Corporate Training

Information Security & Cyber Security Training

Build Security-Aware People. Strengthen Organisational Cyber Capability.

Vebsters helps organisations strengthen information security and cyber security capability across employees, managers, business functions, IT teams, security professionals and leadership.

Our programs can be designed around the learner's role, level of responsibility, security exposure, technology environment, organisational policies and capability requirements.

From workforce security awareness to role-based cyber security capability development, Vebsters can support organisations through Masterclasses, Workshops, Structured Training Programs, Role-Based Learning, Simulations, Hands-On Labs and Expert-Led Sessions.

The Vebsters LEAD Approach: Learn → Execute → Achieve → Demonstrate

Security Training Must Go Beyond Awareness.

Cyber security is not only the responsibility of the security team.

Employees handle information, access systems, communicate with customers, use applications, share documents, work remotely and make decisions that can affect organisational security.

At the same time, IT and Cyber Security professionals require deeper technical and operational capabilities to identify, protect, detect, respond and recover.

Effective security capability therefore needs to be built according to the role and level of responsibility.

That is why Vebsters approaches Information Security & Cyber Security Training through the LEAD Framework.

LEARN — Understand Security Risks, Responsibilities and Practices

Employees and professionals first need to understand the security concepts, risks, policies, technologies and practices relevant to their roles.

Learning may include areas such as:

  • Information Security Fundamentals
  • Cyber Security Awareness
  • Phishing Awareness
  • Social Engineering
  • Password Security
  • Identity and Access Awareness
  • Data Protection
  • Information Classification
  • Secure Email Practices
  • Safe Internet Usage
  • Remote Working Security
  • Mobile Device Security
  • Cloud Security Awareness
  • Secure Use of AI Tools
  • Incident Reporting
  • Cyber Risk
  • Security Governance
  • Secure Development
  • Network Security
  • Application Security
  • Cloud Security
  • Threat Detection
  • Incident Response

The objective is not simply to make employees aware that cyber threats exist. It is to help them understand what security responsibility means in the context of their actual work.

EXECUTE — Apply Secure Practices in Everyday Work

Security capability becomes valuable when people consistently apply secure behaviours and technical practices.

For employees, this may include:

For IT and Cyber Security teams, execution may include:

Vebsters programs can incorporate:

  • Identifying Suspicious Emails
  • Protecting Credentials
  • Handling Sensitive Information
  • Sharing Information Securely
  • Following Access-Control Practices
  • Reporting Security Incidents
  • Protecting Devices
  • Using Approved Applications
  • Working Securely from Remote Locations
  • Recognising Social Engineering
  • Protecting Confidential Information When Using AI Tools
  • Configuring Security Controls
  • Monitoring Security Events
  • Analysing Threats
  • Managing Vulnerabilities
  • Investigating Incidents
  • Securing Networks
  • Securing Cloud Environments
  • Testing Applications
  • Managing Identities
  • Applying Secure Development Practices
  • Performing Security Assessments
  • Security Scenarios
  • Case Discussions
  • Simulations
  • Phishing Awareness Exercises
  • Hands-On Labs
  • Technical Demonstrations
  • Incident Scenarios
  • Security Assessments
  • Role-Based Exercises

to help learners move from awareness to execution.

ACHIEVE — Strengthen Security Behaviour and Organisational Resilience

The goal of Information Security & Cyber Security Training is not simply course completion.

It is to strengthen how people recognise risk, protect information, follow secure practices and respond appropriately.

Depending on the role and program objective, capability development may support:

  • Stronger Security Awareness
  • Improved Security Behaviour
  • Better Protection of Organisational Information
  • Faster Recognition of Suspicious Activity
  • Improved Incident Reporting
  • Better Secure-Working Practices
  • Stronger Security Decision-Making
  • Better Vulnerability Management
  • Improved Threat Detection
  • Stronger Incident Response Capability
  • Better Security Governance Awareness
  • Improved Secure Development Practices
  • Stronger Cyber Risk Understanding

The focus shifts from: "Have employees completed security training?" to: "Can employees and security professionals apply the right security practices when it matters?"

DEMONSTRATE — Demonstrate Security Capability Through Behaviour and Practice

Security capability becomes visible through how individuals behave, make decisions, identify threats and respond to security situations.

Employees may demonstrate capability by:

Security professionals may demonstrate capability through:

  • Recognising Phishing Attempts
  • Protecting Sensitive Information
  • Applying Secure Password Practices
  • Reporting Suspicious Activity
  • Using Systems Responsibly
  • Following Organisational Security Policies
  • Protecting Confidential Information
  • Security Assessments
  • Hands-On Labs
  • Threat Analysis
  • Vulnerability Analysis
  • Secure Configuration
  • Incident Investigation
  • Security Monitoring
  • Penetration Testing Exercises
  • Security Architecture Exercises
  • Secure Coding Activities
  • Cyber Incident Simulations

Learn. Execute. Achieve. Demonstrate.

From Security Awareness to Security Capability.

Vebsters helps organisations move beyond one-time cyber awareness towards role-based, practical and continuously reinforced security capability development.

Build Security Capability Across Employees, Business Functions, IT Teams and Cyber Security Professionals

Vebsters can design Information Security & Cyber Security Training interventions for:

Programs can be delivered individually or combined into structured security capability journeys depending on the organisation's environment, policies and security requirements.

Designed for

  • All Employees
  • Freshers
  • Managers
  • Business Functions
  • IT Professionals
  • Developers
  • Administrators
  • Security Analysts
  • Security Engineers
  • Security Managers
  • Leaders
  • Senior Management

CYBER SECURITY AWARENESS

  • Cyber Security Awareness
  • Information Security Awareness
  • Cyber Security Fundamentals for Employees
  • Security Awareness for Corporate Professionals
  • Understanding Cyber Threats
  • Cyber Hygiene
  • Everyday Cyber Security
  • Safe Digital Behaviour
  • Protecting Organisational Information
  • Security Responsibilities of Employees
  • Cyber Security Awareness for Remote Employees
  • Cyber Security Awareness for Hybrid Workforces
  • Cyber Security for New Joiners
  • Annual Security Awareness Programs
  • Role-Based Cyber Security Awareness

INFORMATION SECURITY FUNDAMENTALS

  • Information Security Fundamentals
  • Confidentiality, Integrity and Availability
  • Information Security Principles
  • Understanding Information Assets
  • Information Classification
  • Information Handling
  • Information Security Responsibilities
  • Information Security Risk Awareness
  • Security Controls Awareness
  • Information Security Governance Fundamentals
  • Information Security for Business Professionals

PHISHING AWARENESS

  • Phishing Awareness
  • Recognising Phishing Emails
  • Spear Phishing Awareness
  • Email Security Awareness
  • Identifying Suspicious Messages
  • Business Email Compromise Awareness
  • Safe Link and Attachment Practices
  • Reporting Phishing Attempts
  • Phishing Simulation Awareness
  • Phishing Prevention for Employees

SOCIAL ENGINEERING AWARENESS

  • Social Engineering Awareness
  • Understanding Social Engineering
  • Human-Based Cyber Attacks
  • Impersonation Attacks
  • Pretexting Awareness
  • Baiting Awareness
  • Tailgating Awareness
  • Voice Phishing Awareness
  • SMS Phishing Awareness
  • Social Media Engineering Risks
  • Recognising Manipulation Techniques
  • Protecting Against Social Engineering

PASSWORD & CREDENTIAL SECURITY

  • Password Security
  • Strong Password Practices
  • Credential Protection
  • Multi-Factor Authentication Awareness
  • Password Manager Awareness
  • Avoiding Credential Reuse
  • Protecting Authentication Information
  • Account Security
  • Secure Login Practices
  • Credential Theft Awareness

DATA PROTECTION & INFORMATION HANDLING

  • Data Protection Awareness
  • Protecting Sensitive Information
  • Data Classification
  • Secure Data Handling
  • Data Sharing Practices
  • Data Storage Awareness
  • Confidential Information Management
  • Protecting Customer Information
  • Personal Data Awareness
  • Secure File Sharing
  • Secure Document Handling
  • Data Loss Prevention Awareness

PRIVACY AWARENESS

  • Data Privacy Awareness
  • Privacy Fundamentals for Employees
  • Handling Personal Information
  • Privacy Responsibilities
  • Data Minimisation Awareness
  • Secure Handling of Personal Data
  • Privacy in the Workplace
  • Privacy Risk Awareness
  • Privacy and Cyber Security
  • Responsible Information Use

Where organisations require training linked to particular privacy laws, regulations or internal compliance frameworks, the content should be aligned with the organisation's approved legal, compliance and policy requirements.

EMAIL SECURITY

  • Email Security Awareness
  • Safe Email Practices
  • Suspicious Email Identification
  • Attachment Security
  • Link Security
  • Email Impersonation
  • Business Email Compromise
  • Secure Email Communication
  • Protecting Confidential Information in Email
  • Email Security for Corporate Employees

INTERNET & BROWSING SECURITY

  • Safe Internet Usage
  • Secure Web Browsing
  • Website Risk Awareness
  • Malicious Website Awareness
  • Download Safety
  • Browser Security Awareness
  • Online Fraud Awareness
  • Safe Search Practices
  • Secure Internet Behaviour

REMOTE WORK SECURITY

  • Cyber Security for Remote Workers
  • Secure Work-from-Home Practices
  • Remote Access Security
  • Home Network Security Awareness
  • Secure Wi-Fi Practices
  • Protecting Devices Outside the Office
  • Secure Collaboration
  • Remote Data Handling
  • Remote Meeting Security
  • Hybrid Work Security

MOBILE DEVICE SECURITY

  • Mobile Security Awareness
  • Smartphone Security
  • Secure Mobile Working
  • Mobile Application Awareness
  • Device Locking and Authentication
  • Mobile Data Protection
  • Public Wi-Fi Awareness
  • Lost Device Response
  • Mobile Phishing Awareness
  • Bring Your Own Device Awareness

PHYSICAL SECURITY AWARENESS

  • Physical Security Awareness
  • Workplace Security Practices
  • Tailgating Prevention
  • Visitor Security Awareness
  • Clean Desk Awareness
  • Protecting Printed Information
  • Secure Disposal Awareness
  • Device Protection
  • Workplace Access Awareness
  • Protecting Confidential Conversations

INSIDER THREAT AWARENESS

  • Insider Threat Awareness
  • Understanding Insider Risk
  • Accidental Insider Threats
  • Malicious Insider Threat Awareness
  • Information Misuse
  • Privileged Access Awareness
  • Recognising Suspicious Behaviour
  • Reporting Insider Security Concerns
  • Building Security Responsibility

CYBER FRAUD AWARENESS

  • Cyber Fraud Awareness
  • Digital Fraud
  • Online Scam Awareness
  • Payment Fraud Awareness
  • Invoice Fraud
  • Business Email Compromise
  • Identity Fraud Awareness
  • Social Engineering Fraud
  • Financial Scam Awareness
  • Fraud Prevention for Employees

AI SECURITY AWARENESS

  • Secure Use of Generative AI
  • AI Security Awareness
  • Protecting Confidential Information When Using AI
  • Data Privacy and AI
  • AI Tool Risk Awareness
  • Responsible AI Tool Usage
  • Unapproved AI Tool Awareness
  • AI Prompt Security
  • AI-Generated Content Verification
  • AI and Information Security
  • Security Risks of Public AI Tools
  • Shadow AI Awareness

Role-specific AI capability development can also be addressed separately through the Vebsters Role-Based AI Training portfolio.

CYBER SECURITY FOR MANAGERS

  • Cyber Security for Managers
  • Information Security Responsibilities for Managers
  • Cyber Risk Awareness for Managers
  • Managing Security Behaviour in Teams
  • Security Incident Escalation
  • Protecting Team Information
  • Security Responsibilities in Hybrid Teams
  • Cyber Risk Decision-Making
  • Managing Third-Party Security Awareness
  • Manager Role in Building Security Culture

CYBER SECURITY FOR SENIOR LEADERS

  • Cyber Security Awareness for Senior Leaders
  • Cyber Risk for Business Leaders
  • Cyber Security for CXOs
  • Understanding Enterprise Cyber Risk
  • Cyber Security Governance Awareness
  • Leadership Responsibilities in Cyber Security
  • Cyber Incident Leadership
  • Cyber Risk Decision-Making
  • Security Investment Awareness
  • Cyber Resilience for Leaders
  • Board-Level Cyber Security Awareness

CYBER SECURITY FOR HR TEAMS

  • Cyber Security for HR Professionals
  • Protecting Employee Data
  • Secure Recruitment Practices
  • HR Data Security
  • Employee Onboarding and Security
  • Employee Offboarding and Access Awareness
  • Social Engineering Risks for HR
  • Protecting Candidate Information
  • Secure HR Communication
  • Insider Risk Awareness for HR

CYBER SECURITY FOR FINANCE TEAMS

  • Cyber Security for Finance Professionals
  • Payment Fraud Awareness
  • Invoice Fraud
  • Business Email Compromise
  • Financial Data Security
  • Secure Payment Processes
  • Social Engineering for Finance Teams
  • Protecting Financial Information
  • Cyber Risk in Vendor Payments
  • Fraud Escalation Awareness

CYBER SECURITY FOR SALES & CUSTOMER-FACING TEAMS

  • Cyber Security for Sales Professionals
  • Protecting Customer Information
  • Secure Customer Communication
  • Social Engineering Risks for Sales Teams
  • Sharing Documents Securely
  • CRM Security Awareness
  • Customer Data Handling
  • Secure Travel Practices
  • Cyber Risk in Customer-Facing Roles

CYBER SECURITY FOR PROCUREMENT & SUPPLY CHAIN

  • Cyber Security for Procurement Professionals
  • Third-Party Cyber Risk Awareness
  • Supplier Security Awareness
  • Vendor Security Considerations
  • Secure Procurement Processes
  • Cyber Risk in Supply Chains
  • Protecting Commercial Information
  • Third-Party Access Risk Awareness
  • Vendor Data Handling
  • Cyber Security Questions for Suppliers

CYBER SECURITY FOR DEVELOPERS

  • Secure Coding Fundamentals
  • Security for Software Developers
  • Secure Software Development
  • OWASP Awareness
  • Application Security Fundamentals
  • Input Validation
  • Authentication and Authorisation Fundamentals
  • Session Security
  • Secure Error Handling
  • Secure API Development
  • Secure Code Review
  • Common Software Vulnerabilities
  • Secrets Management Awareness
  • Dependency Security
  • Security in the Software Development Lifecycle

SECURE SOFTWARE DEVELOPMENT LIFECYCLE

  • Secure SDLC Fundamentals
  • Security Requirements
  • Threat Modelling Fundamentals
  • Secure Design
  • Secure Coding
  • Security Testing
  • Code Review
  • Vulnerability Management
  • Dependency Management
  • Application Security Testing
  • DevSecOps Fundamentals
  • Security Throughout the Development Lifecycle

APPLICATION SECURITY

  • Application Security Fundamentals
  • Web Application Security
  • Secure Web Development
  • Common Application Vulnerabilities
  • OWASP Top Risks Awareness
  • Authentication Security
  • Authorisation Security
  • Session Management Security
  • API Security
  • Secure Application Configuration
  • Application Vulnerability Management
  • Application Security Testing Fundamentals

API SECURITY

  • API Security Fundamentals
  • Secure API Design
  • API Authentication
  • API Authorisation
  • API Access Control
  • API Input Validation
  • API Security Testing
  • API Vulnerability Awareness
  • Protecting API Keys and Secrets
  • Secure API Development Practices

WEB SECURITY

  • Web Security Fundamentals
  • Web Application Threats
  • Secure Web Development
  • Cross-Site Scripting Awareness
  • Injection Vulnerabilities
  • Authentication Weaknesses
  • Access-Control Risks
  • Session Security
  • Web Security Testing Fundamentals
  • Secure Web Configuration

NETWORK SECURITY

  • Network Security Fundamentals
  • Network Threats
  • Network Security Controls
  • Firewalls
  • Network Segmentation
  • Secure Network Architecture
  • Intrusion Detection Awareness
  • Intrusion Prevention Awareness
  • Network Monitoring
  • VPN Security
  • Wireless Security
  • Network Access Control
  • Network Security Troubleshooting

CLOUD SECURITY

  • Cloud Security Fundamentals
  • Shared Responsibility Model
  • Cloud Identity and Access Management
  • Cloud Data Protection
  • Cloud Network Security
  • Cloud Configuration Security
  • Cloud Logging and Monitoring
  • Cloud Security Posture
  • Cloud Workload Security
  • Cloud Security Risk
  • Secure Cloud Architecture
  • Multi-Cloud Security Awareness

Platform-specific programs can be designed around organisational environments such as AWS, Microsoft Azure or Google Cloud where required.

IDENTITY & ACCESS MANAGEMENT

  • Identity and Access Management Fundamentals
  • Authentication Fundamentals
  • Authorisation Fundamentals
  • Role-Based Access Control
  • Privileged Access Awareness
  • Access Governance
  • Identity Lifecycle Management
  • Multi-Factor Authentication
  • Single Sign-On Fundamentals
  • Zero Trust Identity Concepts
  • Access Review Fundamentals
  • Privileged Access Management Awareness

ZERO TRUST SECURITY

  • Zero Trust Fundamentals
  • Zero Trust Principles
  • Identity-Centric Security
  • Least Privilege
  • Continuous Verification
  • Device Trust
  • Network Segmentation
  • Zero Trust Architecture Awareness
  • Implementing Zero Trust Principles
  • Zero Trust for IT Teams

ENDPOINT SECURITY

  • Endpoint Security Fundamentals
  • Device Security
  • Endpoint Protection
  • Malware Protection
  • Endpoint Monitoring
  • Patch Management Awareness
  • Device Hardening
  • Endpoint Detection and Response Awareness
  • Secure Endpoint Configuration
  • Mobile Endpoint Security

MALWARE & RANSOMWARE AWARENESS

  • Malware Awareness
  • Ransomware Awareness
  • Understanding Malware
  • Ransomware Attack Lifecycle Awareness
  • Preventing Malware Infection
  • Safe File Handling
  • Protecting Against Ransomware
  • Incident Reporting
  • Backup Awareness
  • Ransomware Response Awareness

VULNERABILITY MANAGEMENT

  • Vulnerability Management Fundamentals
  • Vulnerability Identification
  • Vulnerability Assessment
  • Vulnerability Prioritisation
  • Remediation Management
  • Patch Management
  • Risk-Based Vulnerability Management
  • Vulnerability Reporting
  • Vulnerability Lifecycle Management
  • Vulnerability Management for IT Teams

PENETRATION TESTING

  • Penetration Testing Fundamentals
  • Ethical Hacking Fundamentals
  • Penetration Testing Methodology
  • Reconnaissance Fundamentals
  • Web Application Testing
  • Network Penetration Testing
  • Vulnerability Validation
  • Security Testing
  • Reporting Security Findings
  • Remediation Verification

Hands-on programs should be conducted only in authorised lab or organisational environments with appropriate permissions and controls.

ETHICAL HACKING

  • Ethical Hacking Fundamentals
  • Cyber Attack Techniques Awareness
  • Reconnaissance
  • Vulnerability Discovery
  • Network Security Testing
  • Web Security Testing
  • Authentication Testing
  • Security Assessment
  • Ethical Hacking Labs
  • Reporting and Remediation

All practical exercises should be performed only within authorised environments.

SECURITY OPERATIONS CENTRE — SOC

  • SOC Fundamentals
  • Security Operations Fundamentals
  • Role of a SOC Analyst
  • Security Monitoring
  • Event Analysis
  • Alert Investigation
  • Log Analysis
  • Security Incident Triage
  • Threat Detection
  • Escalation Procedures
  • SOC Processes
  • SOC Analyst Development
  • Security Operations Improvement

SIEM

  • SIEM Fundamentals
  • Security Event Monitoring
  • Log Collection
  • Log Analysis
  • Correlation Fundamentals
  • Alert Investigation
  • SIEM Use Cases
  • Security Monitoring
  • Incident Detection
  • SIEM for SOC Analysts

Technology-specific programs can be developed according to the organisation's deployed SIEM environment.

THREAT DETECTION & ANALYSIS

  • Threat Detection Fundamentals
  • Security Event Analysis
  • Threat Identification
  • Indicators of Compromise
  • Suspicious Activity Analysis
  • Behavioural Detection Awareness
  • Threat Detection Use Cases
  • Detection Engineering Fundamentals
  • Threat Analysis for SOC Teams

THREAT INTELLIGENCE

  • Cyber Threat Intelligence Fundamentals
  • Threat Intelligence Lifecycle
  • Threat Actor Awareness
  • Indicators of Compromise
  • Threat Research
  • Threat Analysis
  • Intelligence Sources
  • Threat Intelligence for SOC Teams
  • Applying Threat Intelligence
  • Threat Intelligence Reporting

INCIDENT RESPONSE

  • Incident Response Fundamentals
  • Security Incident Management
  • Incident Identification
  • Incident Triage
  • Incident Containment
  • Incident Eradication
  • Recovery
  • Incident Communication
  • Incident Escalation
  • Post-Incident Review
  • Cyber Incident Simulations
  • Incident Response for Technical Teams

CYBER INCIDENT MANAGEMENT FOR LEADERS

  • Cyber Incident Leadership
  • Executive Cyber Incident Awareness
  • Cyber Crisis Decision-Making
  • Incident Escalation
  • Crisis Communication Awareness
  • Business Continuity During Cyber Incidents
  • Leadership Roles During Incidents
  • Cyber Incident Tabletop Exercises

DIGITAL FORENSICS FUNDAMENTALS

  • Digital Forensics Fundamentals
  • Evidence Handling Awareness
  • Forensic Investigation Process
  • Log Investigation
  • Endpoint Investigation Fundamentals
  • Network Forensics Awareness
  • Incident Evidence Collection
  • Digital Forensics for Incident Responders

SECURITY MONITORING & LOG ANALYSIS

  • Security Monitoring Fundamentals
  • Log Analysis
  • Windows Security Logs
  • Linux Security Logs
  • Network Logs
  • Application Logs
  • Identifying Suspicious Events
  • Security Monitoring Use Cases
  • Log Investigation
  • Security Analysis Techniques

CYBER THREAT HUNTING

  • Threat Hunting Fundamentals
  • Hypothesis-Based Hunting
  • Threat Hunting Data Sources
  • Indicators and Behaviours
  • Log-Based Threat Hunting
  • Endpoint Threat Hunting Fundamentals
  • Network Threat Hunting Fundamentals
  • Threat Hunting for SOC Teams

DEVSECOPS

  • DevSecOps Fundamentals
  • Security in DevOps
  • Shift-Left Security
  • Secure CI/CD
  • Code Security
  • Dependency Security
  • Secrets Management
  • Container Security
  • Infrastructure-as-Code Security
  • Security Automation
  • Security Testing in Pipelines
  • DevSecOps Culture

CONTAINER & KUBERNETES SECURITY

  • Container Security Fundamentals
  • Docker Security
  • Container Image Security
  • Container Configuration Security
  • Kubernetes Security Fundamentals
  • Kubernetes Access Control
  • Kubernetes Network Security
  • Kubernetes Workload Security
  • Secrets Management
  • Container Runtime Security
  • Kubernetes Security Monitoring

DATABASE SECURITY

  • Database Security Fundamentals
  • Database Access Control
  • Database Authentication
  • Database Privilege Management
  • Data Encryption Awareness
  • Database Activity Monitoring
  • Secure Database Configuration
  • Database Vulnerability Awareness
  • Protecting Sensitive Data
  • Database Security for Administrators

DATA SECURITY

  • Data Security Fundamentals
  • Data Classification
  • Data Access Control
  • Encryption Fundamentals
  • Data Loss Prevention
  • Secure Data Storage
  • Secure Data Transfer
  • Data Retention Awareness
  • Data Security for Cloud Environments
  • Protecting Sensitive Business Information

CRYPTOGRAPHY FUNDAMENTALS

  • Cryptography Fundamentals
  • Encryption Concepts
  • Symmetric and Asymmetric Encryption
  • Hashing
  • Digital Signatures
  • Public Key Infrastructure Fundamentals
  • Certificate Awareness
  • Key Management Fundamentals
  • Cryptography for Developers

SECURITY ARCHITECTURE

  • Security Architecture Fundamentals
  • Designing Secure Systems
  • Security Architecture Principles
  • Defence in Depth
  • Identity-Centric Architecture
  • Network Security Architecture
  • Cloud Security Architecture
  • Application Security Architecture
  • Security Design Reviews
  • Enterprise Security Architecture Awareness

CYBER RISK MANAGEMENT

  • Cyber Risk Fundamentals
  • Information Security Risk Management
  • Cyber Risk Identification
  • Risk Assessment
  • Risk Analysis
  • Risk Treatment
  • Security Control Selection
  • Risk Monitoring
  • Cyber Risk Reporting
  • Third-Party Cyber Risk
  • Cyber Risk for Managers
  • Enterprise Cyber Risk Awareness

THIRD-PARTY CYBER RISK

  • Third-Party Cyber Risk Fundamentals
  • Vendor Security Risk
  • Supplier Security Assessment Awareness
  • Third-Party Access Risk
  • Security Requirements for Vendors
  • Third-Party Data Risk
  • Vendor Security Monitoring Awareness
  • Supply Chain Cyber Security
  • Third-Party Incident Awareness

INFORMATION SECURITY GOVERNANCE

  • Information Security Governance Fundamentals
  • Security Roles and Responsibilities
  • Security Policies
  • Security Standards
  • Security Procedures
  • Security Governance Structures
  • Security Metrics Awareness
  • Security Reporting
  • Security Accountability
  • Security Governance for Managers
  • Governance for Security Leaders

INFORMATION SECURITY MANAGEMENT SYSTEM — ISMS AWARENESS

  • ISMS Fundamentals
  • Information Security Management Awareness
  • Security Policy Frameworks
  • Risk-Based Security Management
  • Security Control Awareness
  • Information Security Roles
  • Continual Improvement Awareness
  • ISMS Awareness for Employees
  • ISMS Awareness for Managers

Where formal ISO or other certification-specific training is required, the program scope should clearly distinguish awareness or capability training from accredited certification, auditor or qualification programs.

ISO 27001 AWARENESS

  • ISO 27001 Awareness
  • Information Security Management Awareness
  • Understanding ISO 27001 Concepts
  • Roles and Responsibilities
  • Risk-Based Information Security
  • Security Control Awareness
  • Employee Responsibilities within an ISMS
  • ISO 27001 Awareness for Managers

Certification, Lead Auditor and Lead Implementer programs should only be represented as such when delivered through the appropriate authorised or recognised certification route.

SECURITY POLICY AWARENESS

  • Information Security Policy Awareness
  • Acceptable Use Policy
  • Password Policy Awareness
  • Data Handling Policy
  • Remote Working Policy
  • Mobile Device Policy
  • Access Control Policy
  • Incident Reporting Policy
  • AI Usage Policy Awareness
  • Employee Security Responsibilities

SECURITY CULTURE

  • Building a Security Culture
  • Security Mindset
  • Human Risk Awareness
  • Security Champions
  • Security Ambassadors
  • Cyber Security Behaviour
  • Building Employee Security Responsibility
  • Security Communication
  • Security Awareness Campaigns
  • Reinforcing Secure Behaviour

CYBER SECURITY FOR FRESHERS

  • Cyber Security Fundamentals
  • Networking Fundamentals for Security
  • Operating System Security Fundamentals
  • Linux Fundamentals for Cyber Security
  • Information Security Fundamentals
  • Security Threats
  • Vulnerability Fundamentals
  • Web Security Fundamentals
  • Network Security Fundamentals
  • Security Monitoring Fundamentals
  • Incident Response Fundamentals
  • Security Labs
  • Cyber Security Career Foundations

SOC ANALYST DEVELOPMENT

  • SOC Analyst Fundamentals
  • Security Monitoring
  • Log Analysis
  • SIEM Fundamentals
  • Alert Investigation
  • Incident Triage
  • Threat Detection
  • Threat Intelligence Fundamentals
  • Incident Response
  • Security Reporting
  • Practical SOC Scenarios

SECURITY ENGINEER DEVELOPMENT

  • Network Security
  • Endpoint Security
  • Identity and Access
  • Security Monitoring
  • Cloud Security
  • Vulnerability Management
  • Security Automation
  • Secure Configuration
  • Security Architecture Fundamentals
  • Incident Response
  • Security Operations

APPLICATION SECURITY PROFESSIONAL DEVELOPMENT

  • Application Security Fundamentals
  • OWASP Awareness
  • Secure Coding
  • Threat Modelling
  • Application Security Testing
  • API Security
  • Secure SDLC
  • Code Review
  • Vulnerability Management
  • DevSecOps
  • Security Architecture

CLOUD SECURITY PROFESSIONAL DEVELOPMENT

  • Cloud Security Fundamentals
  • Cloud Identity
  • Cloud Network Security
  • Cloud Data Protection
  • Cloud Workload Security
  • Cloud Configuration
  • Cloud Security Monitoring
  • Cloud Vulnerability Management
  • Cloud Incident Response
  • Cloud Security Architecture
  • Cloud Governance

SECURITY MANAGER DEVELOPMENT

  • Security Management Fundamentals
  • Cyber Risk Management
  • Security Governance
  • Security Program Management
  • Security Metrics
  • Security Reporting
  • Incident Management
  • Security Culture
  • Third-Party Risk
  • Security Leadership
  • Communicating Cyber Risk to Business Leaders

ROLE-BASED SECURITY TRAINING

Information Security & Cyber Security Training can also be structured specifically around roles. Examples include:

  • Cyber Security Awareness for All Employees
  • Cyber Security for First-Time Managers
  • Information Security for HR Professionals
  • Cyber Security for Finance Teams
  • Security Awareness for Sales Professionals
  • Data Protection for Customer Service Teams
  • Cyber Security for Procurement Managers
  • Third-Party Cyber Risk for Vendor Management Teams
  • Secure Coding for Software Developers
  • Application Security for Development Teams
  • DevSecOps for DevOps Engineers
  • Cloud Security for Cloud Engineers
  • Security Monitoring for SOC Analysts
  • Incident Response for Security Teams
  • Cyber Risk for Business Leaders
  • Cyber Security Governance for Senior Leaders
  • Information Security for CXOs

SECURITY CAPABILITY JOURNEYS

Programs can also be structured as progressive learning journeys.

  • Employee Security Journey
  • Cyber Security Awareness
  • Phishing & Social Engineering
  • Data Protection
  • Secure Digital Behaviour
  • Incident Reporting
  • Role-Based Security Practice
  • Developer Security Journey
  • Security Fundamentals
  • Secure Coding
  • OWASP Awareness
  • API Security
  • Threat Modelling
  • Secure SDLC
  • DevSecOps
  • SOC Analyst Journey
  • Security Fundamentals
  • Networking & Operating Systems
  • Log Analysis
  • SIEM
  • Threat Detection
  • Incident Triage
  • Threat Intelligence
  • Incident Response
  • Security Manager Journey
  • Security Operations
  • Cyber Risk
  • Governance
  • Incident Management
  • Third-Party Risk
  • Security Culture
  • Executive Security Communication
  • Cloud Security Journey
  • Cloud Fundamentals
  • Identity
  • Network Security
  • Data Protection
  • Workload Security
  • Monitoring
  • Vulnerability Management
  • Cloud Security Architecture

Information Security & Cyber Security Training Built Around the Role — Not Just the Threat.

An employee, HR Manager, Finance Professional, Software Developer, SOC Analyst and CXO all contribute to organisational security.

But they do not need the same security training.

Their access, responsibilities, information exposure, decisions, technical environments and security risks are different.

Vebsters can therefore structure Information Security & Cyber Security Training around the:

Role + Security Responsibility + Risk Exposure + Technology Environment + Capability Requirement + Desired Outcome

Learn. Execute. Achieve. Demonstrate.

Build Security Capability. Strengthen Cyber Resilience.

Tell Us How Vebsters Can Help

Send us an email

info@vebsters.com

Location

Registered OfficeNo. 18/21, Bhramashastry Compound, Opp Maremma Temple Line, Kappagal Road, Gandhi Nagar, Ballari, Karnataka, 583103

Branch Office114/3, Al – Azeem Centre, 7th Block, Above Burger King, Near to Forum Mall, Koramangala, Bangalore – 560095

Step 1 — What would you like to discuss?