Why cybersecurity matters in daily life, the CIA triad, and the threat actors behind attacks. Learn to think like a defender with defense-in-depth and an assume-breach mindset, including AI-assisted social engineering awareness.
How computers process, store, and move data across Windows, macOS, Linux, Android, and iOS. Covers file permissions, USB and external media risks like BadUSB, and safe setup and update habits.
What routers, switches, and Wi-Fi actually do, with IP, MAC, DNS, and DHCP explained in simple terms. Includes ports, firewalls, and hardening basics for home and office networks.
Enforce the Principle of Least Privilege on user accounts, secure file permissions and processes, and audit startup items and logs. Ends with update automation, recovery tools, and common OS misconfigurations to avoid.
Topic 4
Section 2: Threat Landscape, Malware, and Authentication
Map the sum of all entry points an attacker could exploit and how targets are chosen via scanning and OSINT. See how small mistakes chain into big incidents, plus new AI threat vectors like deepfake voice cloning.
From ransomware, spyware, trojans, and viruses to modern infostealers that hijack active browser sessions. Covers generative AI-powered phishing and man-in-the-middle network attacks.
Why passwords fail and how attackers exploit them, plus passphrases and password managers as first defenses. Dives into legacy MFA weaknesses and phishing-resistant passkeys built on FIDO2 and WebAuthn.
Topic 7
Section 3: Data Protection, Email, and Application Security
Encryption essentials for disks, files, and messages using symmetric and asymmetric keys. Applies the 3-2-1 backup rule with tested restores, and covers secure deletion and device disposal.
Dissect email headers, links, and attachments, and spot phishing by contextual cues rather than typos. Includes browser extension risks, certificate trust signals, and quishing attacks that smuggle malicious links in QR codes.
How websites and apps collect and send data, and how untrusted input enables injection attacks. Covers mitigating cookie and session theft, hardening password reset flows, and safe use of online portals.
Set up WPA3 and guest networks, browse public Wi-Fi safely with VPNs, and lock down Bluetooth and NFC pairing. Reviews mobile app permissions and remote lock and wipe steps for lost or stolen phones.
The risks in connected appliances, cameras, and sensors, from default passwords to missing firmware updates. Learn to segment IoT devices onto separate networks and manage camera, lock, and vendor trust settings.
Cloud storage, sync, and sharing basics, plus auditing stale OAuth tokens that grant back-door account access. Covers expiring shared links, reviewing active sessions, and basic incident reporting to providers.
Why your personal data is valuable to trackers, brokers, and identity thieves. Audit app permissions and ad targeting, share more safely on social media, and run regular data-broker removal and cleanup routines.
Why rules and policy baselines matter online and at work, with a tour of cybercrime, privacy, and copyright law. Covers acceptable use, responsible vulnerability disclosure, and when to seek professional or legal help.
Risk as assets, threats, vulnerabilities, and impact combined into a simple equation. Select balanced technical, administrative, and physical controls, weigh cost versus benefit, and revisit risks after incidents.
Topic 16
Section 6: Monitoring, Incident Response, and Careers
What logs, events, and alerts tell defenders about system and network behavior. Interpret antivirus, firewall, and SIEM signals, and triage alerts calmly to separate true positives from noise.
Understand bugs, CVEs, and severity scores, then automate and verify patch deployment. Prioritize internet-facing flaws first and test updates safely in staging with documented rollbacks.
Classify incidents, contain affected systems, and preserve evidence with a proper chain of custody. Rebuild from clean backups, run post-incident reviews, and practice with interactive tabletop exercises.
Beginner roles, certification pathways, and how to build an isolated home practice lab. Engage CTF platforms and communities, then move from theory to hands-on lab modules and portfolio projects.
Topic 20
Section 7: Reference Materials, Free Learning Ecosystems, and Pathways
A curated library of free blogs, industry news, and portals, plus interactive labs like PortSwigger Academy and Cybrary. Includes YouTube channels such as NetworkChuck, Professor Messer, John Hammond, and Simply Cyber.
Governance, Risk, and Compliance explained through frameworks like ISO 27001, NIST CSF, SOC 2, and GDPR. Maps practical business skills, entry-level certifications, and non-coding career roles like GRC Analyst.