Apprise Cyber a recently delivered a hands-on Cyber Hygiene workshop for the team at Forteve, covering phishing awareness, threat response, password hygiene, and essential security practices for everyday work.
Why Is Cybersecurity Awareness Training Important for Software Companies?
Because people are the first and most effective line of defence. Forteve is a software house, and software houses hold client source code, API keys, cloud logins, and user data. Attackers know that breaching one vendor can open the door to many clients.
The session opened with a reminder that most breaches involve human error. The good news is that most attacks fail the moment a trained employee pauses, questions, and reports.
What Did the Workshop Cover?
The session ran about 90 minutes and mixed theory, live demos, and team challenges. Instead of slides alone, participants saw how real attacks work.
How Do Attackers Target Software Teams?
They target developers directly, using fake coding tests, poisoned packages, leaked secrets, and weak client access. We covered:
- Fake recruiter coding tests that install malware
- Look-alike npm and pip packages
- API keys and .env files pushed to Git or shared on chat apps
- Missing MFA on GitHub, AWS, and Firebase
What Does an Attacker Already Know About You?
More than most people expect. We ran a live recon demo showing how public sources reveal staff roles, email formats, and technology stacks. The takeaway: reduce what you expose, and stay alert once it has been gathered.
How Do You Build a Password Attackers Cannot Crack?
Use a passphrase of 16+ characters made from unrelated words, and keep it unique for every important account. Length beats complexity. Participants built passphrases in four steps, then watched a weak password and a strong passphrase race against a cracking tool in real time.
We also covered MFA, including MFA fatigue, where attackers spam login prompts hoping someone taps “Allow”. The rule is simple: if you did not trigger it, deny it and report it.
How Do You Spot a Phishing Email?
Check the sender domain, question any urgency, hover over links, and never act on unusual requests from the email itself. Phishing works because it targets psychology: urgency, authority, fear, and reward.
We dissected sample emails, including a fake debit alert, a spoofed HR attachment, and a look-alike domain. In the “Spot the Phish” challenge, teams compared two near-identical emails and explained their reasoning. A live phishing autopsy showed how to inspect a suspicious link safely, without ever visiting it.
What Is Social Engineering Beyond Email?
It is any attempt to manipulate people by phone, text, or in person. We covered vishing, smishing, pretexting, and baiting. A live voice-cloning demo showed how convincing a fake “call from the boss” can sound. Any call demanding urgent payment or secrecy needs a second, independent check.
How Should Teams Handle Devices, Networks, and Data?
Lock screens, patch quickly, use the company VPN, and classify data before sharing it. Practical habits included:
- Applying updates within 48 hours
- Enabling full-disk encryption and remote wipe
- Avoiding public Wi-Fi for sensitive work
- Treating data as Public, Internal, Confidential, or Restricted
What Should You Do When Something Goes Wrong?
Stop, report, contain, cooperate, and recover, in that order. Panic is the enemy. Participants worked through realistic scenarios: a CEO fraud message, an unknown USB drive, a malicious QR code, and a ransom note on a Monday morning.

What Were the Key Takeaways?
Ten golden rules for the whole team:
- Use passphrases with a password manager
- Enable MFA everywhere
- Think before you click
- Apply updates within 48 hours
- Lock your screen when you step away
- Use the company VPN outside the office
- Back up critical work to approved storage
- Label data correctly
- Follow the remote-work checklist
- Report anything suspicious immediately
A Security-First Culture Starts With Awareness
Thank you to our trainers, Laiba Khalid and Muzammil Ishaq Gabol, for leading the session, and to Forteve’s CIO, Amir Anwar, for organizing it. It was great to see the Forteve team so engaged throughout.
Want the Same Training for Your Team? (H2)
Apprise Cyber Pvt Ltd offers a free cybersecurity seminar led by our security experts.
- WhatsApp: wa.me/923352777473
- Email: [email protected]
Need a free cybersecurity seminar for your organisation? The Apprise Cyber team is available.


