Sii Poland

SII UKRAINE

SII SWEDEN

  • Trainings
  • Career
Join us Contact us
Back

Sii Poland

SII UKRAINE

SII SWEDEN

Back

Become a Cybersecurity Specialist

Training language: PL/EN

  • The number of participants 8-16 people
  • Duration 6 days

Why take this course

Cybersecurity is one of the fastest-growing industries—and one of those facing a significant shortage of qualified professionals.

This training is designed for individuals entering the cybersecurity field or transitioning their careers within IT. Over six intensive days, participants progress from foundational concepts to independently conducting a complete security assessment of an organization.

The program combines theory (maximum 30 minutes per session) with immediate hands-on practice. Every concept is tested on the same day in a laboratory environment and documented within a project that participants take away as part of their professional portfolio.

The methodology is based on Malcolm Knowles’ principles of andragogy: adults learn most effectively when they can see the direct application of knowledge and gradually build increasingly independent competencies.

The training follows six core principles of adult learning:

  • Every day starts with “Why?”
    • A real-world security incident introduces each topic before the theory begins.
  • Theory limited to 30 minutes
    • Every theoretical block is immediately followed by a practical exercise.
  • Peer Review
    • Before submitting each section of the KIRA Project, participants exchange their work for review.
  • Scaffolding
    • Days 1–2: guided exercises and templates.
    • Days 5–6: independent analysis and decision-making.
  • Daily Retrospective (15 minutes)
    • What happened?
    • Why does it matter?
    • What will I do differently?
  • Gamification
    • Daily quizzes.
    • Visible progress in the final report.
    • Optional evening CTF (Capture The Flag) challenges.

What you'll learn

After completing the course, participants will be able to:

  • Identify and document web application vulnerabilities according to the latest OWASP Top 10 standards.
  • Conduct security assessments of AI systems based on the OWASP Top 10 for LLM Applications.
  • Analyze system logs and detect incidents using SIEM platforms.
  • Write scripts that automate everyday security analyst tasks.
  • Perform passive reconnaissance (OSINT) using open-source tools.
  • Analyze network traffic and recognize attack patterns.
  • Build risk registers and develop remediation plans.
  • Understand the operational requirements of NIS2, DORA, and GDPR.
  • Present security assessment findings in a format understandable to executive management.

Participants leave the training with a complete security assessment report for a fictional organization—a portfolio-ready document suitable for showcasing during job interviews.

Certification & Exam

Participants receive a personalized certificate confirming completion of the training and the acquisition of practical cybersecurity competencies.

There is no final exam.

Assessment is based on active participation, laboratory exercises, and the completion and presentation of the KIRA Security Assessment Project.

Who is this course for

This training is intended for individuals without prior cybersecurity experience but with a general technical background, including:

  • Graduates of Computer Science or related technical degree programs.
  • Network administrators, system administrators, and helpdesk specialists looking to transition into cybersecurity.
  • Software developers or software testers interested in IT security.
  • IT professionals pursuing a career change toward cybersecurity.

KIRA Project

The central element of the entire program is the KIRA Project, which runs throughout all six training days.

Participants take on the role of an external security consulting team performing the first security assessment of a fictional organization prior to an investment round.

The training environment includes:

  • A vulnerable web application
  • A chatbot powered by a Large Language Model
  • Network infrastructure containing intentionally insecure configurations

Each day participants complete another section of the final assessment report, creating tangible evidence of practical cybersecurity skills.

Training schedule

Day 1

Building a Common Security Language and Environment Setup

Participants explore cybersecurity foundations through the analysis of real-world incidents while immediately working with system logs and OSINT tools.

Topics

  • CIA Triad
  • Zero Trust
  • Authentication and Authorization models (AAA)
  • Security control categories and types based on NIST CSF and CIS Controls
  • Linux and Windows log analysis
  • Threat actor profiles
  • Impact of Generative AI on the threat landscape
  • Passive reconnaissance:
    • OSINT
    • Google Dorks
    • DNS analysis
  • Cybersecurity career paths and job market overview

Laboratory

  • SIEM environment configuration
  • Attack simulation and real-time alert monitoring
  • OSINT reconnaissance of a training domain

KIRA Project

  • Project scope definition
  • Asset inventory
  • OSINT findings

Day 2

Human-Centered Threats and Malware

Most security incidents begin with human factors. Participants examine this layer from social engineering psychology to malware analysis and data protection.

Topics

  • Psychology of social engineering
  • Six decision triggers commonly exploited by attackers
  • Phishing:
    • Spear phishing
    • Business Email Compromise (BEC)
    • Vishing
    • Deepfake attacks
  • Warning signs and attack indicators
  • Pretexting and impersonation
  • Malware taxonomy:
    • Viruses
    • Worms
    • Trojans
    • Ransomware
    • Rootkits
    • Fileless/LOTL attacks
    • Botnets
  • Ransomware attack lifecycle
  • Defense-in-Depth model
  • Data classification
  • Data states:
    • At Rest
    • In Transit
    • In Use
  • Data Loss Prevention (DLP)
  • Physical security

Laboratory

  • Phishing analysis:
    • Email headers
    • SPF, DKIM, and DMARC records
    • Indicators of Compromise (IoCs)
  • Malware behavior analysis:
    • Processes
    • Network connections
    • File system artifacts

KIRA Project

  • STRIDE-based Threat Model

Day 3

Cryptography, Networks, and Identity Security

Participants learn the three core technical pillars required to understand attacks and defensive mechanisms.

Topics

  • Symmetric and asymmetric encryption
  • Hashing and password protection
    • Secure algorithms
    • Dictionary attacks
    • Rainbow tables
    • Salting
  • Digital signatures
  • Public Key Infrastructure (PKI)
  • Digital certificates
  • TLS negotiation
  • Post-quantum cryptography and emerging NIST standards
  • Passkeys and FIDO2/WebAuthn authentication
  • Next-generation firewalls
  • DMZ architecture
  • IDS/IPS systems
  • VPN technologies
  • Authentication evolution:
    • SMS OTP
    • TOTP
    • Passkeys
  • Privileged Access Management (PAM)
  • Single Sign-On (SSO)
  • Identity federation protocols
  • Access control models
  • Microsegmentation

Laboratory

  • Key and certificate generation
  • Network scanning and service documentation
  • Network traffic analysis:
    • HTTP
    • HTTPS
    • DNS

KIRA Project

  • Initial Infrastructure Findings:
    • TLS configuration
    • Open ports
    • IAM configuration

Day 4

Offensive Testing and Secure AI

The most practical day of the training. Participants attack a web application and an LLM-powered chatbot within a controlled environment.

OWASP Top 10 Topics

  • Broken Access Control
  • Security Misconfiguration
  • Software Supply Chain Failures
  • Cryptographic Failures
  • Injection:
    • SQL Injection
    • XSS
    • Command Injection
  • Insecure Design
  • Authentication Failures
  • Software and Data Integrity Failures
  • Security Logging Failures
  • Mishandling of Exceptional Conditions

OWASP Top 10 for LLM Applications

  • Prompt Injection:
    • Direct
    • Indirect
  • Sensitive Information Disclosure
  • Excessive Agency
  • System Prompt Leakage
  • Embedding and vector database vulnerabilities
  • RAG architecture attacks

Laboratory

  • Minimum five web vulnerability exercises
    • Payload documentation
    • Results
    • Remediation recommendations
  • LLM attacks:
    • Prompt Injection
    • System prompt extraction
    • Excessively privileged agent scenarios

KIRA Project

  • Complete Application Findings sections:
    • Web Security
    • AI Security
  • Proof of Concept (PoC)
  • CVSS assessment

Day 5

Automation, Threat Intelligence, and SOC Operations

Automation Topics

  • The 2026 philosophy of working with code:
    • Logic and debugging over syntax memorization
  • Bash scripting:
    • Log analysis
    • IoC extraction
  • Python scripting:
    • Data parsing
    • Automated IoC enrichment via APIs

Threat Intelligence Topics

  • Strategic, operational, tactical, and technical intelligence
  • IoC enrichment
  • Open-source TI platforms
  • Public threat intelligence feeds
  • MITRE ATT&CK framework
  • Mapping incidents to tactics and techniques
  • Threat Hunting methodologies

SOC Topics

  • SIEM architecture
  • Detection rule creation
  • Alert triage
  • SOC Tier 1 / Tier 2 / Tier 3 responsibilities
  • Playbook automation
  • AI-assisted false-positive reduction

Laboratory

  • Bash script:
    • Extracting the Top 10 attacking IP addresses from logs
  • Python script:
    • IoC enrichment with CSV export
  • PCAP analysis and MITRE ATT&CK mapping

KIRA Project

  • Risk Register
  • 5×5 Risk Matrix
  • Initial POA&M Remediation Plan

Day 6

Risk Management, Compliance, and Executive Communication

Participants learn the business, legal, and financial impacts of cybersecurity vulnerabilities and build actionable remediation strategies.

Risk Management

  • Risk calculations:
    • SLE
    • ARO
    • ALE
  • Four risk treatment strategies
  • Residual risk
  • Finalizing the POA&M plan
  • Business continuity metrics:
    • BIA
    • RTO
    • RPO
  • Supply chain security

Regulations and Compliance

  • NIS2
    • Essential entity obligations
    • Incident reporting
      • 24-hour initial notification
      • 72-hour full report to CERT
    • Financial penalties
  • DORA
    • ICT risk management in financial services
    • Resilience testing
    • Third-party oversight
  • GDPR
    • Technical and organizational measures
    • 72-hour breach notification
    • Data Protection Officer responsibilities

Cloud Security and Incident Response

  • Shared responsibility models:
    • SaaS
    • PaaS
    • IaaS
  • Current cloud threats
  • Digital forensics fundamentals
    • Chain of custody
    • Evidence integrity
  • Incident response frameworks

Laboratory

  • Finalizing the KIRA Project report
  • Completing the POA&M
  • Calculating ALE values
  • Preparing an Executive Summary for senior management

Final Presentation (approximately 3 hours)

Each participant or team presents their complete assessment report to a panel simulating an executive board.

The panel evaluates:

  • Financial exposure
  • Regulatory compliance
  • Remediation priorities
  • Risk-based decision making

Additional Information

 

  • The entire training is conducted in a Kali Linux environment.
  • Only free and open-source tools are used.
  • No commercial licenses are required.
  • KIRA Project templates, finding sheets, cheat sheets, and the complete lab environment are included in the course fee.

 

Technical Requirements

  • Laptop with:
    • Quad-core processor
    • Minimum 16 GB RAM
    • At least 50 GB of free SSD storage

A detailed environment setup guide is provided before the training.

Have questions about this training?

Ewelina Rutkowska-Chruściel Business Development Manager
Contact me
Interested in training?
Contact us to get more information

Contact our expert

Your file

Uploaded file:
  • file_icon Created with Sketch.

Acceptable files: doc, docx, pdf. (max 5MB)
Please submit your file in DOC, DOCX or PDF format
The upload size is limited to 5 MB
File is empty
File was not uploaded

At any time, you may withdraw your consent to the processing of personal data, but such withdrawal shall not affect the legal compliance of any processing of such data, which had occurred before you withdrew your consent. Detailed information on the processing of your personal data is specified in the Privacy Policy.

Ewelina Rutkowska-Chruściel

Business Development Manager

Your message was sent successfully

We will look over your message and get back to you as soon as possible

Sorry, something went wrong and your message was not delivered

Refresh the page and try again. Contact us, if problem occurs again

We’re sorry, but the selected file appears to be damaged and we can't process it.

Please try uploading a different copy or a new version of the file. Contact us, if problem occurs again.

Processing…

Similar trainings

ITIL® and PRINCE2® are registered trademarks of AXELOS Limited, used under permission of AXELOS Limited. All rights reserved. AgilePM® is a registered trademark of Agile Business Consortium Limited. All AgilePM® Courses are offered by Sii, an Affiliate of Eraneos Iberia S.L.U., an Accredited Training Organization of The APM Group Ltd. Lean IT® Association is a registered trademark of the Lean IT Association LLC. All rights reserved. Sii is an Affiliate of Accredited Training Organization Eraneos Iberia S.L.U. SIAM™ is a registered trademark of EXIN Holding B.V. All prices presented on the website are net prices. 23% VAT should be added.

Get in touch Find training

Änderungen im Gange

Wir aktualisieren unsere deutsche Website. Wenn Sie die Sprache wechseln, wird Ihnen die vorherige Version angezeigt.

Einige Inhalte sind nicht in deutscher Sprache verfügbar.
Sie werden auf die deutsche Homepage weitergeleitet.

Möchten Sie fortsetzen?