Complete Guide to Enterprise Cyber Defense
6h 33mBeginner2025-10-21
Authors

Malcolm Shore
Cybersecurity Expert, Former Director of GCSB

Ian Wilson
Course details
If you’re an enterprise IT or security professional, you need to stay up to date with the latest trends in cyber defense. In this course, instructors Ian Wilson and Malcolm Shore outline the security processes and technologies necessary to manage cybersecurity for an enterprise, using real-world technology examples based on both community and open-source solutions. Learn how to set up and run a cybersecurity program, and to monitor its efficiency and effectiveness. Discover skills to establish activities within the cybersecurity program to govern, identify, protect, respond, and recover to security incidents according to the NIST Cybersecurity Framework. Along the way, you’ll also explore how to meet the demands of digital operational resilience and leverage AI for enhanced cybersecurity.
Learning objectives
Analyze the components of the NIST Cybersecurity Framework to develop a comprehensive enterprise security program that incorporates governance, identification, protection, response, and recovery mechanisms.
Evaluate the security implications and risks associated with implementing AI systems in an enterprise environment, including potential vulnerabilities in training data and model deployment.
Design appropriate security controls and guardrails for AI systems that ensure safe and proper use while maintaining operational effectiveness.
Implement prompt engineering defense strategies to protect AI models from adversarial attacks and unauthorized manipulations.
Integrate digital operational resilience principles into cybersecurity programs to ensure continuous business operations during and after security incidents.
Learning objectives
Analyze the components of the NIST Cybersecurity Framework to develop a comprehensive enterprise security program that incorporates governance, identification, protection, response, and recovery mechanisms.
Evaluate the security implications and risks associated with implementing AI systems in an enterprise environment, including potential vulnerabilities in training data and model deployment.
Design appropriate security controls and guardrails for AI systems that ensure safe and proper use while maintaining operational effectiveness.
Implement prompt engineering defense strategies to protect AI models from adversarial attacks and unauthorized manipulations.
Integrate digital operational resilience principles into cybersecurity programs to ensure continuous business operations during and after security incidents.
Concepts
Introduction
- Understanding enterprise cyber defense
- What you need to know
- Disclaimer
Cyber Defense Leadership
- Understanding cyberspace
- Cyber as a modern source of business risk
- Executive oversight of cybersecurity
- Supplier and service provider oversight
- Incident communications
- The role of cyber insurance
- Security scorecards
The Foundations of Cyber Defense
- The cyberattack process
- Understanding the cyber defense program
- Compliance vs. risk
- Understanding on-premises, hybrid, and cloud-native technology
- Privacy and cybersecurity
- Data breaches and why they count
- Handling a ransomware event
- Understanding supply chain risk
- Understanding resilience
- Earning trust through Zero Trust
- Cybersecurity and AI
Architecting Business-Aligned Cyber Defense
- Evolution of the security paradigm
- The ESA as a business enabler
- Linking cyber risk to business risk
- COBRA as a lightweight ESA
- Modeling cybersecurity risks
- Taking a walk through COBRA
- Architecting with ArchiMate
- Modelling security with Archi
- Adding security to the model
Governance for Cyber Defense
- Achieving cybersecurity governance
- Policy and planning for cybersecurity
- Cybersecurity standards and frameworks
- Awareness programs
- Measuring cybersecurity performance
- Information sharing
Threat-Driven Risk and Controls Framework
- Understanding exploits
- Maintaining awareness of cyber threats
- Maintaining an enterprise threat repository with OpenCTI
- Sharing threat intelligence
- Using STIX with TAXII
- Managing vulnerabilities
- Introduction to the Greenbone Vulnerability Manager
- Managing cyber risk assessments
- Introducing SimpleRisk
- Taking SimpleRisk for a spin
- Understanding controls
Identity and Access Management
- What are identities
- Traditional and emerging authentication of identities
- Controlling access to systems and applications
- Active Directory as an identity platform
- Using tickets for managing access
- Privileges and authorities
- Introduction to PAM
- Auditing accounts and privileges
Protecting Information
- Classifying business information
- Protecting information
- Introduction to cryptography
- Understanding certificates
- Protecting payment card data
- Data loss prevention
- AI and data leakage
Network Zoning with Zero Trust
- Networks in an enterprise
- Using firewalls to create security zones
- Understanding network penetrations
- Best practices in defending Wi-Fi networks
- Diving into Zero Trust
Securing IT Platforms
- Hardening platforms
- Managing workstation security
- Web servers and OWASP
- Protecting web servers with a web application firewall (WAF)
- Understanding Windows attacks
- Understanding Linux attacks
Securing Enterprise Applications
- Enterprise applications
- Making SharePoint secure
- Understanding MSSQL attacks
- Confluence exploits
- Understanding attacks on Jira
Assurance Techniques for Cyber Defense
- Forms of testing
- Security testing with KiwiTCMS
- Penetration testing for assurance
- The scope of pen testing
- Red teaming as an adversary
Auditing the Cyber Defenses
- Audit in the enterprise
- The IT assurance framework
- Auditing the IT fleet
- Auditing Linux with Lynis
- Using Wazuh to audit Windows
- Auditing Active Directory
The Operational Security Program
- SOC management
- The basics - Backups and disaster recovery
- Understanding SIEM monitoring
- Monitoring with ELKStack
- Running a cyber drill
- Understanding security analytics
- Introduction to incident response
- Incident playbooks
- Tooling for incident response
- Managing incidents with DFIR-IRIS
- Hunting with Malcolm