Develop the knowledge and practical skills to detect, investigate, and respond to cyber threats. This 16-week professional programme takes you from cybersecurity fundamentals through network security, SOC operations, SIEM, threat intelligence, incident response, digital forensics, and automation — culminating in a practical capstone project.
Week 1 — Cybersecurity Fundamentals
Cybersecurity concepts, modern threats, common cyberattacks, CIA Triad, SOC analyst roles, responsibilities, and career pathways.
Week 2 — Cybersecurity Primer
Attack vectors, threat actors, attacker motivations, Cyber Kill Chain, MITRE ATT&CK, and attack scenario analysis.
Week 3 — Security Models & Controls
CIA Triad, access control models, AAA, Zero Trust, and preventive, detective, corrective, and compensating security controls.
Week 4 — Security Models & Defence
Defence-in-depth, least privilege, security architecture, hardening, patching, segmentation, endpoint security, NIST CSF, and CIS Controls.
Week 5 — Network Security Basics
Networking fundamentals, OSI and TCP/IP, IP addressing, subnetting, protocols, firewalls, IDS/IPS, network segmentation, VPNs, and secure remote access.
Week 6 — Traffic Analysis
Packet capture, Wireshark, network traffic analysis, suspicious traffic detection, NetFlow, port scans, ARP poisoning, and DNS tunnelling.
Week 7 — Blue Team Operations
SOC structure and tiers, alert triage, escalation, workflows, playbooks, shift handovers, communication, and SOC performance metrics.
Week 8 — Blue Team Tools & Architecture
EDR, NDR, threat intelligence platforms, SIEM integration, Zeek, Suricata, Wazuh, TheHive, and SOC architecture.
Week 9 — SIEM Part 1
SIEM fundamentals, log management, log collection, normalisation, parsing, SIEM architecture, security platforms, queries, and detection use cases.
Week 10 — SIEM Part 2
Alert analysis, true and false positives, correlation rules, dashboards, investigations, SIEM tuning, alert fatigue, and escalation.
Week 11 — Threat Intelligence
Threat intelligence, threat actors, MITRE ATT&CK, Diamond Model, Pyramid of Pain, OSINT, Indicators of Compromise, STIX/TAXII, and intelligence-driven detection.
Week 12 — Vulnerability Management
Vulnerability management lifecycle, vulnerability scanning, CVEs, CVSS, risk-based prioritisation, patch management, tracking, and reporting.
Week 13 — Incident Triage & Analysis
Incident classification, alert analysis, scoping, affected assets, timelines, containment, NIST incident response phases, and incident reporting.
Week 14 — Digital Forensics Basics
Digital forensic principles, evidence collection, chain of custody, memory and disk analysis, forensic tools, system artefacts, timeline analysis, and forensic reporting.
Week 15 — Automation & Analytics
SOC automation, SOAR, automated security playbooks, security analytics, threat hunting, dashboards, AI-assisted detection, and the future of cybersecurity operations.
Week 16 — Capstone Project & Presentation
Apply your skills to a realistic multi-stage security incident. Complete detection, triage, containment, investigation, threat intelligence enrichment, vulnerability or forensic analysis, SIEM evidence, and a final incident response and lessons-learned report.














