Cybersecurity
Build practical security judgement across identity, web risk, detection, and response using plain language, realistic scenarios, and defensible evidence.
This course is written for people who need to understand security decisions without being buried in jargon or vendor theatre. By the end, you should be able to explain what matters, where the exposure sits, and what to do about it.
What you will learn
- Explain the CIA triad, risk, and controls in plain language with concrete examples
- Apply structured threat modelling to systems and identify assets, actors, and entry points
- Use interactive tools to assess passwords, URLs, hashes, and risk matrices
- Relate enterprise security decisions to NIST CSF 2.0, ISO 27001, and Cyber Essentials
- Design high-level secure architectures for web and cloud-based systems
- Communicate security risks and mitigations to non-technical stakeholders
Single learning path
- Senior executive leaders who now lead technical teams and need to build defensible cybersecurity judgement from first principles
- Technical professionals who want a complete cybersecurity spine from foundations through architecture, operations, governance, and executive risk
- Teams preparing for Cyber Essentials v3.3, NIST CSF 2.0, ISO/IEC 27001:2022, OWASP, and related evidence-based security reviews
- Career changers and specialists who need one rigorous path rather than separate executive and engineering tracks
Prerequisites: None. Course starts from absolute basics with everyday examples.
Course curriculum
Read the modules in order on the first pass. Use the practice and stage tests when you want a stricter check on what stuck.
Stage 1. Foundations
9 modules · 8 hours
Stage 2. Applied cybersecurity
7 modules · 8 hours
Stage 3. Practice and strategy
9 modules · 11 hours
Cybersecurity summary and games
1 hour
A recap and practice space to consolidate judgement with scenarios and short drills.
Standards and references
This course is aligned to the following standards, frameworks, and certification objectives.
- 1NIST Cybersecurity Framework (CSF) 2.0 (2024) - 6 functions: Govern, Identify, Protect, Detect, Respond, Recover
- 2OWASP Top 10:2025 - A01 Broken Access Control through A10 Mishandling of Exceptional Conditions
- 3OWASP ASVS 5.0.0 - application security verification requirements
- 4ISO/IEC 27001:2022 - 93 controls across 4 categories (Organisational, People, Physical, Technological)
- 5MITRE ATT&CK v19.1 (current release, 28 April 2026) - detection and coverage taxonomy
- 6CIS Controls v8.1 - 18 controls, 153 safeguards across 3 implementation groups
- 7Cyber Essentials requirements v3.3 (effective 27 April 2026) - five technical control themes
- 8CompTIA Security+ SY0-701 - 5 domains (General Concepts, Threats, Architecture, Operations, Management)
- 9EU NIS2 Directive (2023)