Building a Cyber-Resilient Organization: The Cyber Security Professional Program (Online / Remote)
1Summary
A single phishing email, an unpatched server, or a weak password can be enough to bring a network down — and the people responsible for stopping that are rarely the ones who caused it. Cyber security today isn’t an IT afterthought; it’s a core skill needed by anyone who touches a network, a system, or sensitive data.
The Cyber Security Professional Program from the Arab British Fellowship Training Academy takes participants from the fundamentals of protecting networks and data through to the practical skills of detecting threats, responding to incidents, and securing applications and identities. By the end of the program, participants will be able to recognize where an organization is exposed and take concrete steps to close the gap.
2Objectives and target group
Who Should Attend?
- Anyone whose work depends on the internet, telecom, or local networks.
- IT and network staff responsible for day-to-day security.
- Professionals who want to learn how to identify cyber threats and prevent attacks.
- Anyone considering a career move into cyber security.
Knowledge and Benefits:
After completing the program, participants will be able to master the following:
- Understand the fundamentals of managing and protecting networks and systems.
- Detect threats early and respond to cyber-attacks effectively.
- Build practical solutions that prevent breaches before they happen.
- Assess the risks and business impact of a data breach.
- Grasp the core principles of information security — confidentiality, integrity, and availability.
- Apply the basic concepts of cryptography to protect sensitive data.
3Course Content
Module 1: The Cyber Threat Landscape Today
- Common threats: malware, phishing, insider risk, and how attacks actually unfold.
- The CIA triad — confidentiality, integrity, availability — in practice.
- Case studies of major real-world cyber attacks.
Module 2: Governance – Frameworks, Standards and Compliance
- Key frameworks: NIST, ISO 27001, CIS Controls.
- Regulatory requirements: GDPR, HIPAA, PCI DSS.
- Why compliance and risk management matter beyond the checkbox.
Module 3: Securing the Network
- Networking fundamentals: TCP/IP and the OSI model.
- Firewalls and intrusion detection/prevention systems.
- Best practices for hardening network infrastructure.
Module 4: Designing for Security from the Start
- Defense in depth and least privilege as design principles.
- Secure system and application architecture.
- Key considerations for cloud security.
Module 5: Finding the Weak Points Before Attackers Do
- Vulnerability management processes and scanning tools (Nessus, OpenVAS).
- Ethical hacking principles and techniques.
- Turning scan results into a remediation plan.
Module 6: When an Incident Happens
- The incident response lifecycle: preparation, detection, containment, eradication, recovery.
- Building and communicating an incident response plan.
- SIEM, logging, and spotting suspicious activity before it escalates.
Module 7: Securing Applications and Data
- Common application vulnerabilities (OWASP Top Ten) and secure SDLC.
- Encryption, hashing, and key management essentials.
- Data loss prevention strategies.
Module 8: Controlling Who Gets Access
- Principles of identity and access management.
- Authentication methods: multi-factor authentication and biometrics.
- Role-based access control and least privilege in practice.
Module 9: Cyber Security for What Comes Next
- Security considerations for IoT, AI, and machine learning.
- Blockchain’s impact on cyber security.
- Trends and challenges shaping the future of the field.