SiberMate SMLearn Core Syllabus: Complete Knowledge Base & Course Catalog

Welcome to the definitive SiberMate SMLearn Core Syllabus Guide. As an expert Cybersecurity Instructional Designer, this knowledge base details the 36 Core Modules, structural frameworks, subject breakdowns, and chat-native implementation strategies that power SiberMate Human Risk Management platform.

Program Overview & Architecture

The SiberMate SMLearn Core Modules form the foundation of an organization’s human cyber defense. Delivered natively via messaging platforms like Email, WhatsApp, Microsoft Teams, and Slack, the curriculum is designed to eliminate technical jargon and deliver high-impact, bite-sized learning directly into employees' daily workflows.

  • Total Core Courses: 36 Modules (~4 hours total curriculum).
  • Core Subject Areas: 7 Strategic Focus Areas.
  • 3-Tier Progression: Beginner (Gap Assessment) —> Intermediate —> Advanced.
  • Delivery Engine: Chat-Native SMLearn AI Personal Trainer (1–3 minute micro-reads).
  • Target Audience: Non-Technical Employees (HR, Finance, Operations, Sales, Executive Leadership).

Core Syllabus at a Glance

Subject Area

Total Courses

Total Duration

Level (Beginner / Intermediate / Advanced)

Primary Focus & Threat Vector

Phishing & Social Engineering

9

65 min

2 / 4 / 3

Manipulation via email, voice, text, QR, and impersonation.

Passwords & Authentication

3

21 min

1 / 1 / 1

Credential hygiene, privacy, and MFA fatigue defense.

Malware & System Threats

6

44 min

0 / 3 / 3

Infection vectors, patching, ransomware, DoS, and adware.

Devices & Physical Security

4

25 min

3 / 0 / 1

Mobile devices, removable media, office, and clear-desk rules.

Internet, Email & Cloud

6

39 min

3 / 1 / 2

Browsing, cloud platforms, file sharing, and online payments.

Remote & Home Working

7

47 min

3 / 2 / 2

Public Wi-Fi, VPNs, home IoT, video calls, and remote safety.

Emerging Technology Risks

1

8 min

0 / 1 / 0

Generative AI, Large Language Models (LLMs), and data leakage.

TOTAL

36

249 min

12 / 12 / 12

Full Organizational Human Risk Coverage



Complete Catalog of 36 Core SMLearn Modules

1. Phishing & Social Engineering (9 Courses | 65 min Total)

Focuses on how attackers manipulate human psychology across various channels.

  • Phishing (Beginner | 8 min): Essential introduction to identifying email phishing attacks.
  • Social Engineering (Beginner | 6 min): Recognizing psychological manipulation tactics.
  • Smishing (Intermediate | 7 min): Detecting and neutralizing SMS and text message scams.
  • The Insider Threat (Intermediate | 7 min): Understanding malicious and accidental insider risk.
  • Vishing (Intermediate | 7 min): Identifying phone-based scams and voice impersonation.
  • What Makes a Cyber Criminal? (Intermediate | 7 min): Understanding hacker motivations to anticipate threats.
  • Deepfakes (Advanced | 8 min): Recognizing AI-generated video and voice deception.
  • Email Thread Hijacking (Advanced | 7 min): Spotting attackers who inject themselves into real email chains.
  • Quishing (Advanced | 8 min): Defending against malicious QR code phishing tactics.


2. Passwords & Authentication (3 Courses | 21 min Total)

Covers credential hygiene and modern authentication attacks.

  • Passwords and Authentication (Beginner | 8 min): Creating resilient passwords and authentication basics.
  • MFA Fatigue Attacks (Intermediate | 7 min): Defeating push notification spamming and authenticator overload.
  • Protecting Your Online Privacy (Advanced | 6 min): Safeguarding digital footprints and personal data online.


3. Malware & System Threats (6 Courses | 44 min Total)

Explores software-based threats, operational disruption, and system hygiene.

  • Denial of Service Attacks (DoS) (Intermediate | 6 min): Basics of DoS attacks and operational impacts.
  • Patching & Updating (Intermediate | 7 min): The vital role of routine system updates in preventing breaches.
  • Ransomware (Intermediate | 7 min): How ransomware spreads and preventing corporate encryption events.
  • Data Breaches (Advanced | 7 min): Anatomy of a breach, impacts, and containment responsibilities.
  • Malware (Advanced | 8 min): Types of malicious software, infection pathways, and defense.
  • Spyware & Adware (Advanced | 9 min): Preventing unauthorized tracking software and malicious adware.


4. Devices & Physical Security (4 Courses | 25 min Total)

Protects physical workspace hardware and endpoint security.

  • Mobile Device Security (Beginner | 7 min): Securing smartphones and tablets used for corporate work.
  • Physical Security (Beginner | 6 min): Protecting office premises, tailgating risks, and physical assets.
  • Removable Media (Beginner | 6 min): Safe handling and risks of USB drives and external hardware.
  • Clear Desk Policy (Advanced | 6 min): Securing physical documents, screens, and sensitive printed data.


5. Internet, Email & Cloud Use (6 Courses | 39 min Total)

Guides secure day-to-day digital habits across web, email, and cloud platforms.

  • Cloud Security (Beginner | 6 min): Safe use of cloud storage platforms and shared workspace tools.
  • Internet & Email Use (Beginner | 7 min): Safe web browsing habits and foundational email safety.
  • Social Media (Beginner | 7 min): Managing social media risks and preventing oversharing.
  • Secure Email Use (Intermediate | 7 min): Best practices for handling business communications.
  • File Sharing in the Workplace (Advanced | 6 min): Secure file-sharing protocols and access permissions.
  • Online Payments (Advanced | 6 min): Executing secure corporate online transactions and vendor payments.


6. Remote & Home Working (7 Courses | 47 min Total)

Addresses risks specific to hybrid, home, and mobile working environments.

  • Public Wi-Fi (Beginner | 6 min): Hazards of unencrypted public Wi-Fi networks in cafes/airports.
  • Security at Home (Beginner | 7 min): Extending corporate cyber defense habits to home settings.
  • Working Remotely (Beginner | 6 min): Security protocols for mobile workers outside the office.
  • The Internet of Things (IoT) (Intermediate | 7 min): Risks associated with smart devices on home networks.
  • Videoconferencing Security (Intermediate | 7 min): Safe meeting settings, link sharing, and screen security.
  • Home Network Security (Advanced | 7 min): Securing home routers, Wi-Fi passwords, and guest networks.
  • Secure VPN Use (Advanced | 7 min): When and how to properly utilize corporate Virtual Private Networks.


7. Emerging Technology Risks (1 Course | 8 min Total)

Navigates modern technology vectors and AI compliance.

  • LLM Data Exposure (Intermediate | 8 min): Preventing accidental corporate leakage when using AI tools like ChatGPT or Copilot.


Chat-Native Implementation Blueprint Examples

To convert these core syllabus courses into SMLearn chat-native micro-learning flows, use the 5-part structure below:


Blueprint 1: Quishing (QR Code Phishing)

1. Course Title & Core Hook: The QR Code Menu Trap: Don't Swallow the Scam!

2. Target Audience: All Employees, Hybrid Workers, Sales Teams.

3. 3-Minute Micro-Learning Breakdown:

    • Minute 1 (The Hook): "You're having lunch at a cafe. You scan a QR code on the table for the menu, but it prompts you to 'Log in with your corporate Microsoft account' to view discounts. Do you log in?"
    • Minute 2 (The Threat): "Stop! This is Quishing (QR Code Phishing). Scammers paste fake QR stickers over real codes. Unlike web links, you can't preview a QR code URL with your eyes before scanning! Real menus never ask for work passwords."
    • Minute 3 (Action Plan): "1. Feel QR stickers to see if they're layered. 2. Never input work passwords on sites opened via physical QR codes. 3. Check the preview URL before tapping.

  • 4. Adaptive Quiz Question:
    • Scenario: You scan a QR code on an incoming office delivery box. The landing page asks for your work email and password to 'release the shipment'. What should you do?
    • A) Enter your password to clear the delivery.
    • B) Close the page and check the order directly on the official courier portal. (Correct)
    • C) Share the QR code in a team chat to see if anyone else can open it.


  • 5. Automatic Remediation Trigger: Dispatched automatically within 5 minutes if an employee scans a test QR code in an SMPhish physical/digital drill.


Blueprint 2: LLM Data Exposure & UU PDP

  • 1. Course Title & Core Hook: ChatGPT & UU PDP: Is Your AI Prompt Leaking Corporate Secrets?
  • 2. Target Audience: HR, Finance, Operations, Customer Support.
  • 3. 3-Minute Micro-Learning Breakdown:
    • Minute 1 (The Hook): "You need to format a customer spreadsheet quickly, so you paste customer names, NIK numbers, and bank details into ChatGPT. Harmless hack?"
    • Minute 2 (The Threat): *"Think twice! Public AI models retain and learn from what you feed them. Under Indonesia's Personal Data Protection Law (UU PDP), leaking personal data can trigger severe corporate fines and personal liability." *
    • Minute 3 (Action Plan): "1. Anonymize all personal data before pasting into AI. 2. Use only company-approved enterprise AI tools. 3. Never input raw financial databases."


  • 4. Adaptive Quiz Question:
    • Scenario: You want an AI tool to summarize a vendor contract containing employee phone numbers and NIKs. What is the compliant step?
    • A) Upload the file directly since the session is private.
    • B) Remove all names, phone numbers, and NIKs prior to pasting. (Correct)
    • C) Paste the data only after business hours.


  • 5. Automatic Remediation Trigger: Triggered automatically when SiberMate Policy Management detects upload attempts of sensitive data formats to unapproved public AI sites.

Key Success Benchmarks

When deploying the complete SiberMate 36 Core Module curriculum through SMLearn, organizations achieve:

  • 90%+ Employee comprehension of compliance obligations.
  • 75%+ Reduction in phishing simulation click-through rates.
  • 95%+ Reporting rate for suspicious incidents.
  • Instant Automated Remediation following SMPhish simulation missteps.
Did this answer your question? Thanks for the feedback There was a problem submitting your feedback. Please try again later.