Cyber Security Fundamentals for IT Professionals Training Course
| Course code | SD-CS-001 |
|---|---|
| Duration | 5 days |
| Level | Intermediate |
| Category | Cyber Security |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
IT professionals are routinely asked to deploy systems, support users, manage cloud services and respond to incidents, yet security controls are often added late or handled as a specialist concern. This creates preventable exposure: misconfigured access, unpatched services, weak logging, insecure web applications and unclear incident escalation. This course gives technical staff a practical security baseline for recognising these conditions, discussing risk accurately and building safeguards into everyday IT operations.
Participants examine the threat landscape through the lenses of confidentiality, integrity and availability; asset and data classification; identity and access management; network segmentation; vulnerability management; endpoint protection; logging; and incident response. They use structured methods to identify attack paths, interpret common security findings, prioritise remediation by risk, and recommend controls aligned with the CIS Controls v8 and OWASP Top 10. Practical sessions introduce packet inspection with Wireshark, service discovery with Nmap and evidence-based analysis of authentication, network and web application events.
The course is delivered through instructor-led technical briefings, guided demonstrations, lab exercises and team-based case work. Participants work through a simulated organisation with exposed services, suspicious network traffic, access-control gaps and a developing security incident. By the end of the week, each participant produces a security improvement pack containing an asset-risk register, prioritised remediation plan, incident triage record and 90-day action plan that can be adapted for their own environment.
It is designed for IT professionals who already work with infrastructure, applications, cloud platforms or service operations and need a sound, operational understanding of cyber security. It is particularly valuable for teams seeking a shared vocabulary and repeatable approach before progressing to specialist penetration testing, security operations or advanced cloud security training.
Course objectives
By the end of this course, participants will be able to:
- Classify business assets and data using confidentiality, integrity and availability impact criteria
- Map attack surfaces and likely threat paths across endpoints, networks, identities and web applications
- Use Nmap scan results to identify exposed services and prioritise basic remediation actions
- Interpret Wireshark packet captures to investigate suspicious network connections and authentication activity
- Apply CIS Controls v8 safeguards to common IT operational weaknesses
- Assess web application risks against OWASP Top 10 categories and recommend proportionate controls
- Create an incident triage record with evidence, severity, containment actions and escalation decisions
- Produce a 90-day cyber security improvement plan based on a prioritised risk register
Benefits of attending
For you
- Gain a practical method for turning technical findings into risk-based remediation priorities
- Build confidence interpreting scan output, packet captures and security alerts during operational investigations
- Contribute more credibly to security reviews, change approvals and incident discussions
- Create evidence-based recommendations using recognised references such as CIS Controls v8 and OWASP Top 10
- Leave with reusable risk register, incident triage and improvement-plan templates for workplace use
For your organisation
- Reduce avoidable exposure by helping IT staff identify insecure services, weak access controls and missing patches earlier
- Improve consistency of security decisions through shared use of asset classification and risk-prioritisation methods
- Strengthen first-line incident handling with clearer evidence capture, containment and escalation practices
- Support more targeted security investment by linking technical weaknesses to business impact and control actions
- Create a documented 90-day improvement backlog that managers can assign, track and review
Target competencies
Who should attend
- Systems Administrators — who configure servers, identities and endpoint controls that can introduce or reduce operational risk
- Network Administrators — who manage connectivity, segmentation, firewalls and monitoring points
- IT Support and Service Desk Analysts — who identify suspicious user activity, malware indicators and access issues early
- Cloud Administrators — who administer cloud identities, storage, workloads and configuration settings
- Application Support Analysts — who support business applications and need to recognise common web and access-control weaknesses
- IT Managers and Technical Team Leaders — who must prioritise security improvements and coordinate incident escalation
Requirements and prerequisites
Participants should be comfortable using a Windows or Linux workstation and understand basic IT concepts including IP addressing, TCP/IP, DNS, user accounts, file permissions, web browsers and client-server applications. Experience supporting infrastructure, applications, cloud services or end users is useful and matches the intermediate audience. Participants do not need prior cyber security qualifications, programming ability, penetration-testing experience or detailed knowledge of security operations centres. This is a fundamentals course for working IT professionals; complete beginners to IT should first gain practical familiarity with networks, operating systems and administration tasks.
Training methodology
The instructor combines short technical explanations with guided demonstrations in a safe lab environment. Participants inspect packet captures in Wireshark, review controlled Nmap discovery output, analyse identity and configuration scenarios, and map findings to CIS Controls v8 and OWASP Top 10 guidance. Small groups work through a simulated organisation's security issues, making evidence-based prioritisation and escalation decisions. Each day closes with a practical artefact, and the final session converts the case findings into an individual 90-day security improvement plan for workplace application.
Course outline
Day 1: Security foundations and risk context
- Cyber security objectives: confidentiality, integrity and availability
- Threat actors, attack motives and common attack chains
- Asset inventory and business service dependency mapping
- Data classification and handling requirements
- Attack surface identification across people, processes and technology
- Likelihood-impact risk scoring and risk treatment options
- Security governance, policy ownership and accountability
Workshop: Participants build an asset-risk register for a simulated business service and identify its three highest-priority security exposures.
Day 2: Identity, endpoints and network defence
- Identity lifecycle management and least-privilege access
- Multi-factor authentication and privileged access controls
- Endpoint hardening, patching and secure configuration baselines
- Network segmentation and trust boundary design
- Firewall rules, secure remote access and service exposure
- Nmap host discovery and service enumeration fundamentals
- CIS Controls v8 safeguard selection
Workshop: Participants review a controlled Nmap scan and access-control scenario, then produce a prioritised hardening recommendation.
Day 3: Monitoring, logging and vulnerability management
- Security logging objectives and event source selection
- Authentication, endpoint, network and application log fields
- Wireshark packet capture filters and protocol inspection
- Indicators of compromise and suspicious behaviour patterns
- Vulnerability scanning, CVSS concepts and remediation validation
- Patch prioritisation using exploitability and asset criticality
- False positives, evidence quality and escalation thresholds
Workshop: Participants analyse a Wireshark capture and sample log events to document indicators, scope and an initial triage decision.
Day 4: Application, cloud and data security
- OWASP Top 10 risk categories and control objectives
- Input validation, authentication and session-management weaknesses
- Secrets management and secure configuration practices
- Cloud shared-responsibility models and identity risks
- Cloud storage permissions, encryption and logging considerations
- Data protection, backup integrity and recovery objectives
- Third-party access and supplier security assurance
Workshop: Participants assess a web and cloud service scenario against OWASP Top 10 and produce a control recommendation matrix.
Day 5: Incident response and security improvement planning
- Incident response phases: preparation, detection, containment, eradication and recovery
- Incident severity classification and decision authority
- Evidence preservation, timelines and chain-of-custody basics
- Communication plans for technical teams, management and affected users
- Post-incident review and corrective action tracking
- Security metrics for patching, access, logging and incident response
- Ninety-day security improvement roadmap development
Workshop: Participants complete an incident triage record and present a 90-day security improvement plan based on the week's simulated organisation.
Tools & standards covered
Wireshark, Nmap, CIS Controls v8, OWASP Top 10
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
-
28 Sep – 02 Oct 2026Book
Live Online · USD 1,500 -
28 Sep – 02 Oct 2026Book
Kigali · USD 3,500 -
05 – 09 Oct 2026Book
Dar es Salaam · USD 3,500 -
05 – 09 Oct 2026Book
Kigali · USD 3,500 -
12 – 16 Oct 2026Book
Live Online · USD 1,500 -
19 – 23 Oct 2026Book
Live Online · USD 1,500 -
26 – 30 Oct 2026Book
Cape Town · USD 4,200 -
02 – 06 Nov 2026Book
Dubai · USD 4,500
49 more dates — ask us.
Group of 5+?
Request in-house delivery or group rates →Related courses in Cyber Security
Tenable Nessus Professional Vulnerability Assessment Training Course
Vulnerability assessment programmes often fail not because organisations lack a scanner, but because scan scope is incomplete, credentials a…
NIST Cybersecurity Framework Risk Management Training Course
Cybersecurity leaders are expected to explain which risks matter, who owns them, how controls reduce exposure, and when residual risk is acc…
CrowdStrike Falcon Endpoint Detection and Response Administration Training Course
Security teams cannot respond consistently when endpoint telemetry is incomplete, prevention policies are poorly tuned, and analysts must wo…
Wireshark Network Packet Analysis Training Course
Network incidents, intermittent application failures and suspected data exfiltration are often hidden in packet captures that are too large …