Cybersecurity
Network, web and personal security: attacks and defences
Learn cybersecurity from the defender's side: how to assess risk, protect your accounts and devices, understand how hashing and encryption work, and secure networks and web applications. You will then practise incident response, threat modelling, zero-trust architecture and the ethical and legal rules of the field. All practice happens only on systems you own or are authorised to test.
Course content
Security foundations
BeginnerThe CIA triad, threats, vulnerabilities and risk, types of attackers, and protecting your own accounts and devices.
- 1The CIA triad, threats and riskLearn the three goals of security, the difference between a threat, a vulnerability and a risk, the types of attackers and the stages of the cyber kill chain.16 min
- 2Personal security: passwords, MFA and phishingMeasure password strength in bits, understand how password managers and multi-factor authentication work, recognise social engineering in realistic examples and keep your devices in good shape.18 min
Cryptography and network security
IntermediateHashing and salting, symmetric and asymmetric encryption, TLS, digital signatures and defending a network.
- 3Hashing and salting: how passwords are storedLearn the properties of cryptographic hash functions, why MD5 and SHA-1 are retired, and how salt and slow hashing protect passwords — with Python examples.17 min
- 4Encryption, TLS and certificatesLearn symmetric and asymmetric encryption, the Diffie–Hellman key exchange, the TLS handshake behind HTTPS, digital signatures and certificates.18 min
- 5Network security: ports, firewalls, VPNs and Wi-FiUnderstand the attack surface through ports, write firewall rules, choose VPN and Wi-Fi protection, and learn the defences against MITM, DNS spoofing and DDoS attacks.18 min
Application security
AdvancedThe OWASP Top 10, SQL injection, XSS, CSRF and the habits of secure coding.
- 6Web security: the OWASP Top 10Learn the most critical risks of web applications: SQL injection and parameterised queries, XSS and escaping, CSRF, authentication failures and security headers.20 min
- 7Secure codingFour core habits: validating input with an allow-list, the principle of least privilege, keeping secrets out of code and tracking vulnerabilities in dependencies.18 min
Security operations and careers
AdvancedIncident response, the basics of digital forensics, and careers and certifications in cybersecurity.
- 8Incident response and digital forensicsLearn the phases of incident response, how to look for traces of an attack in logs, how to protect evidence with hashes, the order of volatility and the chain of custody.18 min
- 9Careers and certifications in cybersecurityLearn about blue and red team roles, jobs from SOC analyst to penetration tester, the CompTIA Security+, CEH, OSCP and CISSP certifications, and a plan for entering the field legally.14 min
Security engineering, ethics and law
UniversityThreat modelling with STRIDE, zero-trust architecture, responsible disclosure and data-protection law.
- 10Threat modelling with STRIDEModel a system with a data-flow diagram, find threats systematically with STRIDE, put a price on risks with SLE, ARO and ALE, and calculate whether a control pays off.25 min
- 11Security architecture and zero trustEvaluate defence in depth with probabilities, build the NIST SP 800-207 zero-trust model and its policy decision point, and calculate the availability of components in series and in parallel.25 min
- 12Ethics and law in cybersecurityLearn what authorisation means legally, responsible (coordinated) disclosure, the Budapest Convention, Azerbaijan's Law on Personal Data and the core principles of the GDPR, its fine cap and the 72-hour notification rule.24 min