
Real attacks almost never look like the films. Most of them walk through a door somebody left open. Five lessons on which doors those are, and what your student can actually do about them.
Lesson 1 is the mechanism — phishing, reused passwords, credential stuffing, social engineering — with a message realistic enough to be worth pulling apart, because real phishing is clean and professional rather than full of spelling mistakes. Lesson 2 replaces "be careful about everything" with two axes you can apply to any situation: how sensitive the data is, and how exposed it is. Lesson 3 separates one person's bad moment from a weakness that was already there. Lesson 4 is the accountability chain, built so there is no single villain to pick. Lesson 5 is the project: your student writes the security policy they will actually follow, marked against a rubric out of 20.
No device is required anywhere in the unit — that is deliberate, so the work is recognizing patterns rather than clicking anything.
The five per-lesson teacher guides are printed with the handouts as they were written. On top of them, this edition adds four pages of the same guidance rewritten for one student and a parent — objective, timing, what to watch for, and the specific places the conversation goes wrong — plus the project rubric on a page of its own.
Written by a licensed K-12 business teacher with more than thirteen years in the classroom. Built to be taught by a parent with no background in the subject.



