Cybersecurity

Build practical security judgement across identity, web risk, detection, and response using plain language, realistic scenarios, and defensible evidence.

This course is written for people who need to understand security decisions without being buried in jargon or vendor theatre. By the end, you should be able to explain what matters, where the exposure sits, and what to do about it.

28 hours3 stages plus summary, 25 modulesBeginners welcomeFree, no account
Start with Module 1
Code on a screen - photo by Sai Kiran Anagani on Unsplash

What you will learn

  • Explain the CIA triad, risk, and controls in plain language with concrete examples
  • Apply structured threat modelling to systems and identify assets, actors, and entry points
  • Use interactive tools to assess passwords, URLs, hashes, and risk matrices
  • Relate enterprise security decisions to NIST CSF 2.0, ISO 27001, and Cyber Essentials
  • Design high-level secure architectures for web and cloud-based systems
  • Communicate security risks and mitigations to non-technical stakeholders

Single learning path

  • Senior executive leaders who now lead technical teams and need to build defensible cybersecurity judgement from first principles
  • Technical professionals who want a complete cybersecurity spine from foundations through architecture, operations, governance, and executive risk
  • Teams preparing for Cyber Essentials v3.3, NIST CSF 2.0, ISO/IEC 27001:2022, OWASP, and related evidence-based security reviews
  • Career changers and specialists who need one rigorous path rather than separate executive and engineering tracks

Prerequisites: None. Course starts from absolute basics with everyday examples.

Course curriculum

Read the modules in order on the first pass. Use the practice and stage tests when you want a stricter check on what stuck.

4

Cybersecurity summary and games

1 hour

A recap and practice space to consolidate judgement with scenarios and short drills.

Standards and references

This course is aligned to the following standards, frameworks, and certification objectives.

  1. 1NIST Cybersecurity Framework (CSF) 2.0 (2024) - 6 functions: Govern, Identify, Protect, Detect, Respond, Recover
  2. 2OWASP Top 10:2025 - A01 Broken Access Control through A10 Mishandling of Exceptional Conditions
  3. 3OWASP ASVS 5.0.0 - application security verification requirements
  4. 4ISO/IEC 27001:2022 - 93 controls across 4 categories (Organisational, People, Physical, Technological)
  5. 5MITRE ATT&CK v19.1 (current release, 28 April 2026) - detection and coverage taxonomy
  6. 6CIS Controls v8.1 - 18 controls, 153 safeguards across 3 implementation groups
  7. 7Cyber Essentials requirements v3.3 (effective 27 April 2026) - five technical control themes
  8. 8CompTIA Security+ SY0-701 - 5 domains (General Concepts, Threats, Architecture, Operations, Management)
  9. 9EU NIS2 Directive (2023)