
Eight weeks, face to face
Cyber Security Career Pathway
From basic computer literacy to Security+ certified and able to work a SOC alert queue. 208 contact hours, taught face to face in a small group.
An intensive pathway that takes someone with basic computer knowledge to the point where they are CompTIA Security+ certified, cloud literate, and able to work a SOC alert queue. It is built the way the industry actually layers: you cannot secure a network you do not understand, and you cannot investigate an alert if you do not know what normal looks like. So hardware and operating systems come first, then networking, then servers and identity, then security, then cloud, then offensive technique, and finally SOC operations on top of all of it.
~50%
Time in the lab
Building, breaking and fixing rather than listening.
9
Modules
Grouped into three blocks, available separately.
This is for you if
- You have basic computer literacy and want a route into security that ends in a job rather than a certificate.
- You are changing career and need structure, not a playlist.
- You are in IT support or a service desk and want to move across deliberately.
- You can commit to six days a week for eight weeks, plus six to eight hours of independent practice.
It is not, if
- You want a part-time course alongside a full-time job. This is intensive by design.
- You are looking for a certification pass and nothing else. Certification is one outcome here, not the outcome.
- You already work in a security team. The AI Security and Governance course is the better fit.
What you will be able to do
- Build, configure and troubleshoot a PC, a virtual machine and a small network from scratch.
- Design and defend a small Active Directory domain, and harden both Windows and Linux hosts.
- Sit and pass CompTIA Security+, the certification most UK employers screen entry-level candidates on.
- Explain cloud architecture and identify common misconfigurations in Azure and AWS.
- Run reconnaissance, scanning and basic exploitation inside a closed lab, and understand how an attacker thinks.
- Work a SOC alert queue: triage, investigate, escalate and document an incident end to end.
- Write detection queries in a SIEM and map observed activity to MITRE ATT&CK.
- Present a portfolio of lab work, a security-focused CV, and interview readiness for junior SOC roles.
Curriculum
Session days are either four or six hours, so day counts are approximate while the hours are exact. 48 days, 208 contact hours in total.
Orientation, baseline assessment and lab build
1 days · 4 hours · Personal lab running
Baseline diagnostic for each delegate, learning agreement, safety and ethics briefing, and building the personal virtual lab used for the rest of the programme.
Foundations: PC hardware, operating systems and endpoints
6 days · 26 hours · A+ level knowledge
Components and how they fail, POST and BIOS/UEFI, storage and RAID, Windows installation and internals, file systems, users and NTFS permissions, command line and PowerShell basics, systematic troubleshooting method.
Networking essentials
6 days · 26 hours · Network literacy
OSI and TCP/IP, cabling, switching, routing, IPv4 and IPv6 addressing, subnetting worked to fluency, VLANs, DHCP and DNS, NAT, wireless security, firewalls, and packet analysis with Wireshark. Scoped to what security work actually requires.
Servers, Active Directory and Linux
6 days · 24 hours · Domain lab built
Windows Server roles, Active Directory design, users, groups, OUs and Group Policy, file services and backup. Linux essentials: shell, permissions, package management, services, systemd, logging, SSH and basic hardening.
Security fundamentals (Security+ SY0-701)
11 days · 48 hours · CompTIA Security+
Full coverage of the current exam objectives, delivered with continuous lab work, weekly knowledge checks and two full mock exams before the certification attempt.
Cloud fundamentals and cloud security
5 days · 22 hours · SC-900 optional
Service and deployment models, shared responsibility, core Azure and AWS services, cloud identity, network security groups, storage security, key management, cloud logging, and a guided hunt for common misconfigurations.
Ethical hacking essentials
5 days · 22 hours · Offensive lab skills
The attacker lifecycle, reconnaissance, scanning and enumeration with Nmap, vulnerability identification, basic exploitation and post-exploitation, password attacks, web application basics, and reporting. Taught strictly inside the closed lab.
SOC operations and SIEM
6 days · 28 hours · SOC analyst skillset
SOC structure and tiers, the alert lifecycle, log sources and log quality, SIEM architecture, hands-on with Sentinel and Splunk plus Wazuh and Security Onion, detection rules, KQL and SPL, threat intelligence, MITRE ATT&CK, phishing and header analysis, malware triage, EDR, and the incident response lifecycle.
Capstone, portfolio and employability
2 days · 8 hours · Portfolio, CV, interviews
A simulated multi-stage attack against the lab which each delegate must detect, investigate, contain and report on. Then portfolio assembly, a security-focused CV and LinkedIn rewrite, technical interview practice, and a personal 90-day plan.
Taken in blocks, or in full
The programme runs end to end, and each block can also be taken on its own if you would rather commit one at a time.
Block A: Foundations
Modules 0 to 3 · 19 days · 80 hours
Hardware, operating systems, networking, servers and identity. Available separately.
Block B: Security and Cloud
Modules 4 to 5 · 16 days · 70 hours
Security+ in full, then cloud fundamentals and cloud security. Available separately.
Block C: Offensive and SOC
Modules 6 to 8 · 13 days · 58 hours
Attacker technique, SOC operations, and the capstone. Available separately.
Week by week
Six days a week, 26 contact hours: five days of four hours and one longer day of six, which is reserved for extended lab work because that needs uninterrupted blocks.
| Week | Focus | Modules |
|---|---|---|
| 1 | Orientation, baseline diagnostic, lab build. PC hardware: components, POST, BIOS/UEFI, storage. Windows installation and internals. | M0 / M1 |
| 2 | File systems, NTFS permissions, command line and PowerShell, systematic troubleshooting. Networking begins: OSI and TCP/IP, cabling, switching. | M1 / M2 |
| 3 | IP addressing and subnetting to fluency, VLANs, routing, DHCP, DNS, NAT, wireless, firewalls. Packet analysis with Wireshark. | M2 / M3 |
| 4 | Windows Server, Active Directory, Group Policy. Linux essentials: shell, permissions, services, logging, SSH, hardening. | M3 / M4 |
| 5 | Security+ part 1: threats, attacks, malware, social engineering, threat actors, MITRE ATT&CK. Cryptography, PKI, certificates, secure protocols, VPN. | M4 |
| 6 | Security+ part 2: identity and access management, zero trust, secure architecture, endpoint and application security, risk, governance, BCP and DR. Two mock exams. | M4 / M5 |
| 7 | Cloud fundamentals and security: shared responsibility, Azure and AWS, cloud IAM, network security groups, logging, misconfiguration hunting. Ethical hacking begins. | M5 / M6 |
| 8 | Exploitation and post-exploitation in the closed lab. SOC operations: SIEM, KQL, alert triage, threat intelligence, phishing analysis, incident response. Capstone, portfolio, CV and interviews. | M6 / M7 / M8 |
Labs, tooling and equipment
The programme is lab-led. Roughly half of all contact time is spent building, breaking and fixing things rather than listening, and the weekly six-hour session is entirely practical because extended lab work needs uninterrupted blocks.
- Virtualisation: VMware Workstation or Oracle VirtualBox, running on your own machine.
- Lab environment: Windows 11, Windows Server, Ubuntu and Kali virtual machines, plus a simulated corporate domain.
- Security tooling: Wireshark, Nmap, Metasploit, Burp Suite Community, Microsoft Sentinel, Splunk Free, Wazuh, Security Onion, and cloud free tiers.
- Practice platforms: guided hands-on ranges for reinforcement between sessions.
Equipment: Each delegate needs a laptop with at least 16 GB RAM (32 GB strongly preferred), a modern multi-core processor with virtualisation enabled, and 250 GB of free storage. Advice on a suitable specification is provided free of charge before the start date, and a machine can be sourced on request at cost.
What almost nobody else does
You build the lab, and you keep it
Almost every other programme hands you a pre-built cloud lab and takes it away on the last day. You finish the course with a certificate and no environment to practise in, which is why so much of what people learn evaporates within a month. Here, building the lab is itself taught: it is Module 0, and you rebuild and extend it throughout.
- The environment runs on your own machine, so it does not expire when the programme does.
- You learn the build, not just the use: virtualisation, networking between virtual machines, snapshots and rollback, and safe isolation of anything hostile.
- You can rebuild it from nothing, which means you can rebuild it differently for whatever you study next.
- You can break it deliberately. A lab you cannot destroy is a lab you cannot really learn in.
- It becomes portfolio material: a documented environment you designed is something to talk about in an interview.
How it can be delivered
All three programmes are instructor-led and live. That is the distinction that matters: almost everything sold as online security training is recorded video you watch alone. This is a person teaching, answering the question when you ask it rather than in a forum three days later.
Face to face
Cambridge, or at your site
In the room. Best where a team is learning together, where the discussion matters as much as the material, or where somebody benefits from being able to turn a screen round and point at it.
Live online
Anywhere
The same sessions, same schedule, same labs, delivered over video with screen sharing both ways. Every lab already runs on your own laptop, so the practical work is identical rather than reduced.
Hybrid
Mixed
Common for corporate delivery where part of a team is on site and part is not, and for individuals who want the intensive blocks in person and the rest remote.
What actually differs
The material, the labs and the schedule do not change between modes. Two things genuinely do. Reading a room is easier in person, so remote delivery relies more on asking directly whether something has landed, which I do more often as a result. And the informal conversation either side of a session, the question somebody asks while the laptops are booting, happens less online. Neither is a reason to avoid remote delivery, and both are worth knowing before choosing.
Certification
Exam vouchers are not included in the training fee. That keeps the headline honest and means you are never paying a mark-up on an exam. The Security+ attempt is booked outside contact hours, after week 6.
CompTIA Security+ (SY0-701)
The core certification, and the one most UK employers screen entry-level candidates on.
Microsoft SC-900
Security, compliance and identity fundamentals. Recommended, and low cost.
Microsoft AZ-900
Azure fundamentals. Optional.
Next step
Start with a conversation.
Every delivery is scoped to who is in the room. Before anything is quoted we talk through where you are starting from, what you need to be able to do afterwards, and whether this programme is honestly the right one. If it is not, I will say so.
Last reviewed: