Role-aligned learning Four pathways, one connected range

Train for the work.
Understand the whole system.

Choose a focused route into defensive security, offensive security, leadership or GRC. Each pathway uses the same enterprise-style environment, so your speciality develops in context rather than isolation.

Find your direction

Cyber security careers demand different kinds of judgement.

A SOC analyst follows evidence through telemetry. A penetration tester tests assumptions. A security manager weighs capability and consequence. A GRC practitioner connects obligations to controls and proof. Practical training should reflect those differences.

01

Blue Team

Defensive Security

See the signal. Understand the system. Act with evidence.

Learn how defenders collect telemetry, investigate alerts, validate incidents and improve controls across endpoints, identity, network and cloud-connected services.

Roles this pathway supports
  • SOC Analyst
  • Cyber Security Analyst
  • Security Monitoring Analyst
  • Incident Responder
  • Threat Hunter
  • Detection Engineer
  • Vulnerability Analyst
  • Endpoint Security Analyst
Explore pathway
02

Red Team

Offensive Security

Test the controls by thinking like the adversary.

Work through authorised reconnaissance, vulnerability discovery, exploitation and lateral movement inside a contained range, then trace the evidence each action leaves behind.

Roles this pathway supports
  • Penetration Tester
  • Red Team Operator
  • Ethical Hacker
  • Adversary Emulation Specialist
  • Purple Team Analyst
  • Vulnerability Assessment Specialist
  • Application Security Tester
  • Security Consultant
Explore pathway
03

Leadership

Security Management

Turn technical reality into priorities people can act on.

Develop the operational and leadership judgement needed to manage security teams, programmes, incidents, stakeholders and risk-informed decisions.

Roles this pathway supports
  • Cyber Security Manager
  • Security Operations Manager
  • Information Security Manager
  • Cyber Security Program Manager
  • Security Project Manager
  • Security Consultant
  • Head of Cyber Security
  • Chief Information Security Officer
Explore pathway
04

GRC

Governance, Risk & Compliance

Connect the control statement to the system that proves it.

Learn how governance, risk and compliance work becomes stronger when policies, access reviews, audit logs, incidents and technical evidence are understood together.

Roles this pathway supports
  • GRC Analyst
  • Cyber Risk Analyst
  • Compliance Analyst
  • Information Security Auditor
  • ISMS Coordinator
  • Third-Party Risk Analyst
  • Security Assurance Analyst
  • Privacy and Security Officer
Explore pathway

A shared technical foundation

Specialise without losing sight of the environment.

Every pathway draws from the same connected range. That matters because identity decisions affect detection. Network design affects attack paths. Audit requirements affect logging. Incident findings affect management priorities.

01InfrastructureESXi, firewall, VLANs and services
02IdentityAD, IAM, RBAC, SSO and MFA
03VisibilityEvents, telemetry, SIEM and dashboards
04AdversaryReconnaissance, exploitation and movement
05ResponseTriage, containment, recovery and reporting
06GovernanceRisk, controls, evidence and improvement

Unsure where to begin?

Start with the kind of problem you want to solve.

If you enjoy investigating what happened, begin with defensive security. If you want to test how systems fail, examine offensive security. If your focus is prioritisation, people and delivery, explore management. If you are drawn to risk, controls and evidence, look at GRC.

Talk through your options