Skip to main content

Earn €500 when a friend you refer enrols, and help them kickstart their future.

Join affiliate programme

Cyber Security Technician

Gain the skills and knowledge to protect your organisation from cyber threats as a qualified cyber security technician.

  • Off-the-job training: ~450 hours. Level 3 — Entry level. Coding at L3 is introduced as a supporting skill: reading, adapting, and writing simple scripts to assist cyber security operations.
Duration

18 months delivery + 3 months EPA

Standard

Level 3 Cyber Security Technician

Funding Band

£11,000

What you’ll be able to do

First-line cyber security operations

Operate as a first-line cyber security professional within a Security Operations Centre or helpdesk function - monitoring, escalating, and documenting security events following incident response best practices and forensic evidence-handling principles

Cyber security risk assessment

Assess and manage cyber security risk by conducting vulnerability assessments, building risk registers, and producing actionable reports that translate technical findings into business-relevant recommendations for stakeholders

Security controls

Protect digital environments by implementing and maintaining technical, physical and procedural security controls aligned with industry frameworks and UK legislation

Threat detection and response

Detect and respond to cyber threats using enterprise-grade open-source tooling - including SIEM platforms (Wazuh/Elastic Stack), vulnerability scanners (OpenVAS/Nessus), and threat intelligence frameworks (MITRE ATT&CK)

CompTIA Security+ exam preparation

Prepare for optional CompTIA Security+ certification across all five exam domains: Security Concepts, Threats & Vulnerabilities, Security Architecture, Security Operations, and Governance, Risk & Compliance. Exam fees are not included.

Security awareness and governance

Design and promote a security-aware culture by developing awareness campaigns, drafting organisational policies, supporting compliance audits, and advising on governance frameworks such as Cyber Essentials and ISO 27001

Tools you'll learn

WazuhElastic StackOpenVASNessusWiresharkpfSenseiptablesSnortSuricataMITRE ATT&CKOpenSSLGPGBurp SuiteOWASP WebGoatDVWAREMnux

Curriculum

10 Modules · 69 Topics

01Cyber Security Foundations & Landscape50h · 7 topics

Key Skills Gained

  1. Classify SME information assets by CIA (Confidentiality, Integrity, Availability) requirements and conduct a controls inventory

  2. Research real-world SME breaches and map attack patterns

  3. Capture and analyse basic network traffic using Wireshark

  4. Explore web vulnerabilities (SQLi, XSS) with OWASP WebGoat

  5. Encrypt files using GPG and inspect TLS certificates

  6. Classify data assets by sensitivity level

  7. Produce a security landscape assessment for your SME

02Threats, Actors & Social Engineering50h · 8 topics

Key Skills Gained

  1. Map threat actors to SME industry using MITRE ATT&CK Navigator

  2. Conduct attack surface analysis of an SME digital footprint

  3. Analyse phishing emails and design staff awareness exercises

  4. Set up and use a malware analysis sandbox (REMnux)

  5. Simulate malware scenarios and identify mitigations

  6. Produce threat intelligence reports for business stakeholders

  7. Identify and classify indicators of compromise (IoCs)

  8. Create phishing response flowcharts for SME helpdesks

03Vulnerabilities, Attacks & Assessment50h · 7 topics

Key Skills Gained

  1. Explore web application vulnerabilities in depth (OWASP WebGoat/DVWA)

  2. Demonstrate credential attacks in lab (Burp Suite)

  3. Assess AI/LLM security risks relevant to SME operations

  4. Run vulnerability scans using OpenVAS/Nessus Essentials

  5. Score and prioritise findings using CVSS/NVD

  6. Produce vulnerability assessment reports with remediation roadmaps

  7. Scope vulnerability assessments for SME environments

04Identity, Data Protection & Asset Management45h · 7 topics

Key Skills Gained

  1. Configure LDAP/AD with role-based access control

  2. Implement MFA and enforce password policies

  3. Conduct user access rights reviews for SME staff

  4. Build and maintain SME asset inventories with lifecycle tracking

  5. Create data classification schemes and apply DLP rules

  6. Analyse user behaviour logs for insider threat indicators

  7. Design insider threat awareness guidance for SME management

05Cryptography40h · 6 topics

Key Skills Gained

  1. Encrypt files and communications using AES/GPG

  2. Generate and manage RSA key pairs for secure transfer

  3. Create CSRs and manage SSL/TLS certificates (OpenSSL)

  4. Configure HTTPS with proper TLS settings on web servers

  5. Verify file integrity using SHA-256 hashing

  6. Implement data masking on sample databases

06Hardening, Network Security & Monitoring45h · 7 topics

Key Skills Gained

  1. Harden Windows/Linux servers using CIS benchmarks

  2. Configure firewall rules (pfSense/iptables)

  3. Deploy and tune IDS alerts (Snort/Suricata)

  4. Set up email authentication (DMARC/SPF/DKIM)

  5. Deploy SIEM and ingest multi-source logs (Wazuh/Elastic Stack)

  6. Create monitoring dashboards and automated alert rules

  7. Build a SOC-in-a-Box monitoring solution for an SME

07Security Architecture, Resilience & Change Management50h · 7 topics

Key Skills Gained

  1. Design secure network architectures for SME environments

  2. Configure VPN connections and network segmentation (VLANs)

  3. Implement Zero Trust access policies in a lab

  4. Build disaster recovery plans with RTO/RPO calculations

  5. Configure automated server backup solutions

  6. Conduct tabletop DR exercises for SME scenarios

  7. Document change management processes (CAB, impact analysis, backout plans)

08Incident Response & Digital Forensics40h · 6 topics

Key Skills Gained

  1. Execute incident response tabletop exercises (ransomware scenario)

  2. Create forensic disk images and maintain chain of custody

  3. Reconstruct incident timelines from SIEM and log data (Wazuh/Elastic Stack)

  4. Parse and correlate logs across multiple data sources

  5. Write incident reports for technical and non-technical audiences

  6. Conduct threat hunting using dashboards and packet captures

09GRC, Compliance & Security Awareness50h · 8 topics

Key Skills Gained

  1. Build risk registers with quantitative analysis (SLE/ARO/ALE)

  2. Map SME policies against UK legislation and identify compliance gaps

  3. Conduct vendor assessments and draft SLA requirements

  4. Perform mock compliance audits (Cyber Essentials/ISO 27001)

  5. Design security culture improvement plans

  6. Create phishing simulation campaigns with success metrics

  7. Develop security awareness training calendars for SME staff

  8. Draft key security policies (AUP, incident response, data handling)

10Security+ Exam Preparation & EPA Readiness30h · 6 topics

Key Skills Gained

  1. Apply exam strategies for Security+ PBQs and scenario questions

  2. Demonstrate integrated security assessment across all domains

  3. Compile and present a professional apprenticeship portfolio

  4. Articulate all KSBs confidently in professional discussion format

  5. Conduct timed practice exams with gap analysis and targeted revision

  6. Perform mock EPA practical demonstrations (patching, access control, IR)

The Learning Model

A proven approach designed to build real, job-ready skills through practice, feedback, and community

Self-Paced, Flexible Learning

Students learn through flexible online study, not traditional lectures, so they can organise their learning around their life and progress at their own speed.

Intensive Sprint-Based Curriculum

The curriculum is organised into short intensive sprints that use curated, high-quality learning material and prioritise hands-on practice over passive content consumption.

Real-World Projects

Each sprint ends with a practical real-world project designed to simulate industry challenges, so students apply knowledge immediately.

Professional Reviews

After completing a project, students receive two one-on-one reviews — typically with a Senior Team Lead and a Junior Team Lead or peer — replicating the kind of review experience used at tech companies.

Peer Review & The Protégé Effect

Students also review others' work, which reinforces their understanding (through the Protégé Effect) and builds teamwork and critical thinking skills.

Community & Expert Support

Learning is supported by a community of learners, weekly standups, open support sessions, and guidance from experienced industry professionals.

Workshops for Mastery

Learners get access to weekly masterclass workshops for the most popular topics, allowing them to learn from experts together with peers.

Why This Model Works

By combining self-directed learning with structured sprints, real-world projects, and professional feedback loops, our model mirrors how successful tech teams operate. Students don't just learn theory — they build the habits, skills, and confidence needed to contribute from day one in a professional environment.

Curriculum updates

Topic details and content may evolve over time as we respond to industry developments and continuously improve our courses to ensure the best learning experience.

Boom Training

© 2026 Turing College. All rights reserved.