Cybersecurity

Course Overview & Objectives

Cybersecurity is a critical function for every SME, yet most small teams lack the time, expertise, or budget for advanced protection systems. AI tools can help non-experts quickly identify suspicious content, analyse potential threats, detect malware, and improve digital hygiene. With the right prompts, learners can use AI to recognise risks early, act faster, and reduce the likelihood of cyberattacks.

AI supports cybersecurity across key areas relevant to SMEs, including: 

  • Network protection: Monitoring traffic for anomalies.
  • SIEM Management: Aggregating and analyzing security events.
  • Malware Analysis: Scanning files and URLs for threats. 
  • Incident and Breach Management: Automating alerts and initial responses.

These applications provide advanced protection without requiring large IT teams.

Learning outcomes

By the end of this course, learners will be able to:

  • Explain how AI supports basic cybersecurity tasks in SMEs.
  • Analyse suspicious emails and identify phishing risks using an AI assistant.
  • Simulate malware detection using VirusTotal’s free online scanner.
  • Apply practical steps to improve organisational cyber hygiene.
  • Understand the limitations of AI in cybersecurity and when human validation is necessary.

AI and Human Integration in Cybersecurity

AI turbo – boosts cybersecurity by handling speed and volume – scanning millions of events for patterns humans can’t match quickly.

But AI needs humans for: 

  • Context: Business – specific rules (e.g., trusted IPs for travel)
  • Ethics/Nuances: False positives that could block legit work.
  • Novel Threats: Zero – day attacks without training data.

Real SME Example: AI (like Gemini) flags suspicious login → Human verifies user location/story → Team blocks if breach is confirmed.

This hybrid cuts response time 70% while avoiding errors.

Why It Matters: Pure AI risks over – blocks; pure human is too slow, but TOGETHER: SME’s get pro-level protection without experts.

Tools Introduced

Gemini can analyse suspicious emails, identify red flags, evaluate risks, and provide step-by-step cyber-hygiene guidance for non-technical users. It is ideal for phishing identification and awareness training.

VirusTotal is a free online malware-analysis tool. Users can safely upload files or paste URLs, and VirusTotal scans them using over 70 antivirus engines. Perfect for demonstrating how AI-enhanced threat detection works.

Step-by-Step Activities

Activity 1 — Phishing Detection & Cyber Hygiene with Gemini

Scenario

You work in a small business. Several employees have received a suspicious email claiming to be from your bank asking them to “verify account information”. You must confirm whether it is legitimate.

Task

Use Gemini to analyse whether the email is a phishing attempt.

Steps

  1. Go to https://gemini.google.com/app

  2. Copy and paste the following email into Gemini:

Suspicious Email Text (copy/paste)

Subject: IMPORTANT — Action Required Immediately

Dear Customer,

We noticed unusual activity on your business account. To avoid suspension, please verify your information within 24 hours.

Click the link below to secure your account:

http://secure-business-verification-check.com/login

Failure to act will result in permanent account closure.

Thank you,
Business Account Support Team

  1. Use this prompt:

Prompt:
“Analyse this email for phishing risks. Identify red flags, suspicious links, sender credibility issues, tone inconsistencies, and any signs of fraud. Then give me a short checklist of what employees should do next.”

  1. Review Gemini’s output.

 It should highlight:

  • Suspicious link
  • Urgent/scare language
  • No real bank details
  • Generic sender
  • No personalisation
  • Non-secure domain

  1. Ask a follow-up:

“Rewrite this into a simple internal security alert to send to all staff.”

Activity 2 — Malware Detection Simulation with VirusTotal

Task

Use VirusTotal to safely simulate malware detection.

Steps

  1. Go to https://www.virustotal.com

  2. At the top, choose either:

    • File (to upload a test file), or

    • URL (to analyse a suspicious link)

  3. Copy and paste this test link — it’s a harmless example flagged for training:
    https://www.harmful-example-test-link.com (VirusTotal will show risk indicators but won’t expose you to any harm.)

  4. Review:

    • Security vendor detections
    • Community comments
    • Behavioural analysis

  5. Answer: Would you open this link? Why or why not?

Result

Learners see how a professional-grade malware scanner works without requiring any technical skills or installing software.

Activity 3 — AI-Powered Incident Response Simulation with SOAR

Scenario 

You work in a small SME. Your security dashboard shows an alert: “Unusual login from unknown IP on the finance system.” This could be a breach attempt. You must triage and respond quickly using AI-powered SOAR tools.

Task 

Use TryHackMe SOC Simulator to practice SOAR triage and automated response (free, no install, simulates real SIEM/SOAR workflows).

Steps 

  1. Go to https://tryhackme.com/soc-sim  

   https://tryhackme.com/soc-sim 

(Free cybersecurity training platform with interactive SOC rooms – no risk, gamified for beginners.)

  1. Start a free room (e.g., Phishing Triage or Alert Investigation – pick any basic incident; no login needed for demo).
  2. In the simulator dashboard, select the alert and use this prompt in the query/analysis field:  

Prompt 

“Triage this unusual login alert: Unknown IP on the finance system. Prioritize threat level, suggest auto-actions (quarantine? Notify?), run playbook steps, and recommend human checks.”

  1. Review the simulator’s output.  

   It should highlight:  

  • Threat score (high/medium/low based on IP reputation)  
  • Auto-enrichments (geolocation, past alerts)  
  • Playbook steps (block IP, isolate user, email admin)  
  • Escalation flags (needs human review if novel threat)
  1. Ask a follow-up:  

“Generate a simple SME incident report: Summary, actions taken, next steps for the team.”

Result 

Learners experience professional SOAR in action – AI automates triage, speeds response from hours to minutes, and flags human-needed decisions. Perfect for SMEs without full-time SOC teams. No technical skills required; builds confidence in handling real breaches.

Assessment

Funded by the European Union. Views and opinions expressed are however those of the author(s) only and do not necessarily reflect those of the European Union or the European Education and Culture Executive Agency (EACEA). Neither the European Union nor EACEA can be held responsible for them. [Project number: 2024-1-AT01-KA220-VET-000245796]

Scroll to Top