You don’t need to be a cybersecurity professional to teach the people around you how to stay safe online. This toolkit gives you everything to run a 60-minute session for a school, mosque committee, women’s group, small business association, or any community group, with no preparation beyond reading this page once.

Who this is for

Teachers, imams and community elders, NGO field staff, small business owners, university society leads, or anyone who’s been asked “can you explain this cyber stuff to us” and wants a structure to lean on instead of winging it.

What you’ll need

Session structure (60 minutes)

1. Open with a question, not a lecture (5 min)

Ask the room: “Has anyone here, or someone in your family, lost money or had an account taken over online?” In almost every group, someone has a story. Let one or two people share briefly. This does more to earn attention than any statistic would, and it means you’re not opening with a claim you’d need a citation for.

2. The four scam patterns to know (15 min)

Walk through these, asking “has anyone seen this?” after each one rather than just reading it out:

  • The fake job offer. A WhatsApp message offering easy remote work, often asking for an upfront “registration fee” or your CNIC details before any real interview happens. Real employers do not ask for money to hire you.
  • The mobile wallet call. Someone calls claiming to be from JazzCash, EasyPaisa, or your bank, saying your account has a problem, and asks for your PIN or the OTP code that just arrived by SMS. No legitimate bank or wallet provider will ever ask for your PIN or OTP over the phone.
  • The marketplace scam. On Daraz or a Facebook Marketplace-style listing, a seller asks you to pay outside the platform’s official checkout, or a buyer sends a fake “payment confirmation” screenshot and asks you to ship before the money actually arrives.
  • The CNIC-linked message. A message claiming your SIM, bank account, or a government service tied to your CNIC will be blocked unless you click a link and “verify” your details immediately. The urgency is the tell, real institutions give you time.

Trainer note: don’t invent statistics here (“X% of Pakistanis have experienced this”). If someone asks how common something is, it’s fine to say “I don’t have an exact number, but I hear about this pattern often” rather than making one up.

3. The three habits that stop most of this (15 min)

Rather than a long technical list, teach these three:

  1. Slow down before you act. Every scam pattern above depends on urgency. If a message or call is pressuring you to act right now, that pressure is itself the warning sign. Hang up, close the app, and verify independently (call the bank’s official number, not one given to you in the message).
  2. Never share an OTP or PIN, ever, with anyone. Not a “bank employee,” not a “delivery agent,” not a family member’s friend. This one habit prevents the majority of account-takeover fraud.
  3. Use a separate, strong password for anything involving money. Reusing one password across your email, mobile wallet, and social media means one leak compromises everything. If your phone supports passkeys, mention that CyberWalk has a separate guide for that.

4. Hand out the checklists (10 min)

Distribute the printed Home Network Checklist and Password & Passkey Checklist. Give attendees five minutes to actually check one item on the spot (most people will check their Wi-Fi password or turn on two-factor on one account right there in the room). Action taken during the session sticks far better than a checklist taken home and never opened.

5. Close with “who do you tell” (10 min)

Make sure everyone leaves knowing:

  • If they’re a victim of cybercrime in Pakistan, they can report it to the National Cyber Crime Investigation Agency (NCCIA) helpline, 1991, or via cybercrime.gov.pk
  • They should tell a trusted person immediately if something feels wrong, embarrassment is what scammers count on to stop people from reporting

Leave five minutes for questions.

Adapting the session

  • Shorter (30 min): Do sections 2 and 3 only, skip the opening discussion and hand out checklists without the live walkthrough.
  • For a school/youth audience: Add a short discussion on not sharing personal photos or location with strangers online, and what to do if a stranger online asks to keep a conversation secret from parents, tell a trusted adult, always.
  • For a small business audience: Spend more time on section 3’s password/2FA habits, applied to shared business accounts (social media pages, payment gateways), since one compromised employee account can affect the whole business.

Keep this toolkit sourced

If you’re asked something during a session that you can’t answer confidently, it’s fine to say so and follow up later rather than guessing. Scam patterns shift, and the goal is trust, not appearing to know everything.

 

This toolkit pairs with CyberWalk’s Home Network Checklist and Password & Passkey Checklist. If you run a session using this guide and learn of a new scam pattern worth adding, get in touch, this page is meant to stay current.