Cyber Security Fundamentals for IT Professionals Training Course

5 days Cyber Security Certificate on completion
Course codeSD-CS-001
Duration5 days
LevelIntermediate
CategoryCyber Security
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

IT professionals are routinely asked to deploy systems, support users, manage cloud services and respond to incidents, yet security controls are often added late or handled as a specialist concern. This creates preventable exposure: misconfigured access, unpatched services, weak logging, insecure web applications and unclear incident escalation. This course gives technical staff a practical security baseline for recognising these conditions, discussing risk accurately and building safeguards into everyday IT operations.

Participants examine the threat landscape through the lenses of confidentiality, integrity and availability; asset and data classification; identity and access management; network segmentation; vulnerability management; endpoint protection; logging; and incident response. They use structured methods to identify attack paths, interpret common security findings, prioritise remediation by risk, and recommend controls aligned with the CIS Controls v8 and OWASP Top 10. Practical sessions introduce packet inspection with Wireshark, service discovery with Nmap and evidence-based analysis of authentication, network and web application events.

The course is delivered through instructor-led technical briefings, guided demonstrations, lab exercises and team-based case work. Participants work through a simulated organisation with exposed services, suspicious network traffic, access-control gaps and a developing security incident. By the end of the week, each participant produces a security improvement pack containing an asset-risk register, prioritised remediation plan, incident triage record and 90-day action plan that can be adapted for their own environment.

It is designed for IT professionals who already work with infrastructure, applications, cloud platforms or service operations and need a sound, operational understanding of cyber security. It is particularly valuable for teams seeking a shared vocabulary and repeatable approach before progressing to specialist penetration testing, security operations or advanced cloud security training.

Course objectives

By the end of this course, participants will be able to:

  • Classify business assets and data using confidentiality, integrity and availability impact criteria
  • Map attack surfaces and likely threat paths across endpoints, networks, identities and web applications
  • Use Nmap scan results to identify exposed services and prioritise basic remediation actions
  • Interpret Wireshark packet captures to investigate suspicious network connections and authentication activity
  • Apply CIS Controls v8 safeguards to common IT operational weaknesses
  • Assess web application risks against OWASP Top 10 categories and recommend proportionate controls
  • Create an incident triage record with evidence, severity, containment actions and escalation decisions
  • Produce a 90-day cyber security improvement plan based on a prioritised risk register

Benefits of attending

For you

  • Gain a practical method for turning technical findings into risk-based remediation priorities
  • Build confidence interpreting scan output, packet captures and security alerts during operational investigations
  • Contribute more credibly to security reviews, change approvals and incident discussions
  • Create evidence-based recommendations using recognised references such as CIS Controls v8 and OWASP Top 10
  • Leave with reusable risk register, incident triage and improvement-plan templates for workplace use

For your organisation

  • Reduce avoidable exposure by helping IT staff identify insecure services, weak access controls and missing patches earlier
  • Improve consistency of security decisions through shared use of asset classification and risk-prioritisation methods
  • Strengthen first-line incident handling with clearer evidence capture, containment and escalation practices
  • Support more targeted security investment by linking technical weaknesses to business impact and control actions
  • Create a documented 90-day improvement backlog that managers can assign, track and review

Target competencies

Risk-based remediationAttack surface mappingNetwork traffic analysisAccess control reviewIncident triageSecurity control selection

Who should attend

  • Systems Administrators — who configure servers, identities and endpoint controls that can introduce or reduce operational risk
  • Network Administrators — who manage connectivity, segmentation, firewalls and monitoring points
  • IT Support and Service Desk Analysts — who identify suspicious user activity, malware indicators and access issues early
  • Cloud Administrators — who administer cloud identities, storage, workloads and configuration settings
  • Application Support Analysts — who support business applications and need to recognise common web and access-control weaknesses
  • IT Managers and Technical Team Leaders — who must prioritise security improvements and coordinate incident escalation

Requirements and prerequisites

Participants should be comfortable using a Windows or Linux workstation and understand basic IT concepts including IP addressing, TCP/IP, DNS, user accounts, file permissions, web browsers and client-server applications. Experience supporting infrastructure, applications, cloud services or end users is useful and matches the intermediate audience. Participants do not need prior cyber security qualifications, programming ability, penetration-testing experience or detailed knowledge of security operations centres. This is a fundamentals course for working IT professionals; complete beginners to IT should first gain practical familiarity with networks, operating systems and administration tasks.

Training methodology

The instructor combines short technical explanations with guided demonstrations in a safe lab environment. Participants inspect packet captures in Wireshark, review controlled Nmap discovery output, analyse identity and configuration scenarios, and map findings to CIS Controls v8 and OWASP Top 10 guidance. Small groups work through a simulated organisation's security issues, making evidence-based prioritisation and escalation decisions. Each day closes with a practical artefact, and the final session converts the case findings into an individual 90-day security improvement plan for workplace application.

Course outline

Day 1: Security foundations and risk context

  • Cyber security objectives: confidentiality, integrity and availability
  • Threat actors, attack motives and common attack chains
  • Asset inventory and business service dependency mapping
  • Data classification and handling requirements
  • Attack surface identification across people, processes and technology
  • Likelihood-impact risk scoring and risk treatment options
  • Security governance, policy ownership and accountability

Workshop: Participants build an asset-risk register for a simulated business service and identify its three highest-priority security exposures.

Day 2: Identity, endpoints and network defence

  • Identity lifecycle management and least-privilege access
  • Multi-factor authentication and privileged access controls
  • Endpoint hardening, patching and secure configuration baselines
  • Network segmentation and trust boundary design
  • Firewall rules, secure remote access and service exposure
  • Nmap host discovery and service enumeration fundamentals
  • CIS Controls v8 safeguard selection

Workshop: Participants review a controlled Nmap scan and access-control scenario, then produce a prioritised hardening recommendation.

Day 3: Monitoring, logging and vulnerability management

  • Security logging objectives and event source selection
  • Authentication, endpoint, network and application log fields
  • Wireshark packet capture filters and protocol inspection
  • Indicators of compromise and suspicious behaviour patterns
  • Vulnerability scanning, CVSS concepts and remediation validation
  • Patch prioritisation using exploitability and asset criticality
  • False positives, evidence quality and escalation thresholds

Workshop: Participants analyse a Wireshark capture and sample log events to document indicators, scope and an initial triage decision.

Day 4: Application, cloud and data security

  • OWASP Top 10 risk categories and control objectives
  • Input validation, authentication and session-management weaknesses
  • Secrets management and secure configuration practices
  • Cloud shared-responsibility models and identity risks
  • Cloud storage permissions, encryption and logging considerations
  • Data protection, backup integrity and recovery objectives
  • Third-party access and supplier security assurance

Workshop: Participants assess a web and cloud service scenario against OWASP Top 10 and produce a control recommendation matrix.

Day 5: Incident response and security improvement planning

  • Incident response phases: preparation, detection, containment, eradication and recovery
  • Incident severity classification and decision authority
  • Evidence preservation, timelines and chain-of-custody basics
  • Communication plans for technical teams, management and affected users
  • Post-incident review and corrective action tracking
  • Security metrics for patching, access, logging and incident response
  • Ninety-day security improvement roadmap development

Workshop: Participants complete an incident triage record and present a 90-day security improvement plan based on the week's simulated organisation.

Tools & standards covered

Wireshark, Nmap, CIS Controls v8, OWASP Top 10

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

You do not need a cyber security certification or penetration-testing background. You should already understand basic networking, operating systems, user accounts and common IT administration tasks, because the course applies security controls to those areas.

A laptop is recommended for live online delivery and useful for classroom lab work; access requirements are provided before the course. Exercises use controlled lab material and introduce Wireshark and Nmap without requiring participants to scan live production systems.

Yes. IT support, service desk and infrastructure staff are often the first to see suspicious access attempts, malware symptoms, misconfigurations or user reports. The course shows how to recognise, document and escalate those issues appropriately.

This course focuses on defending and operating IT environments: reducing attack surface, selecting controls, interpreting basic evidence and managing incidents. It does not train participants to conduct advanced exploitation, red-team engagements or formal penetration tests.

Participants can use the asset-risk register during service reviews, apply the control checks to changes and configurations, and use the incident triage template when investigating alerts. The 90-day plan provides a practical starting point for assigning improvement actions within their team.

You leave with a completed asset-risk register, a prioritised remediation approach, an incident triage record and a 90-day security improvement plan. These artefacts are developed from the course case study and are designed to be adapted to your organisation.

Upcoming sessions

  • 28 Sep – 02 Oct 2026
    Live Online · USD 1,500
    Book
  • 28 Sep – 02 Oct 2026
    Kigali · USD 3,500
    Book
  • 05 – 09 Oct 2026
    Dar es Salaam · USD 3,500
    Book
  • 05 – 09 Oct 2026
    Kigali · USD 3,500
    Book
  • 12 – 16 Oct 2026
    Live Online · USD 1,500
    Book
  • 19 – 23 Oct 2026
    Live Online · USD 1,500
    Book
  • 26 – 30 Oct 2026
    Cape Town · USD 4,200
    Book
  • 02 – 06 Nov 2026
    Dubai · USD 4,500
    Book

49 more dates — ask us.


Group of 5+?

Request in-house delivery or group rates →

Related courses in Cyber Security

5 Days Certificate

Tenable Nessus Professional Vulnerability Assessment Training Course

Vulnerability assessment programmes often fail not because organisations lack a scanner, but because scan scope is incomplete, credentials a…

5 Days Certificate

NIST Cybersecurity Framework Risk Management Training Course

Cybersecurity leaders are expected to explain which risks matter, who owns them, how controls reduce exposure, and when residual risk is acc…

5 Days Certificate

CrowdStrike Falcon Endpoint Detection and Response Administration Training Course

Security teams cannot respond consistently when endpoint telemetry is incomplete, prevention policies are poorly tuned, and analysts must wo…

5 Days Certificate

Wireshark Network Packet Analysis Training Course

Network incidents, intermittent application failures and suspected data exfiltration are often hidden in packet captures that are too large …