Executive summary
This section introduces learners to the discipline of cyber security — what it is, why it matters, and how organisations protect themselves against an evolving threat landscape. Learners begin with the fundamentals: the aims of cyber security, the risks organisations face, and the legal and regulatory framework (including GDPR and the role of the ICO). They then move into the practical methods used to protect networks, devices and data, before learning how to manage and respond to cyber attacks through structured incident management. The section closes with an applied breach scenario that ties the knowledge together and prepares learners for assessment.
Aims
The section aims to give learners a working understanding of cyber security as both a technical and organisational concern. It develops their ability to recognise threats and risks, evaluate appropriate protection methods for given situations, and plan a coherent response to security incidents — grounding all of this in real legal, regulatory and organisational context.
Summary of learning outcomes
| LO1 | Understand the fundamentals of cyber security — its purpose, associated risks, relevant laws and regulations, and its historical development and impact. |
| LO2 | Understand the methods used to protect systems, networks and devices against cyber threats. |
| LO3 | Understand how to manage and respond to cyber attacks through incident management. |
Indicative content
- Fundamentals: definition and aims of cyber security; distinguishing security from non-security controls; risk management (policies, processes, incident management); data protection law, GDPR and the ICO; the evolution of cyber security and its impact on individuals and organisations.
- Protection methods: network security (firewalls, VPNs, access logs, firmware updates); penetration and vulnerability testing; anti-virus; mobile device management (MDM); access control reviews.
- Managing attacks: components of an incident management plan (classification, responsibilities, process); managing communications and roles; the correct sequence of incident actions; root cause analysis and post-incident review.
Assessment approach
Understanding is checked continuously through MCQ and scenario-based quizzes (for example, choosing the appropriate control for a scenario, or interpreting a penetration-test report) and short-answer tasks (such as outlining an incident plan for a small company). The section culminates in an applied case study — a simulated breach in which the learner completes an incident template — followed by an all-LO review and an assignment-readiness checklist.
Curriculum
- 4 Sections
- 9 Lessons
- 280 Hours
- Subsection 1: Cyber Security Fundamentals (LO1)This section introduces learners to the discipline of cyber security — what it is, why it matters, and how organisations protect themselves against an evolving threat landscape. Learners begin with the fundamentals: the aims of cyber security, the risks organisations face, and the legal and regulatory framework (including GDPR and the role of the ICO).3
- Subsection 2: Protection Methods (LO2)2
- Subsection 3: Managing Cyber Attacks (LO3)2
- Subsection 4: Applied Case Study & Assessment2








