Beginner
Cybersecurity
Defending systems, networks and data, from the fundamentals of information security through to running a live security assessment. Network defense, cryptography, ethical hacking, web application security, malware analysis, incident response and security operations, each practiced against a running target rather than a slide.

- 38 lessons
- Beginner
Cybersecurity is one of the few skills that decides whether an organization keeps its data or loses it. This course takes a learner from the fundamentals of information security through to running a live security assessment.
It is built around a single idea: you cannot defend a system you have never attacked. Learners work from both sides, studying how an intrusion is carried out and then building the controls that stop it.
What a graduate can do
- Explain the CIA triad, name the main classes of threat actor, and map common attack vectors to the vulnerabilities they exploit.
- Design and defend a network using firewalls, IDS and IPS, segmentation, VPNs and TLS, including wireless.
- Apply symmetric and asymmetric encryption, hashing and digital signatures, and manage certificates under a public key infrastructure.
- Run an ethical hacking engagement end to end, from reconnaissance and vulnerability scanning through exploitation to a written report with remediation steps.
- Find and fix the OWASP Top 10 in a web application, and apply secure coding and input validation.
- Harden Windows and Active Directory and Linux, run patch management, and deploy endpoint detection and response.
- Identify malware by type and behavior, work the incident response lifecycle, carry out basic digital forensics, and investigate using SIEM tooling.
- Work inside a security operations center: threat intelligence and hunting, log management and analysis, and security automation.
How it is taught
Twelve to thirteen weeks, two sessions a week of two to three hours, online and instructor-led, with a self-paced track alongside it. Learners work in a virtual lab with Kali Linux, Metasploit, Wireshark and the supporting toolchain, and are given penetration testing ranges and capture-the-flag challenges to practice on.
Assessment and certification
Practical labs and simulated incidents throughout, then a capstone assessment presented to the instructors. Completion is earned on the capstone, not on attendance. The syllabus is aligned to CompTIA Security+ and to CEH, though those exams are taken with the awarding body.
Finishing the course does not produce a certificate on its own. The certificate is issued by Quantaledge Tech Empowerment Foundation and carries the signature of the Chairman.
Before you start
None. The course starts at the fundamentals of information security and assumes no prior security experience.
What the course covers
9 modules · 38 lessons
1. Introduction to cybersecurity
Fundamentals of information security and the CIA triad, the threat landscape and its actors, common attack vectors and vulnerabilities, and the career paths open in security.
- Fundamentals of information security and the CIA triadEnroll to open
Reading · optional
- The cybersecurity landscape and threat actorsEnroll to open
Reading · optional
- Common attack vectors and vulnerabilitiesEnroll to open
Reading · optional
- Career paths in cybersecurityEnroll to open
Reading · optional
2. Network security fundamentals
TCP/IP and network architecture, firewalls, IDS and IPS, segmentation, VPNs, SSL and TLS, and wireless network security.
- TCP/IP protocols and network architectureEnroll to open
Reading · optional
- Firewalls, IDS and IPS systems, and network segmentationEnroll to open
Reading · optional
- VPNs, SSL and TLS, and secure communication protocolsEnroll to open
Reading · optional
- Wireless network security and best practicesEnroll to open
Reading · optional
3. Cryptography and data protection
Symmetric and asymmetric encryption, hashing functions and digital signatures, public key infrastructure and certificate management, and encryption at rest and in transit.
- Symmetric and asymmetric encryption algorithmsEnroll to open
Reading · optional
- Hashing functions and digital signaturesEnroll to open
Reading · optional
- Public key infrastructure and certificate managementEnroll to open
Reading · optional
- Data encryption at rest and in transitEnroll to open
Reading · optional
4. Ethical hacking and penetration testing
Methodologies, reconnaissance and information gathering, vulnerability scanning, exploitation and post-exploitation, and reporting findings with remediation recommendations.
- Ethical hacking methodologiesEnroll to open
Reading · optional
- Reconnaissance and information gatheringEnroll to open
Reading · optional
- Vulnerability scanning and assessment toolsEnroll to open
Reading · optional
- Exploitation and post-exploitationEnroll to open
Reading · optional
- Reporting findings and remediation recommendationsEnroll to open
Reading · optional
5. Web application security
The OWASP Top 10, SQL injection, XSS and CSRF, secure coding and input validation, and web application firewalls and testing tools.
- The OWASP Top 10Enroll to open
Reading · optional
- SQL injection, XSS, CSRF and other web attacksEnroll to open
Reading · optional
- Secure coding practices and input validationEnroll to open
Reading · optional
- Web application firewalls and security testing toolsEnroll to open
Reading · optional
6. Operating system security
Windows hardening and Active Directory, Linux configuration and permissions, patch management and vulnerability mitigation, and endpoint detection and response.
- Windows security hardening and Active DirectoryEnroll to open
Reading · optional
- Linux security configuration and permissionsEnroll to open
Reading · optional
- Patch management and vulnerability mitigationEnroll to open
Reading · optional
- Endpoint detection and responseEnroll to open
Reading · optional
7. Malware analysis and incident response
Viruses, trojans, ransomware and rootkits, detection and analysis techniques, the incident response lifecycle, digital forensics fundamentals, and SIEM tooling.
- Malware types: viruses, trojans, ransomware and rootkitsEnroll to open
Reading · optional
- Malware detection and analysis techniquesEnroll to open
Reading · optional
- The incident response lifecycle and its proceduresEnroll to open
Reading · optional
- Digital forensics fundamentalsEnroll to open
Reading · optional
- Security information and event management toolingEnroll to open
Reading · optional
8. Security operations and monitoring
Security operations center practice, threat intelligence and hunting, log management and analysis, and security automation and orchestration.
- Security operations center practiceEnroll to open
Reading · optional
- Threat intelligence and threat huntingEnroll to open
Reading · optional
- Log management and analysisEnroll to open
Reading · optional
- Security automation and orchestrationEnroll to open
Reading · optional
9. Capstone project
Conduct a full security assessment, design a security architecture for an organization, write an incident response plan, and present findings and recommendations.
- Conduct a full security assessmentEnroll to open
Reading · optional
- Design a security architecture for an organizationEnroll to open
Reading · optional
- Write an incident response plan and its proceduresEnroll to open
Reading · optional
- Present findings and recommendationsEnroll to open
Reading · optional
Past cohorts
Runs of this course that have already been taught, with a facilitator and a group working through it together.