Ransomware & BEC Awareness

Ransomware and Business Email Compromise are the two most financially damaging cyber attacks on Malaysian organisations. Together they account for the majority of reported cyber losses, and both succeed primarily because staff do not recognise them until it is too late. This 1-day programme changes that.

These two attack types are covered together because they share an entry point and a target, and because business email compromise quietly costs Malaysian organisations more than ransomware does. Participants work through how each attack actually begins, which is almost always a person rather than a system, and the warning signs available before the damage is done. Payment verification procedure gets specific attention, since a single callback on a known number defeats most business email compromise attempts. The session also covers what to do in the first hour, including what not to do, because well-intentioned actions frequently destroy the evidence needed later.

Participants leave knowing exactly how these attacks work, what the warning signs look like in real email and system scenarios, and what to do in the first critical hours of an incident.

HRD Corp Training Provider Malaysia HRD Corp SBL-Khas Claimable

Programme Agenda

01

8:30 AM - 9:00 AM

Registration & Welcome

Participant registration, programme overview, and objectives.

02

9:00 AM - 10:15 AM

Understanding Ransomware

How ransomware enters organisations, phishing, RDP, vulnerable software; encryption and extortion mechanics; double extortion and data leak threats; ransomware-as-a-service and affiliate models; real Malaysian and regional incident examples.

03

10:15 AM - 10:30 AM

Break

04

10:30 AM - 12:00 PM

Business Email Compromise

Anatomy of a BEC attack; CEO fraud and executive impersonation; invoice and payment fraud; fake vendor account changes; account takeover via phishing; why BEC causes larger financial losses than ransomware; Malaysian police report statistics and case studies.

05

12:00 PM - 1:00 PM

Lunch

06

1:00 PM - 2:15 PM

Recognising the Warning Signs

Red flags in emails: domain spoofing, display name deception, urgency cues, unusual sender patterns; signs of ransomware activity on your device or network; what a compromised email account looks like from the inside; practical exercises using real-world examples.

07

2:15 PM - 3:15 PM

Prevention & Safe Habits

Multi-factor authentication explained simply; safe link and attachment handling; payment verification procedures that stop BEC; backup fundamentals and why offline backups matter; what IT controls are protecting you and what gaps remain.

08

3:15 PM - 3:30 PM

Break

09

3:30 PM - 4:15 PM

When You Are Under Attack

Immediate response steps for ransomware: isolate, do not pay immediately, preserve evidence; immediate steps for BEC: contact your bank within the hour, do not delete emails; reporting to NACSA, PDRM Cybercrime Division, and Bank Negara Malaysia; what information authorities need from you.

10

4:15 PM - 4:45 PM

Assessment

Individual written assessment. 70% pass mark required. One resit permitted within 14 days.

11

4:45 PM - 5:00 PM

Closing Remarks & Certificate Presentation

Programme wrap-up, open Q&A, and certificate presentation.

Key Outcomes

  • Understand how ransomware and BEC attacks work and why they succeed
  • Recognise warning signs of a ransomware infection or BEC attempt in progress
  • Apply safe habits and verification procedures that prevent successful attacks
  • Know exactly what to do in the first hours of a ransomware or BEC incident
  • Report incidents correctly to Malaysian authorities and financial institutions

Training Mode   Physical / Online / Hybrid / e-learning

HRD Corp   SBL-Khas Claimable

Level   Foundational, suitable for all staff regardless of role or technical background

Duration   1 Day  |  8:30 AM - 5:00 PM

Venue   Kuala Lumpur, Malaysia, or in-house at client's premises

Assessment   Written knowledge check, 70% pass mark. One resit within 14 days.

Certificate   Certificate of Completion issued by Orbix Tech Sdn Bhd upon successful assessment and full attendance

Includes   Training materials, workbook, assessment, and Certificate of Completion. Participants responsible for travel and accommodation.

PriceContact us to register or enquire about group rates

Frequently Asked Questions

Yes. Ransomware & BEC Awareness is HRD Corp SBL-Khas claimable. Employers registered with HRD Corp (PSMB) can claim the training fee against their levy, as Orbix Tech Sdn Bhd is an HRD Corp certified training provider. Submit the SBL-Khas application before the session date.

Ransomware & BEC Awareness runs for 1 day | 8:30 AM - 5:00 PM. It is delivered as an in-house closed group session, so the schedule can be adjusted to fit your team's working hours.

Yes. Delivery options are physical, online, hybrid, e-learning. In-house sessions run at your premises anywhere in Malaysia, online sessions run live over video conference, and hybrid combines both for teams split across sites.

Certificate of Completion issued by Orbix Tech Sdn Bhd upon successful assessment and full attendance. Each certificate carries a certificate number that can be checked at orbixtech.my/certificate-verify.

Level: Foundational, suitable for all staff regardless of role or technical background. The session is built around worked examples and group exercises rather than theory, so participants apply the material to their own organisation during the session.

Half-day and full-day sessions are quoted per session for a closed group, from RM 800 and RM 1,750 respectively. Advanced 2-day programmes are quoted per participant, from RM 4,000. All figures are before any HRD Corp levy claim.