A plain-language awareness programme that changes daily behaviour across departments - phishing, passwords, devices, data handling and incident reporting.
Government cyber security awareness training teaches department staff to recognise phishing and social engineering, handle citizen data under the DPDP Act, secure devices and passwords, and report incidents through the correct CERT-In aligned channel. Nirmal Rabari delivers 3-hour awareness sessions and full-day IT workshops on-site for Indian government departments and PSUs in English, Hindi and Gujarati.
Most breaches in the public sector do not start with an exotic exploit. They start with a convincing email, a reused password, an unpatched machine or a WhatsApp forward carrying a malicious link. The programme is built around those real entry points rather than abstract theory.
Sessions map to CERT-In directions on incident reporting timelines, MeitY guidance for departmental IT, and the DPDP Act's obligations for handling citizen personal data - including where AI tools such as ChatGPT fit and where they must not be used.
How attacks against Indian government systems actually begin, with recent, anonymised case examples.
Email, SMS, WhatsApp and voice scams - spotting them in under ten seconds.
Password managers, passphrases and multi-factor authentication configured live in the room.
Patching, USB discipline, public Wi-Fi, screen locks and safe remote access.
Classification, minimisation, retention and safe sharing of records under the DPDP Act.
What may and may not be pasted into public chatbots, and the sanctioned alternative stack.
Recognise, contain and report within CERT-In timelines using a one-page flowchart.
Controlled phishing exercise with a department-level scorecard and improvement plan.
Government departments, PSUs, municipal bodies, police and administrative staff - from clerical users to IT and department heads.
A 3-hour awareness session for all staff, a full-day workshop for IT teams, and a 2-day programme for security and audit cohorts.
Yes. The curriculum maps to CERT-In advisories, MeitY guidance and the DPDP Act, and includes the department's incident-reporting duties.
Yes. A controlled phishing simulation before and after the session gives the department a measurable improvement number.
English, Hindi and Gujarati, delivered on-site at the department's premises or live online.
A one-page cyber hygiene poster, an incident-reporting flowchart, a simulation report and a 90-day awareness calendar.