Cybersecurity

Build practical security judgement across identity, web risk, detection, and response using plain language, realistic scenarios, and defensible evidence.

This course is written for people who need to understand security decisions without being buried in jargon or vendor theatre. By the end, you should be able to explain what matters, where the exposure sits, and what to do about it.

28 hours4 stages plus summary, 41 modulesBeginners welcomeFree, no account
Start with Module 1
Operator at a control-room desk facing a wall of mimic diagrams and monitoring screens

What you will learn

  • Explain the CIA triad, risk, and controls in plain language with concrete examples
  • Apply structured threat modelling to systems and identify assets, actors, and entry points
  • Use interactive tools to assess passwords, URLs, hashes, and risk matrices
  • Relate enterprise security decisions to NIST CSF 2.0, ISO 27001, and Cyber Essentials
  • Design high-level secure architectures for web and cloud-based systems
  • Communicate security risks and mitigations to non-technical stakeholders

Single learning path

  • Senior executive leaders who now lead technical teams and need to build defensible cybersecurity judgement from first principles
  • Technical professionals who want a complete cybersecurity spine from foundations through architecture, operations, governance, and executive risk
  • Teams preparing for Cyber Essentials v3.3, NIST CSF 2.0, ISO/IEC 27001:2022, OWASP, and related evidence-based security reviews
  • Career changers and specialists who need one rigorous path rather than separate executive and engineering tracks

Prerequisites: None. Course starts from absolute basics with everyday examples.

The cybersecurity course: four stages around one governing habit

Each stage hands the next one thing: a shared vocabulary, then design judgement, then an operating capability, with the Govern hub tied to all four, making governance something exercised at every stage rather than added once the technical work is done.

The course runs Foundations to Applied practice to Practice and strategy to Exam, each handing the next a capability, with Govern tied to every stage because risk-led decisions are made throughout, not at the end. Source: NIST CSF 2.0.

The cybersecurity course: four stages around one governing habit A central Govern hub (the governing habit; Govern: risk-led decisions at every stage) sits above four stage cards, tied to each by thin dashed lines. Stages, left to right: Stage 1 Foundations (threats and risk, identity, people and privacy); Stage 2 Applied practice (threat modelling, web and API security, release gates); Stage 3 Practice and strategy (operations and resilience, regulation, OT and AI); Stage 4 Exam and certification (revision, mocks, certificate). A progression line beneath carries what each hands on: a shared vocabulary and risk model, design judgement under attack, an operating and governing capability, and a final outward arrow from Exam to evidence of expertise. THE CYBERSECURITY COURSE · FOUR STAGES AROUND ONE GOVERNING HABIT THE GOVERNING HABIT · NIST CSF 2.0 Govern: risk-led decisions Exercised at every stage, not bolted on at the end STAGE 1 Foundations Threats and riskIdentityPeople and privacy STAGE 2 Applied practice Threat modellingWeb and API securityRelease gates STAGE 3 Practice andstrategy Operations, resilienceRegulationOT and AI STAGE 4 Exam andcertification RevisionMocksCertificate a shared vocabularyand a risk modeldesign judgement underattackan operating andgoverning capabilityevidence ofexpertise

Every figure and studio tool in the course is catalogued in the cybersecurity toolkit, faceted by CSF 2.0 function and stage.

Course curriculum

Read the modules in order on the first pass. Use the practice and stage tests when you want a stricter check on what stuck.

4

Stage 4. Exam preparation and certification

3 modules · 4.25 hours

5

Cybersecurity summary and games

1 hour

A recap and practice space to consolidate judgement with scenarios and short drills.

Certification routes

Exam preparation written against this course, with timed and untimed practice.

Standards and references

This course is aligned to the following standards, frameworks, and certification objectives.

  1. 1NIST Cybersecurity Framework (CSF) 2.0 (2024) - 6 functions: Govern, Identify, Protect, Detect, Respond, Recover
  2. 2OWASP Top 10:2025 - A01 Broken Access Control through A10 Mishandling of Exceptional Conditions
  3. 3OWASP ASVS 5.0.0 - application security verification requirements
  4. 4ISO/IEC 27001:2022 - 93 controls across 4 categories (Organisational, People, Physical, Technological)
  5. 5MITRE ATT&CK v19.1 (current release, 28 April 2026) - detection and coverage taxonomy
  6. 6CIS Controls v8.1 - 18 controls, 153 safeguards across 3 implementation groups
  7. 7Cyber Essentials requirements v3.3 (effective 27 April 2026) - five technical control themes
  8. 8CompTIA Security+ SY0-701 - 5 domains (General Concepts, Threats, Architecture, Operations, Management)
  9. 9EU NIS2 Directive (2023)