Skip to content
IT Atlas

Learning path · Foundational

Cybersecurity Fundamentals

Understand security as a layer across the whole environment, with detection and recovery as first class concerns.

8 steps

What you will be able to do

  • Map controls to prevent, protect, detect, respond and recover
  • Explain how real intrusions chain minor weaknesses
  • Describe what a SOC does and what telemetry it needs

The path

Work through these in order.

  1. 01IT vs Cybersecurity

    Objectives, accountability and overlap.

    IT builds and runs the environment; cybersecurity assures that it remains trustworthy, overlapping disciplines with different objectives and accountability.

  2. 02Security Architecture

    Coverage across layers and functions.

    The deliberate arrangement of controls across identity, endpoints, applications, data, network and infrastructure, aligned to a maturity model.

  3. 03Zero Trust

    Principles, pillars and what it is not.

    A security model that removes implicit trust based on network location and instead verifies every request explicitly against identity, device and context.

  4. 04IT Attack Paths

    How chains form and where they break.

    How real intrusions chain individually minor weaknesses into full compromise, and where defensive controls interrupt the chain.

  5. 05EDR

    Endpoint detection, containment and coverage.

    Endpoint Detection and Response continuously records endpoint behaviour, detects malicious activity, and enables remote investigation and containment.

  6. 06SIEM

    Telemetry, detection and retention.

    Security Information and Event Management centralises telemetry from across the estate, correlates it into detections, and supports investigation and reporting.

  7. 07Vulnerability Management

    Prioritising by real exploitability.

    The continuous cycle of discovering assets, identifying weaknesses, prioritising by real risk, remediating and verifying.

  8. 08Incident Response

    Lifecycle, authority and preparation.

    The prepared, repeatable process for detecting, containing, eradicating and recovering from security incidents, and learning from them.

Other paths