Module 1 — Cyber Defense Foundations and Defensive Architecture
- Cyber-defense principles and threat landscape
- Attack surfaces and adversary behavior
- Defense-in-depth and Zero Trust
- Defensive architecture and resilience
Detect Earlier. Respond Effectively. Recover Securely. Build Cyber Resilience.
Modern organizations face ransomware, credential attacks, cloud compromise, malicious insiders, supply-chain attacks, advanced persistent threats, AI-enabled attacks, data breaches, endpoint compromise, application attacks, and rapidly evolving vulnerabilities.
Detect Earlier. Respond Effectively. Recover Stronger.
Master the core areas of cyber defense.
Modern organizations face ransomware, credential attacks, cloud compromise, malicious insiders, supply-chain attacks, advanced persistent threats, AI-enabled attacks, data breaches, endpoint compromise, application attacks, and rapidly evolving vulnerabilities.
Organizations therefore need cyber-defense professionals who can do more than recognize cybersecurity terminology. They need professionals who can monitor environments, detect threats, analyze security evidence, investigate incidents, contain attacks, support recovery, and strengthen resilience.
The Certified Cyber Defense Professional (CCDP®) is a comprehensive, vendor-neutral professional certification designed to validate practical competency across the modern cyber-defense lifecycle.
Offered by the:
International Board of AI, Cybersecurity & Technology Professionals (IBACTP®)
The CCDP® Professional Mission
Detect Threats → Analyze Evidence → Contain Incidents → Investigate Effectively → Recover Securely → Strengthen Cyber Resilience
Professional level — Three-year certification cycle with continuing professional education
Build the practical cyber-defense competencies organizations need to identify threats earlier, investigate security activity accurately, contain incidents effectively, and strengthen cyber resilience.
The Certified Cyber Defense Professional (CCDP®) is a comprehensive, vendor-neutral professional certification from the International Board of AI, Cybersecurity & Technology Professionals (IBACTP®) designed for professionals responsible for protecting modern digital environments.
CCDP® Professional Objective
Identify Exposure → Detect Threats → Analyze Activity → Contain Incidents → Investigate Compromise → Recover Securely → Strengthen Resilience
Modern cyber defense is no longer a collection of isolated technical tasks.
A single security alert can involve endpoint activity, identity compromise, cloud services, network traffic, exploitable vulnerabilities, threat intelligence, digital evidence, incident response, business disruption, and recovery—all at the same time.
Organizations therefore need cyber-defense professionals who can understand how these signals connect, determine what matters most, and support effective defensive action across the complete incident lifecycle.
The Certified Cyber Defense Professional (CCDP®) is designed around this integrated operational reality.
CCDP® develops the ability to move from isolated security events to informed defensive decisions.
Professionals learn to answer practical questions such as:
CCDP® helps professionals connect the full cyber-defense chain:
This integrated perspective is critical because effective cyber defense depends on more than recognizing an attack.
Professionals must be able to understand:
Identify suspicious behavior, attack indicators, vulnerabilities, and affected assets.
Determine severity, scope, exploitability, business impact, and organizational exposure.
Prioritize investigation, escalation, containment, eradication, and recovery actions.
Apply lessons learned to strengthen monitoring, controls, response procedures, recovery capability, and resilience.
CCDP® brings together competencies that are often treated separately:
SOC Operations + Threat Detection + Threat Intelligence + Threat Hunting + Vulnerability Management + Exposure Management + Incident Response + Digital Forensics + Recovery + Cyber Resilience
This enables professionals to see cyber defense as a continuous operational capability, rather than a collection of disconnected security tools and processes.
CCDP® Value Proposition
The certification prepares professionals to move confidently through the defensive lifecycle:
Recognize the Threat → Interpret the Evidence → Prioritize the Response → Contain the Incident → Support Investigation → Recover Securely → Strengthen Resilience
CCDP® is designed for professionals working in or preparing for roles involving:
CCDP® can support career development for:
Cyber Defense Analyst • SOC Analyst • Cybersecurity Analyst • Security Operations Analyst • Incident Response Analyst • Cybersecurity Specialist • Threat Analyst • Threat Hunter • Vulnerability Analyst • Security Engineer • Digital Forensics Analyst • Cyber Incident Analyst • Cloud Security Analyst • Cyber Defense Specialist
The Certified Cyber Defense Professional (CCDP®) curriculum is designed to develop practical, analytical, and professional competency across the complete cyber-defense lifecycle.
Upon successful completion of CCDP® training, participants will be able to:
Evaluate cyber threats, attack surfaces, adversary behavior, defensive controls, defense-in-depth, Zero Trust principles, and resilient security architectures.
Participants develop the ability to connect threats and vulnerabilities with appropriate defensive safeguards across networks, endpoints, identities, applications, cloud environments, and enterprise infrastructure.
Analyze security information from networks, endpoints, identities, cloud services, applications, and security platforms to identify suspicious or malicious activity.
Participants develop competency involving:
Learning Progression:
Monitor → Identify → Validate → Analyze → Escalate
Use threat intelligence, indicators of compromise, adversary behaviors, attack techniques, and analytical hypotheses to support proactive cyber defense.
Participants learn to connect:
Threat Intelligence → Adversary Behavior → Security Telemetry → Hunting Hypothesis → Defensive Action
The objective is to move beyond purely reactive monitoring toward intelligence-driven defense.
Identify and evaluate vulnerabilities, misconfigurations, exposed assets, attack paths, and security weaknesses.
Participants learn to prioritize defensive action using factors such as:
Technical Severity + Exploitability + Threat Activity + Asset Criticality + Exposure + Business Impact
This risk-based approach helps distinguish vulnerabilities that are merely present from exposures requiring urgent defensive attention.
Recognize cybersecurity incidents, determine severity and scope, establish priorities, support containment and eradication, coordinate response activities, and document defensive decisions.
Participants develop competency across:
Detect → Validate → Triage → Investigate → Contain → Eradicate → Recover
Incident response is a defining component of the CCDP® competency model.
Apply forensic-readiness and evidence-handling principles during cybersecurity investigations.
Participants develop competency involving:
The objective is to help professionals determine:
What Happened → How It Happened → What Was Affected → What Evidence Supports the Conclusion
Apply recovery and resilience principles following cybersecurity incidents.
Participants learn to evaluate:
The learning progression is:
Contain → Recover → Validate → Learn → Strengthen
Assess cybersecurity implications associated with AI, Generative AI, defensive automation, cloud-native technologies, APIs, containers, IoT, Operational Technology, software supply chains, and evolving attack techniques.
Participants examine AI from two complementary perspectives:
The emphasis is on responsible application, appropriate validation, human oversight, security controls, and emerging-risk awareness.
Upon completion of the program, participants develop the integrated professional capability to:
The CCDP® learning objective is not simply to understand cyber defense.
It is to develop the competency to apply cyber-defense knowledge when organizations face real threats, incidents, disruptions, and recovery challenges.
The CCDP® certification assessment evaluates whether candidates can apply professional cyber-defense knowledge, interpret security information, exercise technical judgment, and make appropriate defensive decisions.
Assessment is organized across eight integrated competency domains.
Candidates demonstrate the ability to evaluate:
Testing Focus: Select and evaluate appropriate defensive approaches for realistic organizational environments.
Candidates demonstrate the ability to interpret:
Testing Focus: Determine whether observed activity is normal, suspicious, malicious, or requires escalation.
Candidates demonstrate the ability to evaluate:
Testing Focus: Use threat information and available evidence to support proactive detection and defensive decision-making.
Candidates demonstrate the ability to evaluate:
Testing Focus: Determine which exposures create the greatest risk and identify appropriate remediation priorities.
Candidates demonstrate the ability to determine:
Testing Focus: Select defensible incident-response actions based on available evidence, risk, and operational context.
Candidates demonstrate the ability to evaluate:
Testing Focus: Determine how digital evidence supports incident understanding, investigation, documentation, and corrective action.
Candidates demonstrate the ability to evaluate:
Testing Focus: Determine how affected operations can be restored securely while reducing the likelihood or impact of future incidents.
Candidates demonstrate the ability to evaluate cyber-defense considerations involving:
Testing Focus: Evaluate how emerging technologies affect threats, detection, response, defensive controls, and organizational resilience.
The CCDP®–IBACTP® Cyber Defense Competency Model defines the integrated knowledge, technical capabilities, analytical skills, and professional judgment required to operate effectively across the modern cyber-defense lifecycle.
Rather than treating monitoring, threat intelligence, vulnerability management, incident response, forensics, and recovery as separate disciplines, the CCDP® model connects them into eight integrated professional competency dimensions.
Together, these dimensions prepare professionals to move from security visibility and threat recognition to investigation, response, secure recovery, and continuous resilience improvement.
Build the foundation required to understand how organizations design and maintain resilient defensive environments.
Professionals develop competency in:
Professional Focus: Understand how threats interact with enterprise technologies and how layered defensive architectures reduce exposure and support resilience.
Develop the ability to maintain security visibility and recognize suspicious or malicious activity across enterprise environments.
Professionals develop competency in:
Professional Focus: Transform security telemetry into meaningful detection and actionable defensive information.
Develop a proactive understanding of adversaries, attack behaviors, indicators, and emerging threats.
Professionals develop competency in:
Professional Focus: Use threat intelligence and adversary behavior to move cyber defense from purely reactive monitoring toward proactive threat discovery.
Develop risk-based competency for identifying and reducing weaknesses that attackers may exploit.
Professionals develop competency in:
CCDP® emphasizes that vulnerability priority is not determined by technical severity alone.
Professionals learn to consider:
Professional Focus: Identify the exposures that matter most and support risk-based remediation.
Develop the professional judgment required to recognize, classify, investigate, contain, and respond to cybersecurity incidents.
Professionals develop competency in:
The incident progression is:
Professional Focus: Convert detection into coordinated defensive action while limiting organizational impact.
Develop foundational investigative competency required to preserve evidence, understand attack activity, and support defensible incident investigations.
Professionals develop competency in:
Professional Focus: Preserve and interpret digital evidence so organizations can understand what happened, how it happened, what was affected, and what corrective action is required.
Extend cyber defense beyond incident containment by ensuring that affected systems and critical services can be restored securely.
Professionals develop competency in:
The CCDP® resilience approach follows:
Professional Focus: Help the organization restore operations securely while using incident experience to reduce future disruption.
Develop awareness and professional judgment for defending rapidly changing technology environments and using emerging defensive capabilities responsibly.
Professionals develop competency in:
CCDP® addresses AI from both perspectives:
Professional Focus: Evaluate emerging threats and use AI-enabled defensive capabilities with appropriate validation, security controls, and human oversight.
Eligible candidates participating in an approved instructor-led pathway may demonstrate competency through the CCDP® Applied Cyber Defense Capstone.
The Capstone provides an applied alternative that integrates multiple CCDP® competency domains into a realistic cyber-defense scenario. Instead of evaluating competencies only through individual examination questions, candidates demonstrate their ability to analyze an evolving cybersecurity situation, investigate evidence, make defensive decisions, recommend response actions, and strengthen organizational resilience.
Candidates evaluate a simulated organizational environment containing security events, vulnerabilities, alerts, threat information, and potential indicators of malicious activity.
Activities may include:
Determine:
What is happening?
What evidence supports the conclusion?
What is potentially at risk?
What requires immediate investigation?
Candidates investigate the developing cyber incident and determine appropriate defensive actions.
Activities may include:
Determine:
Candidates develop recommendations for secure restoration and post-incident improvement.
Activities may include:
Move the organization from:
Successful Capstone candidates demonstrate their ability to integrate multiple cyber-defense competencies rather than treating each security function independently.
The Capstone evaluates the ability to:
This reflects the interconnected nature of real-world cyber-defense operations.
One Certification Standard. Two Assessment Pathways.
Whether competency is demonstrated through the CCDP® Certification Examination or an eligible Applied Cyber Defense Capstone, the professional objective remains consistent:
Can the Candidate Detect, Analyze, Investigate, Respond, Recover, and Improve?
CCDP® assessment focuses on the ability to transform:
Security Information → Professional Judgment → Defensive Action → Secure Recovery → Cyber Resilience
CCDP® Assessment Philosophy
CCDP® evaluates candidates across multiple levels of professional competency.
Recognize and explain cyber-defense concepts, technologies, threats, vulnerabilities, controls, procedures, and professional practices.
Apply appropriate cyber-defense principles and controls to realistic technical and organizational situations.
Interpret logs, alerts, telemetry, vulnerabilities, threat intelligence, digital evidence, and incident scenarios.
Compare defensive options, prioritize actions, evaluate consequences, and select appropriate responses.
Integrate multiple cyber-defense competencies when addressing realistic threats, incidents, investigations, and recovery situations.
CCDP® evaluates more than a candidate's ability to recall cybersecurity terminology.
Successful candidates demonstrate the ability to combine:
The CCDP® certification competency progression is:
Candidates develop the ability to:
A CCDP® professional should understand:
The Certified Cyber Defense Professional (CCDP®) is a professional-level, vendor-neutral certification designed to validate practical competency in threat detection, security analysis, incident investigation, response, recovery, and cyber resilience.
CCDP® prepares professionals to understand how the major components of modern cyber defense work together across Security Operations Centers, incident-response teams, threat-intelligence functions, vulnerability programs, digital investigations, and recovery environments.
The certification develops competency across:
CCDP® is not designed simply to test whether a candidate understands cybersecurity terminology.
It focuses on whether a professional can interpret security information, identify meaningful threats, evaluate evidence, prioritize defensive actions, support incident response, and contribute to secure recovery.
The defining question is not:
It is:
“Can you recognize the threat, understand the evidence, make the right defensive decision, respond effectively, and help the organization recover securely?”
CCDP® connects the core stages of cyber defense into one practical competency framework:
This prepares CCDP® professionals to contribute across the complete defensive lifecycle—from identifying suspicious activity to helping organizations become more resilient after an incident.
Detect Earlier. Analyze Accurately. Respond Effectively. Recover Securely.
CCDP® training can incorporate practical management and technical-analysis activities.
Analyze security alerts and determine investigation and escalation priorities.
Use indicators and adversary behavior to develop and test a threat-hunting hypothesis.
Compare vulnerabilities using exploitability, threat intelligence, asset criticality, and business impact.
Evaluate a simulated cyberattack and recommend containment, eradication, investigation, and recovery actions.
Evaluate recovery capability, identify resilience gaps, and recommend improvements.
The CCDP® Certification Examination provides a structured assessment of professional cyber-defense knowledge, application, analysis, and decision-making across the CCDP® Body of Knowledge.
The CCDP® Body of Knowledge is designed to reflect recognized cybersecurity, risk-management, incident-response, business-continuity, AI-risk, and professional workforce practices relevant to modern cyber defense.
Rather than requiring candidates to memorize individual standards, CCDP® emphasizes the ability to understand, interpret, and apply recognized principles within practical cyber-defense situations.
The certification incorporates relevant concepts and practices associated with:
Information security management principles, security governance, risk-based controls, and continual improvement.
Information security controls and implementation practices supporting organizational cyber defense.
Information security risk-management principles supporting threat, vulnerability, impact, and risk-based decision-making.
Privacy information management principles relevant to security operations, incident handling, data protection, and privacy-related risk.
Business continuity principles supporting incident preparedness, operational continuity, recovery, and organizational resilience.
Enterprise risk-management principles supporting structured risk identification, analysis, evaluation, treatment, monitoring, and communication.
AI management-system principles relevant to the responsible governance and organizational management of artificial intelligence.
AI risk-management principles relevant to identifying, evaluating, treating, and monitoring risks associated with artificial intelligence.
Risk-based cybersecurity practices supporting the integrated functions of:
Govern • Identify • Protect • Detect • Respond • Recover
Cybersecurity workforce concepts supporting the relationship between professional roles, tasks, knowledge, and skills.
Risk-management principles supporting trustworthy, responsible, secure, and risk-aware use of artificial intelligence.
Recognized practices involving security controls, monitoring, incident handling, digital investigation, vulnerability management, recovery, and cyber resilience.
Relevant defensive practices involving cyber hygiene, vulnerability reduction, threat awareness, incident preparedness, critical infrastructure security, and organizational resilience.
The value of framework alignment is found in how recognized practices work together.
ISO/IEC 27001 + ISO/IEC 27002
Support structured information-security management and security-control practices.
ISO/IEC 27005 + ISO 31000
Support risk-based analysis, prioritization, treatment, and decision-making.
ISO/IEC 27701
Connects information security with privacy-management considerations.
ISO 22301
Supports organizational preparedness, continuity, recovery, and resilience.
ISO/IEC 42001 + ISO/IEC 23894 + NIST AI RMF
Provide relevant perspectives for understanding AI governance, AI-related risk, and responsible adoption of AI-enabled capabilities.
NIST CSF + NIST NICE Workforce Framework + Relevant NIST and CISA Guidance
Connect cyber-risk management with practical cybersecurity activities, workforce competencies, incident response, and defensive operations.
CCDP® is not tied to one:
The certification focuses on the professional capabilities behind the technology.
References to ISO, ISO/IEC 17024, ANAB, NCCA, I.C.E., NIST, NICE, CISA, or other standards, frameworks, credentialing organizations, or professional bodies describe applicable areas of standards alignment, credentialing-quality consideration, workforce relevance, or professional-practice alignment.
Such references do not, by themselves, constitute or imply formal accreditation, endorsement, recognition, approval, authorization, partnership, or affiliation.
Formal accreditation or external recognition of IBACTP® or the CCDP® certification is represented only when it has been officially granted by the applicable authorized organization.
This distinction is particularly important because accreditation under ISO/IEC 17024 involves an independent accreditation process for personnel-certification bodies and schemes.
The Certified Cyber Defense Professional (CCDP®) assessment is designed to evaluate more than cybersecurity knowledge. It measures a candidate’s ability to interpret security information, recognize threats, analyze incidents, exercise technical judgment, support effective response, and strengthen cyber resilience.
CCDP® provides two assessment pathways to accommodate both independent certification candidates and eligible participants completing approved instructor-led programs.
Both pathways are designed around the same core CCDP® competency expectations.
The strength of the CCDP® model is the integration of all eight dimensions.
A professional may begin with:
Security Monitoring
which identifies:
Suspicious Activity
that requires:
Threat and Adversary Analysis
and reveals:
A Vulnerability or Enterprise Exposure
which develops into:
An Incident
requiring:
Investigation and Digital Evidence
followed by:
Secure Recovery
and ultimately:
Improved Cyber Resilience
Throughout this lifecycle, AI and emerging technologies can introduce new risks while also strengthening defensive capabilities.
CCDP® Integrated Competency Progression
The eight dimensions support a unified professional progression:
Prepare → Monitor → Detect → Analyze → Prioritize → Investigate → Respond → Recover → Strengthen
The objective is to develop professionals who can connect technical evidence with effective defensive action.
The CCDP® Professional Standard
A CCDP® professional is prepared to:
Recognize Threats → Interpret Security Evidence → Identify Exposure → Prioritize Action → Investigate Incidents → Support Containment → Recover Securely → Strengthen Cyber Resilience
This integrated competency model represents the central professional promise of CCDP®:
.
The CCDP® curriculum develops competency through an integrated defensive lifecycle:
Prepare → Monitor → Detect → Analyze → Contain → Investigate → Recover → Strengthen
Understand assets, threats, attack surfaces, vulnerabilities, defensive architectures, and incident-readiness requirements.
Maintain visibility across networks, endpoints, identities, cloud services, applications, and security technologies.
Identify anomalies, suspicious behavior, indicators of compromise, vulnerabilities, and potential attacks.
Interpret security evidence and determine severity, scope, potential impact, and appropriate action.
Limit attacker access, reduce damage, isolate affected resources, and support coordinated response.
Preserve evidence, establish timelines, identify attack activity, and support root-cause analysis.
Restore systems and services securely while validating the integrity of the environment.
Apply lessons learned, threat intelligence, vulnerability findings, and performance information to improve resilience.
CCDP® is vendor-neutral while addressing major defensive technology categories, including:
SIEM • SOAR • EDR/XDR • IDS/IPS • Firewalls • Threat Intelligence Platforms • Vulnerability Scanners • Attack-Surface Management • Network Monitoring • Cloud Security • Digital Forensics • Incident Management • Backup & Recovery • AI-Assisted Security
The objective is not certification on a particular product.
The objective is to understand how technologies support detection, investigation, response, recovery, and resilience.
Here is a more comprehensive and professionally positioned version for the CCDP® webpage, with careful language that distinguishes framework alignment from accreditation or endorsement.
CCDP® does not treat standards and frameworks as isolated memorization requirements.
Candidates develop the ability to connect recognized practices with real-world defensive responsibilities.
The CCDP® framework application progression is:
Recognize relevant cybersecurity, risk, continuity, incident-response, workforce, and AI-security principles.
Use appropriate controls, processes, and defensive practices within organizational environments.
Apply monitoring, intelligence, vulnerability, and detection principles to recognize threats and security events.
Use structured incident-response and investigation practices to contain threats and coordinate defensive action.
Apply continuity, restoration, and recovery principles to support the secure return of systems and critical services.
Use incidents, assessments, threat intelligence, lessons learned, metrics, and emerging practices to continuously strengthen cyber-defense capabilities.
By incorporating principles from internationally recognized standards and cybersecurity frameworks, CCDP® provides candidates with a broader professional perspective that can be applied across:
Private Enterprises • Government • Critical Infrastructure • Financial Services • Healthcare • Technology • Manufacturing • Education • Energy • Cloud Environments • Multinational Organizations
The goal is not to train candidates to become specialists in one individual standard.
The goal is to develop cyber-defense professionals who understand how recognized practices can support:
CCDP® is not tied to one:
Security Vendor • SIEM • Cloud Provider • EDR Platform • Firewall • Operating System • Vulnerability Scanner • Forensic Product • AI Security Platform
This allows CCDP® competencies to transfer across organizations, technologies, industries, and countries.
The recommended CCDP® certification cycle is:
Credential holders maintain professional competency through applicable IBACTP® continuing professional education, ethics, and recertification requirements.
CCDP® forms the professional level of the IBACTP® cyber-defense pathway.
Certified Cyber Defense Professional
Monitor • Detect • Analyze • Investigate • Respond • Recover
↓
Certified Cyber Defense Manager
Assess • Strategize • Govern • Prioritize • Lead • Measure • Transform
Move from performing cyber defense to leading enterprise cyber defense.
Below is a more comprehensive, web-ready FAQ section that strengthens candidate information while keeping the answers readable and marketable.
Ready to build your cyber-defense capabilities?
Cyber defense requires more than tools.
It requires professionals capable of turning:
The ultimate testing objective is:
The CCDP® certification is vendor-neutral, but candidates are expected to understand how major cyber-defense technologies support monitoring, detection, investigation, incident response, recovery, and resilience.
The program focuses on technology purpose, defensive use, interpretation of outputs, integration, limitations, and practical application rather than certification on any single commercial product.
CCDP® addresses SIEM technologies used to collect, normalize, correlate, and analyze security events across enterprise environments.
Key applications include:
Cyber Defense Application:
Use SIEM data to identify suspicious activity, correlate events, investigate incidents, and support escalation decisions.
SOAR technologies help security teams coordinate and automate response activities.
Candidates develop an understanding of:
Cyber Defense Application:
Improve response speed and consistency while maintaining appropriate professional oversight and validation.
EDR and XDR technologies provide visibility into suspicious activity across endpoints and connected security environments.
Relevant capabilities include:
Cyber Defense Application:
Detect malicious endpoint behavior, investigate attacker activity, isolate compromised devices, and support incident response.
Network-defense technologies provide visibility into communications between systems, users, applications, and external networks.
CCDP® addresses concepts involving:
Cyber Defense Application:
Use network activity to identify suspicious communications, attack patterns, compromised hosts, and unauthorized access.
Candidates examine the role of firewalls and related network controls in reducing attack surfaces and restricting unauthorized activity.
Relevant areas include:
Cyber Defense Application:
Use network controls to restrict attacker movement, reduce exposure, and support containment during incidents.
Threat-intelligence platforms and services help organizations collect, enrich, analyze, and operationalize threat information.
Candidates examine:
Cyber Defense Application:
Apply threat intelligence to monitoring, detection, vulnerability prioritization, threat hunting, and incident investigation.
CCDP® addresses technologies used to identify and prioritize weaknesses across enterprise environments.
Relevant technology categories include:
Candidates learn to evaluate vulnerability findings using:
Cyber Defense Application:
Prioritize the vulnerabilities and exposures that create the greatest practical risk.
Modern cyber-defense operations increasingly span hybrid and cloud-native environments.
CCDP® addresses:
Cyber Defense Application:
Monitor, detect, investigate, and respond to threats across cloud and hybrid environments.
Identity is a major attack surface in modern environments.
CCDP® addresses technologies and practices involving:
Cyber Defense Application:
Identify suspicious identity activity, credential misuse, privilege abuse, and account compromise.
Digital-forensics technologies support evidence acquisition, analysis, preservation, and investigation.
Relevant applications include:
Cyber Defense Application:
Preserve and analyze evidence to understand attack activity, determine scope, support root-cause analysis, and document findings.
Incident-management technologies support structured coordination of cyber incidents.
Capabilities may include:
Cyber Defense Application:
Coordinate incident-response activities in a consistent, documented, and accountable manner.
Because CCDP® places strong emphasis on recovery and resilience, candidates also examine technologies supporting:
Cyber Defense Application:
Restore systems and services securely after an incident while reducing the risk of reinfection or recurrence.
Artificial Intelligence is becoming increasingly integrated into modern security operations.
CCDP® addresses applications such as:
Candidates also evaluate limitations involving:
Automate Where Appropriate → Validate the Output → Maintain Human Oversight → Document Critical Decisions
Approved training programs may use representative commercial or open-source tools for demonstrations and laboratories.
Examples may include technologies in categories such as:
Specific products may vary by training provider, lab environment, availability, and technology evolution.
CCDP® certification competency does not depend on mastery of a particular vendor product.
The technologies covered within CCDP® support practical applications across the full defensive lifecycle.
Monitor enterprise environments, analyze alerts, investigate suspicious activity, and coordinate defensive actions.
Identify indicators, anomalies, behaviors, and attack patterns that may indicate compromise.
Proactively search for attacker activity that may not have generated conventional alerts.
Identify exploitable weaknesses and prioritize remediation according to organizational risk.
Support identification, triage, escalation, containment, eradication, investigation, and recovery.
Preserve and interpret evidence to determine attack scope, timeline, cause, and impact.
Monitor and investigate threats across cloud services, workloads, identities, APIs, and cloud-native technologies.
Detect suspicious authentication, privilege escalation, account misuse, and credential compromise.
Restore critical services securely and use incident experience to strengthen future defensive capability.
Use AI and automation to improve detection, analysis, prioritization, and response while maintaining responsible human oversight.
CCDP® prepares professionals to understand how multiple technologies work together during a real cyber incident.
A typical defensive workflow may involve:
The objective is to move beyond isolated tool usage and understand how defensive technologies combine to produce better visibility, stronger analysis, faster response, and more secure recovery.
The CCDP® credentialing framework is structured with consideration of recognized professional certification and personnel-credentialing practices associated with:
International requirements for bodies operating certification of persons.
Relevant personnel-certification accreditation principles and practices associated with competence-based certification.
Relevant certification-program quality principles involving governance, assessment, certification policies, examination practices, and continuing competence.
Professional credentialing practices supporting certification quality, governance, assessment, ethics, and continuous improvement.
Broader internationally recognized principles supporting impartiality, consistency, competence assessment, transparency, security, and public confidence in professional credentials.
CCDP® competencies are also structured with consideration of recognized cybersecurity workforce practices.
The NIST NICE Workforce Framework for Cybersecurity describes cybersecurity work through Tasks, Knowledge, and Skills and provides a common framework that can be used by learners, employers, educators, and certification providers.
CCDP® reflects this competency-oriented philosophy by connecting:
This approach supports the professional relevance of the CCDP® Body of Knowledge to cyber-defense, security operations, incident response, investigation, vulnerability management, and resilience responsibilities.
The CCDP® certification framework encompasses:
The certification-quality lifecycle follows:
Establish the professional role, certification scope, eligibility requirements, and competencies.
Use professional and Subject Matter Expert input to validate job tasks, competencies, Body of Knowledge, and assessment requirements.
Evaluate candidates through structured, secure, competency-based certification assessment.
Award the credential based on documented certification requirements and assessment results.
Require applicable continuing professional education, ethics, and recertification activities.
Provide mechanisms for authorized verification of credential status.
Periodically evaluate professional practice, technologies, threats, workforce requirements, and assessment performance.
Update competencies, examinations, policies, security controls, and certification processes as professional requirements evolve.
CCDP® is designed to provide a credential that communicates competency across the complete cyber-defense lifecycle:
Its professional relevance is strengthened through:
CCDP® brings learning, assessment, workforce competency, and credentialing quality together around one central objective:
The complete CCDP® professional progression is:
And the professional outcome is:
Take the next step toward becoming a Certified Cyber Defense Professional.
APPLY NOW →
Already prepared to demonstrate your competency?
REGISTER FOR THE EXAM →
Develop practical competency across the complete cyber-defense lifecycle.
ENROLL NOW →
Eligible instructor-led candidates can demonstrate competency through a structured applied cyber-defense project.
EXPLORE THE CAPSTONE →
Review the Body of Knowledge, eligibility, examination structure, competencies, assessment pathways, and certification requirements.
DOWNLOAD PROGRAM GUIDE →
CCDP® is designed for professionals working in or moving toward roles such as:
It is also suitable for IT professionals seeking to transition into cyber defense and security operations.
The certification curriculum is organized into eight major modules:
Module 1 — Cyber Defense Foundations & Defensive Architecture
Module 2 — Security Monitoring, Detection & SOC Operations
Module 3 — Threat Intelligence, Hunting & Adversary Analysis
Module 4 — Vulnerability, Exposure & Attack-Surface Defense
Module 5 — Incident Detection, Triage & Response
Module 6 — Digital Forensics, Investigation & Evidence
Module 7 — Recovery, Continuity & Cyber Resilience
Module 8 — AI-Enabled Defense & Emerging Cyber Threats
Upon successful completion, participants will be able to:
1. Apply Cyber Defense Principles and Architectures
Evaluate attack surfaces, defensive controls, Zero Trust concepts, adversary behavior, defense-in-depth, and resilient architectures.
2. Perform Security Monitoring and Threat Detection
Interpret network, endpoint, identity, cloud, application, and security-platform telemetry.
3. Apply Threat Intelligence and Threat Hunting
Use threat intelligence, indicators, adversary behaviors, attack techniques, and analytical hypotheses to support proactive defense.
4. Assess Vulnerabilities and Enterprise Exposure
Interpret vulnerability findings, assess exploitability and impact, prioritize remediation, and support exposure reduction.
5. Conduct Incident Triage and Response
Classify incidents, determine severity, investigate activity, recommend containment and eradication actions, and coordinate recovery.
6. Support Digital Forensics and Cyber Investigations
Preserve evidence, maintain chain of custody, analyze relevant artifacts, reconstruct timelines, and document findings.
7. Support Secure Recovery and Cyber Resilience
Apply recovery, continuity, restoration, lessons-learned, and resilience-improvement practices.
8. Evaluate AI-Enabled and Emerging Cyber Defense
Assess AI-assisted attacks, defensive automation, cloud-native environments, IoT, OT, and emerging threats.
The CCDP® certification assessment evaluates whether candidates can apply cyber-defense knowledge to realistic situations.
Candidates are tested on their ability to:
Evaluate threats, attack surfaces, Zero Trust, defense-in-depth, and defensive controls.
Interpret alerts, logs, telemetry, anomalies, and security events.
Analyze threat intelligence, indicators of compromise, adversary behaviors, attack techniques, and hunting scenarios.
Evaluate vulnerabilities, exploitability, asset criticality, attack surfaces, and remediation priorities.
Determine severity, escalation, containment, eradication, communication, and response priorities.
Evaluate evidence, timelines, forensic procedures, investigative findings, and root-cause information.
Evaluate restoration priorities, recovery validation, continuity, lessons learned, and resilience improvements.
Evaluate AI-enabled threats, defensive automation, cloud-native risks, IoT, OT, software supply chains, and emerging technologies.
CCDP® is organized around eight integrated competency dimensions.
Understand threats, attack surfaces, adversary behavior, Zero Trust, defense-in-depth, defensive controls, and resilient security architecture.
Interpret security telemetry, logs, alerts, events, anomalies, and indicators across enterprise environments.
Apply threat intelligence, indicators, adversary techniques, behavioral analysis, and hunting hypotheses.
Identify vulnerabilities, evaluate exploitability, prioritize remediation, and reduce enterprise exposure.
Recognize incidents, establish severity, investigate activity, contain threats, support eradication, and coordinate response.
Preserve evidence, maintain integrity, correlate artifacts, reconstruct timelines, and support cyber investigations.
Restore affected environments, validate recovery, support continuity, capture lessons learned, and strengthen resilience.
Evaluate AI-assisted attacks and defense, automation, cloud-native threats, IoT, OT, APIs, containers, software supply chains, and emerging attack techniques.
The Certified Cyber Defense Professional (CCDP®) is a comprehensive, vendor-neutral professional certification designed to validate practical competency in protecting organizations through effective security monitoring, threat detection, analysis, investigation, incident response, recovery, and cyber resilience.
CCDP® prepares professionals to understand how multiple defensive capabilities work together across modern enterprise technology environments.
The certification bridges the gap between knowing cybersecurity concepts and applying cyber-defense judgment in realistic operational situations.
Its central professional progression is:
CCDP® provides an integrated Body of Knowledge spanning the principal capabilities required for modern cyber defense.
Develop an understanding of how enterprise security controls work together to reduce exposure and improve defensive capability.
Coverage includes:
Cyber-Defense Architecture • Attack Surfaces • Threat Actors • Attack Techniques • Defense-in-Depth • Zero Trust • Network Security • Endpoint Security • Identity Security • Cloud Security • Resilient Architecture
The emphasis is on understanding how architecture affects an organization’s ability to prevent, detect, contain, and recover from cyber threats.
Understand how Security Operations Centers and cyber-defense teams maintain visibility across enterprise environments.
Coverage includes:
SOC Operations • SIEM • Security Analytics • EDR/XDR • Network Monitoring • Log Analysis • Security Telemetry • Alert Triage • Event Correlation • Escalation
Candidates develop the ability to move from:
Develop competency in identifying suspicious and malicious activity across multiple security environments.
Coverage includes:
Detection Concepts • Indicators of Compromise • Behavioral Indicators • Anomaly Analysis • Detection Logic • Endpoint Activity • Network Activity • Identity Activity • Cloud Events • Attack Patterns
CCDP® emphasizes the professional judgment required to distinguish normal activity, suspicious activity, and probable malicious behavior.
Understand how threat information can strengthen both reactive and proactive defense.
Coverage includes:
Threat Intelligence • Adversary Behavior • Indicators • Tactics and Techniques • Threat Profiling • Intelligence Sources • Threat Hunting • Hunting Hypotheses • Evidence Correlation • Intelligence-Driven Defense
Candidates learn to connect intelligence with operational security evidence to determine:
Move beyond simply identifying vulnerabilities to understanding which exposures require priority action.
Coverage includes:
Vulnerability Assessment • Asset Discovery • Exploitability • Asset Criticality • Attack Surfaces • Exposure Management • Configuration Weaknesses • Remediation Prioritization • Threat-Informed Vulnerability Management
CCDP® develops the ability to evaluate:
Incident response is a defining competency within CCDP®.
Coverage includes:
Incident Identification • Alert Triage • Severity Classification • Escalation • Investigation • Containment • Eradication • Communication • Documentation • Recovery Coordination
Candidates learn to evaluate realistic incidents and determine the appropriate response based on available evidence, severity, operational impact, and risk.
The progression is:
Cyber-defense professionals must understand how digital evidence supports incident investigation and defensible conclusions.
Coverage includes:
Evidence Identification • Evidence Preservation • Chain of Custody • Endpoint Evidence • Logs • Network Evidence • Cloud Evidence • Timeline Reconstruction • Artifact Correlation • Root-Cause Analysis
CCDP® is not intended to replace a specialized digital-forensics certification. Instead, it ensures that cyber-defense professionals understand how forensic evidence supports effective incident response.
Cyber defense does not end when an attacker is contained.
Organizations must restore operations securely and determine whether the environment is safe to return to normal operation.
Coverage includes:
Recovery Planning • Restoration Priorities • Backup & Recovery • Recovery Validation • Business Continuity • Disaster Recovery • Critical Services • Lessons Learned • Control Improvement • Cyber Resilience
Candidates learn to consider questions such as:
The objective is not simply:
“Restore the system.”
It is:
The CCDP® Body of Knowledge incorporates relevant principles from recognized frameworks including NIST CSF, the NICE Framework, ISO information-security and risk-management standards, AI risk-management concepts, incident-response practices, and CISA cybersecurity guidance.
NIST’s current CSF 2.0 explicitly organizes cybersecurity outcomes around Govern, Identify, Protect, Detect, Respond, and Recover, while NICE provides a common language for cybersecurity work and competency development. (NIST)
Framework Application Progression
Modern cyber defense is no longer about monitoring one dashboard, managing one security platform, or responding to isolated technical events. Today’s attacks move rapidly across endpoints, identities, networks, cloud platforms, applications, data, and third-party environments, requiring cyber-defense professionals to understand how these components interact throughout an incident.
A security alert may begin as unusual endpoint activity. Further analysis may reveal compromised credentials, unauthorized identity activity, lateral movement, cloud-resource access, exploitation of a known vulnerability, or attempted data exfiltration.
What initially appears to be a single alert can quickly become an enterprise-wide incident requiring coordinated detection, investigation, containment, eradication, recovery, and resilience activities.
For example:
Endpoint Alert → Compromised Identity → Lateral Movement → Cloud Access → Sensitive Data Exposure → Incident Response → Recovery
Investigating such an event may require professionals to correlate information from:
The challenge is therefore no longer simply knowing how to use a cybersecurity tool.
The challenge is knowing what the information means, how different evidence relates, which threats matter most, what action should occur next, and how the organization can recover securely.
Cyber-defense professionals must be capable of moving beyond alert recognition to informed defensive action.
They must be prepared to answer questions such as:
These are the practical questions at the center of CCDP®.
CCDP® develops integrated competency across the defensive lifecycle:
Rather than treating security monitoring, vulnerability management, threat intelligence, incident response, digital forensics, and recovery as separate disciplines, CCDP® connects them into a unified professional framework.
The result is a cyber-defense professional who understands not only how threats are detected, but also how they are investigated, contained, eradicated, recovered from, and converted into opportunities to strengthen organizational resilience.
Multiple Threats. Multiple Technologies. Multiple Evidence Sources. One Integrated Defensive Lifecycle.
CCDP® professionals learn to interpret security information, connect evidence across technologies, assess vulnerabilities and exposures, investigate suspicious activity, support incident containment and eradication, preserve relevant evidence, contribute to secure recovery, and apply lessons learned to strengthen future defensive capability.
Modern cyber-defense professionals must operate in environments where evidence and security controls extend beyond traditional networks.
Coverage includes:
Cloud Security • Cloud Logging • Identity-Centric Security • SaaS Environments • APIs • Containers • Cloud Workloads • Hybrid Environments • Remote Access • Modern Attack Surfaces
The emphasis is on applying transferable cyber-defense principles across changing technology environments.
Artificial intelligence is changing both offensive and defensive cybersecurity.
CCDP® introduces professionals to:
AI-Assisted Detection • Automated Triage • Threat Analysis • Security Automation • AI-Assisted Investigation • AI-Enabled Attacks • Adversarial AI Risks • Cloud-Native Threats • IoT • OT • Software Supply Chains
Candidates are expected to understand both the opportunities and limitations of AI-assisted defense, including the need for validation, human judgment, security, and responsible use.
CCDP® connects these capabilities rather than teaching them as isolated subjects.
Build and understand defensive foundations.
↓
Monitor endpoints, networks, identities, applications, and cloud environments.
↓
Recognize suspicious and malicious activity.
↓
Understand adversaries, indicators, behaviors, and emerging threats.
↓
Determine where the organization is vulnerable.
↓
Prioritize, contain, eradicate, and coordinate.
↓
Preserve evidence, correlate activity, and reconstruct events.
↓
Restore systems and operations securely.
↓
Apply lessons learned and strengthen future readiness.
The certification does not simply ask:
CCDP® asks whether you can apply that understanding when it matters:
Can you recognize a threat, interpret the evidence, determine its significance, prioritize the response, contain the incident, support the investigation, recover securely, and help prevent recurrence?
That distinction defines the CCDP® professional.
Many cybersecurity programs focus heavily on individual technologies or narrow technical disciplines.
CCDP® integrates the capabilities required to understand how an organization moves from exposure to detection, from detection to response, and from response to recovery.
Understand vulnerabilities, assets, attack surfaces, exploitability, and organizational risk.
Interpret telemetry, logs, alerts, anomalies, identities, endpoints, networks, applications, and cloud activity.
Determine what happened, how it happened, what is affected, and what evidence supports the conclusion.
Triage incidents, determine severity, escalate appropriately, contain threats, and support eradication.
Preserve evidence, reconstruct events, correlate artifacts, and support root-cause analysis.
Restore affected systems securely and validate that threats have been removed.
Apply lessons learned to strengthen future defensive capability.
CCDP® remains vendor-neutral while introducing candidates to the categories of technologies commonly used in cyber defense.
SIEM • SOAR • EDR/XDR • Security Analytics • Threat Intelligence • Monitoring Platforms
Firewalls • IDS/IPS • Network Detection • Packet Analysis • Segmentation • Zero Trust Technologies
Vulnerability Scanners • Asset Discovery • Attack-Surface Management • Exposure Platforms • Configuration Assessment
Digital Forensics • Log Analysis • Network Analysis • Endpoint Evidence • Timeline Analysis
Cloud Security • CSPM Concepts • API Security • Container Security • DevSecOps • Application Security
Incident Management • Backup & Recovery • Continuity Technologies • Crisis Coordination
Automated Triage • Detection Analytics • Threat Enrichment • Security Automation • AI-Assisted Investigation
The objective is:
100 Questions
90 Minutes
Multiple-Choice + Scenario-Based Questions
Closed Book
Secure Online Proctoring or Approved Testing Center
Recommended Passing Score: 70%
Assessment emphasis:
Knowledge • Detection • Analysis • Threat Recognition • Incident Judgment • Investigation • Recovery • Resilience
Eligible candidates participating in an approved instructor-led pathway may demonstrate professional competency through the CCDP® Applied Cyber Defense Capstone.
The Capstone integrates:
Framework alignment does not constitute accreditation, recognition, endorsement, or approval by referenced organizations.
Organizations need professionals capable of connecting:
Threat Intelligence + Security Telemetry + Vulnerabilities + Incidents + Evidence + Recovery
The NICE ecosystem explicitly identifies defensive cybersecurity, digital forensics, and incident response as Protection and Defense work roles, reinforcing the importance of integrated defensive competencies.
CCDP® develops professionals who can contribute across that integrated environment.
Certified Cyber Defense Professional
Monitor • Detect • Analyze • Investigate • Respond • Recover
↓
Everything you need to plan your sitting.
Exam code for the Professional-level Cyber Defense credential.
Multiple choice, completed in 120 minutes.
Passing score. Delivered in English.
A minimum of two years of experience in cyber defense or a closely related technology discipline.
IBACTP® approved testing centers and online proctored delivery
Three-year certification cycle with continuing professional education
Every route leads to the same CCDP® examination and the same designation.
Start as a Professional. Advance as a Leader.
Exam fee only, with complimentary course materials provided — $400 USD.
4 days, 2 hours daily online. All course materials + Exam — $1,200 USD.
10 days, 2 hours daily. All course materials + Exam — $1,800 USD.
Certify a whole team on a schedule that suits your organization. Fees negotiable.
Find answers to common questions about the Certified Cyber Defense Professional (CCDP®) certification, training, assessment, competency areas, and professional pathway.
The Certified Cyber Defense Professional (CCDP®) is a professional-level, vendor-neutral certification designed to validate practical competency across the modern cyber-defense lifecycle.
CCDP® covers security monitoring, threat detection, SOC operations, threat intelligence, threat hunting, vulnerability and exposure management, incident response, digital forensics, secure recovery, cyber resilience, and AI-enabled defense.
The certification emphasizes practical application and professional judgment—not simply memorization of cybersecurity terminology.
CCDP® is designed for professionals working in, entering, or advancing within cyber-defense and security-operations roles.
Relevant professionals may include:
It can also benefit IT professionals seeking to transition into operational cybersecurity and cyber-defense responsibilities.
CCDP® focuses on transferable cyber-defense competencies rather than expertise with one particular product, platform, cloud provider, or security vendor.
Candidates develop an understanding of technology categories such as SIEM, SOAR, EDR/XDR, IDS/IPS, threat-intelligence platforms, vulnerability scanners, cloud-security technologies, forensic tools, and incident-management platforms without making certification dependent on a particular commercial product.
Yes.
No. Advanced cybersecurity experience is not required to begin CCDP® training.
Candidates benefit from foundational familiarity with:
Previous technical-support, networking, systems-administration, cybersecurity, or IT experience can be beneficial.
CCDP® concentrates specifically on the defensive side of cybersecurity and places significant emphasis on incident response, recovery, and resilience.
Its competency progression connects:
Rather than covering cybersecurity only as a broad collection of topics, CCDP® focuses on how professionals use security information and defensive capabilities to recognize attacks, investigate incidents, support response, restore operations, and improve future resilience.
Candidates develop competency involving:
The emphasis is on understanding how SOC information is transformed into detection, analysis, investigation, and defensive action.
Candidates learn how threat intelligence supports defensive decision-making, including understanding threat actors, indicators of compromise, adversary behaviors, attack techniques, intelligence sources, and emerging threats.
The objective is to use intelligence to help answer:
Yes.
CCDP® introduces threat-hunting concepts that help professionals proactively search for malicious activity that may not have triggered traditional security alerts.
Candidates examine:
Threat hunting reinforces the transition from purely reactive security monitoring to proactive cyber defense.
Yes.
CCDP® addresses vulnerability identification, exploitability, attack surfaces, asset criticality, threat context, exposure management, and remediation prioritization.
Candidates learn that technical severity alone does not always determine remediation priority.
CCDP® encourages a broader perspective:
Yes.
This helps professionals identify which weaknesses require the greatest defensive attention.
Yes. Incident response is one of the defining competency areas of CCDP®.
Candidates examine the complete incident lifecycle, including:
Candidates develop the professional judgment required to move from:
CCDP® introduces digital-forensics and investigation principles relevant to cyber-defense professionals.
Topics include:
The goal is to prepare professionals to preserve and interpret evidence while supporting defensible cyber investigations.
Yes.
CCDP® recognizes that cyber defense does not end when an attacker is contained.
Candidates examine how cybersecurity incidents interact with business continuity, disaster recovery, restoration priorities, critical services, backup strategies, and recovery validation.
The objective is to help ensure that affected systems and services are not only restored quickly, but restored securely and reliably.
Yes.
Because preventing every cybersecurity incident is not realistic.
Organizations must also develop the capability to withstand attacks, limit disruption, respond effectively, recover critical operations, learn from incidents, and adapt their defenses.
CCDP® therefore connects incident response with:
Cyber resilience is a defining element of the CCDP® professional competency model.
CCDP® addresses security monitoring, detection, exposure, incident response, evidence, and defensive considerations relevant to modern cloud and cloud-native environments.
The certification remains vendor-neutral and does not require candidates to specialize in one particular cloud provider.
Yes.
Candidates explore areas including:
The central perspective is:
CCDP® considers evolving defensive challenges involving areas such as:
Artificial Intelligence • Generative AI • Cloud-Native Systems • APIs • Containers • IoT • Operational Technology • Automation • Software Supply Chains • Emerging Attack Techniques
The goal is to prepare professionals for cyber-defense environments that continue to change as technology evolves.
The CCDP® Body of Knowledge incorporates relevant principles and practices associated with recognized cybersecurity, risk, continuity, workforce, and AI frameworks, including areas represented by:
CCDP® emphasizes practical professional application rather than memorization of standards.
CCDP® provides two certification assessment pathways.
The recommended examination structure includes:
100 Questions • 90 Minutes • Multiple-Choice and Scenario-Based Questions • Closed Book • Secure Proctoring • Recommended Passing Score: 70%
The assessment evaluates knowledge, application, detection, analysis, threat recognition, investigation, incident judgment, recovery, and resilience.
Eligible candidates participating in an approved instructor-led pathway may demonstrate competency through the Applied Cyber Defense Capstone.
The Capstone integrates:
The assessment includes scenario-based questions designed to evaluate whether candidates can apply cyber-defense knowledge to realistic situations.
Candidates may be asked to interpret alerts, analyze security information, prioritize vulnerabilities, evaluate evidence, determine incident severity, select containment actions, or recommend recovery measures.
The emphasis moves beyond:
toward:
Successful candidates demonstrate the ability to integrate technical knowledge, analytical reasoning, incident judgment, and resilience principles.
The CCDP® competency standard can be summarized as:
Credential holders maintain continuing professional competency through applicable IBACTP® continuing professional education, professional ethics, and recertification requirements.
Candidates and credential holders should consult current IBACTP® certification policies for applicable maintenance requirements.
The recommended CCDP® certification cycle is three years.
CCDP® forms the professional level of the IBACTP® cyber-defense certification pathway.
The advanced progression is:
Assess • Strategize • Govern • Prioritize • Lead • Measure • Transform
CCDP® focuses primarily on performing and supporting cyber defense.
CCDM® advances the professional into governing enterprise cyber-defense capabilities, leading major incidents and cyber crises, directing recovery, measuring resilience, prioritizing investments, and communicating with executives and boards.
Ready to Defend What Matters?
Build the skills to detect earlier, respond faster, investigate accurately, and recover securely.
[BECOME CCDP® CERTIFIED]
Certified Cyber Defense Professional (CCDP®) · International Board of AI, Cybersecurity & Technology Professionals (IBACTP®)