In The Bleak Midwinter
Cybersecurity
< All training programs

Cybersecurity

Threat modeling, penetration testing, SOC operations, compliance

A certified curriculum that takes engineers from security fundamentals to offensive and defensive operations, built by practitioners who run real audits and SOC shifts.

What the program covers

Sessions cover threat modeling, network and web application penetration testing, incident response, and the compliance frameworks (ISO 27001, SOC 2, GDPR) your organization is measured against. Every module pairs theory with a lab environment mirroring production infrastructure.

Recent outcomes

  • A financial services client trained 12 engineers to run internal penetration tests, cutting external audit costs by 40%.
  • A SOC team built a full incident-response runbook during the training, now used in production.
  • A public-sector team achieved ISO 27001 readiness after the compliance module.

Technologies covered

  • Kali Linux
  • Burp Suite
  • Metasploit
  • Wireshark
  • Splunk
  • Nessus

Program agenda

Security fundamentals (Day 1)

  • Threat landscape overview
  • Applied cryptography
  • Risk management
  • Legal framework & GDPR

Penetration testing (Days 2–3)

  • Reconnaissance & OSINT
  • Network exploitation
  • Web exploitation (OWASP Top 10)
  • Post-exploitation & pivoting

Defensive operations & SOC (Day 4)

  • Detection & SIEM
  • Incident response
  • Threat hunting
  • Basic forensics

Compliance & governance (Day 5)

  • ISO 27001
  • SOC 2
  • Internal audit
  • Remediation plan

Deliverables

  • Sample penetration test report
  • Incident-response runbook
  • ISO 27001 compliance checklist
  • Certificate of completion

Commitments

  • Group of 6 to 12 people
  • Prerequisites: basic networking & Linux
  • Duration: 5 consecutive days
  • Certified training

Equipment & materials

  • Laptop provided or BYOD
  • Access to an isolated pentest lab
  • Dedicated training VPN
  • Course materials (PDF + slides)