Spot impersonated senders, urgent requests and suspicious attachments, then verify independently.
One Account. One Unique Password.
Use unique passwords, a password manager and MFA, and respond quickly when a password is exposed.
Your OTP. Your Eyes Only.
Keep verification codes private, reject approval prompts you did not start, and report them.
A CAPTCHA Never Needs a Command
Recognise pages that ask you to paste something into Run, PowerShell or Terminal to “verify” or “fix” a problem.
Scan With Suspicion
QR codes in emails, documents or posters can hide sign-in pages or payment requests. Inspect before acting.
Real IT Will Not Rush You
Calls or chats requesting remote access, software installs, resets or MFA approval need independent verification.
Read What You Are Allowing
Apps that ask to “read your mail” or “access your files” can keep that access even after you change your password.
A Real Sign-In Page, the Wrong Person
Someone asks you to enter a code on a genuine sign-in page. Doing so can sign them into your account.
MFA Helps. It Is Not Magic.
Some phishing kits steal your signed-in session after MFA. Phishing-resistant sign-in closes that gap.
Know What the QR Code Connects
A code presented as “join this group” can actually link another device to your messaging account.
The Assessment Is the Attack
Fake recruiters ask developers to clone and run a project. Verify the recruiter and isolate any assessment.
Opening a Folder Can Run Code
Editor tasks, extensions and install scripts in unfamiliar projects can execute automatically. Use restricted mode.
Popular Is Not the Same as Safe
Look-alike package names, unexpected dependency changes and install scripts can bring malware into builds.
Read Before You Run
Fixes in issues, chats, tutorials or AI answers can hide harmful commands. Review the command and its source.
Keys Leak Faster Than You Think
Protect .env files, API keys, GitHub tokens, SSH keys, cloud credentials and debug logs.
Check the Dashboard, Not the Email
Messages claiming your repo, package or account will be suspended are a common lure. Verify on the platform itself.
Helpful Tools Still Need Permissions Reviewed
Review what AI assistants and extensions can access, avoid sharing secrets, and inspect generated code.
Your Pipeline Holds the Keys
Review workflow changes, third-party actions, token permissions and secret access. A related technical-security module.
A Familiar Voice Is Not Verification
Apparent executive instructions by email, voice note or video need a known-channel callback and normal approvals.
New Bank Details? Call First.
Invoice changes and new bank accounts must be verified through contacts established before the request.
Not Every Candidate Is a Candidate
Suspicious CV attachments, candidate portfolio links and software-install requests target HR teams.
Verify Before You Reset
Follow approved identity checks before password resets, MFA resets or device enrolment, even under pressure.
Chat Feels Safe. Verify Anyway.
Suspicious requests through Teams, Slack, WhatsApp and shared documents need the same checks as email.
Free Checklists
One-page checklists built from the guides. Print them or save them as PDF.
Everyday Cyber Safety Checklist
Phishing, passwords, MFA, ClickFix, QR codes, fake IT support and account linking.
Developer Security Checklist
Recruiter tests, repos, dependencies, commands, secrets, AI tools and CI/CD.
Awareness Sessions
Sessions for Your Team
Tell us your audience and goals, and we will shape the session around them.
Cyber Awareness Training
Phishing, accounts, MFA and current social engineering methods for everyday staff and students.
Developer Security Awareness
Fake recruiters, malicious repos, dependencies, secrets and pipeline hygiene for engineering teams.
CTF Access / Technical Labs
Hands-on investigation challenges on the WazuGuardix CTF platform for technical learners.
Build a Security-Aware Team
The request form opens your email app with the details prefilled. You press Send.