Courses

Next-Gen ICT Security: Architectures, Threats & Countermeasures

Course Outline

Advanced ICT Security Technical Foundation is a 4-5 day intensive technical training program designed to equip ICT professionals with in-depth knowledge and practical skills in cybersecurity. The course covers core and cutting-edge security technologies, cyber threat intelligence, attack methodologies, secure infrastructure design, monitoring, incident response, and governance frameworks. It emphasizes real-world scenarios and hands-on activities for advanced competency in protecting complex ICT environments.

Objective

  • By the end of this course, participants will be able to:
  • Understand advanced cybersecurity concepts and architectures across ICT systems.
  • Identify and analyze complex cyber threats and vulnerabilities.
  • Design and implement secure ICT infrastructure using modern best practices.
  • Apply tools and techniques for detection, response, and mitigation of cyber attacks.
  • Evaluate and integrate international standards and frameworks (e.g., NIST, ISO/IEC 27001, MITRE ATT&CK).
  • Leverage emerging technologies (e.g., Zero Trust, AI/ML, SOAR) for enhanced security postures.

Contents

Session 1: Cybersecurity Landscape and Frameworks

  • Evolving threat landscape and attacker tactics, techniques, and procedures (TTPs)
  • Cybersecurity principles (CIA triad, Zero Trust, defense in depth)
  • Global frameworks and compliance standards: NIST CSF, ISO/IEC 27001, CIS Controls
  • Risk management lifecycle and threat modeling (STRIDE, DREAD)
  • Case Study: SolarWinds Attack (2020) – Understanding the risk of compromised supply chains and third-party software vulnerabilities

Session 2: Secure Infrastructure Design and Network Defense

  • Security architecture for modern ICT infrastructures (cloud, on-prem, hybrid)
  • Network segmentation, secure configurations, VPNs, NAC, and firewalls
  • Advanced IDS/IPS systems and network monitoring techniques
  • Secure protocols (TLS, SSH, IPsec) and encryption best practices
  • Case Study: Colonial Pipeline Ransomware Attack (2021) – Analyzing the consequences of infrastructure vulnerabilities and weak network segmentation

Session 3: Endpoint, Identity, and Application Security

  • Hardening operating systems and endpoint protection strategies
  • IAM, MFA, and modern identity federation (OAuth, SAML, OpenID)
  • Secure software development (DevSecOps, CI/CD pipeline risks)
  • Web and API security (OWASP Top 10, API security testing tools)
  • Case Study: Okta and GitHub Token Abuse (2022) – Identity provider attack and source code access breach through compromised personal tokens

Session 4: Threat Detection, SIEM, and Incident Response

  • Cybersecurity operations and Security Information & Event Management (SIEM)
  • Threat hunting, anomaly detection, and incident response workflows
  • Forensic analysis basics and malware reverse engineering overview
  • Hands-on Lab: Investigating a breach using ELK Stack or Splunk
  • Case Study: Uber Data Breach (2022) – Compromised credentials and privilege escalation leading to major data exposure

Session 5: Cybersecurity in Emerging Technologies

  • Security in virtualized and containerized environments (Docker, Kubernetes)
  • Cloud security (AWS, Azure, GCP – shared responsibility model)
  • IoT and 5G security challenges and threat vectors
  • AI/ML in cybersecurity: detection, automation, and adversarial attacks
  • Case Study: Tesla Kubernetes Dashboard Leak (2018) – Misconfigured cloud container infrastructure and cryptojacking

Session 6: Strategy, Governance, and Future Trends

  • Building a cyber-resilient ICT organization
  • Aligning cybersecurity with business and regulatory needs
  • Preparing for post-quantum cryptography
  • Group Exercise: Designing a cybersecurity improvement roadmap
  • Case Study: Equifax Data Breach (2017) – Strategic governance and compliance failures in patch management and risk oversight

Assessment and Certification

Participants will receive a certificate of completion.
Optional: Practical skills evaluation or final quiz at the end of Day 5.

Entry Requirements

Solid understanding of ICT systems and network fundamentals

Experience with IT infrastructure, software, or system administration

Familiarity with common networking protocols and basic security practices

Target Group:

ICT professionals, system/network engineers, infrastructure architects, or cybersecurity-focused roles seeking to deepen their security expertise.

Mode of Delivery:

Instructor-led learning (virtual classroom or onsite), including live demonstrations, interactive labs, and group activities.

Duration:

4-5 Days (suggested format: 5 days for full coverage including extended hands-on sessions)

 Language:  English

Maximum Number of Participants: 12