
Discover the myths, secrets, and lies that shape cybersecurity decisions and learn practical ways to prevent breaches, allocate resources, and evaluate products.
Meet your course coach, a cybersecurity veteran who built a global practice, trained GCHQ recruits in hacking, authored books on social engineering, and now develops next generation of cybersecurity professionals.
Challenge the lie that breaches are inevitable; learn that all breaches are preventable and focus on prevention with practical cybersecurity insights.
Debunk the myth that cyber attacks are targeted by showing that hackers probe everyone for weaknesses. Focus on fixing vulnerabilities and communicate that security is within our control, not inevitable.
Identify how hackers enter, prioritize breach prevention by focusing on four attack vectors—internet-facing services, via users, third parties, and malicious insiders—and harden externally visible systems.
Prioritize external vulnerabilities visible to hackers and patch them first. Use CVE, CVSS, and EPs to grade and guide action, then address internal risks as resources allow.
Debunk the myth that you get hacked without the latest tech; prioritize proven configurations, mature vendors, and prudent evaluation of your existing security tools.
Show that most breaches come from people, not malicious insiders. Focus on real daily risks rather than insider threats.
Beware the lie that new IT technologies automatically improve security; adopt proven, established systems and prioritize security testing, PCI compliance, and vulnerability discovery before deployment.
The cloud does not inherently improve cyber security; it introduces new risks, requires active due diligence, and often makes services sticky and hard to exit.
Explore how BYoD undermines security and apply business and personal device separation to reduce risk, while evaluating the true value of such products and services.
Question the value of dark web monitoring, as this lecture debunks the myth that cyber attacks are targeted and highlights dubious access and limited actionable insight.
Question the hype around zero-day protection by examining what guarantees actually cover, why they're marketing promises, and how new vulnerabilities are realistically mitigated in real systems.
Analyze data loss prevention (DLP) tools and their limitations, including false positives and data labeling challenges. Assess encrypted traffic, legal risks, and real-world performance by consulting existing customers before adopting.
Expose the myth that secure email is a good idea by showing how secure portals enable phishing, concentrate sensitive messages behind one login, and invite provider risks.
Assess cyber insurance incident response versus using your own responders, noting slow insurer-led timelines, cost incentives, and conflicts of interest; secure a professional retainer and prioritize rapid, transparent containment.
debunk the myth that big organizations are secure by exploring real-world patching failures, misconfigurations in cloud and Mpls, and poor IT due diligence during mergers.
Dispel the myth that information technology teams don't understand cybersecurity and learn to balance the two-hat reality of information technology and security under delivery pressure, forging a respectful, risk-aware partnership.
Scan and remediate your systems first, then bring in penetration testers to add value; rotate tests only with purpose, and prioritize quality and timely, management-friendly reporting.
Regular password changes do not meaningfully improve security and can prompt bad practices like reusing passwords across multiple systems; implement strong business passwords and multi-factor authentication (mfa), plus account lockouts.
Exposes how outsourcing web design and hosting can create cyber security gaps due to unclear responsibilities, insecure builds, and patching failures, and stresses securing websites through clear contracts and responsibilities.
Dispel the myth that cybersecurity user education works by showing that training is often irrelevant and overbroad, and advocate targeted phishing testing, business-personal device separation, and concise role-specific guidance.
Don't assume data is encrypted; test it with entropy analysis to verify. Ransomware may block access rather than encrypt, and recovery relies on backups or law enforcement keys.
Learn how management can make sound cybersecurity decisions when technical teams translate risks into simple, actionable terms and provide clear solutions that fit business priorities.
Apply the golden rules of resource allocation: balance technology, people, and management time at 20% each, and allocate 80% of effort to prevention, with 20% for detection, response, and insurance.
Focus on eliminating user mistakes, not chasing hackers, to prevent breaches. Apply simple defenses and actionable security practices to reduce attackers' opportunities and protect your systems.
Do the basics well: patch, run routine scans, and fix the top risk first. Prioritize simple risk assessment, external patching, and phishing training to prevent breaches.
Are you, or do you aspire to be, responsible for cyber security in your organization or team? Then, this essential, non-technical course is designed for you.
Appealing to all levels of experience and expertise, you will learn the hidden Myths, Secrets & Lies that will help you navigate an industry trying to sell to you, hacked organisations hiding their truth, and hackers trying to exploit you.
What Will You Gain from This Course?
Unlock Insider Secrets: Learn the invaluable secrets of cyber security that organizations pay thousands of dollars for.
Avoid Costly Mistakes: Prevent the errors that lead to expensive cyber breaches and protect your job.
Advance Your Career: Enhance your decision-making with expert knowledge and boost your cyber security career.
Navigate the Industry Wisely: Avoid being misled by those trying to sell you unproven cyber technologies.
Brought to you by Cyber Academy
Launched in 2024, Cyber Academy is dedicated to training the next wave of cyber security experts. Our innovative courses offer unique content unavailable elsewhere, with no hidden fees or subscriptions. Pay once and gain lifetime access to invaluable materials, allowing you to learn at your own pace.
Look out for new courses coming soon...
Social Engineering Mastery: An Advanced Course
Navigating Major Cyber Incidents: Your First 2 Weeks of Response
Cybersecurity Management: Thriving in Your First 100 Days