Topics inside this course
Awareness and induction depth — not an accredited occupational qualification.
- How ransomware arrives, without exploit detail
- Symptoms: encryption notes, missing shares, locked screens
- First actions: report, don’t pay, don’t freelance a fix
- Unofficial USB backups are not a strategy
- Link to phishing and incident-reporting courses
Built for the people who take the training
All staff with devices or shared-drive access, including people who think ransomware is “an IT problem”.
What learners leave able to do
- Recognise likely ransomware symptoms without becoming a malware analyst
- Report immediately and follow the playbook (including don’t pay unless policy says otherwise)
- Avoid unofficial backups and mystery USB “fixes”
- Connect this module to phishing and incident reporting rather than treating it as a one-off scare
Modules you can expect
Structure may tighten when you localise from your own source pack in Kre8AI — this is the shape of the library title.
- 1What ransomware is
Business interruption, not a movie hacker.
- 2How it gets in
Phish, stolen passwords, exposed remote access.
- 3If it looks wrong
Stop, report, follow the playbook.
- 4Don’t make it worse
Paying, wiping, unofficial tools.
- 5Knowledge check
Short scored assessment.
Short scored assessment. Not malware analysis, threat-actor negotiation, or a legal position on payment unless the policy states one.
Written for the workplace, not for the statute book alone
Ransomware courses that only show a skull wallpaper do not change the first five minutes. This module is those minutes: symptoms, reporting, not paying, not running a cousin’s “decryptor”, not hiding the pop-up until Monday.
How it arrives is named at awareness level — phishing, reused passwords, careless remote access — without teaching anyone to exploit a system. Depth lives in the phishing, passwords, and incident-reporting titles.
Backups are described as an organisational control staff must not undermine with shadow copies of customer data on personal drives. Payment is a policy decision; the course does not freelance one.
Generate from CISA/NCSC pages and your IR staff page in Kre8AI. Export as SCORM or HTML. Keep it short enough to assign after a simulation.
Pair with cybersecurity awareness for the annual core, and with incident reporting as the spine. Re-export when the playbook’s first-action steps change.
Play the library demo, or generate ransomware awareness from your IR pack in Kre8AI.
What you would upload in Kre8AI
Incident response playbook, backup awareness FAQ
- CISA StopRansomware staff pages
- NCSC ransomware guidance — staff sections
- Your incident-response playbook (staff page) and backup FAQ
Formats, coach and provenance
- Standalone HTML to play in the browser; SCORM 2004 for your LMS.
- Optional AI course coach on Growth and Scale — grounded in approved material; off on quizzes and final assessment by default. Course plays offline; coach needs a network.
- Built in Kre8AI and reviewed before we published it. Not a substitute for your organisation's own policy — review before you make it mandatory.
Get the SCORM package while you are here.
Same course, SCORM 2004. Load it to settle the tracking question — and keep it as a course your people can take after you review it.
Request the package
SCORM 2004 zip. We ask for an email so we know which LMS you are testing — and so we can send the download.

