Cybersecurity Defense Professional (Foundation Certificate)
Become a cyber defender: protect systems, detect threats and respond to incidents. Networking, endpoints and cryptography, then detection and vulnerability work, then security architecture and incident response -- across three progressive terms.
About 452 hours of real coursework
Enroll in this PathwayCybersecurity Defense Professional (Foundation Certificate)
Finishing every course is not what earns this credential. You earn it by demonstrating all 13 required competencies through real, assessed evidence, then bringing them together in the Project below — reviewed end to end, not graded on attendance.
Professional & Solution Architecture
- Identify the Underlying Problem
- Elicit Functional Requirements
Cybersecurity and Digital Defense
- Network Security Fundamentals
- Threat Detection & Monitoring
- Threat Reconnaissance & Analysis
- Enterprise Security Architecture
- Incident Response & Forensics
- Networking for Defenders
- Operating Systems & Endpoint Security
- Security Fundamentals & Cryptography
- Attack Techniques & the Kill Chain
- Vulnerability Assessment & Management
- Security Operations & Governance
Fundamentals
Build the essential knowledge of a defender: how a network carries data, how operating systems and endpoints work, the cryptography you must reason about, and how an attack actually unfolds. You finish able to read traffic and investigate an endpoint.
"A short orientation. What defensive ("blue team") security is, the CIA triad, the defender's job across protect / detect / respond, how blue and red team work relate, and the ethics and law that bound the work. How the three levels build and where the pathway leads."
Included Modules
"You cannot defend a network you do not understand. TCP/IP and the protocols, reading packets in Wireshark, how the common network attacks look on the wire, and how normal-vs-abnormal traffic is the first signal of a compromise."
Included Modules
"The endpoint is where most attacks land. Windows and Linux internals for defenders -- users and privileges, processes, services, the registry and the filesystem, and the logs that matter -- then persistence mechanisms, endpoint hardening, and what EDR does."
Included Modules
"The security principles and the cryptography a defender must be able to reason about -- not implement. Authentication vs authorization, hashing vs encryption, symmetric vs asymmetric, PKI and certificates, TLS, password storage and cracking, and the crypto mistakes that become vulnerabilities."
Included Modules
"You defend better when you understand the attack. The attack lifecycle -- reconnaissance, initial access, execution, persistence, privilege escalation, lateral movement, exfiltration -- mapped to the MITRE ATT&CK framework, with the defensive control that counters each stage. Thinking like an attacker, to defend."
Included Modules
Skills Gained at This Stage
- Reading network traffic in Wireshark
- Investigating a Windows or Linux endpoint
- Reasoning about hashing, encryption and certificates
- Mapping an attack to the kill chain and MITRE ATT&CK
Professional Competencies
- • Networking for Defenders
- • Operating Systems & Endpoint Security
- • Security Fundamentals & Cryptography
- • Attack Techniques & the Kill Chain
Industry Tools
Applied
Do the daily work of defense. Design network controls, build SIEM detections, run and prioritise a vulnerability scan, profile a threat, and bring it all together in a hands-on lab investigation. You finish able to detect and investigate an intrusion.
"Defending the network in practice. Firewalls and rule design, network segmentation and zero-trust segmentation, VPNs and secure remote access, IDS/IPS deployment and tuning, and network security monitoring -- the sensors, the traffic, and what to alert on."
Included Modules
"Turning logs into detections. Log sources and collection, a SIEM in practice (searching, correlating, dashboards), writing and testing detection rules against ATT&CK techniques, alert triage and prioritisation, and the discipline of tuning so the signal survives."
Included Modules
"Finding the weaknesses before an attacker does, and driving them down. Scanning with a real scanner (Nessus / OpenVAS), reading and validating results, CVSS and risk-based prioritisation, patch and remediation management, and running a vulnerability-management cycle that actually closes findings."
Included Modules
"Understanding the adversary. OSINT technique and tooling, mapping your own external attack surface the way an attacker would, threat-actor profiling, tracking vulnerabilities relevant to your stack, and turning it into threat intelligence a defender can act on."
Included Modules
"A hands-on practicum in a virtual lab. Wireshark, Nmap, a SIEM (Splunk or ELK), Suricata / Snort, and an endpoint agent -- used together on a realistic scenario: a simulated intrusion, from first alert to a written finding. The course where the Applied skills come together before the Project."
Included Modules
Skills Gained at This Stage
- Designing and tuning firewall and IDS rules
- Writing SIEM detections against MITRE ATT&CK
- Running and prioritising a vulnerability scan
- OSINT on your own attack surface
- A full lab investigation from alert to finding
Professional Competencies
- • Network Security Fundamentals
- • Threat Detection & Monitoring
- • Vulnerability Assessment & Management
- • Threat Reconnaissance & Analysis
Industry Tools
Professional
Architect the defense and run the response. Threat-model an environment and write a security design, apply a framework at organisational scale, run an incident end to end with forensics, and operate security as a function -- then prove it in the Professional Cyber Defense Project.
"From "we need a firewall" to "what are we protecting, from whom, and what does the defense actually need to do?" Threat modelling, risk assessment, eliciting security requirements from a business context, and producing a defensible security design a team could implement and you could justify to a decision-maker. First in-program vehicle for the two Solution Architecture competencies."
Included Modules
"Defense at organisational scale. Defense in depth and zero-trust architecture, identity as the perimeter, the standard frameworks (NIST CSF, ISO 27001, CIS Controls) and how to use them without drowning, security policy, and threat modelling a whole environment rather than one system."
Included Modules
"When prevention fails. The incident-response lifecycle (prepare, detect, contain, eradicate, recover, learn), evidence collection and chain of custody, disk and memory forensics fundamentals, timeline analysis, post-incident reporting, and running a tabletop exercise."
Included Modules
"How defensive security runs as a function, not a project. The SOC and its tiers, on-call and shift handover, runbooks and playbooks, the metrics that show whether the programme is working, security awareness, and the governance and compliance work that keeps it aligned with the business."
Included Modules
Skills Gained at This Stage
- Threat-modelling an environment and writing a security design
- Applying a framework (NIST CSF / ISO 27001)
- Running an incident end to end with forensics
- Operating security as a function
Professional Competencies
- • Identify the Underlying Problem
- • Elicit Functional Requirements
- • Enterprise Security Architecture
- • Incident Response & Forensics
- • Security Operations & Governance
Industry Tools
Professional Cyber Defense Project
A realistic environment threat-modelled, monitored, then an incident investigated and reported: discover the assets and threats, define the defensive design, stand up the detection, and respond to a simulated intrusion end to end. This is where the program's capabilities come together as integrated evidence -- not one more course.
-
1
Discover
A realistic environment: assets, exposure, and the threats that matter to it.
-
2
Define
A threat model, a risk assessment, and a defensive design.
-
3
Engineer
Monitoring and detections stood up in the lab; coverage mapped to ATT&CK.
-
4
Execute
A simulated incident investigated end to end, with a post-incident report and recommendations.
Ready to Start?
This program is part of the Cybersecurity Defense Architect — Emergence Pathway. You'll pick your starting cohort for Cybersecurity Defense Professional (Foundation Certificate) — the first program in the pathway — on the next step.
Reserve Your Spot