Cybersecurity Fundamentals
IT support staff, system administrators, junior developers and anyone moving into a security role. You should be comfortable using computers and the command line at a basic level.
- Cybersecurity
- Foundation
- 5 days, or 10 half-day sessions
- Instructor-led cohort · In-house for your team · Online, live
What you will be able to do
- Explain the main threats facing organisations in East Africa, from phishing and SIM-swap fraud to ransomware.
- Apply the basics of identity and access control, including strong authentication and least privilege.
- Harden a Windows or Linux machine and a small network against common attacks.
- Read logs and alerts to spot signs of an attack, and know what to do first.
- Follow an incident response plan and record what happened clearly.
- Describe your organisation's duties under the Kenya Data Protection Act 2019 when a breach happens.
The basics, done properly
Most security incidents do not start with a clever exploit. They start with a reused password, an unpatched server, a phishing email or an administrator account nobody remembered to close.
This course covers the basics that stop most of them, taught through hands-on work in a lab rather than slides alone.
How it is taught
You work in an isolated lab built for the course: you configure machines, read real-looking logs and respond to a simulated incident. Every technique is practised only on systems you are authorised to test.
The examples come from the threats East African organisations actually face, including mobile-money fraud and SIM-swap attacks, alongside the global ones.
Developers who want to go further can continue with Secure Development and Application Security.
Syllabus
Security principles
- Confidentiality, integrity and availability
- Threats, vulnerabilities and risk
- Security controls and defence in depth
The threat landscape
- Phishing, business email compromise and social engineering
- Mobile-money fraud and SIM-swap attacks
- Malware, ransomware and insider threats
Identity and access
- Passwords, password managers and multi-factor authentication
- Least privilege and access reviews
- Managing shared and administrator accounts
Securing systems and networks
- Patching and secure configuration of Windows and Linux
- Firewalls, network segmentation and Wi-Fi security
- Backups that survive ransomware
Monitoring and detection
- What to log, and how long to keep it
- Reading logs and alerts in a lab
- Basic network analysis with Wireshark
Incident response
- Preparing an incident response plan
- The first hour of an incident, step by step
- Evidence, communication and lessons learned
Law, policy and people
- The Kenya Data Protection Act 2019 and breach notification
- The Computer Misuse and Cybercrimes Act 2018, in outline
- Security awareness for staff, and writing policies people follow
Assessment and certificate
- A practical assessment in a lab: you harden a machine against a checklist, investigate a simulated incident from its logs, and write a short incident report.
- Deefrent Academy certificate, awarded on passing the course assessment.
- Ask for dates and fees. Tell us the course and the format you prefer, and we reply with the next dates and the fee.
Training a whole team?
This course can run privately for your organisation, at your premises or online, with examples drawn from your own systems.
Ready to join the next cohort?
Tell us how you would like to attend. We reply with the next dates, the fee and what you need before you start.