Learning path · Foundational
Cybersecurity Fundamentals
Understand security as a layer across the whole environment, with detection and recovery as first class concerns.
What you will be able to do
- Map controls to prevent, protect, detect, respond and recover
- Explain how real intrusions chain minor weaknesses
- Describe what a SOC does and what telemetry it needs
The path
Work through these in order.
- 01IT vs Cybersecurity
Objectives, accountability and overlap.
IT builds and runs the environment; cybersecurity assures that it remains trustworthy, overlapping disciplines with different objectives and accountability.
- 02Security Architecture
Coverage across layers and functions.
The deliberate arrangement of controls across identity, endpoints, applications, data, network and infrastructure, aligned to a maturity model.
- 03Zero Trust
Principles, pillars and what it is not.
A security model that removes implicit trust based on network location and instead verifies every request explicitly against identity, device and context.
- 04IT Attack Paths
How chains form and where they break.
How real intrusions chain individually minor weaknesses into full compromise, and where defensive controls interrupt the chain.
- 05EDR
Endpoint detection, containment and coverage.
Endpoint Detection and Response continuously records endpoint behaviour, detects malicious activity, and enables remote investigation and containment.
- 06SIEM
Telemetry, detection and retention.
Security Information and Event Management centralises telemetry from across the estate, correlates it into detections, and supports investigation and reporting.
- 07Vulnerability Management
Prioritising by real exploitability.
The continuous cycle of discovering assets, identifying weaknesses, prioritising by real risk, remediating and verifying.
- 08Incident Response
Lifecycle, authority and preparation.
The prepared, repeatable process for detecting, containing, eradicating and recovering from security incidents, and learning from them.
