← Cybersecurity Professional Programme

Module 01Onboarding1 day

Introduction

A clear orientation to the entire 12-week programme — how the six modules connect, what cybersecurity actually covers as a field, and what to expect before diving into any technical content.

01

Learning outcomes

  • Understand what cybersecurity is, in broad terms, and why it matters
  • Understand how the programme's six modules relate to one another
  • Understand the distinction between offensive, defensive, and strategic security
  • Feel oriented and ready to begin Module 2
02

What this module covers

What cybersecurity really is, in broad termsHow the six modules relate to one anotherOffensive vs defensive vs strategic securityProgramme format and weekly commitment
03

Lessons

Lesson 1What Is Cybersecurity, Really?

Cybersecurity is the practice of protecting systems, networks, devices, and data from unauthorized access, damage, or disruption. That's the textbook definition — but it's worth immediately widening it, because a common misconception among beginners is picturing cybersecurity as one narrow activity (often imagined as “hacking” in a dramatic, movie-style sense).

In reality, cybersecurity is a broad field made up of very different kinds of work:

  • Some professionals spend their day trying to break into systems on purpose, with permission, to find weaknesses before real attackers do
  • Others spend their day watching network activity, looking for signs that something has already gone wrong
  • Others still work on policy, risk assessment, and compliance — making sure an organization's rules and processes around security are sound, not just its technology

Teaching point

This module exists specifically to prevent a narrow mental model from forming before you have even started. Cybersecurity isn't one job — it's an entire ecosystem of specialized roles that all serve the same overall goal: keeping systems and data safe. The rest of this module explains how this programme is structured around exactly that reality.

Lesson 2Why Cybersecurity Matters — Real-World Stakes

It's worth grounding the field in real consequences before going further. Cybersecurity failures aren't abstract — they have direct, often severe real-world impact:

  • For individuals: stolen personal data, drained bank accounts, identity theft, blackmail from leaked private information
  • For businesses: financial loss from breaches, reputational damage, legal liability, sometimes complete business failure following a serious incident
  • For critical infrastructure: hospitals, power grids, water systems, and government services increasingly depend on digital systems — meaning a serious cybersecurity failure can have consequences well beyond financial loss

Teaching point

This isn't meant to be alarmist — it's meant to establish genuine stakes early, since they motivate why the depth and rigor of the coming eleven and a half weeks is actually warranted. This is not an abstract academic subject; it's a field that exists because real harm happens when it's neglected, and organizations increasingly need genuinely skilled people to prevent that harm.

Lesson 3The Three Pillars of This Programme

This programme is deliberately structured around three broad security domains, each becoming its own dedicated module later in the course:

  • Offensive Security (Module 3) — thinking and acting like an attacker, on purpose and with permission, to find weaknesses before malicious actors do. Often called “ethical hacking” or “penetration testing.”
  • Defensive Security (Module 4) — monitoring, detecting, and responding to security threats and incidents as they happen or after they've occurred. This is the work of a Security Operations Center (SOC).
  • Strategic Security (Module 5) — the governance, risk management, and compliance side: making sure an organization's policies, standards, and processes actually support good security, not just its technology.

The single most important framing idea of this module

These three domains aren't competing specialties where you pick a “team” and ignore the rest — they're three interconnected perspectives on the same underlying problem. An effective offensive security professional understands defensive monitoring well enough to know what will and won't get detected. An effective defensive analyst understands offensive techniques well enough to recognize what an attack actually looks like in their logs. And both are only genuinely effective within an organization that has sound strategic governance guiding what gets protected and why. This programme's structure — offense, then defense, then strategy — is designed to build genuine fluency across all three, not expertise in just one at the expense of the others.

Lesson 4How Fundamentals (Module 2) Fits In

Before any of the three pillars, Module 2 (Fundamentals) exists to build the baseline IT and cybersecurity literacy that all three pillars assume you already have. This includes basic IT skills, environment setup for later hands-on labs, foundational cybersecurity vocabulary, and core awareness/operational security concepts.

Teaching point

Frame this directly as load-bearing infrastructure for everything that follows — skipping or rushing Fundamentals would mean starting Offensive Security (Module 3) without the IT literacy that module assumes is already in place, which would make every subsequent lesson harder than it needs to be. Module 2's two-week length, relative to this module's single day, reflects how much genuine foundation-building work happens there.

Lesson 5What to Expect — Format and Commitment

A brief, practical orientation to what the next eleven and a half weeks will actually feel like:

  • Approximately 30–35 hours of content per week, combining reading/reference material, hands-on activities in controlled lab environments, and MCQ-style knowledge checks
  • A steadily increasing technical demand — Module 2 is foundational and accessible; Modules 3 and 4 involve genuinely hands-on technical lab work; Module 5 shifts toward more theoretical, standards-based content; Module 6 is a shorter, lighter career-focused close
  • Guided, step-by-step instructions for hands-on exercises, meaning you are not expected to already know how to do any of this — the programme is built to teach it progressively

Teaching point

Set realistic expectations honestly here — this is a substantial time commitment and the difficulty genuinely increases through Modules 3 and 4 specifically. Rather than downplaying that, naming it directly helps you plan your pace and not be caught off guard when the offensive and defensive security modules demand noticeably more hands-on technical effort than this orientation day does.

04

Guided hands-on activity

Programme Orientation Reflection

  1. 1.Review the six-module structure of the full programme (Introduction, Fundamentals, Offensive Security, Defensive Security, Strategic Security, Advancement).
  2. 2.Write a short reflection (a few sentences) responding to: “Which module are you most excited about, and why? Which domain — offensive, defensive, or strategic — do you expect to be your strongest interest, and which do you expect to find most challenging?”
  3. 3.Set up your own basic study environment — a dedicated notes system (physical or digital) for tracking new terminology across the programme, since Module 2 onward introduces substantial new vocabulary.

Teaching point

This activity is intentionally light and reflective rather than technical, matching the module's own “1 day” scope — its purpose is orientation and honest self-assessment of interest and expectations, not skill-building. The reflection also gives you a useful baseline to look back on at the end of the programme, to see how your sense of the field may have shifted after direct exposure to all three pillars.

05

Knowledge Check

Question 1 of 5

What are the three core security domains this programme is structured around?