Cybersecurity Awareness
Version: 2.0
Review date: 01 January 2027
Clinical approval: Nominated Individual
Approved by: Dr James Glass, Nominated Individual
Operational lead: Caroline Lawrence, Registered Manager
Minimum pass mark: 12 out of 15
Refresher frequency: At induction and annually or sooner following a significant incident or material change
1. Purpose of this module
Cybersecurity is the protection of devices, accounts, systems and information from unauthorised access, alteration, loss, disruption or misuse.
It is not simply an IT issue. It is part of information governance, patient safety and the safe operation of WMI Psychiatry.
A compromised email account could expose confidential health information. Ransomware could prevent staff from accessing appointments, prescriptions and urgent clinical messages. A fraudulent payment request could cause financial loss. Altered or unavailable records could affect decisions about care.
Administration staff are often the first people to receive unexpected emails, file-sharing invitations, password-reset messages, payment requests and calls asking for information. This makes the administration team an important part of WMI Psychiatry’s cybersecurity controls.
The central rule is:
Pause when something is unexpected. Verify it through a trusted route. Report concerns promptly.
Staff will be supported when they promptly report an honest mistake or near miss.
This module will
explain common cyber threats within an outpatient psychiatry service
provide practical guidance about email, accounts, devices, files, payments and remote working
explain what to do after a suspicious click, lost device or possible breach
clarify the limits of the administration role
support prompt reporting and organisational learning
This module does not
authorise administration staff to investigate a cyberattack themselves
authorise staff to access another person’s account or records
replace technical security controls, access management or backups
require staff to decide whether a breach must be reported to the Information Commissioner’s Office
authorise staff to wipe, reconfigure or destroy a device
permit the use of personal email or personal cloud storage for clinic information
permit staff to use unauthorised messaging services for confidential information
replace WMI Psychiatry’s incident, data breach or business continuity procedures
2. Learning outcomes
By the end of this module staff should be able to:
Explain why cybersecurity matters to confidentiality, patient safety and service continuity.
Recognise phishing, social engineering, impersonation and fraudulent payment requests.
Use passkeys, passwords and two-step verification safely.
Protect accounts and respond to unexpected sign-in requests.
Use work email, approved systems and authorised sharing methods.
Check recipients, permissions and attachments before sending information.
Protect laptops, phones and workspaces during office and remote working.
Respond safely to suspicious links, malware warnings and ransomware.
Recognise a possible personal data breach or cyber incident.
Take immediate containment steps within the limits of their role.
Preserve relevant evidence.
Report incidents and near misses promptly without concealing mistakes.
Recognise when a request must be verified through a separate trusted channel.
Understand that administration staff must not conduct technical investigations or make regulatory reporting decisions.
Apply WMI Psychiatry’s procedures to realistic situations.
3. WMI Psychiatry local contacts and procedures
The following information must be completed before this module is issued.
Internal escalation
Registered Manager: Caroline Lawrence
Nominated Individual: Dr James Glass
Data Protection Lead: James Glass
Google Workspace administrator: James Glass
IT support provider: Zanda Health Support and Google Workspace Support
Out-of-hours cybersecurity escalation: Registered Manager or Nominated Individual using their designated work contact details
Incident reporting system: WMI Psychiatry Incident Reporting System
Data breach log: WMI Psychiatry Data Breach Log
Location of current policies: WMI Google Drive > Policies and Procedures
Location of business continuity information: WMI Google Drive > WMI Business Continuity Policy
Approved systems
WMI Psychiatry’s core systems currently include:
Google Workspace for work email, approved files and authorised collaboration
Zanda Health for appointments, patient administration and authorised clinical records
AppSheet for approved clinic jobs and governance workflows
Stripe for authorised payment processing
A system being approved does not mean that every member of staff is authorised to use every function. Access must be appropriate to the person’s role.
Staff must not share accounts, passwords or verification codes.
Immediate local response
If a cyber incident may have occurred:
Stop the risky activity.
Do not continue opening files, entering details or approving requests.
If a device may be infected disconnect it from Wi-Fi and any network cable where this can be done safely.
Do not wipe the device or continue investigating.
Contact the Registered Manager and urgent IT support immediately using a trusted contact method.
If an account may be compromised contact support from a separate trusted device.
Preserve the email, message, screen details and relevant times.
Do not delete evidence unless instructed.
Record the incident or near miss through the approved system as soon as possible.
4. Confidentiality, integrity and availability
Cybersecurity incidents can affect three main areas.
Confidentiality
Confidentiality is affected when information is accessed or shared with someone who is not authorised to receive it.
Examples include:
emailing a report to the wrong parent
sharing a file using a public link
allowing another person to use your account
discussing patient information where others can hear
leaving a record visible on an unlocked screen
Integrity
Integrity is affected when information is altered without proper authority or can no longer be trusted.
Examples include:
bank details on an invoice being changed
information in a patient record being altered
an attacker sending messages from a staff member’s account
important information being deleted
an unauthorised person changing appointment details
Availability
Availability is affected when information or systems cannot be accessed when needed.
Examples include:
ransomware preventing access to appointment records
an account being locked following compromise
files being deleted
a system being taken offline because of an attack
an urgent clinical message being inaccessible
In healthcare all three can affect people. A privacy breach may cause distress, embarrassment, discrimination or loss of trust. Altered records could lead to incorrect decisions. Unavailable systems could delay care and urgent communication.
5. Common cyber threats
Phishing
Phishing is a message or website designed to make someone reveal information, approve access, send money or install harmful software.
Phishing may arrive through:
email
text message
a messaging application
a QR code
social media
a telephone call
a file-sharing invitation
an online advertisement
a false website
The message may appear to come from a patient, clinician, manager, bank, supplier, payment provider or software company.
Social engineering
Social engineering uses trust, urgency, fear, authority or helpfulness to influence someone.
An attacker may:
claim that immediate action is needed
ask staff to keep the request secret
pretend to be a senior manager
threaten that an account will be closed
claim that a patient will be harmed if staff do not act
ask staff to bypass the usual process
offer to help resolve a supposed technical problem
use information found online to make the approach convincing
The attacker may know staff names, roles, suppliers or recent clinic events. Accurate information does not prove that the person is genuine.
Account takeover
An attacker may use a stolen password, session token or approved sign-in request to access an account.
Once inside an account they may:
read confidential messages
impersonate a member of staff
create automatic email-forwarding rules
hide or delete messages
reset other accounts
access shared files
change payment information
send phishing emails to colleagues or patients
Malware
Malware is harmful software designed to damage, disrupt or obtain unauthorised access to devices and information.
It may be installed through:
a malicious attachment
an infected website
unauthorised software
a browser extension
a false update
a remote-access tool
an unknown USB device
Ransomware
Ransomware may encrypt information, steal it or prevent systems from working. The attacker may demand payment to restore access or prevent publication.
Paying does not guarantee that information will be recovered or deleted.
Administration staff must not communicate with an attacker, negotiate or pay a ransom.
Payment and invoice fraud
An attacker may impersonate a manager, supplier, patient or payment provider.
They may request:
a payment to a new bank account
an urgent refund
a payroll change
gift cards
cryptocurrency
payment of an altered invoice
disclosure of payment information
A familiar email address may itself have been compromised. Staff must still follow the usual financial controls.
Insider risk and accidental error
Not every cybersecurity incident is a deliberate attack.
Incidents may also result from:
sending information to the wrong recipient
using excessive sharing permissions
leaving a device unlocked
losing a laptop or telephone
uploading a file to an unauthorised location
using a personal email account
giving another person access to an account
failing to remove access when someone leaves the organisation
Prompt reporting allows the organisation to contain the problem and reduce harm.
6. Recognising suspicious messages
No single feature proves that a message is malicious. Staff should consider the complete situation and whether the request was expected.
Possible warning signs include:
the sender’s address or domain is slightly different from the expected address
the display name is familiar but the underlying address is not
the message creates pressure to act immediately
the sender asks for secrecy
the request bypasses the usual process
the message asks for a password or verification code
the message asks you to approve a sign-in
a file or link was not expected
the link destination does not match the visible text
a QR code directs you to sign in or make a payment
the sender asks for new bank details to be used
the sender asks for gift cards or cryptocurrency
the message asks you to move to a personal account
the document asks you to enable macros
the sender asks you to install software
the sender asks you to grant remote access
the tone or timing is unusual for the person
an unexpected invoice or refund request is received
Good spelling, a correct logo, a familiar writing style or knowledge of clinic information does not prove that a message is genuine.
AI tools can help attackers create convincing text, audio, images and video.
7. Pause, check and report
Use the following approach when a message or request is unexpected.
Pause
Do not:
click the link
open the attachment
scan the QR code
enter your password
approve the sign-in
provide a verification code
make a payment
disclose information
install software
Check
Verify the request through a route obtained independently.
You may:
call a previously known telephone number
start a new email using the saved address
open the service through the usual bookmark
contact the manager through the established work route
check the request directly within the approved system
Do not verify a suspicious request by replying to the same message or calling a number provided within it. The attacker may control both.
Report
Use the approved phishing or incident-reporting route.
Urgent risks must also be reported directly to the Registered Manager and IT support.
Reporting a suspicious message does not mean that you have done anything wrong.
8. Passwords, passkeys and two-step verification
Passwords
Staff should:
use a unique password for every work account
use the organisation-approved password manager where provided
keep passwords private
avoid reusing a work password for a personal account
change a password promptly when instructed following suspected compromise
Staff must not:
share a password with a colleague
share a password with a manager
send a password by email
store passwords in an unprotected document
keep passwords on visible paper notes
use another person’s account
ask another person for their password
No legitimate support process requires staff to disclose their password.
Passkeys
Passkeys can reduce phishing risk because they are connected to the genuine service.
Use passkeys where WMI Psychiatry has approved and configured them.
A passkey must still be protected by:
the device’s screen lock
secure account recovery arrangements
appropriate control of the device
prompt reporting if the device is lost
Two-step verification
Two-step verification adds another check when signing into an account.
Never approve an unexpected sign-in request.
Repeated requests may be an attempt to wear you down. This is sometimes called multi-factor authentication fatigue.
If an unexpected request appears:
Deny the request.
Do not approve it to make the prompts stop.
Report it immediately.
Contact support through a trusted route.
Follow instructions about securing the account.
Never read a verification code to someone who telephones or messages you.
IT support may ask you to confirm your identity. They should not ask you to disclose your password or send them a one-time verification code.
9. Email safety
Staff must use the WMI Psychiatry work email account for patient and professional correspondence.
Before sending an email:
check the full recipient address
confirm that the recipient is authorised to receive the information
check all attachments
review the previous email history included in the message
ensure that only the minimum necessary information is included
check whether Bcc is required
check that autofill has selected the intended person
Staff must not:
forward clinic email to a personal account
use a personal email address for clinic work
create an automatic forwarding rule without authorisation
send information simply because a family member requests it
assume that a parent, partner or relative is authorised
send confidential information using an unapproved method
Report:
sent messages you do not recognise
missing emails
unexpected forwarding rules
unexplained password-reset messages
changes to account recovery information
unexpected sign-in alerts
Sending sensitive information
Before sending sensitive information confirm:
the person’s identity
their authority to receive it
the purpose of the disclosure
the minimum information required
the approved secure method
Cybersecurity does not replace consent, confidentiality or identity-verification procedures.
10. Files, links and cloud sharing
Staff should:
open work systems through trusted bookmarks or approved applications
check that a file-sharing invitation is expected
share files with named authorised people
use the least level of access required
use viewer access rather than editor access where appropriate
remove access when it is no longer required
check whether links have been made public
store files only within approved work systems
Staff must not:
upload clinic documents to personal Google Drive
upload clinic documents to personal Dropbox or another consumer service
create public links for patient information
download confidential information to a personal device without explicit authorisation
enable macros because a document asks them to
bypass a security warning
install a browser extension to open a file
move files to an unauthorised platform because the approved system is unavailable
If a document is accidentally uploaded or shared incorrectly remove access where this can be done safely and report the incident immediately.
Do not assume that deleting the visible file means that there was no breach. Another person may have opened, downloaded or copied it.
11. Devices and physical security
Staff should:
use only authorised devices for work
use a strong device passcode
use biometric protection where approved
lock the screen whenever they step away
install approved security updates promptly
allow the device to restart when required
keep antivirus and firewall controls active
keep devices physically secure
report loss, theft or unexpected behaviour immediately
Staff must not:
disable antivirus or firewall controls
disable device encryption
install unauthorised software
install unauthorised browser extensions
install remote-access tools without approval
connect unknown USB devices
allow family members or friends to use a work device
leave a work device unattended in a vehicle
lend a work device to another person
Printing and paper records
Cybersecurity also includes physical information.
Staff should:
collect printing immediately
avoid leaving patient lists or letters visible
store paper records securely
use the approved confidential-waste route
check printers and scanners after use
Staff must not photograph a screen or document using a personal telephone unless a current authorised procedure specifically permits this.
12. Remote and mobile working
When working remotely staff should:
work where conversations cannot be overheard
position screens where they cannot be viewed by unauthorised people
use an approved device
use the approved browser profile
follow the approved network arrangements
lock the device when stepping away
close systems at the end of the session
store work in approved systems rather than on the local desktop or Downloads folder where possible
use a privacy screen where required
Staff should avoid:
public or shared computers
discussing patients in public places
displaying confidential information during travel
allowing other household members to view work
leaving papers visible at home
using an unapproved personal service when the approved system is unavailable
Public Wi-Fi may be imitated by an attacker. Staff must follow WMI Psychiatry’s approved connection arrangements.
If the approved method is unavailable contact the manager for a safe alternative.
13. Telephone calls, identity and impersonation
A caller may claim to be:
a patient
a parent
a clinician
a bank
a software provider
an IT engineer
a police officer
a senior manager
a supplier
Caller identification can be falsified. A confident manner or knowledge of staff names does not prove identity.
Staff should:
follow the approved identity-verification process
verify unusual requests through a separate trusted route
end an unsolicited technical-support call
contact the organisation using a published or saved number
report attempts to obtain information
Staff must not disclose:
passwords
verification codes
confidential patient information
staff home addresses
personal telephone numbers
details of security arrangements
whether someone is a patient without appropriate authority
Staff must not install software or grant screen access during an unsolicited call.
14. Payment, refund and bank-detail fraud
Financial requests require additional verification because urgency and authority are commonly used to manipulate staff.
Staff should:
follow the approved payment and refund workflow
independently verify new or changed bank details
use an already-known telephone number for verification
retain evidence that verification was completed
check unexpected Stripe messages by opening Stripe through the usual route
report suspected fraud immediately
Staff must not:
allow an urgent email to replace required approval
process gift-card purchases for a manager
make cryptocurrency payments
send unusual transfers without the normal checks
use bank details supplied only within an unexpected email
make a payment because a sender claims that it is confidential
bypass controls because the request appears to come from a senior person
A message that appears to come from Dr Glass, Caroline Lawrence, a clinician or a supplier must still follow the normal approval and verification process.
Authority does not remove the need for verification.
15. Software updates, technical support and remote access
Security updates close known weaknesses.
Staff should allow approved updates to install and restart devices when required.
Unsupported devices or software must be reported.
Remote-access tools can give another person control of a device.
Staff must not install or activate remote-access software following:
an unsolicited telephone call
an unexpected email
a pop-up message
a website warning
an unexpected text message
Use only WMI Psychiatry’s established support route.
Verify the support person through the agreed process before granting access.
16. Malware and ransomware warning signs
Possible warning signs include:
files not opening
files having unfamiliar names
a message demanding payment
the device becoming unusually slow
repeated pop-ups
antivirus being disabled unexpectedly
the mouse moving without your action
windows opening without your action
unexpected software appearing
many files being changed or deleted
colleagues receiving messages you did not send
being locked out of an account
verification details changing unexpectedly
Immediate response
If malware or ransomware is suspected:
Stop using the affected device.
Disconnect it from Wi-Fi and any network cable where this can be done safely.
Do not connect backup drives or USB devices.
Do not connect another work device.
Contact the Registered Manager and urgent IT support from a separate trusted device.
Do not pay a ransom.
Do not negotiate.
Do not delete files.
Do not run cleaning software.
Do not wipe or reset the device.
Record what you observed and the time.
Preserve relevant messages through an authorised method.
17. What to do after clicking or entering information
People sometimes click convincing messages. Rapid and honest reporting is more valuable than trying to conceal the mistake.
You opened the message but did not interact with it
stop
do not click links
do not open attachments
report the message through the approved phishing route
You clicked a link
close the page
do not enter any information
contact the manager and IT support immediately
preserve the original message
You entered a password
stop using the page
report it immediately
follow support instructions
change the password from a trusted device when instructed
ensure that active sessions are reviewed or revoked
You approved a sign-in request or shared a code
Treat this as an urgent possible account compromise.
Do not wait to see whether anything happens.
You opened an attachment or installed something
stop using the device
disconnect it from the network
contact urgent support
do not attempt to remove the software yourself
You made a payment or disclosed bank information
report it immediately to management
follow the fraud-response procedure
preserve the message and payment details
act promptly because recovery may be time-sensitive
18. Personal data breaches and cyber incidents
A personal data breach is a security incident that affects the confidentiality, integrity or availability of personal data.
It can be accidental or deliberate.
Examples include:
an email sent to the wrong person
an attachment sent to the wrong person
a patient file shared with excessive permissions
a lost or stolen device
an unauthorised person viewing a record
a compromised account
altered or deleted records
ransomware making records unavailable
patient information uploaded to an unauthorised platform
paper records being lost
confidential information being placed in ordinary waste
WMI Psychiatry must record personal data breaches and assess whether notification is required.
Some breaches must be reported to the Information Commissioner’s Office without undue delay and where feasible within 72 hours of awareness.
Administration staff must report a possible breach immediately.
They must not delay while deciding whether the legal reporting threshold has been met.
Administration staff must not contact the Information Commissioner’s Office independently unless this is part of their authorised role.
19. Reporting and preserving evidence
Report the incident as soon as possible.
Include:
the date and time of discovery
the device, account or system involved
the communication method
what you saw
what you did
whether a link was clicked
whether an attachment was opened
whether a QR code was scanned
whether credentials were entered
whether a sign-in was approved
whether information or money was disclosed
the type of personal data involved where known
the approximate number of people affected where known
containment steps already taken
who was notified
the time they were notified
Preserve:
the original email
messages
relevant screen information
call records
payment information
system alerts
relevant times
authorised screenshots or logs
Do not:
alter records
delete evidence
fabricate information
forward sensitive evidence to a personal account
post screenshots in an informal staff group
attempt to make the incident appear less serious
attempt to investigate another person’s account
20. Near misses and a just culture
A near miss is an event that could have caused harm but did not.
Examples include:
noticing an incorrect email recipient before sending
receiving a convincing fraudulent invoice without paying it
denying an unexpected sign-in request
identifying excessive file permissions before confidential information is accessed
recovering a work device before it is lost
Near misses should be reported because they can reveal weaknesses in systems and processes.
WMI Psychiatry expects prompt and honest reporting.
An inadvertent error reported immediately should be used to support containment, learning and improvement.
Deliberate misuse, concealment or repeated disregard of policy may require a separate management process.
21. Access control and role boundaries
Staff should:
use only their own account
access only the information needed for their work
use only the permissions provided for their role
report when access is excessive
report when necessary access is missing
report access that is no longer required
challenge unexpected requests for bulk exports
challenge unexpected requests for administrator access
Staff must not:
browse records out of curiosity
use another staff member’s unlocked session
share an account
approve their own additional access
retain access after their role changes
retain access after their work ends
use a colleague’s credentials to complete urgent work
Least privilege means giving each person only the access needed for their role.
This limits the harm which can occur if an account is compromised.
22. Business continuity during a cyber incident
A cyber incident may make email, Zanda Health, Google Workspace, AppSheet, payment systems or telephone services unavailable.
Staff must follow the current Business Continuity Plan rather than creating unapproved workarounds.
Staff should:
follow management instructions about which systems must not be used
use only approved contingency records
use only approved communication routes
record urgent clinical messages through the authorised process
maintain a clear record of actions taken during the outage
escalate risks to care or urgent communication to the responsible clinician
Staff must not:
move patient information to a personal account
use an unauthorised consumer service
reconnect an isolated device without IT authorisation
use another person’s account
create an unapproved local database
assume that a system is safe because it appears to be working again
23. Practical scenarios
Scenario 1: Unexpected shared document
An administrator receives an email stating that a clinician has shared a patient report. The sign-in page looks like Google but the invitation was not expected.
Appropriate response:
Do not use the link.
Contact the clinician through a trusted route.
Open Google Workspace through the usual bookmark to check whether a genuine share exists.
Report the message through the approved phishing route.
Scenario 2: Unexpected verification prompt
A sign-in approval appears on the administrator’s telephone while they are not signing in.
Appropriate response:
Deny the request.
Do not approve it to make the prompts stop.
Report it immediately as a possible account compromise.
Follow support instructions through a trusted route.
Scenario 3: Urgent refund request
A message appearing to be from Caroline asks an administrator to send an urgent refund to new bank details. The message states that she cannot take a telephone call.
Appropriate response:
Do not process the payment.
Verify the request using a previously known contact method.
Follow the normal approval process.
Report the suspicious message.
Scenario 4: Wrong recipient
An administrator sends an appointment letter to the wrong email address because autofill selected a similar name.
Appropriate response:
Notify the Registered Manager immediately.
Attempt recall if this is available but do not assume it worked.
Follow instructions about contacting the recipient and containing the breach.
Complete the incident or data breach record promptly.
Scenario 5: Lost laptop
A work laptop is missing after a journey.
Appropriate response:
Report the loss immediately.
Provide the last known time and place.
Confirm whether the device was locked.
Follow instructions about remote locking, account sessions and police reporting.
Do not delay because you hope the device will be found.
Scenario 6: Ransom message
A device displays a payment demand and files will not open.
Appropriate response:
Stop using the device.
Disconnect it from networks where this can be done safely.
Contact management and urgent IT support from another device.
Do not pay, wipe or attempt to repair the device.
Scenario 7: IT support telephone call
A caller states that they are from Google and need the administrator’s verification code to stop an attack.
Appropriate response:
Do not provide the code.
End the call.
Contact the approved support route using known contact details.
Report the attempt.
Scenario 8: Personal cloud upload
A patient document is accidentally uploaded to a personal cloud account.
Appropriate response:
Remove access where this can be done safely.
Report the incident immediately even if the file has been deleted.
Provide details of the account, file and possible access.
Do not assume that deletion means there was no breach.
Scenario 9: New supplier bank details
A genuine-looking invoice states that the supplier has changed bank accounts.
Appropriate response:
Do not rely on the invoice email.
Verify the change using the saved supplier telephone number.
Follow the approved financial process.
Record how the change was verified.
Report inconsistencies as suspected fraud.
Scenario 10: Unauthorised browser extension
A website states that a browser extension is needed to view a referral.
Appropriate response:
Do not install the extension.
Close the page.
Check the referral through the approved system.
Report the website or message.
Scenario 11: Video meeting link
An unexpected person asks to join an online clinical meeting and states that the clinician invited them.
Appropriate response:
Do not admit the person based only on the claim.
Verify their identity and authority through the approved process.
Protect meeting details and patient confidentiality.
Report suspicious access attempts.
Scenario 12: Colleague requests a login
A colleague cannot access Zanda Health and asks to use another administrator’s account for one appointment.
Appropriate response:
Do not share the account or password.
Ask the colleague to use the authorised access-support route.
Escalate urgent work through the manager.
Report repeated or pressured requests for shared access.
24. Key learning points
Cybersecurity protects confidentiality, information accuracy and service availability.
Unexpected urgency, secrecy or a bypass of normal processes should make staff pause.
A familiar display name, logo, voice or writing style does not prove identity.
Sensitive requests should be verified through an independently trusted route.
Staff must use unique credentials and approved passkeys or two-step verification.
Passwords and one-time codes must never be shared.
Unexpected sign-in requests must not be approved.
Only approved work systems, devices and accounts should be used.
Recipients, attachments and sharing permissions must be checked before sending.
Devices should be updated, locked and physically secure.
Staff must not install software or grant remote access following an unsolicited request.
A device which may be infected should no longer be used and should be isolated where safe.
Suspicious clicks, lost devices, wrong recipients and near misses must be reported immediately.
Staff must not conceal mistakes or attempt to investigate alone.
Evidence should be preserved through approved routes.
Administration staff report incidents but do not make regulatory notification decisions alone.
The Business Continuity Plan should be followed when systems are unavailable.
Knowledge assessment
Learner instructions
Choose the single best answer.
You must achieve at least 12 out of 15 to pass.
Any incorrectly answered safety-critical question must be reviewed even if the overall pass mark is achieved.
Question 1
Which statement best explains why cybersecurity matters in an outpatient psychiatry service?
A. It is only an issue for the IT provider
B. It protects confidentiality, reliable information and access to services
C. It applies only when money is stolen
D. It applies only to clinical staff
Question 2
Which feature proves that an email is genuine?
A. It uses the clinic logo
B. It contains correct staff names
C. It has no spelling mistakes
D. None of these features proves that it is genuine
Question 3
You receive an unexpected link to a shared patient document. What should you do?
A. Sign in so that you can see whether it is genuine
B. Forward it to a personal email account
C. Verify the share through a trusted route and report the suspicious message
D. Reply to ask the sender whether it is safe
Question 4
You entered your work password on a page reached from a suspicious email. What should you do?
A. Wait to see whether anything happens
B. Report it immediately and follow support instructions from a trusted device
C. Delete the email and say nothing
D. Change one letter in the password next week
Question 5
Which statement about two-step verification is correct?
A. Approve requests until they stop
B. Share a code with anyone who knows your job title
C. Deny and report an unexpected request
D. Two-step verification makes password sharing acceptable
Question 6
A message from a senior manager requests an urgent payment outside the normal process. What is the best response?
A. Pay because the sender is senior
B. Verify the request through an independent trusted route and follow the normal approval process
C. Reply to the message and accept the answer
D. Use a personal account to make the payment faster
Question 7
A caller claiming to be IT support asks for your one-time verification code. What should you do?
A. Provide it if the caller sounds professional
B. Provide half of it
C. Refuse, end the call and contact approved support through a trusted route
D. Ask the caller to email you and then provide it
Question 8
Which action is appropriate when sharing a clinic file?
A. Create a public link because it is faster
B. Share it with named authorised people using the least access required
C. Upload it to personal cloud storage
D. Give editor access to everyone in the organisation
Question 9
You accidentally email a patient letter to the wrong person. What should you do first?
A. Hope that they do not open it
B. Delete the sent message only
C. Report it immediately and follow the breach-containment procedure
D. Contact the Information Commissioner’s Office before telling your manager
Question 10
Which statement about personal data breach reporting is correct?
A. Staff should investigate fully before telling anyone
B. Only deliberate attacks count as breaches
C. Staff should report promptly so that the organisation can assess and contain the event
D. A deleted file can never be a breach
Question 11
What should you do with an unexpected multi-factor sign-in request?
A. Approve it once
B. Deny it and report possible account compromise
C. Ignore repeated requests for several days
D. Ask a colleague to approve it
Question 12
A computer displays a ransom demand and files will not open. What is the best immediate response?
A. Pay the demand
B. Continue working to identify every affected file
C. Stop using the device, disconnect it from the network where safe and obtain urgent help
D. Wipe the device immediately
Question 13
Why should near misses be reported?
A. To punish staff for every mistake
B. To identify weaknesses and prevent future harm
C. Because every near miss must be reported to the police
D. Near misses should not be reported
Question 14
A colleague asks to use your Zanda Health account because their access is not working. What should you do?
A. Share it for five minutes
B. Sign in and leave the session open for them
C. Refuse and use the authorised access-support and escalation route
D. Send them your password and change it later
Question 15
Which best summarises the administration team’s role during a cyber incident?
A. Investigate the attacker and decide whether to notify the Information Commissioner’s Office
B. Stop risky activity, contain the incident within the limits of the role, report promptly and preserve evidence
C. Delete all suspicious information
D. Keep the incident private until the next governance meeting
Learner declaration
I confirm that:
I have completed the full module.
I know how to contact the Registered Manager and urgent IT support.
I understand how to recognise and report suspicious messages.
I will not share passwords or verification codes.
I will not approve unexpected sign-in requests.
I understand how to verify payment and bank-detail requests.
I know what to do after clicking a suspicious link or entering credentials.
I know how to respond if a device may be infected or affected by ransomware.
I know where cyber incidents, personal data breaches and near misses must be recorded.
I understand that I must report promptly and must not conceal an error.
I understand that I must use approved work accounts, devices and systems.
I understand my role boundaries during technical and regulatory investigations.
I know how to access WMI Psychiatry’s current policies and Business Continuity Plan.
Learner’s name: ______________________________
Role: ______________________________
Date completed: ______________________________
Attempt number: ______________________________
Signature: ______________________________
Score: ______ / 15
Result: Pass / Further learning required
Safety-critical errors reviewed: Yes / No / Not applicable
Manager or assessor: ______________________________
Renewal date: ______________________________
Manager’s marking guide
Question 1
Correct answer: B
Cybersecurity protects confidentiality, the reliability of information and the availability of systems needed for care and administration.
Question 2
Correct answer: D
Logos, names and fluent writing can be copied or generated. The sender and request must be checked using trusted controls.
Question 3
Correct answer: C
The learner should avoid the link, check through the known system or sender and report the suspicious invitation.
Question 4
Correct answer: B
Entered credentials may be used immediately. Rapid reporting allows password reset, session revocation and investigation.
Question 5
Correct answer: C
An unexpected request may mean that someone has obtained the password. It must be denied and reported.
Question 6
Correct answer: B
Seniority and urgency do not replace financial controls. Independent verification reduces the risk of impersonation and compromised-email fraud.
Question 7
Correct answer: C
Verification codes are authentication secrets. The call should be ended and approved support should be contacted independently.
Question 8
Correct answer: B
Named access and least privilege reduce accidental disclosure and limit harm if an account is compromised.
Question 9
Correct answer: C
A wrong-recipient email may be a personal data breach. Immediate reporting enables recall attempts, recipient contact and risk assessment.
Question 10
Correct answer: C
Staff should report the facts promptly. The authorised lead assesses the event and decides whether the Information Commissioner’s Office or affected people must be notified.
Question 11
Correct answer: B
An unexpected sign-in request must not be approved. It may indicate an attempted account takeover.
Question 12
Correct answer: C
Stopping use and isolating the device can reduce the spread of malware. Staff should obtain urgent help and must not pay or wipe the device.
Question 13
Correct answer: B
Near misses reveal weaknesses in messages, workflows and controls before harm occurs.
Question 14
Correct answer: C
Accounts are individual. Urgent work must be escalated without sharing credentials.
Question 15
Correct answer: B
Administration staff should stop risky activity, take approved containment steps, report promptly and preserve evidence. Technical investigation and regulatory decisions require authorised leads.
Questions 4, 5, 7, 9, 10, 11, 12 and 14 are safety-critical.
For every incorrect answer the manager should:
Discuss the correct response with the learner.
Record that the answer was reviewed.
Ask the learner to explain the correct local procedure in their own words.
Confirm that the learner knows the urgent reporting route.
Require reassessment if understanding remains uncertain.
A learner must not be recorded as competent if they remain uncertain about:
unexpected sign-in requests
credential disclosure
wrong-recipient information
suspected malware
ransomware
urgent incident reporting
account sharing
preserving evidence
payment verification
CQC and governance implementation requirements
Before issuing this module WMI Psychiatry should:
complete and test every local contact and reporting route
confirm the current list of approved systems
remove obsolete systems from the module
ensure the module matches the current Information Governance Policy
ensure the module matches the current incident and data breach procedures
provide every user with an individual account
ensure access is appropriate to each person’s role
enable passkeys or two-step verification where supported and authorised
maintain joiner, mover and leaver access controls
maintain supported devices
install security updates promptly
maintain malware protection and encryption
maintain tested backups
maintain a current Business Continuity Plan
provide an approved phishing-reporting route
provide an urgent IT-support route
maintain a personal data breach and cyber incident log
encourage prompt reporting of honest errors and near misses
review cyber incidents through governance meetings
review account activity and sharing permissions proportionately
protect staff personal details from impersonation and social engineering
maintain financial verification controls
prohibit shared credentials
prohibit unauthorised remote-access tools
provide practical induction on WMI Psychiatry’s actual systems
retain the learner’s answers, score, declaration and attempt number
record completion in the staff training matrix
document review of safety-critical errors
provide refresher training annually
provide additional training after relevant incidents or significant system changes
consider supportive phishing simulations or practical exercises
review whether controls are effective
ensure security arrangements do not encourage unsafe workarounds
CQC Regulation 17 requires records to be secure and accessed, amended or destroyed only by authorised people.
CQC expects organisations to provide regular data-security training, restrict access according to role and maintain plans for responding to threats.
CQC Regulation 18 requires staff to receive appropriate support and training.
The UK GDPR security principle requires appropriate technical and organisational measures to protect personal data.
These duties cannot be met through e-learning alone. The training must be supported by effective policies, technical controls, access management, incident reporting, backups, supervision and business continuity arrangements.
Further reading and authoritative guidance
National Cyber Security Centre: Small organisations guide to cyber security
National Cyber Security Centre: Phishing attacks – defending your organisation
National Cyber Security Centre: Secure your important online accounts
National Cyber Security Centre: Keeping devices and software up to date
National Cyber Security Centre: How to secure your online meetings
Information Commissioner’s Office: Personal data breaches – a guide
Information Commissioner’s Office: Responding to a personal data breach
Care Quality Commission: Handling personal information to the required standards
NHS England: A just culture guide for information governance and cybersecurity
Cybersecurity guidance and legal requirements change. The Registered Manager should confirm that this module remains aligned with current NCSC, ICO, CQC and NHS guidance at each review and following any significant incident or system change.