Module 15 / 15
πŸ†

Your Cybersecurity Summary and Action PlanUpdated: 2026

Consolidate what you've learned, adopt the 15 essential habits, and build your 30-day action plan. You're ready for the final test.

⏱️ ~20 min
πŸ“š 7 lessons
🎯 Beginner
🎯 Module objective

By the end of this module, you'll be able to…

  • Consolidate the key knowledge from the previous 14 modules
  • Apply a concrete 30-day action plan
  • Build lasting security habits into your daily routine
  • Raise awareness among your family, friends and coworkers
  • Prepare confidently for the final certification test
1

The 15 must-know habits

Every module in this training gave you one key habit. Here's the full list to display, print, or share:

  1. M01 β€” Think in layers of defense: no single protection is foolproof. Combine MFA + strong password + updates + backups.
  2. M02 β€” Verify before you obey: any urgent, unusual request (transfer, password, access) must be confirmed through another channel.
  3. M03 β€” Check the sender and the URL: the real domain is what comes right before the .com/.ca. An email from "rbc-alert.com" isn't RBC.
  4. M04 β€” Use a password manager: one unique, strong password per site, stored in Bitwarden, 1Password or similar.
  5. M05 β€” Never pay a ransom without consulting someone: paying funds crime and doesn't guarantee recovery. Isolate, report, restore.
  6. M06 β€” Check HTTPS and the sender: a padlock β‰  a legitimate site, but no padlock = guaranteed leakage of anything you type.
  7. M07 β€” Exercise your rights over your data: you can request access, correction and deletion of your personal data.
  8. M08 β€” Avoid public Wi-Fi without a VPN: on an uncontrolled network, all your unencrypted communications are readable.
  9. M09 β€” Encrypt your devices and enable locking: a stolen, unlocked phone = all your data accessible.
  10. M10 β€” Back up using the 3-2-1 rule: 3 copies, 2 different media, 1 offsite (or cloud). Test the restore.
  11. M11 β€” Lock your screen the moment you step away: Win+L or Cmd+Ctrl+Q. Shoulder surfing and physical access are real risks.
  12. M12 β€” Set your social media privacy settings: your public posts feed targeted OSINT attacks.
  13. M13 β€” Call the person back at their usual number: facing an urgent call or video request, hang up and call back at a number you already know.
  14. M14 β€” Isolate and document from the first sign: disconnect from the network, take screenshots, don't power off, alert IT.
  15. M15 β€” Keep your vigilance over time: threats evolve. Follow a news source, join simulations, train the people around you.
2

Your 30-day action plan

Cybersecurity is built through gradual habits. Here's a realistic plan, week by week:

πŸ—“οΈ Week 1 β€” The basics (30 min)

  • Install a password manager (Bitwarden is free)
  • Enable MFA on your main email
  • Check if your addresses are compromised at haveibeenpwned.com
  • Enable automatic updates on all your devices

πŸ—“οΈ Week 2 β€” Passwords (45 min)

  • Migrate your 10 most important accounts into the manager
  • Enable MFA on your bank and your social media
  • Delete online accounts you no longer use

πŸ—“οΈ Week 3 β€” Data and backups (1h)

  • Set up an automatic backup of your important files
  • Review your social media privacy settings
  • Enable disk encryption (BitLocker/FileVault)

πŸ—“οΈ Week 4 β€” Share and consolidate (30 min)

  • Share the 15 habits with a friend or coworker
  • Test your backup restore
  • Take the ObjectifCyber final certification test
3

Layered defense β€” the systemic approach

Effective cybersecurity isn't a single tool, but a series of layers that complement each other. If one layer fails, the others limit the damage.

Defense-in-depth model:
Strong MFA β†’ Unique strong password β†’ Regular updates β†’ 3-2-1 backup β†’ Ongoing training

An attacker who bypasses your password (e.g., a database leak) will be stopped by MFA. Ransomware that encrypts your files will be neutralized by your backups. That's what professionals call resilience: the ability to absorb an attack without disaster.

βœ— False senses of security

  • "I have antivirus, so I'm protected" β€” antivirus doesn't protect against social engineering or data leaks.
  • "I have nothing important, no one will target me" β€” 70% of cyberattacks target "ordinary" people to reach their contacts.
  • "My Mac is secure by default" β€” Macs are targeted too, notably via malware disguised as legitimate apps.
4

Staying vigilant over time

Cyber threats evolve quickly. What you've learned today will still be relevant in 5 years β€” the core principles (verify, back up, limit access) don't change β€” but new tactics constantly emerge.

βœ“ Recommended sources to follow

  • cyber.gc.ca β€” Canadian Centre for Cyber Security: official alerts for Canada
  • crtc.gc.ca β€” CRTC: report spam and phone fraud
  • cisa.gov/news-events β€” CISA (United States): technical alerts and bulletins
  • Krebs on Security (krebsonsecurity.com) β€” cybersecurity investigative journalism
  • Have I Been Pwned (haveibeenpwned.com) β€” alerts if your emails appear in leaks

Subscribe to the Canadian Centre for Cyber Security's email alerts. You'll get warned as soon as a major threat affects Canadians.

5

Cybersecurity as a team

Scenario

Marie completed the entire training. Her passwords are in a manager, MFA is on everywhere, her backups are automatic. But her coworker Thomas clicks every link he gets. A phishing email targeting Thomas compromises the team's shared account. Marie's security was bypassed through the weakest link.

Cybersecurity is a team effort. A single untrained person on a team can compromise the whole group. That's why security culture matters as much as technical tools.

βœ“ How to raise awareness around you

  • Share the 15 habits (a simple list, not a 15-module course)
  • Do a "live" phishing demo β€” show how to spot a fake email
  • Offer to help set up a password manager together
  • At work: ask your IT team for regular phishing simulations
  • Normalize security questions: "did you check the sender?"
6

Self-assessment β€” Where do you stand?

Check off what you've already put in place. Automatically saved in your browser.

7

Ready for the final test

You've completed all 15 modules of the ObjectifCyber training. That's a significant milestone β€” you now have a solid understanding of cyber threats and practical countermeasures.

Final test: 20 questions covering every module. Passing score: 80%. To be completed in a single session. The certificate is generated automatically and is printable. The certification test is currently available in French only.

If you're not yet confident about certain modules, reread the corresponding lessons. Modules 03 (phishing), 04 (passwords) and 14 (incidents) are the most represented in the final test.

Take the final test (FR) β†’ Certification

Module quiz

Test what you've learned with 4 questions.

See also