One class for one hour is not much time at all. To get the most out of it, I would actually try to keep the scope as narrow as possible. I would really dig into these two things:
Password management (make good passwords, use a pw-manager to avoid reusing a pw, change passwords regularly)
Spotting social engineering (I would spend at least 2/3 of the class on this topic) this is by far the most common vector through which people get hurt by poor tech literacy. If you want to do the most good for the most people I would recommend focusing on drilling this skill.
My point is that the law is just going to keep creeping up in severity because of workarounds like this.