Cybersecurity
Build practical security judgement across identity, web risk, detection, and response using plain language, realistic scenarios, and defensible evidence.
This course is written for people who need to understand security decisions without being buried in jargon or vendor theatre. By the end, you should be able to explain what matters, where the exposure sits, and what to do about it.

What you will learn
- Explain the CIA triad, risk, and controls in plain language with concrete examples
- Apply structured threat modelling to systems and identify assets, actors, and entry points
- Use interactive tools to assess passwords, URLs, hashes, and risk matrices
- Relate enterprise security decisions to NIST CSF 2.0, ISO 27001, and Cyber Essentials
- Design high-level secure architectures for web and cloud-based systems
- Communicate security risks and mitigations to non-technical stakeholders
Single learning path
- Senior executive leaders who now lead technical teams and need to build defensible cybersecurity judgement from first principles
- Technical professionals who want a complete cybersecurity spine from foundations through architecture, operations, governance, and executive risk
- Teams preparing for Cyber Essentials v3.3, NIST CSF 2.0, ISO/IEC 27001:2022, OWASP, and related evidence-based security reviews
- Career changers and specialists who need one rigorous path rather than separate executive and engineering tracks
Prerequisites: None. Course starts from absolute basics with everyday examples.
The cybersecurity course: four stages around one governing habit
Each stage hands the next one thing: a shared vocabulary, then design judgement, then an operating capability, with the Govern hub tied to all four, making governance something exercised at every stage rather than added once the technical work is done.
The course runs Foundations to Applied practice to Practice and strategy to Exam, each handing the next a capability, with Govern tied to every stage because risk-led decisions are made throughout, not at the end. Source: NIST CSF 2.0.
Every figure and studio tool in the course is catalogued in the cybersecurity toolkit, faceted by CSF 2.0 function and stage.
Course curriculum
Read the modules in order on the first pass. Use the practice and stage tests when you want a stricter check on what stuck.
Stage 1. Foundations
12 modules · 8 hours
Stage 2. Applied cybersecurity
9 modules · 8 hours
Stage 3. Practice and strategy
17 modules · 11 hours
Stage 4. Exam preparation and certification
3 modules · 4.25 hours
Cybersecurity summary and games
1 hour
A recap and practice space to consolidate judgement with scenarios and short drills.
Certification routes
Exam preparation written against this course, with timed and untimed practice.
- CompTIA Security+ (SY0-701)Study routes mapped to published objectives, with timed and untimed practice paths.
- ISC2 Certified in Cybersecurity (CC)Study routes mapped to published objectives, with timed and untimed revision paths.
- NIST Cybersecurity Framework 2.0Outcome-based thinking and scenario application against the framework functions.
Standards and references
This course is aligned to the following standards, frameworks, and certification objectives.
- 1NIST Cybersecurity Framework (CSF) 2.0 (2024) - 6 functions: Govern, Identify, Protect, Detect, Respond, Recover
- 2OWASP Top 10:2025 - A01 Broken Access Control through A10 Mishandling of Exceptional Conditions
- 3OWASP ASVS 5.0.0 - application security verification requirements
- 4ISO/IEC 27001:2022 - 93 controls across 4 categories (Organisational, People, Physical, Technological)
- 5MITRE ATT&CK v19.1 (current release, 28 April 2026) - detection and coverage taxonomy
- 6CIS Controls v8.1 - 18 controls, 153 safeguards across 3 implementation groups
- 7Cyber Essentials requirements v3.3 (effective 27 April 2026) - five technical control themes
- 8CompTIA Security+ SY0-701 - 5 domains (General Concepts, Threats, Architecture, Operations, Management)
- 9EU NIS2 Directive (2023)