Cyber Security Awareness: Phishing and Whaling
Your team is the weakest link in your security posture—and attackers know it. This course cuts through the noise to show you exactly how phishing and whaling attacks work, why they succeed, and how to spot them before they land. In under an hour, you’ll gain the awareness that transforms employees from liability into your first line of defence.
AIU.ac Verdict: Essential for anyone handling email or sensitive data, from support staff to senior leaders. Todd Edmands delivers practical, immediately applicable threat recognition without unnecessary jargon. The main limitation: it’s awareness-focused rather than technical remediation, so you’ll need complementary security controls in place.
What This Course Covers
The course dissects real-world phishing and whaling attack vectors, examining how threat actors craft convincing messages, exploit trust, and manipulate psychology to bypass technical controls. You’ll learn to recognise red flags in sender addresses, links, attachments, and urgency tactics—the hallmarks of both mass phishing campaigns and targeted whaling attacks aimed at executives. Practical scenarios show how these threats manifest across email, messaging platforms, and social media.
Beyond recognition, the course emphasises your role in the broader security ecosystem: reporting procedures, incident response protocols, and why your vigilance matters to organisational resilience. You’ll understand the business impact of successful attacks and how awareness translates into measurable risk reduction. The 54-minute format is designed for busy professionals—ideal for onboarding, refresher training, or compliance requirements.
Who Is This Course For?
Ideal for:
- Office-based employees and remote workers: Anyone with email access needs this foundation; phishing remains the leading attack vector across sectors.
- Senior leaders and executives: Whaling specifically targets C-suite and finance teams; this course arms you against impersonation and wire-fraud schemes.
- Security awareness programme managers: Use this as a core module for mandatory training rollouts; Pluralsight’s production quality supports engagement and completion rates.
May not suit:
- Security operations and incident response teams: You need deeper technical analysis and forensics; this is awareness-level content, not SOC-grade threat intelligence.
- Learners seeking hands-on lab environments: This is video-based instruction without interactive sandboxes; Pluralsight’s labs are available in other courses but not this one.
Frequently Asked Questions
How long does Cyber Security Awareness: Phishing and Whaling take?
54 minutes. Designed for busy professionals—complete in one sitting or split across two short sessions.
Is this suitable for non-technical staff?
Yes. Todd Edmands avoids jargon and focuses on practical recognition skills. No coding or technical background required.
Will this help us meet compliance requirements?
Absolutely. Many frameworks (ISO 27001, NIST, GDPR) mandate security awareness training. This course provides documented, expert-led content suitable for audit trails.
Can we use this for team training at AIU.ac?
Yes. Pluralsight offers team and enterprise licensing. Contact your learning administrator to discuss group access and tracking options.
Course by Todd Edmands on Pluralsight. Duration: 0h 54m. Last verified by AIU.ac: March 2026.




