
Students in the cyber security specialist workshop praise the professor for one-on-one guidance and flexible meeting times, noting increased experience and new opportunities gained through classes and work.
Gain real-world cybersecurity experience with the InfoSec4TC Cybersecurity Specialist Program, designed for those transitioning into the field, offering remote, senior-level roles protecting the integrity, availability, and confidentiality of systems.
Join the cyber security specialist workshop as the session begins in about a minute. Thank you for joining us; the session will begin in about a minute.
Gain practical real-life cybersecurity experience by engaging with a knowledgeable, supportive instructor and a quick, responsive support team that helps advance your career.
Develop a resume that highlights training stories and skills, backed by research and teamwork, drawing on CISSP trainings and many courses.
Join the cybersecurity specialist program to learn cybersecurity through hands-on projects that build practical skills.
Gain real cybersecurity experience through projects and operational activity, not theory. Suitable for network administrators, developers, IT support, and others with basic IT skills to start or switch into cybersecurity.
Identify the four barriers to starting a cybersecurity career—clear guidance, lack of hands-on experience, real-environment practice, and mentorship—and learn how the program provides a real-project path and mentor support.
Explore implementing ISO 27001 ISMS for an insurance company through risk assessment, policy creation, asset registers, and cross-department controls, with mapping to NIST and PCI DSS.
Explore IAM and risk management within ISO 27001 implementation, focusing on information asset registers, asset owners and custodians, and defining roles and controls.
Learn risk management fundamentals, from risk assessment and asset registers to mitigation, acceptance, and heat-map prioritization, with policy-backed methodologies guiding management decisions.
Begin with a baseline, the minimum security requirement, to secure all devices using CIS benchmarks and asset registers. Conduct vulnerability assessments with Nessus and coordinate patching with IT.
Master vulnerability management using nessus to run basic, advanced, and dynamic scans, identify CVEs, and generate reports for remediation and governance of vulnerability management programs.
Explore data loss prevention in a dlp implementation project, including policy scope and regulatory considerations, and learn to begin with a statement of work, asset register, and proof of concept.
Learn to build a disaster recovery framework by creating a business impact analysis, restoration plans, and testing to ensure critical services recover within defined MTD, RTO, and RPO.
Learn the fundamentals of network security, including public vs private IPs, ports, and firewalls, and translate them into a practical network security policy protecting data at rest and in transit.
Master access control concepts, including identification, authentication, authorization, and accounting, with DAC and MAC models. Emphasize need-to-know, logs, and policy.
Master log management and SIEM basics by centralizing logs from devices, operating systems, applications, and security tools with an agent-based setup, and configure use cases and alerts.
This session offers hands-on practice with the sim solution, the open-source GRC tool Iramba, and a honeypot to analyze real incidents, automate asset management, and strengthen governance, risk, and compliance.
Gain hands-on practice with XDR and GRC tools to monitor endpoints, detect malware, track vulnerabilities, and ensure cloud and on-premises compliance.
Master the full cycle of cybersecurity governance and technical operations by integrating GRC, SIM, SOAR, and threat intelligence, while practicing risk assessment and Upwork-based freelancing to build your CV.
Implement ISO 27001:2022 in a mid-size hospital to secure patient information, protect processes and services, and apply a comprehensive information security framework in a real-world project.
This course explains ISO 27001:2022 as an information security management framework for risk, detailing 11 clauses and annex A with 93 controls across organizational, people, physical, and technical domains.
Explore the CIA triad—confidentiality, integrity, and availability—and how controls such as access control, encryption, backups, and disaster recovery secure hospital data under ISO 27001.
Implement ISO 27001:2022 in a real hospital to protect patient information and hospital services. Learn to assess assets, infrastructure, and risks, and plan backups and redundancy.
Explore ISO 27001 organizational controls by crafting information security policies with document control, responsibilities, and policy mapping to standards, including email and internet security policies.
Explore starting an information security management system by building an information asset register, including asset inventory, ownership, custodian roles, classification, and its link to risk assessment and disaster recovery planning.
Develop and implement an information asset register template for ISO 27,001, build an information asset management policy, craft a presentation to department champions, and propose a four-level hospital classification scheme.
Learn to conduct practical risk assessments for any organization by applying risk management steps, asset identification, vulnerability and threat analysis, and a risk heat map using ISO 27005 guidelines.
Learn to conduct a risk assessment within risk management by identifying vulnerabilities and threats, assessing likelihood and impact, and using ISO 27,005 heat maps to build a risk register.
Explore a real risk register with security and document controls, plus an ISO 27,005 heat map, and learn to consolidate assets by custodian and value to assess risk.
Learn to conduct a call center risk assessment by building a three-asset risk register (hardware, software, people), identifying vulnerabilities and threats, and assessing likelihood and impact through scenarios.
Identify and score cybersecurity risks, populate the risk register, then hand them off to departments to implement controls, accept, transfer, or avoid, with a formal mitigation plan and deadlines.
Learn how management approves risk acceptance, documents it on a formal risk acceptance form in the risk register, and signs off after an annual risk assessment with mitigating controls.
Discover baselines as the minimum security requirement for devices, guiding ISO 27001 domains and CIS benchmarks. Learn to prepare baselines and coordinate with it for implementation.
Explore the foundation of cybersecurity through information assets and risk management, then translate that into technical security controls like antivirus and data loss prevention.
Implement baseline across all devices using asset registers and scanning tools, and collaborate with the information technology department to plan, enforce, and document milestones for evidence for auditors.
Define and validate security baselines for known and custom solutions, and use cloud and application security checklists to assess encryption, access control, and vulnerability management.
Validate the Windows server baseline by auditing services against the baseline document, focusing on disabling required services. Provide checks and screenshots to decide if the server may connect to network.
Discover how mac addresses identify devices within a network, explain the 48-bit six-pair format, and show how arp tables and switches use these addresses for packet routing.
Explore ethical hacking, security threats, and the hacking process, including social engineering and server or client side attacks, with demos of reconnaissance, Google dorking, Shodan, Maltego, nmap, and ARP spoofing.
Identify the IP address as a type of IOC and a unique network asset, and note that defenders block malicious IP addresses while attackers can register new ones.
See how a 32-bit subnet mask identifies the network and host portions to determine if two addresses like 192.168.1.100 and 192.168.1.101 can communicate, using 255.255.255.0 and slash notation /24.
Explore how the domain name system translates domain names to IP addresses, and review DNS records, the DNS hierarchy, and HTTP vs HTTPS basics.
Learn how the dynamic host configuration protocol automates ip address allocation, subnet mask, dns, and gateway assignments via a dhcp server, preventing conflicts as devices join or leave the network.
Explore how network address translation maps private IPs to a public IP, enabling multiple devices behind a router to access the internet while masking private addresses for security.
Learn how network switches connect devices by learning mac addresses on each port and building a mac address table to forward frames, and distinguish layer two from layer three switches.
The router directs data between different networks, forwards packets between them, and manages security and traffic prioritization, including internet connectivity through NAT.
Understand how a firewall protects a private network by monitoring and blocking traffic based on security rules, and prepare to configure a hardware firewall in real-life scenarios.
Learn how virtual private networks create secure, encrypted connections that mask IP addresses, enabling personal, client, and site-to-site VPN deployments for remote access and branch connectivity.
Verify at least eight gig of ram, a core i5, and 50 gig free space on the hard drive, then download and install Oracle VirtualBox on Windows host.
Explore how VirtualBox uses a hypervisor to create virtual machines, allocate RAM and CPU cores, assign storage, and connect VMs with host-only, NAT, or bridged networks, plus snapshots.
Load two virtual machines, Windows Server 2019 and Windows 10, by downloading, extracting, and adding them to VirtualBox, then prepare the lab for connectivity checks in the next lecture.
Set up and verify a security lab environment by configuring machines, managing snapshots, and ensuring connectivity between Windows server 2019 and Windows 10 through IP, DHCP, DNS, and firewall rules.
Explore endpoint security concepts, identify threats, and apply policy controls using Microsoft Endpoint Security Intune, including MDM vs MAM, device enrollment, baselines, disk encryption, EDR compliance, and configuration profiles.
Work with active directory domain to create sales organizational units, move PC1 to sales computers, and create John in sales with a group and password change on first login.
Learn how group policy lets admins centrally manage Windows-based networks by configuring users and computers in Active Directory, linking GPOs to OUs like sales and the default domain policy.
Configure and audit domain password policy via group policy objects, covering password history, age, length, and complexity. Validate changes by updating policies and testing password changes on pcs.
Block access to the control panel by creating and linking a user policy (GPO) in Active Directory. Update policies with gpupdate /force and verify user restrictions.
Apply a computer configuration policy to prevent shutdown and restart on the sales computers OU. Link the GPO and run gpupdate /force to enforce the policy for all users.
Automate vulnerability assessments with Nessus from Tenable, run a basic network scan aligned with PCI-DSS, review results by severity, and export a CSV report for remediation.
Implement the baseline for your technical infrastructure and take responsibility for vulnerability assessment. Use automated tools to identify weaknesses and coordinate with Windows, Linux, and teams to apply patches.
Organize vulnerability assessment findings into a clear, tabbed report by patch category (Microsoft, Oracle, applications) with Nessus-driven solutions, and coordinate patch plans with IT teams for follow-up per ISO 27001.
When a critical vulnerability like CVE 2020295 emerges, conduct an emergency vulnerability assessment using the advanced dynamic scan to target that CVE and apply urgent patching.
Explore cloud security fundamentals by identifying cloud service models such as IaaS, PaaS, SaaS and applying a cloud security checklist, with real-world AWS and Azure architecture scenarios.
Learn how vulnerability scanners detect weaknesses across networks and systems, identify issues like outdated software and weak passwords, and generate actionable reports with severity and remediation tips using Nessus.
Learn to use Naxos, a Nessus vulnerability scanner, to identify and assess vulnerabilities across Windows, Linux, Mac, and networks with a 100,000-plus plugin database, and generate remediation recommendations.
Explore Nessus plugins, their IDs, and how updates keep the vulnerability scanner current, then learn how to enable or disable plugin families and run basic to advanced scans.
Compare port scan and credential scan as vulnerability scans: port scan finds external entry points through open ports, while credential scan uses valid credentials to reveal internal misconfigurations.
Learn how Nessus scan templates enable quick vulnerability scans with pre-configured settings that can be customized for specific needs, including host discovery, basic network, advanced, and advanced dynamic scans.
Conduct host discovery with Nessus to identify active hosts on a 192.168.1.0/24 subnet using arp, tcp, and udp scanning, laying groundwork for vulnerability scanning.
Run a basic network scan with Nessus to identify vulnerabilities via port scanning. Target a range like 192.168.1.0/24, scan all ports, and review results for remediation.
Master advanced scan in Nessus for a comprehensive vulnerability assessment with customizable targets, ports, and plugins, including host discovery, credential scan, and detailed reports in csv format.
Execute an advanced dynamic scan to target a specific kV vulnerability, verify remediation, and review scan results to confirm that vulnerabilities are fixed.
Explain policies and plugin rules for vulnerability scans, create a test advanced policy with credentials and plugins, save, and apply it to a user defined scan with plugin severity controls.
Create a vulnerability management policy detailing assessment processes, roles, patching, and timelines per ISO and PCI DSS standards. Conduct a laptop vulnerability assessment and produce a VA report.
Learn to protect information through data classification, labeling, and data loss prevention; cover information security inventory, retention, and management per PCI DSS and ISO 27001.
Protect hospital patient information by implementing data classification and data loss prevention (DLP) controls that label documents, comply with GDPR, and safeguard medical records.
Learn to use Microsoft Compliance Services to classify information, apply data loss prevention policies, and map controls to GDPR, health care, and other regulations with ready templates.
Classify information using government or commercial models, decide top secret to public levels, and implement document labeling and policies to protect data and enable enforcement through office apps.
Learn to implement organization-wide document labeling according to classification levels, apply labels to documents and emails, and enforce labeling with headers, footers, and security controls using Microsoft compliance tools.
Learn to implement data loss prevention (DLP) policies using Microsoft Compliance to protect PII under GDPR and other standards, with templates, scope settings, and monitoring before publishing.
Define the information asset scope with a detailed SOW before implementing data loss prevention or data labeling, ensuring coverage across windows, mac, pdfs, and mobile devices.
Identify the business need, then vet vendors for a DLP solution. Conduct a POC, test key features on PDFs and Office files across Windows and Mac, and document results.
Assess the hospital’s data classification and DLP needs to plan a compliant deployment. Gather department requirements, build an asset register, draft a vendor statement of work, and test the solution.
Explore data loss prevention (DLP) and understand how it works, focusing on ManageEngine DLP software. Create rules and deploy policies in a lab environment to see DLP in action.
Understand DLP and data loss prevention as it monitors and classifies data by sensitivity, location, and usage, and enforces access based on user roles to protect information during outbound transmissions.
Explore how Manageengine DLP protects sensitive information across networks and endpoints with content-aware data classification, real-time monitoring, alerts, and compliance management for GDPR, HIPAA, and PCI-DSS.
Create and enforce data classification labels across documents, emails, and SharePoint using the Microsoft compliance tool; set default labels, optional auto labeling, and header or watermark markings to prevent leakage.
Deploy policy across Windows by associating a policy with a group and selecting blocking or audit rules. Test with removable storage and browser restrictions to verify 100% deployment.
Explore the fundamentals of cryptography, including ciphers, symmetric and asymmetric keys, hash functions, and digital signatures, and see them demonstrated in action for real-world cybersecurity.
Explore how cryptography secures communications by turning plaintext into ciphertext using algorithms and keys, enabling confidentiality, integrity, non-repudiation, and authentication in e-commerce, digital currencies, computer passwords, and military communications.
Learn how ciphers and keys work in cryptography through a hands-on lab, using the Kaiser shift to encrypt and decrypt text with a shared secret key.
Explore asymmetric key cryptography, using public keys for encryption and private keys for decryption, enabling secure data transfer with recipient public keys in a lab demonstration.
Asymmetric key cryptography uses a public key for encryption and a private key for decryption, allowing confidential data to be shared securely after exchanging public keys.
Learn how hash functions convert data into fixed-size digests to verify integrity, using sha-256 as a one-way function and exploring password protection and dictionary attacks.
Describe how digital signatures use a private key and hash to ensure authenticity, integrity, and non-repudiation, and how recipients verify signatures with the public key.
5 Real Projects & 35 Real Operational Activities
Full recording of the Cybersecurity Specialist live workshop
Cyber Security Specialist Training is following a top-down approach where candidates will learn important cyber security skills implementation in a real business environment. It's well known that candidates learn much faster while working on real cyber security projects than while taking training or online courses accordingly we are giving our students an opportunity to join real cyber security projects with guidance on how to execute real project tasks and give our students a chance to learn by experiences. This approach is much more effective than the normal learning path that depends on traditional training or online courses that will provide candidates with the knowledge but miss the real implementation experience.
Gain cyber security realistic experience through hands-on involvement in cutting-edge security scenarios. This enables learners to apply theoretical knowledge in practical situations, bridging the gap between academic learning and real-world application.
Get real-life implementation experience from real cyber security projects, where you'll be immersed in various aspects of cyber security, from threat analysis to mitigation strategies. This direct exposure to live projects accelerates the learning process, making complex concepts easier to grasp.
Understand the real business challenge by engaging with actual problems faced by organizations. This exposure to the dynamic nature of cyber threats in a business context enhances problem-solving skills and critical thinking.
Get the confidence you need to apply for any job in the cyber security domain. The combination of practical experience and theoretical understanding equips you with a comprehensive skill set, making you a competitive candidate in the rapidly evolving field of cyber security.