Build the Skills to Detect, Defend, Respond and Lead
Cybersecurity has become a critical organizational capability as businesses, governments, educational institutions, healthcare systems, financial organizations, critical infrastructure operators, and technology companies become increasingly dependent on interconnected digital systems.
At the same time, cyber threats continue to evolve in scale, speed, automation, sophistication, and business impact. Ransomware, advanced persistent threats, cloud attacks, identity compromise, supply-chain attacks, insider threats, AI-enabled social engineering, deepfakes, and attacks against Artificial Intelligence systems have expanded the responsibilities of today's cybersecurity professionals.
IBACTP® Cybersecurity & Defense training is designed to help professionals develop the technical, analytical, operational, investigative, governance, risk-management, and leadership competencies required to identify threats, protect systems, detect malicious activity, investigate incidents, respond effectively, recover operations, and strengthen organizational cyber resilience.
Training supports professionals ranging from emerging cybersecurity practitioners and SOC analysts to threat intelligence specialists, security engineers, incident responders, cybersecurity managers, consultants, and senior security leaders.
The IBACTP® Cybersecurity & Defense learning journey emphasizes:
GOVERN
IDENTIFY
PROTECT
DETECT
ANALYZE
RESPOND
RECOVER
IMPROVE
Module 02Cybersecurity & Defense Curriculum
What You Will Learn
Depending on the course, certification pathway, and professional level, IBACTP® Cybersecurity & Defense training may cover the following areas.
Module 03Cybersecurity & Defense Curriculum
Cybersecurity Fundamentals
Participants develop foundational knowledge of modern cybersecurity principles, terminology, threats, technologies, controls, and professional responsibilities.
Topics may include:
Confidentiality, integrity, and availability
Cybersecurity principles
Security controls
Threats and vulnerabilities
Attack surfaces
Risk concepts
Authentication and authorization
Identity and access management
Cryptography fundamentals
Security policies
Defense-in-depth
Security architecture
Security monitoring
Incident management
Cybersecurity ethics
Security awareness
Cyber resilience
Participants learn to view cybersecurity as an integrated combination of: People + Processes + Technology + Governance + Risk + Intelligence
Module 04Cybersecurity & Defense Curriculum
Network Security
Networks remain a primary target for cyber attackers. Training may address:
Network architecture
TCP/IP fundamentals
Network protocols
Firewalls
Intrusion Detection Systems
Intrusion Prevention Systems
Network segmentation
Virtual private networks
Secure remote access
DNS security
Wireless security
Network monitoring
Network traffic analysis
Secure network architecture
Zero Trust network concepts
Participants may learn how to combine network controls to reduce attack surfaces and detect suspicious activity.
Module 05Cybersecurity & Defense Curriculum
Cyber Threat Intelligence
Threat intelligence helps organizations understand the adversaries, capabilities, motivations, infrastructure, and techniques that may threaten their operations.
Participants may learn about:
Threat intelligence lifecycle
Strategic intelligence
Operational intelligence
Tactical intelligence
Technical intelligence
Threat actors
Indicators of Compromise
Tactics, Techniques, and Procedures
Threat intelligence sources
Open-source intelligence
Intelligence collection
Intelligence analysis
Threat reporting
Intelligence dissemination
MITRE ATT&CK concepts
Intelligence sharing
AI-assisted intelligence analysis
The intelligence lifecycle may be presented as:
PLAN
COLLECT
PROCESS
ANALYZE
DISSEMINATE
FEEDBACK
Module 06Cybersecurity & Defense Curriculum
Security Operations Centers
Participants may explore how Security Operations Centers coordinate continuous security monitoring and cyber-defense activities. Training may include:
SOC structures
SOC roles and responsibilities
Security monitoring
Alert management
Event triage
Escalation
Incident identification
Threat intelligence integration
Detection engineering concepts
SOC workflows
SOC metrics
SOC maturity
Analyst performance
AI-assisted SOC operations
Manager-level programs may also address SOC staffing, technology selection, service-level objectives, performance measurement, budgeting, and operational leadership.
Module 07Cybersecurity & Defense Curriculum
SIEM — Security Information and Event Management
Participants may learn how SIEM platforms support centralized security visibility. Training may address:
Log collection
Event normalization
Correlation
Search
Alert generation
Detection rules
Dashboards
Threat investigation
Log retention
Use cases
Security analytics
Threat intelligence integration
Incident support
Participants learn how to transform security telemetry into actionable information.
Module 08Cybersecurity & Defense Curriculum
SOAR — Security Orchestration, Automation and Response
SOAR technologies help cybersecurity teams automate repetitive activities and coordinate response processes. Training may include:
Security orchestration
Workflow automation
Playbooks
Automated enrichment
Alert triage
Threat intelligence integration
Incident workflows
Case management
Automated response
Human approval controls
AI-assisted automation
Participants also examine where automation should remain subject to human judgment and authorization.
Module 09Cybersecurity & Defense Curriculum
Endpoint Security
Endpoints are common entry points for malware, ransomware, credential theft, and unauthorized access. Training may address:
Endpoint protection
Endpoint Detection and Response
Extended Detection and Response
Host-based monitoring
Malware prevention
Application control
Device security
Endpoint hardening
Behavioral detection
Endpoint isolation
Incident investigation
Module 10Cybersecurity & Defense Curriculum
Threat Hunting
Threat hunting involves proactively searching for malicious activity that may not have triggered existing security alerts. Participants may develop competencies in:
Hypothesis-driven hunting
Threat intelligence-driven hunting
Indicators of Compromise
TTP-based hunting
Behavioral analysis
Log analysis
Endpoint telemetry
Network telemetry
Anomaly investigation
Hunt documentation
Detection improvement
The process may follow:
HYPOTHESIZE
SEARCH
INVESTIGATE
VALIDATE
DOCUMENT
IMPROVE DETECTION
Module 11Cybersecurity & Defense Curriculum
Malware Analysis
Training may introduce participants to the concepts and methodologies used to understand malicious software. Topics may include:
Malware categories
Ransomware
Trojans
Worms
Spyware
Rootkits
File analysis
Static-analysis concepts
Dynamic-analysis concepts
Behavioral indicators
Malware persistence
Command-and-control concepts
Indicators of Compromise
AI-assisted malware classification
Training is conducted within appropriate defensive, ethical, and controlled learning contexts.
Module 12Cybersecurity & Defense Curriculum
Vulnerability Management
Participants may learn how organizations identify, assess, prioritize, remediate, and monitor security vulnerabilities. Topics may include:
Vulnerability identification
Vulnerability scanning
Asset inventories
Severity assessment
CVSS concepts
Threat context
Exploitability
Business criticality
Risk-based prioritization
Patch management
Remediation
Exceptions
Validation
Vulnerability metrics
AI-assisted vulnerability prioritization
The lifecycle may follow:
DISCOVER
ASSESS
PRIORITIZE
REMEDIATE
VALIDATE
MONITOR
Module 13Cybersecurity & Defense Curriculum
Incident Response
Participants may learn structured approaches to managing cybersecurity incidents. Training may address:
Incident-response planning
Preparation
Detection
Analysis
Triage
Containment
Eradication
Recovery
Evidence preservation
Communication
Documentation
Post-incident review
Lessons learned
Improvement planning
Participants may work through realistic scenarios involving phishing, ransomware, unauthorized access, compromised credentials, malware, cloud incidents, and data exposure.
Module 14Cybersecurity & Defense Curriculum
Digital Forensics
Digital forensics supports the collection, preservation, examination, analysis, and reporting of digital evidence. Topics may include:
Forensic principles
Evidence preservation
Chain of custody
Disk evidence
Memory concepts
Network evidence
Log evidence
Cloud evidence
Mobile evidence concepts
Timeline analysis
Artifact analysis
Forensic reporting
AI-assisted forensic analysis
Emphasis is placed on evidence integrity, documentation, authorized access, and professional practice.
Module 15Cybersecurity & Defense Curriculum
Cloud Security
Participants may examine cybersecurity within public, private, hybrid, and multi-cloud environments. Training may include:
Shared-responsibility models
Cloud identity
IAM
Privileged access
Cloud configuration
Encryption
Key management
Logging
Cloud monitoring
Workload protection
Cloud vulnerability management
Cloud Security Posture Management concepts
Container security
Cloud incident response
Multi-cloud risk
Module 16Cybersecurity & Defense Curriculum
Zero Trust
Zero Trust represents a security approach in which trust is not automatically granted based on network location. Training may address principles such as:
Verify explicitly
Least privilege
Assume breach
Strong identity
Device trust
Microsegmentation
Continuous authorization
Context-aware access
Data protection
Continuous monitoring
Participants may examine how Zero Trust principles can be incorporated into modern security architecture.
Module 17Cybersecurity & Defense Curriculum
AI-Powered Threat Detection
Artificial Intelligence and machine learning are increasingly used to support security monitoring and analysis. Participants may explore:
AI-assisted anomaly detection
Behavioral analytics
User and Entity Behavior Analytics
Security-event classification
Threat prioritization
AI-assisted alert triage
Pattern recognition
Predictive security analytics
AI-assisted threat hunting
False-positive reduction
Human-AI collaboration
Training also emphasizes that AI-generated security conclusions require appropriate validation and human oversight.
Module 18Cybersecurity & Defense Curriculum
Generative AI Cybersecurity Risks
Generative AI introduces both opportunities and new attack surfaces. Participants may examine:
AI-assisted phishing
Deepfakes
Synthetic identities
Voice cloning
AI-enabled social engineering
Prompt injection
Indirect prompt injection
Sensitive-data leakage
AI hallucinations
Model misuse
Agentic AI risks
AI-generated misinformation
AI application vulnerabilities
Secure generative AI use
Module 19Cybersecurity & Defense Curriculum
Adversarial AI
As organizations increasingly deploy machine learning, attackers may attempt to manipulate AI systems themselves. Training may introduce:
Adversarial examples
Data poisoning
Model evasion
Model extraction
Model theft
Model inversion concepts
Training-data risks
Model robustness
AI supply-chain risk
Defensive testing
AI model monitoring
Module 20Cybersecurity & Defense Curriculum
AI Red Teaming
AI red teaming evaluates AI systems for security, safety, misuse, and control weaknesses in authorized environments. Participants may learn concepts involving:
AI threat modeling
Model testing
Prompt-based security testing
Jailbreak risk assessment
Abuse-case development
RAG security testing
AI-agent security
Model-output evaluation
Data-exposure testing
Guardrail evaluation
Responsible disclosure
Remediation planning
The emphasis is on authorized defensive testing and improving AI-system resilience.
Module 21Cybersecurity & Defense Curriculum
Cyber Governance
Cybersecurity requires organizational accountability in addition to technical controls. Training may address:
Governance structures
Security policies
Roles and responsibilities
Security strategy
Control frameworks
Risk ownership
Compliance
Third-party governance
Metrics
Executive reporting
Board oversight
Security program maturity
Cybersecurity accountability
Manager-level participants learn how cybersecurity programs are aligned with organizational objectives and risk appetite.
Module 22Cybersecurity & Defense Curriculum
Cyber Risk Management
Participants may develop capabilities to identify and manage technology-related risks. Training may cover:
Risk identification
Threat assessment
Vulnerability assessment
Likelihood and impact
Inherent risk
Residual risk
Risk treatment
Risk acceptance
Risk mitigation
Risk transfer
Risk registers
Risk appetite
Key risk indicators
Third-party risk
Cyber-risk reporting
Quantitative and qualitative assessment concepts
Module 23Cybersecurity & Defense Curriculum
Professional Skills Developed
IBACTP® Cybersecurity & Defense training may help participants develop competencies in:
Identifying common cybersecurity threats and vulnerabilities
Preparing for applicable IBACTP® Cybersecurity & Defense certifications
Professional-Level Competency Progression
IDENTIFY
PROTECT
MONITOR
DETECT
ANALYZE
INVESTIGATE
RESPOND
IMPROVE
Module 24Cybersecurity & Defense Curriculum
Manager-Level Skills Developed
Manager-level Cybersecurity & Defense training moves beyond individual technical activities to focus on security leadership, governance, risk, resources, programs, performance, and organizational resilience.
Participants may develop competencies in:
Leading cybersecurity teams
Managing SOC operations
Managing cyber threat intelligence programs
Establishing cybersecurity strategies
Prioritizing security investments
Managing cyber-risk portfolios
Developing cybersecurity policies
Establishing security metrics and KPIs
Managing major cyber incidents
Coordinating crisis response
Overseeing vulnerability-management programs
Managing cloud-security programs
Governing AI cybersecurity risk
Managing third-party cyber risk
Evaluating security technologies
Managing cybersecurity budgets and resources
Communicating cyber risk to executives
Preparing board-level cybersecurity reporting
Supporting regulatory and compliance requirements
Developing cyber-resilience strategies
Managing security workforce capabilities
Developing continuous-improvement programs
The manager-level progression emphasizes:
ASSESS
PRIORITIZE
GOVERN
MANAGE
COORDINATE
MEASURE
COMMUNICATE
LEAD
Training Formats
Module 25Cybersecurity & Defense Curriculum
Flexible, Practical and Scenario-Based Cybersecurity Training
IBACTP® Cybersecurity & Defense programs may combine theoretical instruction, practical exercises, defensive labs, cyber scenarios, case studies, simulations, and certification preparation.
Module 26Cybersecurity & Defense Curriculum
Virtual Instructor-Led Training (VILT)
Live online cybersecurity programs may include:
Instructor-led lessons
Live security demonstrations
Threat-analysis exercises
SOC scenarios
SIEM demonstrations
Incident-response exercises
Threat intelligence analysis
Cloud-security scenarios
AI-security demonstrations
Interactive discussions
Q&A sessions
Certification preparation
This format provides real-time instructor interaction while allowing professionals to participate remotely.
Module 27Cybersecurity & Defense Curriculum
Self-Paced Online Training
Self-paced learning lets participants progress on their own schedules.
Programs may include:
Recorded lessons
Structured learning modules
Security demonstrations
Scenario exercises
Case studies
Knowledge checks
Practice questions
Defensive labs where applicable
Certification-preparation resources
Module 28Cybersecurity & Defense Curriculum
Live Classroom Instructor-Led Training
Face-to-face cybersecurity training may provide:
Instructor-led instruction
Security demonstrations
Group exercises
Threat-analysis activities
Incident-response simulations
SOC exercises
Case studies
Team-based scenarios
Instructor coaching
Certification review
Module 29Cybersecurity & Defense Curriculum
Cybersecurity Bootcamps
IBACTP® Cybersecurity & Defense Bootcamps provide intensive, accelerated training for professionals seeking rapid competency development.
Bootcamp areas may include:
Cybersecurity fundamentals
SOC operations
Threat intelligence
Threat hunting
Incident response
Digital forensics
Cloud security
Vulnerability management
AI cybersecurity
Certification preparation
A typical bootcamp progression may follow:
LEARN
DETECT
INVESTIGATE
DEFEND
RESPOND
RECOVER
Module 30Cybersecurity & Defense Curriculum
Cyber Defense Labs
Where appropriate, participants may complete controlled defensive exercises involving:
Network monitoring
Log analysis
SIEM
Endpoint telemetry
Threat intelligence
Vulnerability assessment
Incident investigation
Digital forensics
Cloud security
AI-assisted security analysis
Labs are designed to reinforce legitimate defensive cybersecurity competencies in controlled environments.
Module 31Cybersecurity & Defense Curriculum
Cyber Range and Simulation-Based Training
Selected programs may incorporate cyber-range or simulated environments where available. Participants may work through scenarios such as:
Phishing incidents
Credential compromise
Ransomware
Malware detection
Cloud misconfiguration
Unauthorized access
Insider threats
Data exposure
SOC alert escalation
AI-enabled social engineering
Simulation-based training helps participants practice decision-making without affecting production systems.
Module 32Cybersecurity & Defense Curriculum
Incident Response Tabletop Exercises
Managers, security teams, and executives may participate in facilitated cybersecurity tabletop exercises. Scenarios may require participants to make decisions involving:
Incident escalation
Containment
Business continuity
Communications
Legal and compliance coordination
Executive notification
Third-party coordination
Recovery
Post-incident improvement
These exercises help organizations evaluate both technical and managerial readiness.
Module 33Cybersecurity & Defense Curriculum
Certification Preparation Programs
IBACTP® certification preparation may include:
Body of Knowledge review
Domain-by-domain instruction
Scenario-based questions
Threat-analysis exercises
Practice examinations
Case studies
Knowledge-gap assessment
Instructor review sessions
Examination-readiness preparation
Completion of training does not automatically confer certification. Candidates must satisfy applicable IBACTP® certification requirements.
Module 34Cybersecurity & Defense Curriculum
Hybrid Training
Hybrid programs may combine:
Self-Paced Study
Virtual Instruction
Defensive Labs
Live Workshops
Simulations
Certification Review
This approach is particularly useful for technical certification pathways and organizational cybersecurity academies.
Module 35Cybersecurity & Defense Curriculum
Cybersecurity Workshops
Focused professional workshops may include:
Cybersecurity Fundamentals
SOC Operations
SIEM and Security Analytics
Cyber Threat Intelligence
Threat Hunting
Vulnerability Management
Incident Response
Digital Forensics
Cloud Security
Zero Trust
AI-Powered Threat Detection
Generative AI Security
AI Red Teaming
Cyber Risk Management
Cybersecurity Governance
Cybersecurity for Executives
Module 36Cybersecurity & Defense Curriculum
Executive Cybersecurity Education
Executive programs may be designed for:
CEOs
CIOs
CISOs
CTOs
Directors
Senior managers
Board members
Risk leaders
Government executives
Programs may focus on:
Enterprise cyber risk
Cybersecurity governance
Board oversight
Cyber resilience
Incident leadership
Cyber crisis management
AI cybersecurity risk
Third-party risk
Security investment
Cybersecurity metrics
Regulatory considerations
Executive decision-making
The objective is to enable leaders to understand cybersecurity as an enterprise risk and strategic leadership responsibility, not simply a technical issue.
Module 37Cybersecurity & Defense Curriculum
Corporate Cybersecurity Training
IBACTP® may provide dedicated cybersecurity programs for:
SOC teams
Security operations teams
IT teams
Cloud teams
Threat intelligence teams
Incident-response teams
Risk and compliance teams
Management
Executive leadership
Organization-wide workforces
Programs may be delivered virtually, onsite, hybrid, or through dedicated corporate cohorts.
Module 38Cybersecurity & Defense Curriculum
Customized Enterprise Cybersecurity Programs
Organizations may request programs aligned with their:
Industry
Threat environment
Technology architecture
Cybersecurity maturity
Workforce roles
Security technologies
Regulatory environment
Risk profile
AI adoption
Business objectives
Customized programs may combine:
Skills Assessment
Role-Based Training
Defensive Labs
Simulations
Certification Preparation
Competency Assessment
Module 39Cybersecurity & Defense Curriculum
Modern Tools and Technologies
Depending on the course and learning objectives, participants may gain exposure to concepts or authorized training environments involving:
SIEM platforms
SOAR platforms
EDR/XDR technologies
Network monitoring tools
Threat intelligence platforms
Vulnerability-management tools
Digital forensic tools
Cloud-security platforms
Identity and access-management technologies
Security automation
AI-assisted security analytics
Threat-hunting technologies
Security dashboards
Cyber-range environments
The emphasis is on developing transferable cybersecurity competencies rather than dependence on a single technology vendor.
Module 40Cybersecurity & Defense Curriculum
Standards and Framework Awareness
Where relevant, training may incorporate concepts associated with recognized cybersecurity and risk frameworks, including:
NIST Cybersecurity Framework
NICE Cybersecurity Workforce Framework
NIST AI Risk Management Framework
ISO/IEC 27001
ISO/IEC 27002
ISO/IEC 27005
ISO/IEC 42001
ISO 31000
MITRE ATT&CK
MITRE D3FEND
Zero Trust principles
CIS Controls
COBIT
Reference to an external standard or framework indicates educational alignment or use of relevant concepts and does not imply accreditation, endorsement, sponsorship, or approval unless formally obtained.
Module 41Cybersecurity & Defense Curriculum
Training Delivery Options at a Glance
IBACTP® Cybersecurity & Defense training may be available through:
Virtual Instructor-Led Training (VILT)
Self-Paced Online Training
Live Classroom Instructor-Led Training
Intensive Cybersecurity Bootcamps
Hands-On Cyber Defense Labs
Cyber Range and Simulation Training
Incident Response Tabletop Exercises
Hybrid Learning
Certification Preparation Programs
Short Courses and Specialized Workshops
Executive Cybersecurity Education
Corporate Team Training
Customized Enterprise Programs
Cohort-Based Training
Module 42Cybersecurity & Defense Curriculum
From Cybersecurity Knowledge to Cyber Resilience
IBACTP® Cybersecurity & Defense training is designed to develop professionals who can understand threats, protect technology environments, detect suspicious activity, investigate incidents, respond effectively, manage cyber risk, and contribute to resilient organizations.
UNDERSTAND
PROTECT
DETECT
ANALYZE
DEFEND
RESPOND
RECOVER
GOVERN
LEAD
Detect Earlier. Defend Smarter. Respond Faster. Lead with Resilience.
IBACTP® Cybersecurity & Defense Training — Developing the Professionals and Leaders Who Protect the Digital Future.
Module 43Cybersecurity & Defense Curriculum
Who Should Attend
This category is suitable for:
Cybersecurity analysts
SOC analysts
Threat intelligence professionals
Security engineers
Incident responders
Digital forensic professionals
Vulnerability analysts
Cyber risk professionals
Security managers
Cybersecurity consultants
IT professionals
Government and defense professionals
Module 44Cybersecurity & Defense Curriculum
Professional and Manager Pathways
Cybersecurity training may support progression from:
Analyst
Specialist
Professional
Manager
Cybersecurity Leader
Professional training emphasizes operational and analytical competency. Manager training emphasizes:
SOC leadership
Program management
Cyber governance
Cyber-risk management
Security strategy
Team leadership
Incident leadership
Executive communication
Module 45Cybersecurity & Defense Curriculum
Tools and Technology Concepts
Participants may encounter:
SIEM
SOAR
EDR/XDR
Threat intelligence platforms
Vulnerability scanners
Cloud security tools
Network monitoring
MITRE ATT&CK
Security automation
AI-assisted security analytics
Forensic tools
Module 46Cybersecurity & Defense Curriculum
Career Relevance
Potential roles include:
Cybersecurity Analyst
SOC Analyst
Threat Intelligence Analyst
Threat Hunter
Incident Response Analyst
Digital Forensics Specialist
Security Operations Manager
Cyber Threat Intelligence Manager
Cybersecurity Manager
Cyber Risk Manager
Security Consultant
Explore Cybersecurity & Defense Training
Detect Threats. Defend Systems. Respond Faster. Lead Cyber Resilience.