CY-SENIOR-065Threat Modeling — The Design-Time Studio
A twenty-hour, highly interactive senior-level course where you are a security architect finding design flaws before they are built — modeling systems as data-flow diagrams with trust boundaries, applying STRIDE to find what can go wrong, and mitigating by design. Proactive, structured, and about design flaws, not code bugs. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-021Incident Response — The Response Lifecycle
A thorough, highly interactive senior course where you lead incident response at the Ridgeline CSIRT with method over panic. Run the full lifecycle as a loop — Prepare, Detect, Triage, Contain, Recover, Learn — preserving evidence, coordinating the effort, and turning each incident into a stronger organization. A circular lifecycle map anchors every lesson, with four hands-on activities each.
৳6,000৳10,000View →
CY-SENIOR-009Third-Party Risk Management — The Vendor Risk Desk
A strategic, decision-focused senior course on managing the risk of the vendors you rely on. Run the vendor risk desk at Harborline — moving each third party through Identify, Tier, Assess, Decide, Contract, Monitor, Respond, and Exit — making proportionate, evidence-based, defensible calls and enabling the business to use third parties safely. Four decision activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-015Web Application Security — The Test Bench
A hands-on, senior-level course that tests and fixes web application vulnerabilities the professional way: probe a surface safely, read the response, then fix the code and re-test until the flaw is closed. Work every OWASP-class flaw — injection, XSS, broken authentication and access control, SSRF, and misconfiguration — on a real HTTP test bench with real requests and real remediation. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-027SaaS Security — Posture Command
A deeply technical senior course on securing the SaaS estate an organization uses — not the infrastructure it builds. Work the SaaS posture board across eight control surfaces — estate, identity, app grants, configuration, data, non-human identity, monitoring, and lifecycle — hardening each with real admin settings and proving it with genuine audit queries against your own tenants. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-052Cyber Law & Ethics — Where the Line Is
A strategic, decision-driven senior course on the legal and ethical boundaries of security work — the 'can we / should we' questions a professional must answer defensibly. Work every dilemma on the line, from Permitted to Prohibited, through four gates — Legal, Authorized, Ethical, Defensible — with judgment, jurisdiction-awareness, and the discipline to get authorization and consult counsel. Four judgment activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-019Model Risk Management — Governing the Models
A senior, decision-driven course on governing the risk that an organization's models — credit, fraud, pricing, and now AI/LLM models — are wrong, misused, or quietly decaying, across eight dimensions of model risk, as the independent second line that challenges rather than builds.
৳6,000৳10,000View →
CY-SENIOR-001Security Leadership & CISO Foundations — The Leadership Loop
A senior-level course that steps up from running security work to leading a security function. Work the leadership loop - eight arenas: Strategy, Team, Budget, Board, Risk, Culture, Crisis, and Influence - making the tradeoffs, telling the story to the board, and building a program that outlasts any one hire. Decision-driven, no terminals. Four activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-002Cloud Security Architecture — The Architecture Board
A senior-level course that designs secure, scalable architecture across a multi-account, multi-cloud estate. Work the architecture board - eight domains: Landing Zone, Identity, Network, Data, Workloads, Boundaries, Automation, and Governance - making the design decisions that let hundreds of teams ship safely by default. Grounded in well-architected security. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-003Security Operations Center Management — The SOC Management Rail
A senior-level course that runs a SOC as a high-performing function, not just an alert queue. Work the SOC management rail - eight stations: Mission, People, Process, Detection, Automation, Metrics, Quality, and Improve - staffing shifts, cutting burnout, tuning detection, and proving value with metrics that matter. Leadership-focused. Four activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-004Detection Engineering at Scale — The Detection Program Staircase
A senior-level course that runs detection engineering as a disciplined program across a large estate. Climb the program staircase - eight steps: Strategy, Coverage, Pipeline, Detection-as-Code, Testing, Tuning, Metrics, and Scale - prioritising by threat, shipping detections as code, and measuring coverage and efficacy at scale. Technical and program-level. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-005Security Governance & Board Reporting — The Governance Loop
A senior-level course that governs a security program and reports it honestly to leadership and the board. Work the governance loop - eight arenas: Charter, Policy, Risk, Committees, Metrics, Reporting, Assurance, and Improve - turning security into decisions leaders can make, with numbers they can trust. Strategic, no terminals. Four activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-006Enterprise Identity Architecture — The Identity Fabric Board
A senior-level course that designs the identity fabric a whole enterprise runs on. Work the identity fabric board - eight domains: Directory, Authentication, Federation, Authorization, Lifecycle, Privileged, Non-Human, and Governance - architecting SSO, MFA, and least privilege for humans and workloads across every system. Technical/architecture. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-007Application Security Program Leadership — The AppSec Program Pipeline
A senior-level course that builds an application security program that scales with engineering. Work the program pipeline - eight stages: Strategy, SSDLC, Tooling, Triage, Champions, Training, Metrics, and Maturity - embedding security into how software is built without becoming the bottleneck. Program-level and practical. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-008Major Incident Command — The Incident Command Funnel
A senior-level course that commands a major security incident - the kind that pulls in executives, legal, and the whole company. Work the incident command funnel - eight stages: Declare, Command, Coordinate, Decide, Communicate, Contain, Recover, and Review - running the response while keeping the business steady under pressure. Leadership under fire. Four activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-010Threat-Informed Defense — The Defense Program Staircase
A senior-level course that aligns defense to the adversaries who actually target you. Climb the defense program staircase - eight steps: Threats, Map, Prioritize, Assess, Emulate, Close, Measure, and Sustain - using MITRE ATT&CK to drive detection, control, and validation decisions across the program. Technical and program-level. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-011Enterprise Data Protection Strategy — The Data Protection Board
A senior-level course that protects data across a whole enterprise, from creation to deletion. Work the data protection board - eight domains: Discovery, Classification, Encryption, Access, DLP, Privacy, Retention, and Governance - designing controls that follow the data wherever it flows. Strategic and architectural. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-012Cyber Resilience & Business Continuity — The Resilience Loop
A senior-level course that keeps the business running through disruption and cyber crisis. Work the resilience loop - eight stages: Analyze, Prioritize, Plan, Backup, Rehearse, Respond, Recover, and Improve - building continuity and disaster recovery that actually work when tested. Leadership and program-level. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-013Zero Trust Program Strategy — The Zero Trust Roadmap Rail
A senior-level course that leads an organisation-wide zero trust transformation, not just a product rollout. Work the roadmap rail - eight stations: Vision, Assess, Prioritize, Identity, Network, Data, Automate, and Measure - sequencing a multi-year journey across the pillars with executive backing and honest maturity tracking. Strategic and architectural. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-014Human Risk Management — The Human Risk Loop
A senior-level course that runs a human-risk program that measurably changes behaviour. Work the human risk loop - eight stages: Measure, Segment, Target, Intervene, Nudge, Phish, Culture, and Improve - moving beyond annual training to data-driven behaviour change across the workforce. Strategic and people-centred. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-016M&A Cybersecurity Due Diligence — The Deal Rail
A senior-level course that assesses and integrates cyber risk through mergers and acquisitions. Work the deal rail - eight stations: Scope, Discover, Assess, Quantify, Report, Negotiate, Integrate, and Monitor - finding what you are really buying and integrating it without inheriting a breach. Strategic and risk-based. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-018Product Security & PSIRT Leadership — The Product Security Pipeline
A senior-level course that secures the products a company ships and handles their vulnerabilities responsibly. Work the product security pipeline - eight stages: Design, Build, Ship, SBOM, Disclose, PSIRT, Patch, and Improve - building security into products and running the PSIRT that answers when researchers find a flaw. Program-level and technical. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-020Regulatory Compliance Strategy — The Compliance Program Staircase
A senior-level course that runs compliance across many overlapping regulations without duplicating work. Climb the compliance program staircase - eight steps: Landscape, Map, Harmonize, Controls, Evidence, Audit, Report, and Sustain - building one control set that satisfies many frameworks and proving it once. Strategic and audit-ready. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-023Platform Security Engineering — The Paved Road Board
A senior-level course that makes the secure way the easy way for hundreds of engineers. Work the paved road board - eight domains: Baselines, Pipelines, Templates, Guardrails, Secrets, Identity, Observability, and Self-Service - building golden paths so teams ship securely by default without a security bottleneck. Technical and platform-level. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-024Security Data Engineering — The Security Data Rail
A senior-level course that builds the data backbone detection and response run on. Work the security data rail - eight stations: Sources, Ingest, Normalize, Enrich, Store, Model, Serve, and Cost - engineering a pipeline that delivers complete, normalized, affordable security telemetry at scale. Technical and data-focused. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-025Cyber Risk Quantification — The Quantification Staircase
A senior-level course that puts credible numbers on cyber risk so leaders can decide. Climb the quantification staircase - eight steps: Scope, Model, Frequency, Magnitude, Data, Simulate, Communicate, and Decide - using FAIR and Monte Carlo to express risk in money, not colors. Technical/quantitative and decision-driven. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-026OT Security Program Leadership — The OT Program Board
A senior-level course that leads a security program for operational technology where safety comes first. Work the OT program board - eight domains: Governance, Inventory, Zones, Access, Monitoring, Patching, Safety, and Response - running an IT/OT program that protects the plant without endangering the process. Program-level and safety-first. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-028Vulnerability Management Program Leadership — The VM Program Funnel
A senior-level course that runs vulnerability management as a measurable, enterprise-wide program. Work the VM program funnel - eight stages: Strategy, Coverage, Prioritize, Orchestrate, Remediate, SLAs, Metrics, and Mature - driving risk down across a huge estate with clear ownership and honest numbers. Program-level and outcome-driven. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-029Cyber Threat Intelligence Program — The CTI Program Staircase
A senior-level course that builds a threat-intelligence program that actually changes decisions. Climb the CTI program staircase - eight steps: Mission, Requirements, Collection, Analysis, Production, Dissemination, Integration, and Measure - running intelligence that drives detection, defense, and leadership decisions, not a feed nobody reads. Program-level. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-030Privacy Program Leadership — The Privacy Program Loop
A senior-level course that runs an enterprise privacy program a DPO can stand behind. Work the privacy program loop - eight stages: Govern, Map, Lawful Basis, Rights, Assess, Vendors, Breach, and Improve - operationalising privacy law into real controls and honest practice across the business. Program-level and rights-respecting. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-031Security Culture & Change Management — The Culture Loop
A senior-level course that changes how an organisation thinks and acts about security. Work the culture loop - eight stages: Assess, Vision, Sponsor, Message, Enable, Embed, Measure, and Sustain - leading the change so security becomes how people work, not a poster on the wall. Strategic and people-centred. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-032Enterprise Cryptography & Key Management Program — The Crypto Program Board
A hands-on senior-level course that runs the enterprise program making every team's use of cryptography governed, inventoried, keyed, certificated, vaulted, and quantum-ready. Work the crypto program board - eight areas a program lead must run together: Policy, Inventory, Key Lifecycle, PKI, HSM & Vaults, Data-at-Rest, Data-in-Transit, and Crypto-Agility - replacing team-by-team crypto habits with one standard, one inventory, and provable evidence, with real crypto-policy, CBOM, key-lifecycle, PKI, HSM/KMS, and post-quantum migration work. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-033Enterprise Network Security Architecture — The Network Rail
A senior-level architecture course that designs the enterprise network security architecture itself, not a single firewall or a single segment. Work the network security rail - eight layers a defensible network is built from: Principles, Segmentation, Perimeter & Edge, Remote Access & SASE, East-West Control, Cloud Interconnect, Monitoring & Telemetry, and Zero-Trust Enforcement - designing deliberate trust boundaries, segmenting crown jewels and OT from IT, converging remote access through SASE, containing lateral movement, interconnecting a hybrid multi-cloud estate, and enforcing zero trust with real policy enforcement points and a funded migration plan.
৳6,000৳10,000View →
CY-SENIOR-035Security Automation & SOAR Program Leadership — The Automation Staircase
A senior-level program-leadership course that leads a SOC automation program end to end. Climb the automation staircase - eight steps from Case to Scale: Case, Use-Cases, Platform, Playbooks, Integrations, Metrics, Governance, and Scale - building the funded case, selecting and sequencing use-cases, choosing and architecting the SOAR platform, hardening playbooks with human gates and rollback, integrating safely, measuring honestly, governing change, and scaling without sprawl, with realistic SOAR CLI, playbook YAML/JSON, and API-integration work. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-036Insider Risk Program Leadership — The Insider Risk Funnel
A senior-level program-leadership course that runs an insider risk program which protects the organisation while respecting the people in it. Work the insider risk funnel - eight stages a responsible program runs together: Charter, Governance, Signals, Detection, Triage, Response, Ethics & Privacy, and Maturity - treating the non-malicious majority fairly, partnering with HR, Legal, and Privacy, and keeping monitoring proportionate, lawful, and transparent. Four hands-on activities in every lesson, built from real program artifacts, not shell commands.
৳6,000৳10,000View →
CY-SENIOR-037Kubernetes & Container Security Architecture — The Container Defense Stack
A hands-on senior-level architecture course that designs container and Kubernetes security as a defense-in-depth stack across a large multi-cluster estate. Work the container defense stack - eight layers a defensible platform is built from: Image & Build, Registry & Supply Chain, Admission Control, Cluster Hardening, Runtime Security, Network Policy, Secrets & Identity, and Observability & Response - so a compromise cannot pass from one layer to the next, with real image signing, admission policy-as-code, RBAC, runtime detection, NetworkPolicy, workload identity, and cluster forensics. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-038API Security Program Leadership — The API Security Loop
A senior-level course that runs an organization-wide API security program, not a single API review, by working the API Security Loop - eight arcs from Inventory through Monitor - to find every API, set the standards they are built on, verify who is calling and what they may touch, enforce the contract, funnel every call through one gateway, stop abuse, prove defenses hold before release, and watch live traffic for what only production reveals, grounded throughout in the OWASP API Security Top 10.
৳6,000৳10,000View →
CY-SENIOR-039Security Operating Model & Organisation Design — The Operating Model Loop
A senior-level course that designs the security organisation itself. Work the operating model loop - eight arcs a head of security must get right: Mandate, Structure, Roles, Sourcing, Interfaces, Decision Rights, Capacity, and Evolve - chartering the mandate, choosing the structure, building the role catalogue, deciding the sourcing mix, defining the interfaces, assigning decision rights, planning capacity against risk, and evolving the model as the company scales. Four hands-on activities in every lesson, built from real operating-model artifacts, not shell commands.
৳6,000৳10,000View →
CY-SENIOR-040Security Investment Strategy & Business Case — The Investment Staircase
A senior-level course that builds the discipline of deciding, justifying, funding, delivering, and proving the value of security investment. Climb the investment staircase - eight steps: Baseline, Risk Link, Options, Business Case, Prioritise, Fund, Deliver, and Prove Value - baselining current spend, linking every ask to risk, weighing real options, writing a CFO-ready business case, prioritising and funding a multi-year portfolio, delivering it, and proving the value. Four hands-on activities in every lesson, built from real investment artifacts, not shell commands.
৳6,000৳10,000View →
CY-SENIOR-041MSSP & MDR Oversight — The Outsourcing Funnel
A senior oversight course that governs and gets real value from outsourced security services - never runs them. Work the outsourcing funnel - eight stages an outsourcing relationship passes through: Scope, Select, Contract, Onboard, Integrate, Operate, Measure, and Renew or Exit - keeping accountability with the bank while a provider does the work, with real RFP evaluation, enforceable SLAs and containment authority, telemetry onboarding, platform integration, ongoing governance, and independent detection validation. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-042Multi-Cloud Security Governance — The Cloud Governance Board
A senior-level course that governs cloud security across hundreds of AWS accounts, dozens of Azure subscriptions, and a growing GCP footprint. Work the cloud governance board - eight tiles: Landing Zones, Account Structure, Guardrails, Identity Federation, Policy as Code, Cost & Risk, Compliance Evidence, and Operating Rhythm - with real SCP/Azure Policy/org-policy JSON, OPA/Rego, Terraform, and multi-cloud CLI work that keeps every account consistent and governed. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-043Software Supply Chain Security Program — The Provenance Funnel
A senior-level, program-scale course that runs software supply chain security as an org-wide program, not a single pipeline. Work the provenance funnel - eight stages: Scope, Inventory, Standards, Build Integrity, Dependencies, Verification, Vendors, and Assurance - proving provenance rather than assuming it across first-party, open-source, commercial, build-infrastructure, and AI-generated code, with real SBOM/VEX, SLSA, signing, admission, dependency-governance, and customer-assurance work. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-044Customer Identity & Access Management Architecture — The Customer Identity Rail
A senior architecture course that builds and defends the identity system tens of millions of customers sign in through. Work the customer identity rail - eight stations: Registration, Authentication, Federation, Sessions & Tokens, Authorization, Account Protection, Privacy & Consent, and Scale & Resilience - making passkeys the default, federating with OIDC/OAuth2 plus PKCE behind a BFF, authorizing per object and per consent, defending against credential stuffing and takeover, and running login as a resilient, migrated, multi-region tier-0 service. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-045Security Architecture Governance & Design Authority — The Design Authority Loop
A senior-level course that builds the design authority function governing security architecture across a whole enterprise. Work the design authority loop - eight arcs: Principles, Reference Architectures, Patterns, Review Gates, Exceptions, Standards Lifecycle, Assurance, and Roadmap - ratifying a small set of binding principles, maintaining reference architectures per domain, building an owned pattern catalogue, running risk-tiered design review gates, managing time-boxed exceptions, running a real standards lifecycle, assuring conformance against reality, and sequencing a funded multi-year roadmap. Four hands-on activities in every lesson, built from real governance artifacts, not shell commands.
৳6,000৳10,000View →
CY-SENIOR-046Enterprise Endpoint Security Architecture — The Endpoint Defense Stack
A senior-level architecture course that designs the target-state endpoint security architecture for a global fleet of tens of thousands of Windows, macOS, Linux, and mobile devices - the tooling strategy, device trust model, and fleet operating model, not single-host hardening. Work the endpoint defense stack - eight layers built firmware-up: Hardware Root of Trust, OS Baseline, Identity & Device Trust, Management Plane, Prevention Controls, Detection & Response, Data Protection, and Lifecycle & Fleet Ops - anchoring hardware trust, holding one cross-platform baseline, gating access on device compliance, consolidating the management plane, layering prevention, unifying detection across every OS, protecting data at scale, and running the fleet as a measured lifecycle. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-047Cyber Exercise & Tabletop Program — The Exercise Staircase
A senior-level course that builds a cyber exercise program end to end. Climb the exercise staircase - eight steps: Objectives, Audience, Scenario Design, Injects, Facilitation, Evaluation, Findings to Action, and Program Cadence - setting testable objectives, mapping the right audience, designing a threat-informed scenario, building the inject list that drives the room, facilitating with real skill, evaluating objectively against the plan, turning findings into owned action, and sustaining a multi-year, regulator-aligned program. Four hands-on activities in every lesson, built from real exercise artifacts, not shell commands.
৳6,000৳10,000View →
CY-SENIOR-048Cyber Insurance & Risk Transfer Strategy — The Risk Transfer Loop
A senior-level course that builds the discipline of deciding what cyber risk to retain, mitigate, transfer, or avoid, and buys and uses cyber insurance well when transfer is the right tool. Work the risk transfer loop - eight arcs: Risk Appetite, Coverage Needs, Market & Underwriting, Controls Evidence, Policy Terms, Claims Readiness, Contracts & Vendors, and Review - setting appetite, sizing coverage, working the market from a position of truth, evidencing controls honestly, reading and negotiating policy terms, rehearsing claims readiness, transferring risk contractually to vendors, and reviewing the program every year. Four hands-on activities in every lesson, built from real risk-transfer artifacts, not shell commands.
৳6,000৳10,000View →
CY-SENIOR-049Cross-Border Data & Sovereignty Strategy — The Sovereignty Board
A senior-level course that builds the strategy deciding where regulated data may live, how it may move, and how to architect and govern for it. Work the sovereignty board - eight tiles: Data Map, Legal Regimes, Transfer Mechanisms, Residency Architecture, Cloud & Vendors, Government Access, Operational Controls, and Governance - mapping every cross-border flow, matching the law to the data, choosing transfer mechanisms that hold, architecting residency, vetting cloud and vendors, limiting government access, enforcing operational controls, and governing it all as a standing decision. Four hands-on activities in every lesson, built from real sovereignty artifacts, not shell commands.
৳6,000৳10,000View →
CY-SENIOR-050Fraud & Financial Crime Risk Program — The Fraud Risk Funnel
A senior-level program-leadership course that runs the enterprise fraud and financial-crime risk program at a digital bank and payments company. Work the fraud risk funnel - eight stages: Threat Picture, Risk Assessment, Controls Design, Detection Strategy, Investigation, Recovery & Loss, Partnership, and Program Metrics - deciding what threats matter, sizing real exposure, designing layered controls, governing detection, investigating fairly, recovering and booking loss honestly, partnering within lawful limits, and reporting the truth to the board. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-051Converged Physical & Cyber Security Program — The Convergence Board
A strategic senior-level course that builds one converged security program out of two teams that used to run apart. Work the convergence board - eight tiles: Shared Risk Picture, Governance, Access Convergence, Facilities & Building Systems, Surveillance & Data, Incident Coordination, People & Insider, and Metrics & Maturity - building a shared risk picture, joint governance, a converged access lifecycle, hardened building and surveillance systems, joint incident coordination, an insider-risk partnership with HR and legal, and honest converged metrics driving a funded roadmap. Four hands-on activities in every lesson, built from real program artifacts, not shell commands.
৳6,000৳10,000View →
CY-SENIOR-053Threat Hunting Program Leadership — The Hunt Program Staircase
A senior-level course that builds and leads a threat hunting program, not a single hunt. Climb the hunt program staircase - eight steps: Charter, Hypotheses, Data Readiness, Hunt Cadence, Tradecraft Standards, Findings to Detections, Metrics, and Scale - leading a brand-new hunt team from an improvised habit to a measured, scaling program, with real KQL/SPL hunt queries, telemetry-coverage checks, and hunt-notebook automation. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-054Enterprise Forensic Readiness Program — The Evidence Rail
A senior-level program course that builds the enterprise capability to investigate your own incidents before one ever happens. Work the evidence rail - eight stations: Scenarios, Evidence Sources, Retention, Collection Capability, Integrity & Custody, Legal Alignment, Cloud & SaaS, and Exercise & Review - so evidence already exists, is retained, can be collected fast, and will stand up to a regulator, a court, or an insurer, with real retention config, EDR live-response, cloud log-export, hashing, and custody-record work. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-055Security Assurance & Testing Strategy — The Assurance Funnel
A strategic senior-level course that builds the org-wide assurance strategy deciding what gets tested, how often, by whom, and how the results are governed - not how to run any single engagement. Work the assurance funnel - eight stages: Assurance Map, Risk-Based Scope, Testing Portfolio, Independence, Vendor & Scheme Selection, Findings Governance, Evidence & Attestation, and Continuous Assurance - mapping every assurance source onto the three-lines model, scoping by risk, building the annual portfolio, protecting independence, choosing vendors and schemes well, governing findings in one register, reusing evidence, and moving to continuous assurance. Four hands-on activities in every lesson, built from real assurance artifacts, not shell commands.
৳6,000৳10,000View →
CY-SENIOR-056Secure-by-Design Product Strategy — The Secure-by-Design Loop
A senior-level strategy course that shifts the burden of security from customers to the product itself, at the company level. Work the secure-by-design loop across eight arcs - Principles, Secure Defaults, Memory Safety & Language Choice, Paved Roads, Threat Modeling at Scale, Customer Transparency, Vulnerability Class Elimination, and Measure & Commit - pairing BY DESIGN against BOLTED ON, with real default-configuration checks, memory-safety and language-inventory queries, paved-road adoption metrics, threat-modeling tooling, SBOM and advisory publishing, and CWE-class elimination tracking. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-057Security Tooling Strategy & Rationalization — The Tooling Board
A senior-level course that rationalizes a security stack grown by accretion into a portfolio someone actually runs on purpose. Work the tooling board - eight tiles: Capability Map, Coverage Gaps, Overlap & Sprawl, Build-Buy-Partner, Evaluation & POC, Integration Architecture, Adoption & Value, and Lifecycle & Exit - mapping capabilities to a real framework, finding true gaps, cutting sprawl and shelfware, deciding build-buy-partner on total cost, evaluating with real POCs, integrating through a hub, proving adoption and value to the CFO, and managing every tool's lifecycle to exit. Four hands-on activities in every lesson, built from real portfolio artifacts, not shell commands.
৳6,000৳10,000View →
CY-SENIOR-058Identity Threat Detection & Response — The Identity Defense Stack
A senior-level program course that builds identity-centric detection and response across an organization's entire identity fabric - Entra ID, on-prem AD, and Okta. Work the identity defense stack - eight layers: Identity Telemetry, Posture & Hygiene, Credential Attacks, Token & Session Abuse, Privilege Escalation, Lateral & Federation Abuse, Response Playbooks, and Program & Metrics - correlating telemetry, hardening posture, detecting credential, token, and privilege attacks on your own estate, containing fast, and measuring the program against MITRE ATT&CK, MTTD/MTTR, and a maturity roadmap. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-059Digital Operational Resilience — DORA & NIS2 Program — The Resilience Staircase
A senior program-level course that builds the digital operational resilience program a supervisor can actually test. Climb the resilience staircase - eight steps: Scope & Applicability, ICT Risk Framework, Critical Functions, Incident Reporting, Resilience Testing, Third-Party ICT Risk, Information Sharing, and Board Accountability - across DORA, NIS2, TIBER-EU, and UK FCA/PRA requirements, with real scope registers, framework mapping, impact tolerances, incident-reporting workflows, TLPT scoping, third-party registers, and board packs. Four hands-on activities in every lesson, built from real program artifacts, not shell commands.
৳6,000৳10,000View →
CY-SENIOR-061Legacy Systems & Modernization Security — The Modernization Rail
A senior-level architecture course that secures a legacy estate - mainframe, unsupported middleware, end-of-life Windows Server - while it is modernized out from under itself. Work the modernization rail - eight stations: Portfolio Discovery, Risk Triage, Contain & Isolate, Compensating Controls, Modernization Paths, Migration Security, Data & Identity Cutover, and Decommission - with real inventory and EOL scans, segmentation and bastion design, allowlisting and virtual patching, migration validation, identity cutover rehearsal, and decommission verification. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-062Continuous Controls Monitoring & Compliance Automation — The Controls Funnel
A senior-level GRC engineering course that turns controls into automated, evidence-producing tests so compliance is continuous rather than an annual scramble. Work the controls funnel - eight stages: Control Inventory, Framework Mapping, Evidence Sources, Automated Tests, Exception Handling, Dashboards & Alerts, Audit Readiness, and Program Maturity - building one control library, mapping once to comply many, collecting evidence API-first, writing control tests as code, handling exceptions as first-class records, alerting owners, satisfying auditors from continuous evidence, and maturing the program, at a healthcare SaaS provider carrying SOC 2, HIPAA, ISO 27001, and HITRUST at once. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-063Data Center & Hosting Security Architecture — The Data Center Stack
A senior-level architecture course that designs and defends the end-to-end security of owned and colocated data centres - physical through platform through operations and exit - for a latency-sensitive financial exchange operator whose workloads cannot move to public cloud. Work the data center stack - eight layers in physical-up order: Physical & Environmental, Hardware & Firmware, Out-of-Band Management, Network Fabric, Compute & Storage Platforms, Workload Isolation, Operations & Change, and Resilience & Exit - evidenced with real BMC/firmware-integrity checks, fabric and switch config, storage zoning, OOB access audits, and change and drift verification. Four hands-on activities in every lesson.
৳6,000৳10,000View →
CY-SENIOR-064Cybersecurity Workforce & Talent Strategy — The Talent Loop
A senior-level course that builds the security team's own workforce and talent strategy. Work the talent loop - eight arcs: Workforce Plan, Role Design, Hiring, Onboarding, Skills Development, Career Paths, Retention & Wellbeing, and Succession - planning real demand and capacity, designing roles against a recognized competency framework, hiring on a structured skills-based process, onboarding for real productivity, growing skills deliberately, building transparent career paths, sustaining retention and wellbeing, and preparing successors for every critical role. Four hands-on activities in every lesson, built from real workforce artifacts, not shell commands.
৳6,000৳10,000View →