QA Pro AcademyCybersecurity A-Z

Course catalogue

300 courses across five levels. Explore any course to see what it covers — sign in to enrol.

Beginner · 110 courses

CYB-101

Cybersecurity Foundations

A ten-hour guided course that teaches how security actually works — from the CIA triad to running a security programme — using one clinic as a continuous case study.

৳2,000৳5,000View →
CY-BEGINNER-002

Emergency Change Control — The Midnight Release

A nine-hour change-war-room simulation where you classify risk, challenge approvals, rehearse rollback, command a midnight emergency, reconstruct evidence, and design a complete operating model.

৳2,000৳5,000View →
CY-BEGINNER-003

Vulnerability Validation Range — From Scanner Finding to Exploitability Decision

A nine-hour authorized technical range where you scope safely, interrogate scanner output, validate with minimum proof, rate exploitability, model attack paths, write findings, and defend retest conclusions.

৳2,000৳5,000View →
CY-BEGINNER-004

Crypto Agility Drill — Surviving Algorithm and Certificate Change

A nine-hour engineering workbench where you inventory cryptography, control certificates and keys, migrate TLS, prepare post-quantum transition, command a CA compromise, and defend a measurable agility programme.

৳2,000৳5,000View →
CY-BEGINNER-005

Vulnerability Remediation Control Tower — From Finding Noise to Exposure Reduction

A nine-hour live operations queue where you recover asset coverage, validate findings, rank attacker opportunity, govern remediation and exceptions, verify closure, and defend a 90-day exposure-reduction programme.

৳2,000৳5,000View →
CY-BEGINNER-006

Asset Truth Expedition — Find, Name, Own, and Retire What the Bank Depends On

A nine-hour guided missing-asset investigation where one unknown branch device opens a map of hardware, software, information, identities, cloud resources, suppliers, lifecycles, and accountable decisions.

৳2,000৳5,000View →
CY-BEGINNER-007

Wireless Airspace Lab — From Radio Evidence to Trusted Access

A nine-hour RF field survey and engineering lab where you map propagation, trace 802.11 sessions, build WPA identity, isolate guests and devices, command a rogue-AP incident, and defend a measurable wireless architecture.

৳2,000৳5,000View →
CY-BEGINNER-008

Human Signal Studio — Design Safer Decisions, Not Blame

A nine-hour behavioral-design studio where you diagnose real work, prototype moment-of-action controls, run ethical simulations, build role missions, strengthen reporting, and defend an evidence-led security culture.

৳2,000৳5,000View →
CY-BEGINNER-009

Detection Foundry — From Threat Hypothesis to Trusted Alert

A nine-hour detection-content foundry where you qualify telemetry, model behavior, build and test analytics, design usable alerts, tune from evidence, validate end to end, and defend transparent coverage.

৳2,000৳5,000View →
CY-BEGINNER-015

Network Access Control — From Unknown Device to Trusted Access

A nine-hour analyst simulation where you discover a real network, contain rogue access, build identity-aware policy, troubleshoot 802.1X and RADIUS, and defend a safe rollout.

৳2,000৳5,000View →
CY-BEGINNER-073

Application Security Field Lab — From Attack Surface to Secure Program

A nine-hour engineering workbench where you map an application's attack surface, neutralize injection, harden authentication and access control, protect data and secrets, control dependencies, build layered testing, and defend a measurable AppSec program.

৳2,000৳5,000View →
CY-BEGINNER-016

Secure SDLC Phase-Gate — Building Security In, Not Bolting It On

A nine-hour lifecycle simulation where you follow one payments feature through requirements, design, build, review, verification, supply chain, deployment, and response — passing a security gate at every phase.

৳2,000৳5,000View →
CY-BEGINNER-039

DevSecOps Pipeline Command — Guardrails at the Speed of Delivery

A nine-hour pipeline-and-on-call simulation where you turn security into automated guardrails across CI/CD, containers, infrastructure as code, secrets, runtime, and incident response — without slowing delivery.

৳2,000৳5,000View →
CY-BEGINNER-072

Cloud Security Posture Studio — Own Your Half of the Cloud

A nine-hour posture studio where you map shared responsibility on a live architecture diagram, then harden identity, network, data, posture, logging, workloads, and governance for a company mid-migration.

৳2,000৳5,000View →
CY-BEGINNER-052

Zero Trust Architecture Studio — Never Trust, Always Verify

A nine-hour architecture studio where you redesign a bank away from castle-and-moat, deciding identity, device, segmentation, least-privilege, continuous verification, and data-centric controls through architecture decision records.

৳2,000৳5,000View →
CY-BEGINNER-061

IAM Access Desk — Who Gets Into What, and Why

A ten-hour beginner course where you work the access desk of a company, learning identity and access management by deciding who gets into which systems — reading an access matrix, applying least privilege, and handling joiners, movers, and leavers.

৳2,000৳5,000View →
CY-BEGINNER-030

Email Security Desk — Spot the Phish, Handle It Safely

A ten-hour beginner course where you work a company's reported-messages desk, learning to read emails the way an attacker hopes you won't — spotting red flags, understanding email authentication and controls, and handling suspicious messages safely.

৳2,000৳5,000View →
CY-BEGINNER-075

Physical Security — The Security Zones

A thorough, highly interactive beginner course where you assess a facility's physical security as layered zones — perimeter, grounds, building, interior, secure area, and asset. Deter, detect, delay, and respond across the layers; physical access can defeat cyber controls; and human safety always comes first. Four hands-on activities in every lesson.

৳2,000৳5,000View →
CY-BEGINNER-084

Cryptography Foundations — How Encryption Works

A gentle, jargon-free beginner's course on how cryptography actually works. Follow a secret message from Alice to Bob — past Eve, the eavesdropper — and build up encryption, keys, public keys, hashing, signatures, and trust one everyday analogy at a time, until the padlock in your browser makes complete sense. Four gentle activities in every lesson.

৳2,000৳5,000View →
CY-BEGINNER-044

Social Engineering Defense — Spotting the Human Hack

A gentle, jargon-free beginner's course on recognizing and defeating the scams that target people instead of computers — phishing emails, scam texts and calls, impersonation, fake login pages, in-person tricks, and everyday money scams. Learn the eight emotional levers every con pulls, and the one calm habit that beats them all, one everyday example at a time. Four gentle activities in every lesson.

৳2,000৳5,000View →
CY-BEGINNER-027

Data Protection — Follow the File

A gentle, story-driven beginner course that follows one student's file through every room data lives in — collecting, labeling, storing, sharing, keeping, destroying, and answering for it — teaching the everyday habits that protect real people's information, in plain words with no code and no jargon left unexplained.

৳2,000৳5,000View →
CY-BEGINNER-010

Cyber Law & Ethics — Doing the Right Thing Online at Work

A gentle, plain-language start to using computers and data the right way at work — built around one simple question, could this hurt someone, and am I allowed? — for anyone in their first job or first weeks handling other people's information.

৳2,000৳5,000View →
CY-BEGINNER-011

AI Security — Working Safely with AI at Work

A gentle, plain-language guide to using AI tools safely and sensibly at work — built around one simple way of working, treat it as a clever assistant you check, keep private things from, and stay in charge of — for anyone newly handed an AI assistant and unsure how to use it wisely.

৳2,000৳5,000View →
CY-BEGINNER-012

Patch Management — Keeping Your Software Up to Date

A gentle, plain-language guide to keeping your software up to date — why those 'update available' messages matter, and the simple habit that closes the holes attackers rely on: turn on automatic updates, deal with prompts promptly, get updates from the right place, and keep everything fresh.

৳2,000৳5,000View →
CY-BEGINNER-013

Security Operations — Keeping Watch, Together

A gentle, plain-language guide to how a security team keeps watch — and your genuine part in it — built around one simple idea: you're part of the watch, so notice what seems wrong, report it, and know your small habits help keep everyone safe.

৳2,000৳5,000View →
CY-BEGINNER-014

Privacy Management — Looking After People's Information, Properly

A gentle, plain-language guide to how a workplace looks after people's personal information as an organised system, not by luck — know what you hold and why, name an owner, live the rules, mind the helpers, answer people properly, and keep it all alive — the friendly beginner's version of a privacy management system (PIMS).

৳2,000৳5,000View →
CY-BEGINNER-017

Disaster Recovery — When Things Go Wrong, and How to Be Ready

A gentle, plain-language guide to being ready for a workplace's worst day — the backups, the one-page plan, the shared basics, and the hour of practice that turn fire, theft, ransomware, or a dead server from a closing-down notice into a rough fortnight.

৳2,000৳5,000View →
CY-BEGINNER-018

OT & ICS Security — The Computers Inside Things

A gentle, plain-language guide to the hidden computers that run machines, factories, and buildings — why their world plays by different rules (the computers have hands), and the ordinary person's real part in keeping it safe: respect the moat, follow the floor rules, notice and report, and back the specialists.

৳2,000৳5,000View →
CY-BEGINNER-019

Container Security — Apps in Boxes, Shipped Safe

A friendly first course on how modern software ships — apps packed into containers — and the six questions that keep the boxes trustworthy: what's in it, where's it from, how fresh, any secrets, how much power, and did it take the road.

৳2,000৳5,000View →
CY-BEGINNER-020

SIEM — The Signal Line: How the Alarm System Hears

A friendly first course on how an organisation hears its own systems — every action leaves a trace, traces travel to one listening post, rules turn them into questions, and people give the questions meaning.

৳2,000৳5,000View →
CY-BEGINNER-021

Understanding Software Flaws — How Cracks Are Found and Mended

A defensive, plain-language guide to the life story of a software flaw: why all software has them, what makes one serious, who finds them, how finders tell responsibly, how fixes are raced out — and the line between authorised testing and trespass.

৳2,000৳5,000View →
CY-BEGINNER-022

Patient Privacy — Holding a Record Well

A gentle, practical guide to health-information privacy for people who work around patients: why records carry extra weight, who may see them and why, the curiosity problem, careful talk, proper sharing, everyday habits, and what to do the moment something slips.

৳2,000৳5,000View →
CY-BEGINNER-023

What Could Go Wrong? — Thinking a Change Through

Threat modelling as an everyday thinking habit rather than a formal method: four plain questions, asked early, of the people who do the work — and they fit a key cupboard as well as a database.

৳2,000৳5,000View →
CY-BEGINNER-024

Who Decides? — Governance in Plain Words

A forbidding word for a simple thing: who is allowed to decide what, and how decisions stick. Authority, records, policies, exceptions, accountability, and checking — for the people who meet all of it at a desk.

৳2,000৳5,000View →
CY-BEGINNER-025

Being Audited Well — When Someone Comes to Look

The auditee's side of an audit: what auditors actually want, why evidence beats assurances, how to prepare honestly, how to answer on the day, and what to do with the findings afterwards.

৳2,000৳5,000View →
CY-BEGINNER-026

Looking From Outside — Attacker Thinking for People Who Defend

The perspective shift that lets anyone look at their own workplace the way somebody outside would — where the easy way in usually is, what is actually worth wanting, where the permission line sits, and how to report what you notice without ever handing over a method.

৳2,000৳5,000View →
CY-BEGINNER-028

The Unwelcome Program — Malicious Software and What to Do About It

Malicious software for people who aren't analysts: what it actually is, how it ordinarily arrives, what it does to an organisation, the four habits that keep most of it out, and exactly what to do in the first ten minutes when you think you have it.

৳2,000৳5,000View →
CY-BEGINNER-029

How It All Fits Together — The Shape of the Systems You Work With

Architecture without the word: what exists, what's joined to what, and what sits between them — why flat arrangements turn one problem into every problem, and the four questions that make you useful without making you an architect.

৳2,000৳5,000View →
CY-BEGINNER-031

What the Rules Say — Policies, Standards, and the Documents Nobody Reads

What a policy is actually for, how policies, standards, procedures, and guidelines differ, how to read one without reading all of it, why some are never followed, how to ask properly to differ, and how to write one somebody can use.

৳2,000৳5,000View →
CY-BEGINNER-032

Holding the Ground — What Defending Actually Looks Like

The defender's craft as a set of habits: learning what normal looks like, doing the boring work consistently, making the safe way the easy way, slowing down when something's off, learning without blaming, and being honest about what isn't covered.

৳2,000৳5,000View →
CY-BEGINNER-033

Whose Number Is Right? — Looking After the Information You Work With

Two departments, two figures, and nobody wrong — what a word actually means, where a number came from, whether it's good enough for what you're doing with it, who owns it, what it was collected for, and how long you keep it.

৳2,000৳5,000View →
CY-BEGINNER-034

Talking to the Machine — Using Language Models at Work

What a language model actually is, what it doesn't know and can't tell you it doesn't know, why it sounds equally sure when it's wrong, what happens to what you type — and how to use one at work without giving the work away.

৳2,000৳5,000View →
CY-BEGINNER-035

What the Record Says — Logs, Gaps, and Being Able to Find Anything

What a record is for, what's actually in one, why 'we'll check the logs' so often fails, why time is harder than it looks, how long things are kept and by whose decision, and whether anybody can find anything.

৳2,000৳5,000View →
CY-BEGINNER-036

Who's On At Three In The Morning — Cover, Handover, and the Hours Nobody Watches

Who is genuinely on at any given hour, what they can actually do, what the night does to a decision, how a handover loses things, who may wake whom, and which hours you have honestly chosen not to cover.

৳2,000৳5,000View →
CY-BEGINNER-037

The Person Who Checks — Looking At Your Own Organisation and Still Working There On Monday

What checking is actually for, why the insider is both the best-placed and the least objective person available, how to ask so people tell you the truth, and how to say what you found without losing the people you need next year.

৳2,000৳5,000View →
CY-BEGINNER-038

The Laptop In Your Bag — What You're Actually Carrying Around

What has quietly accumulated on the machine you carry, the fact that it takes your employer's things outside your employer's walls every evening, why losing the account matters more than losing the laptop, and what happens in the first hour and at the very end.

৳2,000৳5,000View →
CY-BEGINNER-040

Somebody Else's Hands — Depending On People You Don't Control

What you actually bought as against what you actually depend on, what each supplier can reach, the suppliers behind your suppliers, what happens on their bad week, and how you would ever get your things back.

৳2,000৳5,000View →
CY-BEGINNER-041

The Things That Are Always On — Connected Kit In An Ordinary Building

How much of an ordinary building turns out to be a computer, why nobody owns any of it, the password it arrived with, why nothing ever prompts an update, and the fact that it outlives the company that made it.

৳2,000৳5,000View →
CY-BEGINNER-042

You Only See The Tap — Where Your Work Actually Lives

Your work is not on your machine and never has been, the sign-in is the whole of the protection, services get turned on in ninety seconds and nobody ever turns one off, and a sharing link outlives every reason it was made for.

৳2,000৳5,000View →
CY-BEGINNER-043

Somebody Wrote That Rule — What It Means To Hand A Decision To A Machine

What 'automatic' actually is, which decisions are safe to hand over and which are not, why every automatic rule looks more accurate than it is, who is standing at the other end of one, and why 'the system did it' answers nothing.

৳2,000৳5,000View →
CY-BEGINNER-045

Authorised, And Wrong — How Money Leaves An Organisation

Every route money can go out by, why a change of bank details is the highest-consequence task in the building, why the second signature takes four seconds, and the uncomfortable fact that almost every misdirected payment was correctly authorised.

৳2,000৳5,000View →
CY-BEGINNER-046

Sign To Confirm — Why Access Reviews Certify Everything

Three thousand lines sent to people with eleven minutes, entitlement names nobody in the building can explain, and the asymmetry that makes certifying everything the rational answer.

৳2,000৳5,000View →
CY-BEGINNER-047

It Was On The Register — Living With Risk You Have Accepted

What a risk register actually is, what the word 'accepted' commits anybody to, why an unchanged rating tells you nothing about the risk, and the entry that was correct in every respect on the morning it came true.

৳2,000৳5,000View →
CY-BEGINNER-048

It Keeps Happening — What A Management System Actually Is

A forbidding phrase for an ordinary object: the arrangement by which something keeps happening without anybody having to remember — and the several you already run without calling them that.

৳2,000৳5,000View →
CY-BEGINNER-049

Out Of Five — How Anybody Actually Assesses A Risk

Nobody found the scale; somebody chose it. What a score is shorthand for, how people compare a broken minibus with a leaked passenger list, and why the finding is almost never in the numbers.

৳2,000৳5,000View →
CY-BEGINNER-050

Nineteen Questions — Collecting Less Of Other People's Information

The one protection that is complete, permanent and free: not having it. Why forms only ever grow, what the field nobody can explain is doing there, and the four words that empty most of them.

৳2,000৳5,000View →
CY-BEGINNER-051

The First Hour — What To Do When You Find Something

You are not the investigator. Your job is to leave it possible for somebody else to investigate — and most of what makes that impossible is done by helpful people in the first ten minutes, or by a clock nobody at the company set.

৳2,000৳5,000View →
CY-BEGINNER-053

Our Website — The One You're Responsible For And Didn't Build

It is not one thing; it is nine, bought from seven suppliers over eleven years, and four of them are in the name of somebody who left in 2021. What to find out, in what order, without any technical skill at all.

৳2,000৳5,000View →
CY-BEGINNER-054

The Monthly Return — Eight Boxes And What They Are Actually Saying

Twenty-six months of returns, nobody had asked who reads them, and the backups box had been green for fourteen months without anybody ever testing a restore. Reporting a number honestly, from the side of the person who fills it in.

৳2,000৳5,000View →
CY-BEGINNER-055

Side By Side — Arranging An Exercise Honestly

Two groups who do not normally talk, at an agreed time, with written permission, finding out what each of them can actually see. The arrangement, the authorisation and the write-up — and no technique of any kind.

৳2,000৳5,000View →
CY-BEGINNER-056

Somebody Has Asked — The Day You Have To Produce Everything

A letter asking for everything about one matter, a deadline that started before anybody read it, and nine places nobody had ever written down. What to do first, what counts as a record, and why the search that feels thorough misses whole categories.

৳2,000৳5,000View →
CY-BEGINNER-057

A Number You Did Not Make — Relying On What A Model Tells You

A score a machine produces, a decision about a real person, and a box you cannot see inside. What the number is and is not, when it has quietly stopped being right, and why the human still has to decide.

৳2,000৳5,000View →
CY-BEGINNER-058

The Backup You Never Tested — Keeping A Copy You Can Actually Go Back To

A copy you keep so that losing the live version is an inconvenience, not the end. Where it should live, why a sync is not one, and the question that decides whether it is real: have you ever restored it?

৳2,000৳5,000View →
CY-BEGINNER-059

Running the Incident — How a Small Team Handles One Without Falling Apart

Once something is confirmed real, a handful of ordinary people have to run it together. Who is in charge, the running log, telling the right people, deciding without all the facts, calling it over, and learning from it.

৳2,000৳5,000View →
CY-BEGINNER-060

Reading the Audit — What a Cybersecurity Audit Is, and What Its Findings Actually Mean

You have been told you need a cybersecurity audit, or a report has landed on your desk. What an audit is, why independence and the standard matter, what a finding really means, why it is a sample at a point in time and not a guarantee, and how to act on it.

৳2,000৳5,000View →
CY-BEGINNER-062

On the Radar — Using Threat Intelligence in a Small Organisation

You are drowning in threat bulletins and none the wiser. What threat intelligence actually is, how to tell the few threats that are yours from the many that aren't, where a small firm gets it, how to read it critically, and the one test that matters: so what?

৳2,000৳5,000View →
CY-BEGINNER-063

The Chain — How a Supply-Chain Compromise Reaches You, and What a Small Firm Can Do

The attack does not come from a stranger. It rides in on a software update, a plugin, a component you installed because you trusted its source. Why your chain is longer than you think, why you inherit your suppliers' security, and what a small firm can actually do.

৳2,000৳5,000View →
CY-BEGINNER-064

The Phone — Keeping Safe the Most Exposed Device You Own

Your phone is not a gadget. It is the master key to your accounts and your business, carried everywhere and used among strangers. The lock screen, the apps you let in, the message that is the new phishing, the networks it joins, and the plan for the day you lose it.

৳2,000৳5,000View →
CY-BEGINNER-065

The Tiles — Securing a Business That Lives in Software It Doesn't Run

Your business now lives inside browser apps you log into — email, docs, accounting, the CRM. The provider secures the software; you secure your use of it. The login is the whole front door, and the settings, sharing, and access are yours.

৳2,000৳5,000View →
CY-BEGINNER-066

The Signs — How a Small Business Spots Trouble Without a Security Team

You will never build a detection system or run a SIEM. For a small business, detection means one thing: noticing when something is wrong. Knowing your normal, the free alerts you already have, your people, the signs of trouble, and a small routine.

৳2,000৳5,000View →
CY-BEGINNER-067

The Note — Being Ready for Ransomware Without Paying

Ransomware locks everything at once and demands payment. You can't be sure to prevent it — so being ready means being able to recover without paying. What it is, how it gets in, why paying is a trap, and the plan for the day.

৳2,000৳5,000View →
CY-BEGINNER-068

The Framework — Using NIST CSF and CIS Controls Without Drowning

You don't have to invent security — experts wrote down what good looks like. NIST CSF is a map, CIS Controls a prioritised checklist. Above all: you don't do all of it. You choose the essentials, find and fix your gaps, and keep it real.

৳2,000৳5,000View →
CY-BEGINNER-069

The Settings — Why Configuration Is the Security You Already Have

The same device is safe or wide open depending on how it's set up — so the settings are the security. Default isn't safe. Set things to a baseline, change the settings that matter, expect drift, and keep it right.

৳2,000৳5,000View →
CY-BEGINNER-070

The Register — Keeping Up With the Rules That Apply to You

Compliance is keeping up with the rules that apply to you — an ongoing practice, not a certificate. Know which rules apply, keep them in one register, map each to what you do, hold the evidence, keep it current, and keep it honest.

৳2,000৳5,000View →
CY-BEGINNER-071

The Oversight — Managing Your Use of AI Responsibly

AI increasingly makes decisions about real people, so its use must be managed. Know what AI you use, have a policy, check its risks and impacts, keep a human in charge, never trust it blindly, and stay accountable.

৳2,000৳5,000View →
CY-BEGINNER-074

The Lifeline — Keeping the Business Running When Something Stops You

Business continuity is keeping the essential things running when something disrupts you — not just recovering the computers. Know your essentials, how long you could survive without each, and have a way to keep going.

৳2,000৳5,000View →
CY-BEGINNER-076

The Connections — Securing the Keys That Link Your Apps

Every time you connect one app to another, you create a door into your data. An API key is a password; each connection can do whatever access it was given. Know your connections, give the least access, keep keys secret, and revoke the unused.

৳2,000৳5,000View →
CY-BEGINNER-077

The Engine — Letting Tools Do the Repetitive GRC Work

Keeping on top of rules and risks is full of repetitive admin. Automation means letting tools do the repetitive parts — reminders, evidence, issue-tracking — automatically, on a good process, watched, so you're freed for the judgement only a person can do.

৳2,000৳5,000View →
CY-BEGINNER-078

The Findings — Reading and Acting on a Penetration Test Report

A penetration test is a hired, ethical test that finds your weaknesses so you can fix them first. Its report is a to-do list, not a grade. Read it calmly for impact, fix the worst first by severity, and confirm your fixes with a retest.

৳2,000৳5,000View →
CY-BEGINNER-079

The Scope — PCI DSS for a Small Merchant Taking Card Payments

PCI DSS is the set of rules for taking card payments safely. The key is scope: the less card data you touch, the less applies. Let a compliant provider handle the cards, never store the number, do the questionnaire honestly, mind the human side, and keep it up.

৳2,000৳5,000View →
CY-BEGINNER-080

The Shortlist — Buying Suppliers and Software Without Bringing In Risk

When you buy software, a service, or a supplier, you bring their security into your business. So treat a purchase as a security decision: ask before you sign, choose who'll protect your data, put it in writing, check they're real, give only the access they need, don't just chase price, and keep it up.

৳2,000৳5,000View →
CY-BEGINNER-081

The Layers — Why One Defence Is Never Enough

No single defence is perfect, so you use several — layers — and if one fails, the next holds. Learn to stack different kinds of layer, put the most around what matters most, count your people as a layer, distrust any single defence, and keep every layer working.

৳2,000৳5,000View →
CY-BEGINNER-082

The Undo — Making Changes Without Breaking Things

Most things break right after a change — so change carefully and reversibly. Know what a change touches, have a way to put it back, change one thing at a time, check it worked, and tell people. Never rush a change, and never wave a small one through.

৳2,000৳5,000View →
CY-BEGINNER-083

The Check-Up — Getting Your Systems Tested for Weaknesses

You can't fix what you can't see, so a test finds your weaknesses before an attacker does. A scan is broad and shallow; a test is narrow and deep. Match the check to your need, test what matters, choose a good tester, repeat it, and act on what it finds.

৳2,000৳5,000View →
CY-BEGINNER-085

The Cycle — Keeping On Top of Your Weaknesses

New weaknesses keep appearing, so you can never be 'done' — you run a loop. Keep a running list, fix the worst first by risk, decide on each, check fixes hold, and keep the loop turning. Don't chase zero, and don't let the list rot.

৳2,000৳5,000View →
CY-BEGINNER-086

The Inventory — Knowing What You've Got

You can't protect what you don't know you have — and the forgotten things are the dangerous ones. So keep a complete, current list of everything: devices, accounts, services, and data. Hunt the forgotten, give each thing an owner, catch the shadow stuff, and retire what you stop using.

৳2,000৳5,000View →
CY-BEGINNER-087

The Airwaves — Securing Your Small Business Wifi

Your wifi is a door into your business, and its signal reaches past your walls — so anyone nearby can try it. Lock it with a strong password and modern encryption, change the router's known defaults, keep guests on a separate network, look after the router, be careful on wifi that isn't yours, and keep it all up.

৳2,000৳5,000View →
CY-BEGINNER-088

The Dial — Staying Switched On to Security at Work

Being security-aware isn't a technical skill or a once-a-year training — it's keeping the dial turned up: a little calm attention woven through your ordinary work. Security is everyone's business, you're a target, so you slow down and notice, keep a few everyday habits, speak up when something's off, mind what you share, and keep it all up.

৳2,000৳5,000View →
CY-BEGINNER-089

The Drill — Commissioning and Learning From a Security Drill

A red team sounds alarming, but it's really a drill: a safe, planned rehearsal in which, with your permission, a team plays a realistic attacker to see how you'd really cope. It's better to find your gaps in a drill than for real — so you run it with permission and rules, test people and response not just walls, judge it by what you learn, keep it blameless, don't rig it, and act on what it finds.

৳2,000৳5,000View →
CY-BEGINNER-090

The Line — Using the Access You're Trusted With

The access you're given to systems and data is a trust, lent to you for your job. So just because you can see something doesn't mean you may look at it. Use your access only for your job, don't go looking at what isn't your business, don't take data with you, remember there's real law behind it — and do the right thing even when no one is watching.

৳2,000৳5,000View →
CY-BEGINNER-091

The Draft — Using AI Output Responsibly

What an AI tool gives you is a draft, not an answer: a fast, useful first version that can be confidently wrong and never knows it. So you stay in charge, check what matters — especially before you act — keep your own judgement, and own the result. Use it as a draft, and own the result.

৳2,000৳5,000View →
CY-BEGINNER-092

The Later Button — Why You Shouldn't Put Off Updates

A security update closes a known hole in your software, so pressing 'remind me later' leaves that hole open — and 'later' rarely comes, while attackers race to exploit known holes. So you press update, not later, and turn on automatic updates so it mostly happens by itself.

৳2,000৳5,000View →
CY-BEGINNER-093

The First Move — What To Do When Something Goes Wrong

When a security incident happens — a dodgy link clicked, an account acting up, a device lost, a ransom message — the calm first move is simple: stay steady, tell the right person straight away, and don't make it worse. Not panic, not hiding it, not fixing it alone — just the sensible thing anyone can do.

৳2,000৳5,000View →
CY-BEGINNER-094

Travel Light — Holding Only the Personal Data You Need

Every piece of personal data you hold is a liability as well as an asset — a risk and a responsibility, not just something useful. So travel light: collect only what you genuinely need, don't keep things 'just in case', and let go of data once you're done. Hold less, keep less.

৳2,000৳5,000View →
CY-BEGINNER-095

The Gatekeeper — How a Firewall Protects Your Network

Your network has an inside and an outside, and the firewall is the gate between them. Keep it closed by default, open only the few things you genuinely need, and it blocks the uninvited from the internet while still letting your own devices reach out. Not a mystery box — a gatekeeper on your boundary.

৳2,000৳5,000View →
CY-BEGINNER-096

The Foundations — Building Security In From the Start

When you get something new built, bought, or set up, security works best built in from the start — like a building's foundations — not bolted on at the end. Ask what needs protecting and what could go wrong, early; keep it in mind as it's made; treat safe as part of finished. Build it in, don't bolt it on.

৳2,000৳5,000View →
CY-BEGINNER-097

The Safety Copy — Backups That Actually Save You

The single most useful thing you can do to survive a data disaster is keep a safety copy of what matters. But a copy in the same place dies with the original, one copy can fail, a manual one gets forgotten, and an untested one may not work. A real backup is kept somewhere separate, made automatically, and tested by actually restoring.

৳2,000৳5,000View →
CY-BEGINNER-098

Not the Office — Looking After the Computers That Run Machines

The computers that run machines and physical processes aren't office PCs, and the office security playbook doesn't fit them. They control physical things, can't just be patched or rebooted, are often old, and put safety and uptime first. Treat them differently: keep them separate, change them carefully, and work with the people who run them.

৳2,000৳5,000View →
CY-BEGINNER-099

What's in the Box — Keeping Your Containers Clean

A container is a box that ships everything inside it, so its security is mostly about what's in the box. You build on a base image someone else made — and inherit its problems too. Keep the box small, know what's inside, never bake in a secret, and rebuild on updates to stay clean.

৳2,000৳5,000View →
CY-BEGINNER-100

The Footage — Keeping Records So You Can Look Back

Your systems' logs are their footage — the recorded evidence of what happened. Without it you're blind, live and afterwards. So keep good footage: record the things that would matter if something went wrong, keep it long enough, in one place you can search, and protected from tampering — so that when something goes wrong, you can look back and know.

৳2,000৳5,000View →
CY-BEGINNER-101

The Warning Ladder — How Serious Is This Weakness?

A reported weakness isn't yet an attack. How urgent it is depends on how close it is to being a usable, working attack — a ladder from 'a weakness is reported' up to 'it's being used in the wild'. Read the rung to judge the urgency, and whatever the rung, close the weakness — by patching or mitigating. A defender's guide to reading the signal, calmly.

৳2,000৳5,000View →
CY-BEGINNER-102

The Three Safeguards — How a Practice Keeps Health Records Safe

A gentle, practical guide for a small healthcare practice: keeping the health records you hold safe rests on three safeguards held up together — rules & people, doors & desks, and screens & passwords — plus the helpers who touch the records must promise too, and if something slips you tell the right people in time. The practice's own job, done plainly.

৳2,000৳5,000View →
CY-BEGINNER-103

The Crossings — Spotting Where Your Data Is At Risk Before You Build

The craft of threat modelling for a small project, made plain: before you build, draw it simply, follow the data through it, and find the crossings — where data passes between what you control and what you don't — because the crossings are where the risk lives. Then think what could go wrong at each, and decide what to do.

৳2,000৳5,000View →
CY-BEGINNER-104

The Steering Loop — Governing Security on a Rhythm, Not in a Panic

Security governance in plain words, and in motion: a group steering security on purpose, on a regular rhythm — set the direction, meet on a rhythm, look at what matters, decide and make it stick, and follow through — kept turning, so you steer instead of forever firefighting.

৳2,000৳5,000View →
CY-BEGINNER-105

The Spot Check — Checking Your Security by Evidence, Not Assuming

The checker's craft in plain words: find out whether your security basics are actually being done by looking, not assuming. Know the field of what could be checked, check a fair sample by evidence rather than by what people say, and turn the gaps into blameless findings that get closed and stay closed.

৳2,000৳5,000View →
CY-BEGINNER-106

The Agreed Test — Commissioning a Safe Security Check

A decision-maker's plain guide to safely commissioning and receiving an authorised security test: what such a test is, why written permission is everything, how to agree the scope and rules of engagement, the ethic of finding-not-breaking, and how to receive the report well. The commissioner's side only — never how to perform a test.

৳2,000৳5,000View →
CY-BEGINNER-107

The Tiers — Protecting Data by How Sensitive It Is

A gentle, practical guide to the plainest idea in data protection: not all data is equal, so sort it by how sensitive it is and protect each level accordingly. Sort it into a few tiers, label it, guard the precious more (locks and encryption), watch the exits where data leaks, and act fast if it does.

৳2,000৳5,000View →
CY-BEGINNER-108

The Sealed Room — Handling a Suspicious File Safely

A gentle, non-technical guide to the one habit that keeps a suspicious file from hurting you: treat it as a suspect. Don't run it on your real machine and don't just delete it. Contain it, look at the outside first, open it only in a sealed room if you genuinely must, note the fingerprints it leaves, and hand the real analysis to the experts. Safe handling and awareness only.

৳2,000৳5,000View →
CY-BEGINNER-109

The Blueprint — Building Security In From the Start

A gentle, non-technical guide to the plainest idea in security architecture: build security IN when you design, choose, or set something up — don't bolt it on afterwards. Ask the security questions as you design, start safe by default, design for when it goes wrong, and keep it simple.

৳2,000৳5,000View →
CY-BEGINNER-110

The Outbox — Being Careful With What You Send by Email

A gentle, non-technical guide to the other half of email safety — not the threats that arrive, but the mistakes that leave. A send can't be unsent, so a moment's care before you send prevents the everyday leaks: check who it's going to, mind what's attached, ask whether it should go by email at all, and use bcc for a group.

৳2,000৳5,000View →

Mid Level · 109 courses

CY-MID-034

SOC Analyst Command — Working the Live Alert Queue

A sixteen-hour, hands-on-the-console course where you take the analyst's seat on a SOC floor and work real shifts — triaging the queue, investigating to a verdict, responding, escalating, and handing over — through a live console and multi-step shift simulations.

৳4,000৳8,000View →
CY-MID-037

Privacy Engineering — Following the Data

A twenty-hour mid-level course where you are a privacy engineer at a consumer health app, following one piece of personal data along its whole journey — collection, use, storage, sharing, retention, deletion — and learning to steward other people's data in a way that earns their trust, not just passes an audit.

৳4,000৳8,000View →
CY-MID-049

Threat Intelligence Cell — Tradecraft and Judgement

A seventeen-hour mid-level course where you work a financial firm's threat intelligence cell tracking an adversary campaign — turning feeds into decision-ready intelligence on the Diamond Model and intelligence cycle, mapping behaviour to ATT&CK, attributing carefully, and stating confidence rather than certainty.

৳4,000৳8,000View →
CY-MID-021

LLM Application Security — Building AI Features Safely

A twenty-hour, highly interactive mid-level course where you secure an AI assistant along a live LLM-application pipeline — treating the model as untrusted, assuming prompt injection can succeed, containing an agent's blast radius, and building so a manipulated model can do little harm. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-061

Cyber Resilience & Business Continuity — Ready Before the Disruption

A twenty-hour, highly interactive mid-level course where you are a resilience lead at a logistics company, working along the resilience curve — analysing impact, setting recovery objectives, building tested recovery, managing dependencies, exercising, and readying the organisation to withstand and recover from disruption before it comes. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-017

API Security — The Request Checkpoint

A twenty-hour, highly interactive mid-level course where you secure an API at every request — authenticating the caller, authorizing on the server, validating input, controlling data, limiting resources, and knowing every endpoint. APIs are the dominant attack surface, and broken authorization is the number one risk. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-036

Network Traffic Analysis — Reading the Wire

A deeply technical, hands-on mid-level course that reads network traffic at the byte and protocol level. Peel each frame apart on the packet dissector — Ethernet, IP, TCP/UDP, and the application payload — and learn to find, follow, and interpret the packets that matter, from real capture files with real tcpdump and tshark syntax. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-059

Linux Server Hardening — The Hardening Bench

A hands-on, workshop-style mid-level course that hardens a Linux server one control at a time. Work the hardening surface board — Accounts, SSH, Services, Firewall, Filesystem, Kernel, Logging, Updates — applying real commands and configs, verifying every change on the running system, and building a reproducible, fleet-ready baseline. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-074

Web Security — Hardening the Exchange

A hands-on, task-first mid-level course that hardens a real web application one defense surface at a time. Work the exchange inspector across eight surfaces — TLS, headers, cookies, CSP, auth, input/output, framing, and origins — applying real nginx and app configs and proving every defense from the command line with genuine curl and openssl read-backs. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-062

IoT Security — The Device Floor

A technical, field-driven course on securing the connected devices a hospital runs but cannot treat like computers — infusion pumps, monitors, cameras, building systems — across eight attack surfaces, under the first-order constraint that no control may harm a patient or take a life-supporting device offline.

৳4,000৳8,000View →
CY-MID-005

Mobile Security — The Fleet in Your Pocket

A technical, hands-on course on securing a fleet of smartphones and tablets — the most personal, portable, and least controllable computers an enterprise runs — across eight aspects of mobile posture, working with the platform, the management channel, and the personal/work boundary rather than the laptop playbook.

৳4,000৳8,000View →
CY-MID-002

Identity & Access Operations — The Lifecycle Rail

A hands-on mid-level course that runs identity as a living pipeline. Work the access lifecycle rail — Request, Approve, Provision, Authenticate, Elevate, Move, Review, Deprovision — driving joiner/mover/leaver events, phishing-resistant MFA and conditional access, just-in-time privilege and vaulting, access certification, and complete offboarding, with real operator commands across Entra ID, AWS IAM, Active Directory, Okta, and a PAM vault. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-003

Vulnerability Management Operations — The Remediation Funnel

A hands-on mid-level course that runs vulnerability management as a flow: thousands of raw findings in, a proven-fixed few out. Work the remediation funnel — Discover, Scan, Enrich, Prioritize, Assign, Remediate, Verify, Report — prioritizing by real risk (KEV, EPSS, exposure, criticality) over raw CVSS, with real analyst commands across authenticated scanners, container and cloud scanning, patch tooling, and re-scan verification. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-010

Logging & Telemetry Engineering — The Telemetry Ring

A deeply technical mid-level course that builds the telemetry every detection, investigation, and audit depends on. Follow a security event clockwise around the telemetry ring — Sources, Collect, Parse, Time & Integrity, Enrich, Store, Health, Serve — keeping the signal complete, correctly timed, tamper-evident, retained, and usable, with real engineer commands across auditd, Fluent Bit, Kafka, chrony, WORM storage, and OpenSearch. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-013

Cloud Security Posture Management — The Posture Board

A hands-on mid-level course that operates the security posture of a multi-account cloud estate. Work the posture board — Identity, Network, Data, Compute, Guardrails, Secrets, Visibility, and Posture Ops — finding the misconfigurations behind most cloud breaches and fixing them with secure defaults and preventive guardrails, using real commands across AWS and Azure CLI, Terraform, and OPA/Rego policy. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-011

Compliance Operations — The Assurance Staircase

A mid-level course that runs a security compliance program as continuous operations, not an annual scramble. Climb the assurance staircase — Obligations, Scope, Controls, Implement, Evidence, Monitor, Assess, Report — building an unbroken line of sight from each requirement to the evidence that proves a control genuinely operates, with real work across obligation registers and OSCAL, control mapping, automated evidence collection, continuous control testing, and attestation reporting. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-071

Application Security Engineering — The Defense Stack

A hands-on mid-level course that secures a web application layer by layer, as the engineer who builds and fixes it. Work the defense stack — Edge & Transport, Authentication, Authorization, Input Handling, Application Logic, Dependencies, Secrets & Config, and Data & Privacy — finding each vulnerability class with a safe probe against your own app and closing it in the server-side code, verified with a test. Strictly defensive, always paired with the fix. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-033

Backup & Recovery Resilience — The Recovery Timeline

A hands-on mid-level course that builds backups which actually restore, and the ability to recover fast and completely from ransomware or disaster. Work the recovery timeline - four readiness stages before the incident that shrink data loss (RPO) and four recovery stages after it that shrink downtime (RTO): Scope, Strategy, Immutability, Restore Testing, then Declare, Execute, Validate, Improve - with real backup tooling, immutability, restore tests, and recovery runbooks. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-014

Privacy Engineering — The Privacy Map

A hands-on mid-level course that engineers privacy into a product handling a great deal of personal data. Work the privacy map - the person's data at the centre, protected by eight disciplines: Data Mapping, Privacy by Design, Lawful Basis, Consent, Rights, Minimization, De-identification, and Privacy in Analytics - collecting only what is needed, honouring people's rights, and building privacy in by default, with real privacy tooling. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-015

Patch Management Operations — The Patch Pipeline

A hands-on mid-level course that patches a fleet promptly, safely, and verifiably - closing known vulnerabilities before they are exploited without breaking production. Work the patch pipeline - eight stages a patch passes through: Inventory, Detect, Assess, Prioritize, Test, Deploy, Verify, and Report - patching by real risk but tested and verified, with real asset and software inventory, patch scanning, KEV/EPSS prioritization, patch testing, ringed deployment, and verification. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-012

Configuration Management & Secure Baselines — The Config Lifecycle

A hands-on mid-level course that keeps every system in a known, secure configuration and stops it drifting away. Work the config lifecycle - eight stages: Baseline, Harden, Enforce, Detect, Remediate, Change, Audit, and Improve - defining a secure baseline, enforcing it as code, and detecting and remediating drift, with real CIS benchmarks, hardening, config-as-code and desired-state enforcement, drift detection, and change control. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-016

SaaS Security Posture Management — The SaaS Estate

A hands-on mid-level course that secures the sprawling estate of SaaS applications an organization runs, where most of its data and identity now live. Work the SaaS estate - eight domains: Discovery, Identity & SSO, Access, Configuration, Data & Sharing, Integrations & OAuth, Monitoring, and Vendor & Compliance - securing the customer side of the shared responsibility, with real SaaS discovery, SSO/MFA and SCIM, least-privilege, SSPM misconfiguration checks, external-sharing control, OAuth governance, and audit-log monitoring. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-007

Threat Modeling — The Threat Model Loop

A hands-on mid-level course that finds security problems in a design before they are built, by modeling the system and reasoning about what can go wrong. Work the threat model loop - eight stages a model cycles through: Scope, Diagram, Identify, Assess, Mitigate, Validate, Document, and Iterate - answering the four questions and ending in decisions, not a list, with real data flow diagrams, trust boundaries, STRIDE and LINDDUN enumeration, risk rating, and mitigation design. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-004

Email Security Operations — The Email Defense Stack

A hands-on mid-level course that defends an organization's email against phishing, business email compromise, and malware - the channel most attacks arrive through. Work the email defense stack - eight layers a message passes from arrival to the user and back out: Authentication, Reputation, Anti-Spam, Anti-Malware, Content & URL, User, Detection & Response, and Outbound & Data - authenticating senders, filtering and scanning, and stopping phishing and BEC, with real SPF/DKIM/DMARC, MTA-STS, sandboxing, URL protection, and clawback. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-006

Secure CI/CD Pipeline Security — The Pipeline Gates

A hands-on mid-level course that secures the software delivery pipeline so only trusted, verified code and artifacts reach production and the pipeline itself cannot be turned into an attack. Work the pipeline gates - eight gates code passes from commit to release: Source, Dependencies, Build, Test, Artifact, Config, Deploy, and Runtime - making security a gate that fails the build on real findings and verifying every artifact, with real branch protection, SCA/SBOM, SLSA provenance, SAST gates, artifact signing, and OIDC deploy credentials. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-019

IoT & OT Device Security — The OT Security Board

A hands-on mid-level course that secures the operational technology and connected devices running physical processes, where a compromise can stop production or endanger safety. Work the OT security board - eight domains: Inventory, Segmentation, Hardening, Access, Patching, Monitoring, Safety, and Supply Chain - putting safety first, segmenting the network, and monitoring passively, with real passive discovery, Purdue-model zoning, device hardening, and OT-safe patching. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-008

Applied Cryptography & Key Management — The Key Lifecycle

A hands-on mid-level course that uses cryptography correctly and manages keys through their whole life. Work the key lifecycle - eight stages a key climbs from birth to retirement: Generate, Distribute, Store, Use, Rotate, Revoke, Destroy, and Audit - using vetted primitives, keeping keys secret and managed, and never reusing a key or a nonce, with real OpenSSL, KMS/HSM, envelope-encryption, authenticated-encryption, rotation, and crypto-inventory work. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-009

Zero Trust Architecture — The Zero Trust Fabric

A hands-on mid-level course that re-architects a network built on implicit trust into one that never trusts and always verifies. Work the zero trust fabric - eight pillars an architect must make trustless: Identity, Devices, Networks, Applications, Data, Visibility, Automation, and Governance - removing implicit trust, verifying every access explicitly, granting least privilege, and assuming breach, with real conditional-access, ZTNA, micro-segmentation, mTLS, and policy-as-code work. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-018

Detection Engineering — The Detection Pipeline

A hands-on mid-level course that builds detections which catch real attacks without drowning the SOC in noise. Work the detection pipeline - eight stages from idea to measured value: Sources, Hypothesis, Author, Test, Tune, Deploy, Coverage, and Measure - writing threat-informed, robust, tested, tuned, and measured detections with real Sigma rules, SIEM queries, safe atomic tests, and ATT&CK coverage. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-020

Incident Response Operations — The Response Funnel

A hands-on mid-level course that runs a security incident from first alert to lessons learned. Work the response funnel - eight stages a case passes through: Prepare, Detect, Triage, Contain, Eradicate, Recover, Notify, and Learn - responding fast, cleanly, and provably with real containment, evidence handling, eradication, and recovery work. Grounded in NIST 800-61 and SANS PICERL; strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-022

Digital Forensics & Evidence Handling — The Evidence Staircase

A hands-on mid-level course that turns a suspect system into defensible evidence. Climb the evidence staircase - eight steps from scene to stand: Identify, Preserve, Acquire, Authenticate, Examine, Analyze, Report, and Testify - imaging with write-blockers, proving integrity with hashes, keeping chain of custody, and building a timeline that holds up. Grounded in NIST 800-86 and ISO 27037; lawful and authorized throughout. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-023

Endpoint Detection & Response Operations — The Endpoint Defense Stack

A hands-on mid-level course that operates an EDR/XDR platform across a fleet of endpoints. Work the endpoint defense stack - eight layers from Prevention and Telemetry through Detection, Triage, Investigation, Containment, and Remediation to Threat Hunting - reading sensor telemetry, writing ATT&CK-mapped detections, isolating hosts, and hunting proactively. Strictly defensive: you operate on endpoints you manage. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-024

Container & Kubernetes Security — The Cluster Security Board

A hands-on mid-level course that hardens containers and the Kubernetes clusters that run them. Work the cluster security board - eight domains: Images, Supply Chain, Cluster Config, Network Policy, RBAC & Identity, Pod Security, Runtime, and Secrets - building minimal signed images, default-deny network policy, least-privilege RBAC, and policy-as-code admission control. Grounded in the CIS Kubernetes Benchmark and Pod Security Standards; defensive throughout. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-025

Secrets Management — The Secret Lifecycle

A hands-on mid-level course that keeps API keys, credentials, and tokens out of code and safely managed. Work the secret lifecycle - eight stations: Generate, Store, Distribute, Inject, Rotate, Audit, Revoke, and Recover - using a vault, dynamic short-lived secrets, runtime injection, rotation, and secret scanning to close the leaks. Grounded in vault/KMS practice; strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-026

API Security Engineering — The API Defense Loop

A hands-on mid-level course that secures the REST and GraphQL APIs you build and operate. Work the API defense loop - eight arcs: Inventory, Authentication, Authorization, Input Validation, Rate Limiting, Data Exposure, Logging & Monitoring, and Lifecycle - closing the OWASP API Security Top 10 with per-object authorization, validated JWTs, schema validation, and quotas. Every probe is against your own test API and paired with the fix. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-027

Data Loss Prevention Operations — The DLP Pipeline

A hands-on mid-level course that keeps sensitive data from leaving where it shouldn't. Work the DLP pipeline - eight stages: Classify, Discover, Monitor, Detect, Enforce, Educate, Investigate, and Report - across endpoint, network, cloud, and email, with real classification, content inspection, policy enforcement, and investigation. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-029

DNS Security — The DNS Defense Rail

A hands-on mid-level course that secures resolvers, zones, and DNS traffic. Work the DNS defense rail - eight stations: Resolve, Validate, Filter, Encrypt, Authenticate, Monitor, Harden, and Respond - deploying DNSSEC, RPZ filtering, encrypted DNS, tunneling detection, and resolver hardening with real dig, BIND/Unbound, and log work. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-030

DDoS Defense & Mitigation — The DDoS Defense Stack

A hands-on mid-level course that keeps a service online under attack. Work the DDoS defense stack - eight layers: Edge & Anycast, Network Filtering, Rate Limiting, Protocol Defenses, Application Defenses, Scrubbing, Failover & Capacity, and Runbook - absorbing volumetric, protocol, and application-layer attacks with real edge, firewall, and WAF work. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-038

Database Security — The Database Defense Stack

A hands-on mid-level course that secures the databases behind a payments platform. Work the database defense stack - eight layers: Access Control, Authentication, Encryption, Network Isolation, Query Defense, Auditing, Backup & Recovery, and Monitoring - applying least privilege, TDE, private networking, parameterized queries, and audit logging across PostgreSQL, MySQL, and SQL Server. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-028

Windows Server Hardening — The Hardening Board

A hands-on mid-level course that hardens a fleet of Windows Servers to a defensible baseline. Work the hardening board - eight domains: Accounts, Authentication, Services & Roles, Network, Logging & Audit, Updates, App Control, and Backup & Recovery - applying the CIS Benchmark via group policy, LAPS, Credential Guard, SMB signing, WDAC/AppLocker, and audit policy. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-031

Security Awareness Program Management — The Awareness Loop

A hands-on mid-level course that runs a human-risk program that actually changes behaviour. Work the awareness loop - eight stages: Assess, Plan, Build Content, Deliver, Phishing Simulation, Measure, Reinforce, and Improve - designing role-based training, ethical phishing tests, and metrics that reward reporting over shaming. Strategic and people-centred. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-032

Threat Intelligence Operations — The Intelligence Staircase

A hands-on mid-level course that runs a threat-intelligence function that feeds the SOC. Climb the intelligence staircase - eight steps: Direction, Collection, Processing, Analysis, Production, Dissemination, Feedback, and Action - setting requirements, collecting from OSINT and feeds, analysing with the Diamond Model and ATT&CK, and turning intel into detections. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-035

Network Segmentation & Firewall Engineering — The Segmentation Board

A hands-on mid-level course that carves a flat network into defensible zones. Work the segmentation board - eight domains: Zones & Design, Firewalls, Rule Hygiene, Micro-segmentation, East-West Control, Egress Filtering, Remote & VPN, and Monitoring - designing trust zones, least-access firewall rules, and lateral-movement containment with real rule and flow work. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-039

Privileged Access Management — The Privilege Lifecycle

A hands-on mid-level course that brings privileged accounts under control. Work the privilege lifecycle - eight stations: Discover, Vault, Broker, Elevate, Session, Rotate, Audit, and Revoke - putting admin credentials in a vault, granting just-in-time least-privilege access, recording sessions, and rotating secrets. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-040

TLS & PKI Certificate Management — The Certificate Lifecycle

A hands-on mid-level course that runs certificates and trust without outages or weak crypto. Climb the certificate lifecycle - eight steps: Plan, Generate, Issue, Deploy, Validate, Monitor, Renew, and Revoke - building a CA hierarchy, strong TLS, automated renewal, and revocation with real OpenSSL and ACME work. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-041

Ransomware Defense — The Ransomware Defense Stack

A hands-on mid-level course that hardens an organisation against ransomware end to end. Work the ransomware defense stack - eight layers: Email & Web, Endpoint, Identity, Network, Backups, Detection, Response, and Recovery - closing initial-access paths, stopping lateral movement, protecting immutable backups, and rehearsing recovery. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-042

Wireless Network Security — The Wireless Security Board

A hands-on mid-level course that secures enterprise Wi-Fi and the airspace around it. Work the wireless security board - eight domains: Architecture, Authentication, Encryption, Segmentation, Rogue Detection, Guest & BYOD, Monitoring, and IoT Wireless - deploying WPA3-Enterprise, 802.1X, network separation, and rogue-AP detection. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-043

VPN & Secure Remote Access — The Remote Access Rail

A hands-on mid-level course that gives remote users safe access without opening the network. Work the remote access rail - eight stations: Design, Authenticate, Tunnel, Authorize, Posture, Segment, Monitor, and Retire - deploying modern VPN and ZTNA, strong MFA, device posture, and least-privilege access. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-044

Insider Threat Program — The Insider Risk Loop

A hands-on mid-level course that builds a fair, effective insider-risk program. Work the insider risk loop - eight stages: Govern, Identify, Detect, Investigate, Respond, Protect, Educate, and Improve - combining behavioural and technical indicators, privacy-respecting monitoring, and proportionate response. Ethical and rights-respecting throughout. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-045

Security Automation Engineering — The Automation Pipeline

A hands-on mid-level course that automates repetitive security work safely. Work the automation pipeline - eight stages: Identify, Design, Script, Integrate, Test, Guardrail, Deploy, and Maintain - writing Python and API integrations that enrich alerts, gate actions, and run with approvals and rollback. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-046

PCI DSS Compliance — The Compliance Staircase

A hands-on mid-level course that takes a business through PCI DSS v4.0 as real operations. Climb the compliance staircase - eight steps: Scope, Segment, Protect Data, Control Access, Secure Systems, Monitor, Test, and Attest - reducing scope, protecting cardholder data, and building continuous evidence. Honest and audit-ready throughout. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-047

Active Directory Security — The AD Defense Board

A hands-on mid-level course that hardens Active Directory - the keys to the kingdom. Work the AD defense board - eight domains: Accounts, Privilege Tiering, Kerberos, Delegation, GPO & Config, Trusts, Detection, and Recovery - closing the paths attackers use to reach Domain Admin. Grounded in Microsoft's tiered-admin model; strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-048

Threat Hunting — The Hunt Staircase

A hands-on mid-level course that proactively hunts adversaries who slipped past detections. Climb the hunt staircase - eight steps: Hypothesize, Scope, Collect, Baseline, Hunt, Analyze, Respond, and Operationalize - running ATT&CK-informed, behaviour-based hunts and turning findings into new detections. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-050

Cloud Incident Response — The Cloud IR Stack

A hands-on mid-level course that responds to incidents in AWS, Azure, and GCP. Work the cloud IR stack - eight layers: Readiness, Detect, Scope, Preserve, Contain, Eradicate, Recover, and Learn - using cloud logs, snapshots, and APIs to investigate and contain without breaking the business. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-051

Cyber Risk Management — The Risk Loop

A hands-on mid-level course that runs cyber risk as a disciplined, repeatable cycle. Work the risk loop - eight stages: Context, Identify, Analyze, Evaluate, Treat, Monitor, Report, and Improve - building a risk register, scoring consistently, and driving real treatment decisions. Grounded in NIST RMF and ISO 27005; decision-driven. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-052

Software Supply Chain Security — The Supply Chain Pipeline

A hands-on mid-level course that secures everything your build trusts. Work the supply chain pipeline - eight stages: Source, Dependencies, Build, Sign, SBOM, Verify, Deploy, and Respond - defending against dependency, build, and artifact tampering with real SLSA, Sigstore, and SBOM work. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-053

Fraud Detection & Prevention — The Fraud Defense Stack

A hands-on mid-level course that stops account and payment fraud without blocking real users. Work the fraud defense stack - eight layers: Signals, Identity, Device, Behaviour, Rules, Models, Review, and Feedback - combining signals into risk decisions and tuning to catch fraud with low friction. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-054

Cloud IAM — The Cloud Access Rail

A hands-on mid-level course that gets cloud identity and access right across AWS, Azure, and GCP. Work the cloud access rail - eight stations: Identities, Authenticate, Authorize, Federate, Least Privilege, Secrets, Monitor, and Review - eliminating long-lived keys, right-sizing policies, and catching privilege drift. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-055

Security Architecture & Design — The Architecture Board

A hands-on mid-level course that builds security into systems by design. Work the architecture board - eight domains: Requirements, Trust Boundaries, Identity, Data, Network, Resilience, Secure Defaults, and Review - turning requirements and threats into concrete, defensible design decisions. Grounded in secure-by-design principles. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-056

Web Application Firewall Operations — The WAF Defense Stack

A hands-on mid-level course that runs a WAF that blocks attacks without blocking customers. Work the WAF defense stack - eight layers: Deployment, Signatures, Rules, Rate Limiting, Bot Defense, Tuning, Monitoring, and Response - deploying managed and custom rules, cutting false positives, and stopping OWASP-class attacks and bots. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-057

OAuth 2.0 & OIDC Security — The Authorization Staircase

A hands-on mid-level course that implements OAuth 2.0 and OpenID Connect securely. Climb the authorization staircase - eight steps: Flows, Clients, Tokens, Scopes, Validate, Sessions, Federate, and Revoke - choosing the right flow with PKCE, validating JWTs correctly, and closing the misconfigurations that break auth. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-058

Identity Governance & Administration — The Governance Rail

A hands-on mid-level course that governs who has access to what, and proves it. Work the governance rail - eight stations: Sources, Provision, Roles, Request, Approve, Certify, Separate Duties, and Deprovision - automating joiner-mover-leaver, running access reviews, and enforcing segregation of duties. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-060

Serverless Security — The Serverless Security Board

A hands-on mid-level course that secures serverless functions and event-driven apps. Work the serverless security board - eight domains: Identity, Permissions, Code, Dependencies, Secrets, Events, Runtime, and Monitoring - applying least-privilege function roles, input trust, and event-source security across AWS Lambda and friends. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-063

Password & Authentication Security — The Authentication Pipeline

A hands-on mid-level course that builds authentication attackers can't walk through. Work the authentication pipeline - eight stages: Policy, Storage, Login, MFA, Recovery, Sessions, Passwordless, and Monitor - hashing right, adding phishing-resistant MFA, and defending against credential stuffing and account takeover. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-064

Cyber Deception & Honeypots — The Deception Loop

A hands-on mid-level course that catches intruders with deception that produces high-signal alerts. Work the deception loop - eight stages: Strategy, Honeytokens, Honeypots, Placement, Alerting, Triage, Maintain, and Improve - seeding decoys and canaries so any touch is a near-certain intrusion signal. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-065

Data Governance & Classification — The Data Governance Staircase

A hands-on mid-level course that knows what data you hold, how sensitive it is, and who may touch it. Climb the data governance staircase - eight steps: Inventory, Classify, Label, Own, Control, Retain, Protect, and Audit - building a data catalog, classification scheme, and enforceable handling rules. Honest and rights-respecting. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-066

Purple Teaming & Detection Validation — The Validation Rail

A hands-on mid-level course that proves your detections work by testing them safely. Work the validation rail - eight stations: Plan, Emulate, Detect, Measure, Gap, Improve, Automate, and Report - running authorized ATT&CK-based emulation against your own environment and closing detection gaps. Strictly defensive and authorized. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-067

Intrusion Detection & Prevention — The Network Defense Stack

A hands-on mid-level course that detects and blocks attacks in network traffic. Work the network defense stack - eight layers: Sensors, Signatures, Anomaly, Tuning, Prevention, Encrypted Traffic, Correlation, and Response - deploying IDS/IPS, writing and tuning rules, and cutting false positives with real Suricata and Zeek work. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-068

Secure Code Review — The Review Staircase

A hands-on mid-level course that finds security bugs in code before they ship. Climb the review staircase - eight steps: Scope, Threats, Inputs, Auth, Data, Crypto, Errors, and Verify - reviewing real code for injection, broken access control, and secrets, and confirming each fix. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-069

Attack Surface Management — The Attack Surface Funnel

A hands-on mid-level course that finds and shrinks everything an attacker could reach. Work the attack surface funnel - eight stages: Discover, Inventory, Attribute, Assess, Prioritize, Reduce, Monitor, and Report - continuously finding exposed assets, shadow IT, and risky exposure. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-070

ISO 27001 ISMS Implementation — The ISMS Staircase

A hands-on mid-level course that stands up an ISO 27001 information security management system. Climb the ISMS staircase - eight steps: Scope, Leadership, Risk, Controls, Documents, Operate, Audit, and Certify - building a real, working ISMS rather than a binder for the auditor. Honest and audit-ready. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-072

Security Chaos Engineering — The Resilience Rail

A hands-on mid-level course that proves security controls work by safely breaking things on purpose. Work the resilience rail - eight stations: Hypothesize, Scope, Safeguard, Inject, Observe, Learn, Automate, and Report - running controlled security experiments to find where defenses silently fail. Strictly defensive and safe. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-073

Mobile Device Management — The Device Management Board

A hands-on mid-level course that secures the phones, tablets, and laptops accessing company data. Work the device management board - eight domains: Enrollment, Policy, Encryption, Apps, Separation, Compliance, Threats, and Retire - managing corporate and BYOD devices with MDM/UEM. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-075

Bug Bounty & Vulnerability Disclosure — The Disclosure Loop

A hands-on mid-level course that runs a vulnerability disclosure and bug-bounty program that researchers respect and the business trusts. Work the disclosure loop - eight stages: Policy, Scope, Intake, Triage, Reward, Fix, Coordinate, and Improve - turning outside reports into fixed bugs, not legal fights. Honest and good-faith. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-076

Physical Security & Access Control — The Physical Security Board

A hands-on mid-level course that protects the buildings, rooms, and hardware behind the network. Work the physical security board - eight domains: Perimeter, Entry, Access Control, Surveillance, Data Centre, Devices, Monitoring, and Response - layering physical controls so a badge or a locked rack is not the only thing between an intruder and your data. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-077

Network Access Control — The NAC Defense Stack

A hands-on mid-level course that decides what may connect to the network and on what terms. Work the NAC defense stack - eight layers: Discovery, Authentication, Posture, Authorization, Segmentation, Guest, Enforcement, and Monitoring - using 802.1X, device posture, and dynamic VLANs so an unknown or unhealthy device never lands on a trusted segment. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-078

AI & Machine Learning Security — The ML Security Board

A hands-on mid-level course that secures machine-learning systems across their lifecycle. Work the ML security board - eight domains: Data, Training, Model, Supply Chain, Deployment, Inference, Privacy, and Monitoring - defending against poisoning, evasion, model theft, and prompt injection while keeping models trustworthy. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-079

SOC Operations & Alert Triage — The Triage Staircase

A hands-on mid-level course that runs the SOC workflow from alert to closed case. Climb the triage staircase - eight steps: Intake, Enrich, Validate, Scope, Prioritize, Investigate, Escalate, and Close - turning a flood of alerts into fast, consistent, well-documented decisions. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-080

macOS Endpoint Security — The macOS Security Board

A hands-on mid-level course that hardens and manages a fleet of Macs. Work the macOS security board - eight domains: Identity, System Integrity, Gatekeeper, FileVault, Firewall, MDM, Logging, and Response - using the platform's own protections plus MDM to keep Macs secure without fighting the OS. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-081

Secure Cloud Migration — The Migration Pipeline

A hands-on mid-level course that moves workloads to the cloud without moving the risk. Work the migration pipeline - eight stages: Assess, Design, Landing Zone, Data, Migrate, Validate, Cutover, and Optimize - carrying security requirements into a secure landing zone and validating before cutover. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-082

Browser & Web Client Security — The Client Defense Stack

A hands-on mid-level course that protects users at the browser, the last mile of most attacks. Work the client defense stack - eight layers: Policy, Extensions, Isolation, Downloads, Credentials, Web Threats, Data, and Monitoring - hardening enterprise browsers against malicious sites, extensions, and data leakage. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-083

Post-Quantum Cryptography Readiness — The Migration Rail

A hands-on mid-level course that gets an organisation ready for the quantum threat to today's cryptography. Work the migration rail - eight stations: Threat, Inventory, Prioritize, Standards, Test, Hybrid, Migrate, and Govern - building crypto-agility and moving to NIST post-quantum algorithms before harvest-now-decrypt-later bites. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-084

Breach Communication & Crisis Management — The Crisis Loop

A hands-on mid-level course that manages the human, legal, and communication side of a major security incident. Work the crisis loop - eight stages: Prepare, Activate, Assess, Legal, Notify, Communicate, Support, and Learn - coordinating stakeholders and telling the truth well under pressure. Honest and stakeholder-focused. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-085

Firmware & Hardware Security — The Hardware Trust Board

A hands-on mid-level course that secures the layer below the operating system. Work the hardware trust board - eight domains: Boot, Firmware, Root of Trust, Supply Chain, Interfaces, Storage, Runtime, and Recovery - building verified boot, firmware update integrity, and hardware-backed trust so an attacker below the OS cannot own the device. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-086

Blockchain & Smart Contract Security — The Contract Staircase

A hands-on mid-level course that secures smart contracts and the applications built on them. Climb the contract staircase - eight steps: Model, Access, Arithmetic, Reentrancy, Oracles, Keys, Test, and Monitor - finding and fixing the flaws that drain funds, with real Solidity patterns and defensive checks. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-087

HIPAA Security & Privacy Compliance — The Compliance Staircase

A hands-on mid-level course that makes a healthcare organisation genuinely HIPAA-compliant. Climb the compliance staircase - eight steps: Scope, Risk, Administrative, Physical, Technical, Privacy, Breach, and Audit - protecting ePHI with real safeguards, not just paperwork. Honest and audit-ready. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-088

Secure Collaboration & Messaging — The Collaboration Defense Stack

A hands-on mid-level course that secures the chat, file-sharing, and meeting tools work now runs on. Work the collaboration defense stack - eight layers: Identity, Access, Sharing, Apps, Data, Guests, Threats, and Monitoring - hardening Slack, Teams, and Workspace so a message or a shared file is not the way in. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-089

OT & ICS Incident Response — The OT Response Funnel

A hands-on mid-level course that responds to incidents in operational technology without endangering the process. Work the OT response funnel - eight stages: Prepare, Detect, Triage, Isolate, Investigate, Eradicate, Restore, and Learn - responding safety-first where a wrong move can stop a plant or hurt someone. Strictly defensive and safety-first. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-090

Deepfake & Media Authenticity Defense — The Authenticity Board

A hands-on mid-level course that defends against deepfakes and synthetic-media fraud. Work the authenticity board - eight domains: Awareness, Voice, Video, Identity, Verification, Provenance, Process, and Response - stopping voice-clone and video fraud with out-of-band verification and content provenance. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-091

Vendor Security Assessment — The Assessment Rail

A hands-on mid-level course that assesses and manages the security of the vendors you depend on. Work the assessment rail - eight stations: Intake, Tier, Assess, Evidence, Score, Contract, Monitor, and Offboard - running right-sized assessments and continuous oversight instead of a once-a-year questionnaire. Honest and risk-based. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-092

Security Champions Program — The Champions Loop

A hands-on mid-level course that scales security into engineering through a champions program. Work the champions loop - eight stages: Case, Recruit, Enable, Empower, Engage, Measure, Sustain, and Grow - embedding security advocates in dev teams so security scales with the org instead of bottlenecking on one team. People-focused and practical. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-093

Infrastructure as Code Security — The IaC Pipeline

A hands-on mid-level course that ships cloud infrastructure that is secure by default. Work the IaC pipeline - eight stages: Author, Modules, Secrets, Scan, Policy, Review, Deploy, and Drift - writing Terraform that is scanned, policy-gated, and free of hardcoded secrets, so misconfigurations never reach production. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-094

Service Mesh Security — The Mesh Security Board

A hands-on mid-level course that secures service-to-service traffic with a service mesh. Work the mesh security board - eight domains: Identity, mTLS, Authorization, Traffic, Ingress, Secrets, Observability, and Policy - giving every workload an identity and encrypting and authorizing every call between services. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-095

Payment Systems Security — The Payment Defense Stack

A hands-on mid-level course that secures how money moves through an application. Work the payment defense stack - eight layers: Data, Tokenization, Encryption, 3-D Secure, Fraud, APIs, Reconciliation, and Compliance - protecting cardholder data with tokenization, strong authentication, and fraud controls so a payment flow is not the weak link. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-096

NIST Cybersecurity Framework — The CSF Loop

A hands-on mid-level course that uses the NIST Cybersecurity Framework 2.0 to run a real security program. Work the CSF loop - eight stages built on the six functions: Govern, Identify, Protect, Detect, Respond, Recover, Profile, and Improve - assessing current vs target state and driving prioritised improvement. Practical and outcome-driven. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-097

Digital Identity & KYC Security — The Identity Assurance Rail

A hands-on mid-level course that verifies people online without being fooled by fraud. Work the identity assurance rail - eight stations: Enrol, Verify, Document, Biometric, Liveness, Risk, Reverify, and Recover - proving who someone is with document, biometric, and liveness checks that resist injection and deepfake attacks. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-098

SOC 2 Compliance — The SOC 2 Staircase

A hands-on mid-level course that earns and keeps a clean SOC 2 report. Climb the SOC 2 staircase - eight steps: Scope, Criteria, Controls, Evidence, Readiness, Audit, Report, and Sustain - implementing the Trust Services Criteria as real, evidenced controls, not a scramble before the auditor arrives. Honest and audit-ready. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-099

Event Streaming & Message Queue Security — The Streaming Pipeline

A hands-on mid-level course that secures Kafka and the message queues at the heart of modern systems. Work the streaming pipeline - eight stages: Authenticate, Authorize, Encrypt, Topics, Schema, Producers, Consumers, and Monitor - locking down brokers, topics, and data in motion so the event backbone is not wide open. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-100

Bluetooth, NFC & Wireless Protocol Security — The Wireless Protocol Board

A hands-on mid-level course that secures the short-range wireless protocols on the devices around us. Work the wireless protocol board - eight domains: Bluetooth, BLE, Pairing, NFC, RFID, Zigbee, Jamming, and Response - closing the pairing, replay, and cloning weaknesses attackers use up close. Strictly defensive. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-101

Cloud Detection Engineering — The Cloud Detection Stack

A hands-on mid-level course that builds detections specifically for cloud control planes and cloud-native services - not a generic detection pipeline, not incident response. Work the cloud detection stack - eight layers from control-plane logs to guardrailed automated response: Control-Plane Logs, Identity Signals, Network & Flow, Workload & Runtime, Data-Plane Access, Managed Detections, Custom Detections, and Response Hooks - collecting the right telemetry, tuning and verifying managed detections, writing detection-as-code mapped to ATT&CK Cloud, and wiring safe automated containment, with real AWS/Azure/GCP CLI and KQL/SQL-style query work. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-102

Cloud Network Security — The Cloud Network Board

A hands-on mid-level course that builds cloud-native network controls from the ground up. Work the cloud network board - eight controls an engineer must make secure by default: VPC Design, Security Groups, Private Connectivity, Egress Control, Load Balancers & Edge, Cloud Firewalls, Peering & Transit, and Flow Visibility - removing exposures, scoping traffic to least privilege, keeping paths private, and logging every flow, with real aws/az CLI and Terraform/CloudFormation work. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-103

Windows Endpoint Hardening — The Workstation Board

A hands-on mid-level course that hardens the Windows 11 laptop fleet a real organization issues to its people, working the eight domains of the workstation board - Baseline, Local Admin, Attack Surface Reduction, Credential Guard, Application Control, Device Encryption, Update & Compliance, and Telemetry - through real Intune configuration profiles, LAPS, ASR rules, Credential Guard, WDAC, BitLocker, update rings, and Defender for Endpoint onboarding, so one unmanaged laptop never becomes a firm-wide incident. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-104

Virtualization & Hypervisor Security — The Hypervisor Rail

A hands-on mid-level course that hardens and operates the hypervisor layer underneath every VM and clinical system. Work the hypervisor rail - eight stations: Host Hardening, Management Plane, VM Isolation, Virtual Networking, Storage & Snapshots, Templates & Images, Patching & Lifecycle, and Monitoring - locking down ESXi/Hyper-V/KVM hosts, vCenter/SCVMM/Proxmox access, VM isolation, vSwitch segmentation, datastore and snapshot hygiene, golden images, live-migration patching, and hypervisor logging. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-105

SIEM Operations — The SIEM Funnel

A hands-on mid-level course that runs the daily operation of a SIEM - onboarding sources, keeping parsing and normalization correct, enriching events with context, correlating signal into meaningful alerts, and tuning and retaining data without losing detection value. Work the SIEM funnel - eight stages raw logs pass through: Onboard, Parse, Normalize, Enrich, Correlate, Alert, Tune, and Retain - with real source coverage mapping, parser and timestamp fixes, schema mapping, enrichment pipelines, risk-based correlation, alert routing and SLAs, precision-tracked tuning, and tiered, immutable retention. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-106

Secure File Transfer & B2B Integration — The Transfer Staircase

A hands-on mid-level course securing machine-to-machine and partner file transfer across the eight-step Transfer Staircase - Inventory, Protocols, Authentication, Encryption, Integrity, Automation, Partners, and Audit - retiring plaintext FTP, authenticating every partner with vaulted keys, encrypting payloads and landing zones, verifying integrity with checksums and AS2 MDNs, automating safely, and proving the pipeline to a regulator with real sftp, ssh-keygen, gpg, openssl, curl, and MFT-style commands. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-107

Medical Device & IoMT Security — The Clinical Device Board

A hands-on mid-level course that secures the connected medical devices and IoMT clinicians use to treat patients, where a compromise can put a life at risk. Work the clinical device board - eight domains a clinical engineering security specialist must hold: Inventory, Risk Tiering, Network Isolation, Access & Credentials, Patching & Vendors, Monitoring, Incident Handling, and Procurement - putting patient safety first, segmenting devices, and monitoring passively, with real passive discovery, clinical VLAN and NAC policy, vendor-validated patching, and DICOM/HL7-aware monitoring. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-108

Zero-Day & Critical Vulnerability Response — The Emergency Funnel

A hands-on mid-level course that runs the emergency playbook for the day a critical, often actively-exploited vulnerability drops in software you already run. Work the emergency funnel across eight stages - Trigger, Triage, Exposure, Mitigate, Hunt, Patch, Verify, and Learn - responding fast on facts but proving closure, with real advisory intake, KEV/EPSS triage, SBOM/CMDB exposure sweeps, WAF and config mitigation, IOC hunting, expedited patch rollout, and re-scan verification. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-109

Application Control & Allowlisting — The Allowlist Rail

A hands-on mid-level course that controls what is allowed to run on a fleet you own. Work the allowlist rail across eight stations - Inventory, Policy Design, Audit Mode, Publisher Rules, Path & Hash Rules, Scripts & Installers, Enforce, and Maintain - building default-deny WDAC/AppLocker, Santa, and fapolicyd policies with real PowerShell, event-log, and console commands, from audit-mode discovery through ringed enforcement and ongoing maintenance. Four hands-on activities in every lesson.

৳4,000৳8,000View →
CY-MID-110

Source Control Platform Security — The Repository Loop

A hands-on mid-level course that hardens the source control platform itself - org and repo access, branch rules, secret scanning, commit signing, tokens, apps, and audit - through the repository loop's eight arcs: Identity & SSO, Permissions, Branch Protection, Secrets Scanning, Commit Integrity, Automation Tokens, Third-Party Apps, and Audit & Response, with realistic gh/glab CLI, git config, and API/webhook work at every arc. Four hands-on activities in every lesson.

৳4,000৳8,000View →

Senior Level · 65 courses

CY-SENIOR-017

Purple Team Range — Adversary Emulation and Detection, Side by Side

A seventeen-hour senior course where red and blue work side by side on an authorized range, walking the attack lifecycle technique by technique — emulating each move safely, verifying whether detection fires, and closing every gap.

৳6,000৳10,000View →
CY-SENIOR-060

OT & ICS Security Field Assessment — Securing the Plant Floor

A twenty-six-hour senior field-operations course where you are the lead OT/ICS security assessor at a water utility, working the plant on a live Purdue-model zone map — reframing IT instincts around safety, mapping zones and conduits, discovering assets passively, and turning do-no-harm field work into a report and roadmap that make a physical process safer.

৳6,000৳10,000View →
CY-SENIOR-022

Cybersecurity Audit — The Workpaper

A twenty-six-hour senior evidence-room course where you are a cybersecurity auditor at a bank, working every control on a live audit workpaper — testing assertions against evidence, sampling honestly, and turning exceptions into findings and a defensible opinion, with professional skepticism as a way of life.

৳6,000৳10,000View →
CY-SENIOR-034

Penetration Testing — The Authorized Engagement

A twenty-two-hour senior course where you conduct a fully authorized penetration test along an engagement kill chain — scoping and rules of engagement, careful reconnaissance and access, proving impact without causing damage, and a report that makes the client genuinely more secure.

৳6,000৳10,000View →
CY-SENIOR-065

Threat Modeling — The Design-Time Studio

A twenty-hour, highly interactive senior-level course where you are a security architect finding design flaws before they are built — modeling systems as data-flow diagrams with trust boundaries, applying STRIDE to find what can go wrong, and mitigating by design. Proactive, structured, and about design flaws, not code bugs. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-021

Incident Response — The Response Lifecycle

A thorough, highly interactive senior course where you lead incident response at the Ridgeline CSIRT with method over panic. Run the full lifecycle as a loop — Prepare, Detect, Triage, Contain, Recover, Learn — preserving evidence, coordinating the effort, and turning each incident into a stronger organization. A circular lifecycle map anchors every lesson, with four hands-on activities each.

৳6,000৳10,000View →
CY-SENIOR-009

Third-Party Risk Management — The Vendor Risk Desk

A strategic, decision-focused senior course on managing the risk of the vendors you rely on. Run the vendor risk desk at Harborline — moving each third party through Identify, Tier, Assess, Decide, Contract, Monitor, Respond, and Exit — making proportionate, evidence-based, defensible calls and enabling the business to use third parties safely. Four decision activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-015

Web Application Security — The Test Bench

A hands-on, senior-level course that tests and fixes web application vulnerabilities the professional way: probe a surface safely, read the response, then fix the code and re-test until the flaw is closed. Work every OWASP-class flaw — injection, XSS, broken authentication and access control, SSRF, and misconfiguration — on a real HTTP test bench with real requests and real remediation. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-027

SaaS Security — Posture Command

A deeply technical senior course on securing the SaaS estate an organization uses — not the infrastructure it builds. Work the SaaS posture board across eight control surfaces — estate, identity, app grants, configuration, data, non-human identity, monitoring, and lifecycle — hardening each with real admin settings and proving it with genuine audit queries against your own tenants. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-052

Cyber Law & Ethics — Where the Line Is

A strategic, decision-driven senior course on the legal and ethical boundaries of security work — the 'can we / should we' questions a professional must answer defensibly. Work every dilemma on the line, from Permitted to Prohibited, through four gates — Legal, Authorized, Ethical, Defensible — with judgment, jurisdiction-awareness, and the discipline to get authorization and consult counsel. Four judgment activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-019

Model Risk Management — Governing the Models

A senior, decision-driven course on governing the risk that an organization's models — credit, fraud, pricing, and now AI/LLM models — are wrong, misused, or quietly decaying, across eight dimensions of model risk, as the independent second line that challenges rather than builds.

৳6,000৳10,000View →
CY-SENIOR-001

Security Leadership & CISO Foundations — The Leadership Loop

A senior-level course that steps up from running security work to leading a security function. Work the leadership loop - eight arenas: Strategy, Team, Budget, Board, Risk, Culture, Crisis, and Influence - making the tradeoffs, telling the story to the board, and building a program that outlasts any one hire. Decision-driven, no terminals. Four activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-002

Cloud Security Architecture — The Architecture Board

A senior-level course that designs secure, scalable architecture across a multi-account, multi-cloud estate. Work the architecture board - eight domains: Landing Zone, Identity, Network, Data, Workloads, Boundaries, Automation, and Governance - making the design decisions that let hundreds of teams ship safely by default. Grounded in well-architected security. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-003

Security Operations Center Management — The SOC Management Rail

A senior-level course that runs a SOC as a high-performing function, not just an alert queue. Work the SOC management rail - eight stations: Mission, People, Process, Detection, Automation, Metrics, Quality, and Improve - staffing shifts, cutting burnout, tuning detection, and proving value with metrics that matter. Leadership-focused. Four activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-004

Detection Engineering at Scale — The Detection Program Staircase

A senior-level course that runs detection engineering as a disciplined program across a large estate. Climb the program staircase - eight steps: Strategy, Coverage, Pipeline, Detection-as-Code, Testing, Tuning, Metrics, and Scale - prioritising by threat, shipping detections as code, and measuring coverage and efficacy at scale. Technical and program-level. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-005

Security Governance & Board Reporting — The Governance Loop

A senior-level course that governs a security program and reports it honestly to leadership and the board. Work the governance loop - eight arenas: Charter, Policy, Risk, Committees, Metrics, Reporting, Assurance, and Improve - turning security into decisions leaders can make, with numbers they can trust. Strategic, no terminals. Four activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-006

Enterprise Identity Architecture — The Identity Fabric Board

A senior-level course that designs the identity fabric a whole enterprise runs on. Work the identity fabric board - eight domains: Directory, Authentication, Federation, Authorization, Lifecycle, Privileged, Non-Human, and Governance - architecting SSO, MFA, and least privilege for humans and workloads across every system. Technical/architecture. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-007

Application Security Program Leadership — The AppSec Program Pipeline

A senior-level course that builds an application security program that scales with engineering. Work the program pipeline - eight stages: Strategy, SSDLC, Tooling, Triage, Champions, Training, Metrics, and Maturity - embedding security into how software is built without becoming the bottleneck. Program-level and practical. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-008

Major Incident Command — The Incident Command Funnel

A senior-level course that commands a major security incident - the kind that pulls in executives, legal, and the whole company. Work the incident command funnel - eight stages: Declare, Command, Coordinate, Decide, Communicate, Contain, Recover, and Review - running the response while keeping the business steady under pressure. Leadership under fire. Four activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-010

Threat-Informed Defense — The Defense Program Staircase

A senior-level course that aligns defense to the adversaries who actually target you. Climb the defense program staircase - eight steps: Threats, Map, Prioritize, Assess, Emulate, Close, Measure, and Sustain - using MITRE ATT&CK to drive detection, control, and validation decisions across the program. Technical and program-level. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-011

Enterprise Data Protection Strategy — The Data Protection Board

A senior-level course that protects data across a whole enterprise, from creation to deletion. Work the data protection board - eight domains: Discovery, Classification, Encryption, Access, DLP, Privacy, Retention, and Governance - designing controls that follow the data wherever it flows. Strategic and architectural. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-012

Cyber Resilience & Business Continuity — The Resilience Loop

A senior-level course that keeps the business running through disruption and cyber crisis. Work the resilience loop - eight stages: Analyze, Prioritize, Plan, Backup, Rehearse, Respond, Recover, and Improve - building continuity and disaster recovery that actually work when tested. Leadership and program-level. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-013

Zero Trust Program Strategy — The Zero Trust Roadmap Rail

A senior-level course that leads an organisation-wide zero trust transformation, not just a product rollout. Work the roadmap rail - eight stations: Vision, Assess, Prioritize, Identity, Network, Data, Automate, and Measure - sequencing a multi-year journey across the pillars with executive backing and honest maturity tracking. Strategic and architectural. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-014

Human Risk Management — The Human Risk Loop

A senior-level course that runs a human-risk program that measurably changes behaviour. Work the human risk loop - eight stages: Measure, Segment, Target, Intervene, Nudge, Phish, Culture, and Improve - moving beyond annual training to data-driven behaviour change across the workforce. Strategic and people-centred. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-016

M&A Cybersecurity Due Diligence — The Deal Rail

A senior-level course that assesses and integrates cyber risk through mergers and acquisitions. Work the deal rail - eight stations: Scope, Discover, Assess, Quantify, Report, Negotiate, Integrate, and Monitor - finding what you are really buying and integrating it without inheriting a breach. Strategic and risk-based. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-018

Product Security & PSIRT Leadership — The Product Security Pipeline

A senior-level course that secures the products a company ships and handles their vulnerabilities responsibly. Work the product security pipeline - eight stages: Design, Build, Ship, SBOM, Disclose, PSIRT, Patch, and Improve - building security into products and running the PSIRT that answers when researchers find a flaw. Program-level and technical. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-020

Regulatory Compliance Strategy — The Compliance Program Staircase

A senior-level course that runs compliance across many overlapping regulations without duplicating work. Climb the compliance program staircase - eight steps: Landscape, Map, Harmonize, Controls, Evidence, Audit, Report, and Sustain - building one control set that satisfies many frameworks and proving it once. Strategic and audit-ready. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-023

Platform Security Engineering — The Paved Road Board

A senior-level course that makes the secure way the easy way for hundreds of engineers. Work the paved road board - eight domains: Baselines, Pipelines, Templates, Guardrails, Secrets, Identity, Observability, and Self-Service - building golden paths so teams ship securely by default without a security bottleneck. Technical and platform-level. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-024

Security Data Engineering — The Security Data Rail

A senior-level course that builds the data backbone detection and response run on. Work the security data rail - eight stations: Sources, Ingest, Normalize, Enrich, Store, Model, Serve, and Cost - engineering a pipeline that delivers complete, normalized, affordable security telemetry at scale. Technical and data-focused. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-025

Cyber Risk Quantification — The Quantification Staircase

A senior-level course that puts credible numbers on cyber risk so leaders can decide. Climb the quantification staircase - eight steps: Scope, Model, Frequency, Magnitude, Data, Simulate, Communicate, and Decide - using FAIR and Monte Carlo to express risk in money, not colors. Technical/quantitative and decision-driven. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-026

OT Security Program Leadership — The OT Program Board

A senior-level course that leads a security program for operational technology where safety comes first. Work the OT program board - eight domains: Governance, Inventory, Zones, Access, Monitoring, Patching, Safety, and Response - running an IT/OT program that protects the plant without endangering the process. Program-level and safety-first. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-028

Vulnerability Management Program Leadership — The VM Program Funnel

A senior-level course that runs vulnerability management as a measurable, enterprise-wide program. Work the VM program funnel - eight stages: Strategy, Coverage, Prioritize, Orchestrate, Remediate, SLAs, Metrics, and Mature - driving risk down across a huge estate with clear ownership and honest numbers. Program-level and outcome-driven. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-029

Cyber Threat Intelligence Program — The CTI Program Staircase

A senior-level course that builds a threat-intelligence program that actually changes decisions. Climb the CTI program staircase - eight steps: Mission, Requirements, Collection, Analysis, Production, Dissemination, Integration, and Measure - running intelligence that drives detection, defense, and leadership decisions, not a feed nobody reads. Program-level. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-030

Privacy Program Leadership — The Privacy Program Loop

A senior-level course that runs an enterprise privacy program a DPO can stand behind. Work the privacy program loop - eight stages: Govern, Map, Lawful Basis, Rights, Assess, Vendors, Breach, and Improve - operationalising privacy law into real controls and honest practice across the business. Program-level and rights-respecting. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-031

Security Culture & Change Management — The Culture Loop

A senior-level course that changes how an organisation thinks and acts about security. Work the culture loop - eight stages: Assess, Vision, Sponsor, Message, Enable, Embed, Measure, and Sustain - leading the change so security becomes how people work, not a poster on the wall. Strategic and people-centred. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-032

Enterprise Cryptography & Key Management Program — The Crypto Program Board

A hands-on senior-level course that runs the enterprise program making every team's use of cryptography governed, inventoried, keyed, certificated, vaulted, and quantum-ready. Work the crypto program board - eight areas a program lead must run together: Policy, Inventory, Key Lifecycle, PKI, HSM & Vaults, Data-at-Rest, Data-in-Transit, and Crypto-Agility - replacing team-by-team crypto habits with one standard, one inventory, and provable evidence, with real crypto-policy, CBOM, key-lifecycle, PKI, HSM/KMS, and post-quantum migration work. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-033

Enterprise Network Security Architecture — The Network Rail

A senior-level architecture course that designs the enterprise network security architecture itself, not a single firewall or a single segment. Work the network security rail - eight layers a defensible network is built from: Principles, Segmentation, Perimeter & Edge, Remote Access & SASE, East-West Control, Cloud Interconnect, Monitoring & Telemetry, and Zero-Trust Enforcement - designing deliberate trust boundaries, segmenting crown jewels and OT from IT, converging remote access through SASE, containing lateral movement, interconnecting a hybrid multi-cloud estate, and enforcing zero trust with real policy enforcement points and a funded migration plan.

৳6,000৳10,000View →
CY-SENIOR-035

Security Automation & SOAR Program Leadership — The Automation Staircase

A senior-level program-leadership course that leads a SOC automation program end to end. Climb the automation staircase - eight steps from Case to Scale: Case, Use-Cases, Platform, Playbooks, Integrations, Metrics, Governance, and Scale - building the funded case, selecting and sequencing use-cases, choosing and architecting the SOAR platform, hardening playbooks with human gates and rollback, integrating safely, measuring honestly, governing change, and scaling without sprawl, with realistic SOAR CLI, playbook YAML/JSON, and API-integration work. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-036

Insider Risk Program Leadership — The Insider Risk Funnel

A senior-level program-leadership course that runs an insider risk program which protects the organisation while respecting the people in it. Work the insider risk funnel - eight stages a responsible program runs together: Charter, Governance, Signals, Detection, Triage, Response, Ethics & Privacy, and Maturity - treating the non-malicious majority fairly, partnering with HR, Legal, and Privacy, and keeping monitoring proportionate, lawful, and transparent. Four hands-on activities in every lesson, built from real program artifacts, not shell commands.

৳6,000৳10,000View →
CY-SENIOR-037

Kubernetes & Container Security Architecture — The Container Defense Stack

A hands-on senior-level architecture course that designs container and Kubernetes security as a defense-in-depth stack across a large multi-cluster estate. Work the container defense stack - eight layers a defensible platform is built from: Image & Build, Registry & Supply Chain, Admission Control, Cluster Hardening, Runtime Security, Network Policy, Secrets & Identity, and Observability & Response - so a compromise cannot pass from one layer to the next, with real image signing, admission policy-as-code, RBAC, runtime detection, NetworkPolicy, workload identity, and cluster forensics. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-038

API Security Program Leadership — The API Security Loop

A senior-level course that runs an organization-wide API security program, not a single API review, by working the API Security Loop - eight arcs from Inventory through Monitor - to find every API, set the standards they are built on, verify who is calling and what they may touch, enforce the contract, funnel every call through one gateway, stop abuse, prove defenses hold before release, and watch live traffic for what only production reveals, grounded throughout in the OWASP API Security Top 10.

৳6,000৳10,000View →
CY-SENIOR-039

Security Operating Model & Organisation Design — The Operating Model Loop

A senior-level course that designs the security organisation itself. Work the operating model loop - eight arcs a head of security must get right: Mandate, Structure, Roles, Sourcing, Interfaces, Decision Rights, Capacity, and Evolve - chartering the mandate, choosing the structure, building the role catalogue, deciding the sourcing mix, defining the interfaces, assigning decision rights, planning capacity against risk, and evolving the model as the company scales. Four hands-on activities in every lesson, built from real operating-model artifacts, not shell commands.

৳6,000৳10,000View →
CY-SENIOR-040

Security Investment Strategy & Business Case — The Investment Staircase

A senior-level course that builds the discipline of deciding, justifying, funding, delivering, and proving the value of security investment. Climb the investment staircase - eight steps: Baseline, Risk Link, Options, Business Case, Prioritise, Fund, Deliver, and Prove Value - baselining current spend, linking every ask to risk, weighing real options, writing a CFO-ready business case, prioritising and funding a multi-year portfolio, delivering it, and proving the value. Four hands-on activities in every lesson, built from real investment artifacts, not shell commands.

৳6,000৳10,000View →
CY-SENIOR-041

MSSP & MDR Oversight — The Outsourcing Funnel

A senior oversight course that governs and gets real value from outsourced security services - never runs them. Work the outsourcing funnel - eight stages an outsourcing relationship passes through: Scope, Select, Contract, Onboard, Integrate, Operate, Measure, and Renew or Exit - keeping accountability with the bank while a provider does the work, with real RFP evaluation, enforceable SLAs and containment authority, telemetry onboarding, platform integration, ongoing governance, and independent detection validation. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-042

Multi-Cloud Security Governance — The Cloud Governance Board

A senior-level course that governs cloud security across hundreds of AWS accounts, dozens of Azure subscriptions, and a growing GCP footprint. Work the cloud governance board - eight tiles: Landing Zones, Account Structure, Guardrails, Identity Federation, Policy as Code, Cost & Risk, Compliance Evidence, and Operating Rhythm - with real SCP/Azure Policy/org-policy JSON, OPA/Rego, Terraform, and multi-cloud CLI work that keeps every account consistent and governed. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-043

Software Supply Chain Security Program — The Provenance Funnel

A senior-level, program-scale course that runs software supply chain security as an org-wide program, not a single pipeline. Work the provenance funnel - eight stages: Scope, Inventory, Standards, Build Integrity, Dependencies, Verification, Vendors, and Assurance - proving provenance rather than assuming it across first-party, open-source, commercial, build-infrastructure, and AI-generated code, with real SBOM/VEX, SLSA, signing, admission, dependency-governance, and customer-assurance work. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-044

Customer Identity & Access Management Architecture — The Customer Identity Rail

A senior architecture course that builds and defends the identity system tens of millions of customers sign in through. Work the customer identity rail - eight stations: Registration, Authentication, Federation, Sessions & Tokens, Authorization, Account Protection, Privacy & Consent, and Scale & Resilience - making passkeys the default, federating with OIDC/OAuth2 plus PKCE behind a BFF, authorizing per object and per consent, defending against credential stuffing and takeover, and running login as a resilient, migrated, multi-region tier-0 service. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-045

Security Architecture Governance & Design Authority — The Design Authority Loop

A senior-level course that builds the design authority function governing security architecture across a whole enterprise. Work the design authority loop - eight arcs: Principles, Reference Architectures, Patterns, Review Gates, Exceptions, Standards Lifecycle, Assurance, and Roadmap - ratifying a small set of binding principles, maintaining reference architectures per domain, building an owned pattern catalogue, running risk-tiered design review gates, managing time-boxed exceptions, running a real standards lifecycle, assuring conformance against reality, and sequencing a funded multi-year roadmap. Four hands-on activities in every lesson, built from real governance artifacts, not shell commands.

৳6,000৳10,000View →
CY-SENIOR-046

Enterprise Endpoint Security Architecture — The Endpoint Defense Stack

A senior-level architecture course that designs the target-state endpoint security architecture for a global fleet of tens of thousands of Windows, macOS, Linux, and mobile devices - the tooling strategy, device trust model, and fleet operating model, not single-host hardening. Work the endpoint defense stack - eight layers built firmware-up: Hardware Root of Trust, OS Baseline, Identity & Device Trust, Management Plane, Prevention Controls, Detection & Response, Data Protection, and Lifecycle & Fleet Ops - anchoring hardware trust, holding one cross-platform baseline, gating access on device compliance, consolidating the management plane, layering prevention, unifying detection across every OS, protecting data at scale, and running the fleet as a measured lifecycle. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-047

Cyber Exercise & Tabletop Program — The Exercise Staircase

A senior-level course that builds a cyber exercise program end to end. Climb the exercise staircase - eight steps: Objectives, Audience, Scenario Design, Injects, Facilitation, Evaluation, Findings to Action, and Program Cadence - setting testable objectives, mapping the right audience, designing a threat-informed scenario, building the inject list that drives the room, facilitating with real skill, evaluating objectively against the plan, turning findings into owned action, and sustaining a multi-year, regulator-aligned program. Four hands-on activities in every lesson, built from real exercise artifacts, not shell commands.

৳6,000৳10,000View →
CY-SENIOR-048

Cyber Insurance & Risk Transfer Strategy — The Risk Transfer Loop

A senior-level course that builds the discipline of deciding what cyber risk to retain, mitigate, transfer, or avoid, and buys and uses cyber insurance well when transfer is the right tool. Work the risk transfer loop - eight arcs: Risk Appetite, Coverage Needs, Market & Underwriting, Controls Evidence, Policy Terms, Claims Readiness, Contracts & Vendors, and Review - setting appetite, sizing coverage, working the market from a position of truth, evidencing controls honestly, reading and negotiating policy terms, rehearsing claims readiness, transferring risk contractually to vendors, and reviewing the program every year. Four hands-on activities in every lesson, built from real risk-transfer artifacts, not shell commands.

৳6,000৳10,000View →
CY-SENIOR-049

Cross-Border Data & Sovereignty Strategy — The Sovereignty Board

A senior-level course that builds the strategy deciding where regulated data may live, how it may move, and how to architect and govern for it. Work the sovereignty board - eight tiles: Data Map, Legal Regimes, Transfer Mechanisms, Residency Architecture, Cloud & Vendors, Government Access, Operational Controls, and Governance - mapping every cross-border flow, matching the law to the data, choosing transfer mechanisms that hold, architecting residency, vetting cloud and vendors, limiting government access, enforcing operational controls, and governing it all as a standing decision. Four hands-on activities in every lesson, built from real sovereignty artifacts, not shell commands.

৳6,000৳10,000View →
CY-SENIOR-050

Fraud & Financial Crime Risk Program — The Fraud Risk Funnel

A senior-level program-leadership course that runs the enterprise fraud and financial-crime risk program at a digital bank and payments company. Work the fraud risk funnel - eight stages: Threat Picture, Risk Assessment, Controls Design, Detection Strategy, Investigation, Recovery & Loss, Partnership, and Program Metrics - deciding what threats matter, sizing real exposure, designing layered controls, governing detection, investigating fairly, recovering and booking loss honestly, partnering within lawful limits, and reporting the truth to the board. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-051

Converged Physical & Cyber Security Program — The Convergence Board

A strategic senior-level course that builds one converged security program out of two teams that used to run apart. Work the convergence board - eight tiles: Shared Risk Picture, Governance, Access Convergence, Facilities & Building Systems, Surveillance & Data, Incident Coordination, People & Insider, and Metrics & Maturity - building a shared risk picture, joint governance, a converged access lifecycle, hardened building and surveillance systems, joint incident coordination, an insider-risk partnership with HR and legal, and honest converged metrics driving a funded roadmap. Four hands-on activities in every lesson, built from real program artifacts, not shell commands.

৳6,000৳10,000View →
CY-SENIOR-053

Threat Hunting Program Leadership — The Hunt Program Staircase

A senior-level course that builds and leads a threat hunting program, not a single hunt. Climb the hunt program staircase - eight steps: Charter, Hypotheses, Data Readiness, Hunt Cadence, Tradecraft Standards, Findings to Detections, Metrics, and Scale - leading a brand-new hunt team from an improvised habit to a measured, scaling program, with real KQL/SPL hunt queries, telemetry-coverage checks, and hunt-notebook automation. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-054

Enterprise Forensic Readiness Program — The Evidence Rail

A senior-level program course that builds the enterprise capability to investigate your own incidents before one ever happens. Work the evidence rail - eight stations: Scenarios, Evidence Sources, Retention, Collection Capability, Integrity & Custody, Legal Alignment, Cloud & SaaS, and Exercise & Review - so evidence already exists, is retained, can be collected fast, and will stand up to a regulator, a court, or an insurer, with real retention config, EDR live-response, cloud log-export, hashing, and custody-record work. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-055

Security Assurance & Testing Strategy — The Assurance Funnel

A strategic senior-level course that builds the org-wide assurance strategy deciding what gets tested, how often, by whom, and how the results are governed - not how to run any single engagement. Work the assurance funnel - eight stages: Assurance Map, Risk-Based Scope, Testing Portfolio, Independence, Vendor & Scheme Selection, Findings Governance, Evidence & Attestation, and Continuous Assurance - mapping every assurance source onto the three-lines model, scoping by risk, building the annual portfolio, protecting independence, choosing vendors and schemes well, governing findings in one register, reusing evidence, and moving to continuous assurance. Four hands-on activities in every lesson, built from real assurance artifacts, not shell commands.

৳6,000৳10,000View →
CY-SENIOR-056

Secure-by-Design Product Strategy — The Secure-by-Design Loop

A senior-level strategy course that shifts the burden of security from customers to the product itself, at the company level. Work the secure-by-design loop across eight arcs - Principles, Secure Defaults, Memory Safety & Language Choice, Paved Roads, Threat Modeling at Scale, Customer Transparency, Vulnerability Class Elimination, and Measure & Commit - pairing BY DESIGN against BOLTED ON, with real default-configuration checks, memory-safety and language-inventory queries, paved-road adoption metrics, threat-modeling tooling, SBOM and advisory publishing, and CWE-class elimination tracking. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-057

Security Tooling Strategy & Rationalization — The Tooling Board

A senior-level course that rationalizes a security stack grown by accretion into a portfolio someone actually runs on purpose. Work the tooling board - eight tiles: Capability Map, Coverage Gaps, Overlap & Sprawl, Build-Buy-Partner, Evaluation & POC, Integration Architecture, Adoption & Value, and Lifecycle & Exit - mapping capabilities to a real framework, finding true gaps, cutting sprawl and shelfware, deciding build-buy-partner on total cost, evaluating with real POCs, integrating through a hub, proving adoption and value to the CFO, and managing every tool's lifecycle to exit. Four hands-on activities in every lesson, built from real portfolio artifacts, not shell commands.

৳6,000৳10,000View →
CY-SENIOR-058

Identity Threat Detection & Response — The Identity Defense Stack

A senior-level program course that builds identity-centric detection and response across an organization's entire identity fabric - Entra ID, on-prem AD, and Okta. Work the identity defense stack - eight layers: Identity Telemetry, Posture & Hygiene, Credential Attacks, Token & Session Abuse, Privilege Escalation, Lateral & Federation Abuse, Response Playbooks, and Program & Metrics - correlating telemetry, hardening posture, detecting credential, token, and privilege attacks on your own estate, containing fast, and measuring the program against MITRE ATT&CK, MTTD/MTTR, and a maturity roadmap. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-059

Digital Operational Resilience — DORA & NIS2 Program — The Resilience Staircase

A senior program-level course that builds the digital operational resilience program a supervisor can actually test. Climb the resilience staircase - eight steps: Scope & Applicability, ICT Risk Framework, Critical Functions, Incident Reporting, Resilience Testing, Third-Party ICT Risk, Information Sharing, and Board Accountability - across DORA, NIS2, TIBER-EU, and UK FCA/PRA requirements, with real scope registers, framework mapping, impact tolerances, incident-reporting workflows, TLPT scoping, third-party registers, and board packs. Four hands-on activities in every lesson, built from real program artifacts, not shell commands.

৳6,000৳10,000View →
CY-SENIOR-061

Legacy Systems & Modernization Security — The Modernization Rail

A senior-level architecture course that secures a legacy estate - mainframe, unsupported middleware, end-of-life Windows Server - while it is modernized out from under itself. Work the modernization rail - eight stations: Portfolio Discovery, Risk Triage, Contain & Isolate, Compensating Controls, Modernization Paths, Migration Security, Data & Identity Cutover, and Decommission - with real inventory and EOL scans, segmentation and bastion design, allowlisting and virtual patching, migration validation, identity cutover rehearsal, and decommission verification. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-062

Continuous Controls Monitoring & Compliance Automation — The Controls Funnel

A senior-level GRC engineering course that turns controls into automated, evidence-producing tests so compliance is continuous rather than an annual scramble. Work the controls funnel - eight stages: Control Inventory, Framework Mapping, Evidence Sources, Automated Tests, Exception Handling, Dashboards & Alerts, Audit Readiness, and Program Maturity - building one control library, mapping once to comply many, collecting evidence API-first, writing control tests as code, handling exceptions as first-class records, alerting owners, satisfying auditors from continuous evidence, and maturing the program, at a healthcare SaaS provider carrying SOC 2, HIPAA, ISO 27001, and HITRUST at once. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-063

Data Center & Hosting Security Architecture — The Data Center Stack

A senior-level architecture course that designs and defends the end-to-end security of owned and colocated data centres - physical through platform through operations and exit - for a latency-sensitive financial exchange operator whose workloads cannot move to public cloud. Work the data center stack - eight layers in physical-up order: Physical & Environmental, Hardware & Firmware, Out-of-Band Management, Network Fabric, Compute & Storage Platforms, Workload Isolation, Operations & Change, and Resilience & Exit - evidenced with real BMC/firmware-integrity checks, fabric and switch config, storage zoning, OOB access audits, and change and drift verification. Four hands-on activities in every lesson.

৳6,000৳10,000View →
CY-SENIOR-064

Cybersecurity Workforce & Talent Strategy — The Talent Loop

A senior-level course that builds the security team's own workforce and talent strategy. Work the talent loop - eight arcs: Workforce Plan, Role Design, Hiring, Onboarding, Skills Development, Career Paths, Retention & Wellbeing, and Succession - planning real demand and capacity, designing roles against a recognized competency framework, hiring on a structured skills-based process, onboarding for real productivity, growing skills deliberately, building transparent career paths, sustaining retention and wellbeing, and preparing successors for every critical role. Four hands-on activities in every lesson, built from real workforce artifacts, not shell commands.

৳6,000৳10,000View →

Expert Level · 10 courses

CY-EXPERT-034

DFIR Evidence Room — Reconstructing the Breach from the Artifacts

An eighteen-hour expert investigation where you lead a breach case end to end — preserving evidence, reconstructing the forensic timeline across endpoint, memory, log, network, cloud, and identity, scoping and eradicating the intrusion, and reporting conclusions that hold.

৳9,000৳12,000View →
CY-EXPERT-074

AI Security Assurance — Securing and Assuring AI Systems

A twenty-two-hour expert course where you assure an enterprise's AI systems across every layer — data, model, supply chain, inference, tools and agents, and the surrounding application — treating each guardrail as necessary but never sufficient, and recording residual risk honestly.

৳9,000৳12,000View →
CY-EXPERT-071

Cloud Security Architecture — Identity, Blast Radius, and the Attack Path

A twenty-four-hour expert course where you are a cloud security architect hardening a large multi-account estate along a live attack-path graph — treating identity as the perimeter, misconfiguration as the vulnerability, and blast radius as the risk, and designing a secure landing zone that makes teams secure by default.

৳9,000৳12,000View →
CY-EXPERT-011

Malware Analysis — The Isolated Bench

A twenty-hour, highly interactive expert-level course where you are a malware analyst working an escalation ladder inside an isolated lab — triage, static, unpacking, dynamic, network, and code-level analysis — turning unknown, hostile code into the capabilities, IOCs, and detections defenders need. Strictly defensive and contained. Four hands-on activities in every lesson.

৳9,000৳12,000View →
CY-EXPERT-046

Supply Chain Security — The Chain of Verified Trust

A twenty-hour, highly interactive expert-level course where you secure the software supply chain link by link — source, dependencies, build, artifacts, distribution, and deployment — knowing what is in your software and verifying integrity and provenance at every link. Trust is transitive; the chain is only as strong as its weakest link. Four hands-on activities in every lesson.

৳9,000৳12,000View →
CY-EXPERT-002

Container & Kubernetes Security — The Stack

A twenty-hour, highly interactive expert-level course where you secure a Kubernetes platform layer by layer — image, registry, cluster, workload, network, runtime. Containers share the host kernel so isolation is weaker than a VM's, and most risk is misconfiguration and excess privilege. Least privilege and isolation at every layer, so a compromise is contained. Four hands-on activities in every lesson.

৳9,000৳12,000View →
CY-EXPERT-003

SIEM Engineering — The Detection Pipeline

A deeply technical expert course that builds and assures the detection pipeline itself — the eight-stage machine that turns raw events into trustworthy alerts. Engineer sources, collection, parsing, normalization, enrichment, storage, detection, and alerting with real configs, real query syntax, and a tracer event proven at every stage. Four hands-on activities in every lesson.

৳9,000৳12,000View →
CY-EXPERT-026

SOAR Automation — Building the Machine That Responds

An expert, build-it-yourself course on security orchestration and automated response: construct a SOAR practice playbook by playbook — hardened triggers, enrichment engines, versioned decision policy, gated containment with tested rollback, and the platform engineering (pipelines, tests, secrets, self-monitoring) that makes automation trustworthy at 3 a.m. Five build-and-verify activities in every lesson.

৳9,000৳12,000View →
CY-EXPERT-001

OT & ICS Security Engineering — Building the Defended Plant

A twenty-three-hour expert engineering course where you architect the defended plant end to end on a live zone-and-conduit floor plan — partitioning zones and conduits to target security levels, building the IDMZ, living within what industrial protocols can and cannot do, hardening controllers without touching the safety system, and verifying the achieved security level before handover.

৳9,000৳12,000View →
CY-EXPERT-004

Exploit Development — The Exploitability Verdict

The defender's mastery of exploitation: understanding how a bug becomes an exploit well enough to render a verdict on whether it can, defeat it barrier by barrier, and fix the class at the root — with no exploit construction, no weaponisation, and no deployable technique anywhere in the course.

৳9,000৳12,000View →

Pro Level · 6 courses

CY-PRO-033

Enterprise Security Architecture Studio — Design, Assure, and Transform at Scale

A forty-hour Pro-level architecture studio where you lead a regulated multinational's three-year security-architecture transformation — from mandate and method through every domain to Zero Trust, resilience, governance, and a board defense — deciding, assuring, and defending each design.

৳12,000৳15,000View →
CY-PRO-028

CISO Program Command — Lead, Govern, and Defend the Security Program

A thirty-hour Pro-level board simulation where you take the CISO's seat at a financial group after a damaging breach, and lead the whole security program — mandate, strategy, risk, governance, budget, crisis, and board defense — through decision papers and boardroom decisions.

৳12,000৳15,000View →
CY-PRO-071

Ransomware Crisis Command — Enterprise Resilience Under Fire

A forty-hour Pro-level crisis simulation run on a live war-room situation board, where you command a regional hospital group through a destructive ransomware event — from readiness and detonation through containment, the ransom decision, recovery, and communications — and out into a measurable, board-defended resilience programme.

৳12,000৳15,000View →
CY-PRO-051

Cyber Risk Management — The Risk Command

A twenty-hour, highly interactive pro-level course where you are the head of cyber risk, working the risk lifecycle on the enterprise risk heat map — identifying, assessing, evaluating against appetite, treating, monitoring, and governing risk. Risk management is managing risk to acceptable levels, not eliminating it — enabling the right risks knowingly. Four hands-on activities in every lesson.

৳12,000৳15,000View →
CY-PRO-058

Security Metrics, KRIs & KPIs — Numbers the Board Can Govern By

A strategic, decision-driven pro-level course on measurement as an instrument of governance. Build and run the Atlas Group's one-page board pack — deriving metrics from decisions, engineering definitions and data confidence, operating risk appetite as thresholds that fire, reporting honestly through the bad quarters, and running the board meeting itself to minuted decisions. Four judgment activities in every lesson.

৳12,000৳15,000View →
CY-PRO-021

Disaster Recovery — Commanding the Worst Week

A pro-level, decision-driven course on commanding recovery while the clock runs: impact maps and funded RTO/RPO promises, strategies that survive the shared-fate hunt, declaration and command under fog, the long middle of restoration versus resumption, the human and supplier dependencies, exercises run until boring — and the board conversation that owns the residual risk out loud. Four tabletop-driven activities in every lesson.

৳12,000৳15,000View →