# MSP Client Security Awareness Starter Course

A free, reviewable course package for MSPs, vCISOs, and security teams that need a client-ready baseline module without starting from a blank deck.

Use this package as a starter asset. Replace bracketed placeholders with the client’s approved tools, reporting channels, policies, and escalation paths before publishing. This is not legal advice, a compliance guarantee, or a promise of behavior change.

---

## Course overview

**Working title:** Security Habits That Protect Client Work

**Audience:** Employees at an MSP, vCISO, or managed-service client organization

**Format:** 12-15 minute micro-course with scenario practice, quiz feedback, and LMS packaging notes

**Learning objective:** Learners can recognize common client-work security decisions and choose the approved next step for phishing, data handling, access requests, AI tool use, and suspicious activity reporting.

**Reviewer notes:**

- Security/MSP reviewer: confirm examples match the client environment and service scope.
- GRC/compliance reviewer: confirm policy-sensitive wording, contract references, and evidence language.
- L&D reviewer: confirm clarity, tone, accessibility, and quiz feedback quality.
- Client owner: confirm reporting channels, approved tools, and escalation paths.

---

## Lesson 1: Security is part of client trust

Security awareness should not feel like a lecture from the department of no. For client-serving teams, it is part of doing reliable work.

Everyday actions can expose client information, interrupt service, or create avoidable investigation work: approving an unusual login prompt, sharing a document through the wrong link, replying to a payment-change email, pasting client data into an unapproved AI tool, or deleting a suspicious message before reporting it.

The goal of this course is practical. When something looks unusual, employees should know how to pause, verify through an approved path, protect client information, and report quickly.

**Key takeaway:** You are not expected to solve every security question alone. You are expected to use approved tools, verify unusual requests, and ask before guessing.

---

## Lesson 2: Phishing and payment-change requests

Attackers often use routine business language because routine work moves fast. A message about an invoice, contract, shared document, support ticket, password reset, or payment change may look normal at first glance.

For client-serving teams, the safest action is rarely to reply directly to the message. Use the approved verification path already on file.

**Scenario:**

You receive an email that appears to come from a client contact. It says their bank information changed and asks your team to update payment details before the end of the day. The email includes a phone number and says the contact is in meetings, so email is best.

**Safer response:**

Pause. Do not use the phone number or reply path in the message. Verify the request through the approved client contact method on file, follow the documented payment-change process, and report the message if anything seems suspicious.

**Key takeaway:** A familiar name is not enough. Payment, credential, access, and sensitive-data requests need verification through trusted channels.

---

## Lesson 3: Client data handling and sharing

Client information should only be stored, shared, and discussed in approved systems. That includes documents, screenshots, support tickets, exports, logs, contracts, credentials, architecture notes, and anything the client or organization treats as sensitive.

When the data type is unclear, the safe move is to ask before sharing.

**Scenario:**

A teammate asks you to send a client spreadsheet through a public file-sharing link because the client needs it quickly. The spreadsheet includes customer details and internal notes.

**Safer response:**

Use the approved secure sharing method for that client and data type. Limit access to the right recipients, avoid public links for sensitive information, and escalate if you are unsure whether the file can be shared externally.

**Key takeaway:** Speed matters, but not more than sending client information through the right path.

---

## Lesson 4: Access requests and unusual sign-ins

Access requests deserve special care in client environments. A request may be legitimate, but the wrong approval can expose systems, data, or administration pathways.

Unexpected MFA prompts, password reset messages, device enrollment requests, and admin-access requests should be treated as verification moments.

**Scenario:**

You receive an MFA prompt while you are not signing in. A few minutes later, a chat message appears from someone claiming to be IT support and asking you to approve the prompt so they can finish troubleshooting.

**Safer response:**

Deny the prompt. Do not approve it to make the notification stop. Report the event through [approved reporting channel] and contact support through [approved support path].

**Key takeaway:** If you did not start the sign-in, do not approve the prompt.

---

## Lesson 5: AI tools and client information

AI tools can help with drafting, summarizing, planning, and analysis, but client information needs approved handling. Before entering work content into an AI tool, check three things:

1. Is this tool approved for this kind of work?
2. Is the data allowed in this tool?
3. Does the output need human review before use?

**Scenario:**

You want to summarize a client incident note quickly. The fastest tool available is a public AI chatbot open in your browser.

**Safer response:**

Do not paste client incident details into an unapproved public tool. Use [approved AI tool] if permitted for that data type, remove sensitive information when required, follow the client or company policy, and ask [help channel] if the use case is unclear.

**Key takeaway:** Use approved tools, protect client information, and review AI outputs before relying on them.

---

## Lesson 6: Reporting suspicious activity

Fast reporting helps security teams investigate while evidence is still useful. Reporting does not mean you are in trouble. It means the team has a chance to help.

Report suspicious emails, texts, unexpected MFA prompts, lost devices, accidental sharing, unusual client requests, suspicious links, and anything that feels like a security mistake.

**What to include when reporting:**

- What happened
- When it happened
- What system, client, or message was involved
- Whether you clicked, replied, downloaded, approved, or shared anything
- Screenshots or message headers when your process allows them

**What not to do:**

- Do not reply to suspicious senders to test them.
- Do not forward suspicious attachments to coworkers.
- Do not delete evidence before reporting if the security team needs it.
- Do not hide a mistake because you are unsure whether it matters.

**Key takeaway:** Quick, honest reporting is useful, even when the situation turns out to be harmless.

---

## Knowledge check

### Question 1

A client emails a bank-account change request and says the update must happen today. What is the safest next step?

A. Reply to the email asking for confirmation.
B. Call the phone number listed in the email.
C. Verify through the approved client contact and payment-change process already on file.
D. Forward the request to a teammate and ask them to decide.

**Correct answer:** C

**Teaching feedback:** Payment-change requests need trusted-channel verification. Do not rely on contact details included in the suspicious message.

### Question 2

You receive an MFA prompt when you are not signing in. What should you do?

A. Approve it if it only happens once.
B. Deny the prompt and report it through the approved process.
C. Ignore it unless support contacts you.
D. Approve it if someone in chat says they are from IT.

**Correct answer:** B

**Teaching feedback:** Unexpected MFA prompts can be a sign that someone has your password or is trying to trick you into approving access.

### Question 3

You need to summarize a client support note. Which action is safest?

A. Paste the full note into any public AI tool because it is only for drafting.
B. Use an approved tool only if the client information and use case are allowed, then review the output.
C. Remove the client name but leave all other details in the prompt.
D. Ask a coworker to paste it into their AI account.

**Correct answer:** B

**Teaching feedback:** AI use depends on the approved tool, data type, policy, and review process. Removing one identifier may not be enough.

### Question 4

A teammate wants to use a public link for a client spreadsheet because it is faster. What should you do?

A. Use the public link because the client asked quickly.
B. Use the approved secure sharing method and limit access to the right recipients.
C. Email the spreadsheet to a personal account and send it from there.
D. Post the link in a shared chat channel so the team can find it.

**Correct answer:** B

**Teaching feedback:** Sensitive client information should be shared through approved systems with appropriate access controls.

### Question 5

You clicked a suspicious link and then realized it might be unsafe. What should you do?

A. Close the browser and hope nothing happened.
B. Delete the email so nobody else clicks it.
C. Report what happened quickly and honestly through the approved channel.
D. Reply to the sender asking if it was real.

**Correct answer:** C

**Teaching feedback:** Reporting quickly helps the security team investigate and respond. The goal is not blame. The goal is timely information.

---

## Remediation note

If a learner misses questions in this module, assign a short follow-up focused on the missed decision:

- Payment-change verification
- Unexpected MFA prompts
- Approved AI use
- Secure client-data sharing
- Reporting after a mistake

Keep remediation respectful and specific. The learner should understand the safer next step, not feel punished for practicing.

---

## LMS packaging notes

Suggested LMS fields:

- **Course title:** Security Habits That Protect Client Work
- **Description:** A short security awareness module for client-serving teams covering phishing, payment-change verification, secure sharing, MFA prompts, approved AI use, and reporting suspicious activity.
- **Estimated duration:** 12-15 minutes
- **Passing score:** 80 percent or organization-approved threshold
- **Completion rule:** View all lessons and pass the knowledge check
- **Recommended export:** SCORM, xAPI, HTML, or PDF according to the delivery system
- **Accessibility readiness:** Add captions/transcripts for any audio or video, check keyboard navigation for interactions, and review color contrast before publishing.

---

## Jericho AI Studio prompt

Use this prompt in Jericho AI Studio to create a client-fit version:

> Create a 12-minute security awareness micro-course for employees at an MSP or vCISO client organization. Teach five decisions: verifying payment-change requests, handling client information in approved systems, responding to unexpected MFA prompts, using approved AI tools with client data, and reporting suspicious activity quickly. Include practical lesson copy, five scenario-based quiz questions with teaching feedback, a respectful remediation note, captions/transcript guidance, and LMS export notes. Use plain language, avoid fearmongering, mark assumptions for review, and do not claim the course guarantees compliance, prevents breaches, or proves secure behavior.

---

## Human review checklist

Before publishing, confirm:

- The client name, systems, reporting channels, and escalation paths are accurate.
- Payment-change and access-request workflows match approved procedures.
- AI tool guidance matches the current client or organization policy.
- Data-handling examples fit the client’s actual sensitivity labels and contracts.
- The course avoids guarantees around compliance, breach prevention, or behavior change.
- Quiz feedback teaches safer decisions without shaming learners.
- Captions, transcripts, completion rules, and export settings are ready for the LMS.

---

## Create your own version

Open Jericho AI Studio at https://contentstudio.jerichosecurity.com and use the prompt above to create a reviewable course draft, adapt it for a client or department, and package it for your LMS workflow.
