Cybersecurity Fundamentals
This is where you connect all the foundational knowledge into a cohesive security framework. You'll learn cryptographic concepts, how PKI and certificates work, how to model threats, and the OWASP Top 10 vulnerabilities every security professional must know.
📋 Lessons (16 total)
CIA Triad, threat actors, common attack types, defence-in-depth, and how security teams operate.
Understand the OSI model, TCP/IP stack, subnetting, common protocols, and how attackers exploit each layer — the foundation of all network security work.
Understand symmetric and asymmetric encryption, hashing, digital signatures, PKI, and TLS — the mathematical backbone of all secure communication.
Master authentication factors, password security, MFA, session management, OAuth 2.0, and common identity attacks like credential stuffing and session hijacking.
Learn how to defend networks with firewalls, IDS/IPS, VPNs, and network segmentation — and understand the attacker's perspective on each control.
Harden Linux systems through file permissions, user management, privilege escalation prevention, kernel hardening, and system auditing.
Survey the OWASP Top 10 vulnerabilities — from broken access control to injection — understand how each works, how to find it, and how to fix it.
Learn malware types, infection chains, and basic static and dynamic analysis techniques — the skills to understand what a suspicious file actually does.
Learn the IR lifecycle — preparation, detection, containment, eradication, recovery, and lessons learned — plus digital forensics techniques for collecting and analyzing evidence.
Understand how Security Operations Centers work — SIEM log aggregation, alert triage, threat intelligence integration, and the daily reality of defending an organization.
Learn how organizations decide which risks to fund, who is accountable, and how ISO 27001 turns risk management into an auditable, certifiable system.
Map real business scenarios to the compliance frameworks that govern them, and learn what each one actually requires — PCI-DSS, HIPAA, GDPR, and SOC 2.
Tailgating, badge cloning, pretexting, and dumpster diving — the foundational, often-overlooked layer of defense in depth that no firewall can substitute for.
BCP vs DRP, calculating RTO/RPO, hot/warm/cold recovery sites, the 3-2-1 backup rule, and why tabletop exercises are the cheapest way to find a plan's real gaps.
Why a vendor's security posture becomes your own risk, fourth-party risk, key contractual protections, and why not every vendor deserves the same scrutiny.
A 50-question practice set covering all five CompTIA Security+ (SY0-701) domains, for exam-readiness self-assessment.
The Security Foundation
This roadmap teaches the concepts that underpin all of security — from cryptographic primitives to organizational security programs.
What You'll Learn
- ✓ Apply the CIA Triad to real-world scenarios
- ✓ Understand encryption, hashing, and PKI
- ✓ Perform threat modeling and risk assessment
- ✓ Know the OWASP Top 10 vulnerabilities
- ✓ Understand incident response procedures