Cybersecurity Fundamentals
5 Days | 10 Sessions Training Event
Introduction
In an era where cyberattacks are growing in frequency, sophistication, and cost, organizations of every size need people who can identify, prevent, and respond to security threats with confidence. This 5-day, instructor-led program equips participants with the practical knowledge and hands-on skills needed to protect networks, systems, applications, and data against today's most pressing cyber threats. Delivered over ten focused half-day sessions, the course blends core security principles with real-world scenarios – covering everything from network defence and cryptography to identity management, incident response, cloud security, and ethical hacking essentials.
Who Should Attend
IT professionals, network administrators, and system administrators strengthening their security skills
IT managers and team leads responsible for organizational security
Security analysts, SOC analysts, and incident responders
Compliance, risk, and audit professionals
Software developers and DevOps engineers building security into their applications
Professionals preparing for entry- to intermediate-level cybersecurity certifications
Anyone transitioning into a cybersecurity career
Course Outlines
Foundations of Cybersecurity
Understanding the Threat Landscape and Core Security Principles
Why cybersecurity matters: business impact and real-world breach case studies
The CIA Triad: Confidentiality, Integrity, and Availability
Key terminology: threats, vulnerabilities, risks, and exploits
Overview of the modern cyber threat landscape
Categories of attackers: cybercriminals, insiders, nation-states, and hacktivists
Security frameworks and standards (NIST CSF, ISO 27001, CIS Controls)
The security lifecycle: Identify, Protect, Detect, Respond, Recover
Network Security Fundamentals
Securing the Infrastructure that Connects Your Organization
TCP/IP fundamentals and commonly exploited network protocols
Firewalls, proxies, and network segmentation
Virtual Private Networks (VPNs) and secure remote access
Intrusion Detection and Prevention Systems (IDS/IPS)
Wireless network security best practices
Network Access Control (NAC) and Zero Trust architecture
Common network attacks: sniffing, spoofing, and man-in-the-middle
Threats, Vulnerabilities & Attack Techniques
How Attackers Think and Operate
Malware types: viruses, worms, trojans, ransomware, and spyware
Social engineering and phishing techniques
The Cyber Kill Chain and MITRE ATT&CK framework
Vulnerability management and patch management
Common Vulnerabilities and Exposures (CVE) and CVSS scoring
Denial-of-Service (DoS) and Distributed Denial-of-Service (DDoS) attacks
Advanced Persistent Threats (APTs) and supply chain attacks
Cryptography & Data Protection
Protecting Data at Rest, in Transit, and in Use
Symmetric vs. asymmetric encryption
Hashing, digital signatures, and digital certificates
Public Key Infrastructure (PKI) fundamentals
SSL/TLS and secure communication protocols
Data classification and Data Loss Prevention (DLP)
Encryption key management best practices
Overview of data privacy regulations (GDPR, PIPEDA)
Identity & Access Management
Controlling Who Can Access What
Authentication, Authorization, and Accounting (AAA)
Multi-Factor Authentication (MFA) and passwordless authentication
Role-Based and Attribute-Based Access Control (RBAC / ABAC)
Single Sign-On (SSO) and federated identity
Privileged Access Management (PAM)
Identity governance and account lifecycle management
Common identity-based attacks and defences
Security Operations & Incident Response
Detecting, Responding to, and Recovering from Security Incidents
Security Operations Center (SOC) roles and workflows
Security Information and Event Management (SIEM) fundamentals
Log management and threat detection
Incident response lifecycle: preparation, detection, containment, eradication, recovery
Digital forensics basics and evidence handling
Business continuity and disaster recovery planning
Hands-on tabletop exercise: responding to a simulated breach
Application & Cloud Security
Securing Modern Software and Cloud Environments
OWASP Top 10 web application vulnerabilities
Secure Software Development Lifecycle (SSDLC)
API security fundamentals
Cloud security models and the shared responsibility model
Securing AWS, Azure, and Google Cloud environments
Container and DevSecOps security basics
Cloud Access Security Brokers (CASB) and misconfiguration risks
Risk Management, Governance & Compliance
Aligning Security with Business and Regulatory Requirements
Risk assessment methodologies and risk registers
Security policies, standards, and procedures
Regulatory and compliance frameworks (ISO 27001, SOC 2, PCI DSS)
Third-party and vendor risk management
Security awareness training and building a security culture
Metrics and KPIs for measuring security posture
Building a business case for cybersecurity investment
Ethical Hacking & Penetration Testing Essentials
Thinking Like an Attacker to Strengthen Your Defences
Penetration testing methodology and rules of engagement
Reconnaissance and information-gathering techniques
Scanning and vulnerability assessment tools
Exploitation basics and privilege escalation concepts
Web application testing fundamentals ■ Reporting and remediation best practices
Legal and ethical considerations in penetration testing
Building a Resilient Security Culture (Capstone)
Bringing It All Together: Your Organization's Security Roadmap
Emerging threats: AI-driven attacks, deepfakes, and quantum risk
Building a security-first organizational culture
Group exercise: developing a cybersecurity action plan
Course review and key takeaways
Q&A and open discussion with the instructor
Certificate of completion and next steps
Resources for continued learning (CompTIA Security+, CISSP, CEH)
5 Days | 10 Sessions Training Event
Introduction
In an era where cyberattacks are growing in frequency, sophistication, and cost, organizations of every size need people who can identify, prevent, and respond to security threats with confidence. This 5-day, instructor-led program equips participants with the practical knowledge and hands-on skills needed to protect networks, systems, applications, and data against today's most pressing cyber threats. Delivered over ten focused half-day sessions, the course blends core security principles with real-world scenarios – covering everything from network defence and cryptography to identity management, incident response, cloud security, and ethical hacking essentials.
Who Should Attend
IT professionals, network administrators, and system administrators strengthening their security skills
IT managers and team leads responsible for organizational security
Security analysts, SOC analysts, and incident responders
Compliance, risk, and audit professionals
Software developers and DevOps engineers building security into their applications
Professionals preparing for entry- to intermediate-level cybersecurity certifications
Anyone transitioning into a cybersecurity career
Course Outlines
Foundations of Cybersecurity
Understanding the Threat Landscape and Core Security Principles
Why cybersecurity matters: business impact and real-world breach case studies
The CIA Triad: Confidentiality, Integrity, and Availability
Key terminology: threats, vulnerabilities, risks, and exploits
Overview of the modern cyber threat landscape
Categories of attackers: cybercriminals, insiders, nation-states, and hacktivists
Security frameworks and standards (NIST CSF, ISO 27001, CIS Controls)
The security lifecycle: Identify, Protect, Detect, Respond, Recover
Network Security Fundamentals
Securing the Infrastructure that Connects Your Organization
TCP/IP fundamentals and commonly exploited network protocols
Firewalls, proxies, and network segmentation
Virtual Private Networks (VPNs) and secure remote access
Intrusion Detection and Prevention Systems (IDS/IPS)
Wireless network security best practices
Network Access Control (NAC) and Zero Trust architecture
Common network attacks: sniffing, spoofing, and man-in-the-middle
Threats, Vulnerabilities & Attack Techniques
How Attackers Think and Operate
Malware types: viruses, worms, trojans, ransomware, and spyware
Social engineering and phishing techniques
The Cyber Kill Chain and MITRE ATT&CK framework
Vulnerability management and patch management
Common Vulnerabilities and Exposures (CVE) and CVSS scoring
Denial-of-Service (DoS) and Distributed Denial-of-Service (DDoS) attacks
Advanced Persistent Threats (APTs) and supply chain attacks
Cryptography & Data Protection
Protecting Data at Rest, in Transit, and in Use
Symmetric vs. asymmetric encryption
Hashing, digital signatures, and digital certificates
Public Key Infrastructure (PKI) fundamentals
SSL/TLS and secure communication protocols
Data classification and Data Loss Prevention (DLP)
Encryption key management best practices
Overview of data privacy regulations (GDPR, PIPEDA)
Identity & Access Management
Controlling Who Can Access What
Authentication, Authorization, and Accounting (AAA)
Multi-Factor Authentication (MFA) and passwordless authentication
Role-Based and Attribute-Based Access Control (RBAC / ABAC)
Single Sign-On (SSO) and federated identity
Privileged Access Management (PAM)
Identity governance and account lifecycle management
Common identity-based attacks and defences
Security Operations & Incident Response
Detecting, Responding to, and Recovering from Security Incidents
Security Operations Center (SOC) roles and workflows
Security Information and Event Management (SIEM) fundamentals
Log management and threat detection
Incident response lifecycle: preparation, detection, containment, eradication, recovery
Digital forensics basics and evidence handling
Business continuity and disaster recovery planning
Hands-on tabletop exercise: responding to a simulated breach
Application & Cloud Security
Securing Modern Software and Cloud Environments
OWASP Top 10 web application vulnerabilities
Secure Software Development Lifecycle (SSDLC)
API security fundamentals
Cloud security models and the shared responsibility model
Securing AWS, Azure, and Google Cloud environments
Container and DevSecOps security basics
Cloud Access Security Brokers (CASB) and misconfiguration risks
Risk Management, Governance & Compliance
Aligning Security with Business and Regulatory Requirements
Risk assessment methodologies and risk registers
Security policies, standards, and procedures
Regulatory and compliance frameworks (ISO 27001, SOC 2, PCI DSS)
Third-party and vendor risk management
Security awareness training and building a security culture
Metrics and KPIs for measuring security posture
Building a business case for cybersecurity investment
Ethical Hacking & Penetration Testing Essentials
Thinking Like an Attacker to Strengthen Your Defences
Penetration testing methodology and rules of engagement
Reconnaissance and information-gathering techniques
Scanning and vulnerability assessment tools
Exploitation basics and privilege escalation concepts
Web application testing fundamentals ■ Reporting and remediation best practices
Legal and ethical considerations in penetration testing
Building a Resilient Security Culture (Capstone)
Bringing It All Together: Your Organization's Security Roadmap
Emerging threats: AI-driven attacks, deepfakes, and quantum risk
Building a security-first organizational culture
Group exercise: developing a cybersecurity action plan
Course review and key takeaways
Q&A and open discussion with the instructor
Certificate of completion and next steps
Resources for continued learning (CompTIA Security+, CISSP, CEH)

