Certificate in Cybersecurity

IBSF Code: SBFS15 • School of Banking & Financial Services

Certificate in Cybersecurity

Developing Globally Competent Cybersecurity, Information Security & Digital Risk Professionals

School: Banking & Financial Services Qualification: Certificate in Cybersecurity
Duration: 6 Months-Structure: 2 Semesters × 3 Months
Delivery: -- On-Campus | Online | Blended | Part-Time
Target Market: Global Applicants Level: Professional/Academic Certificate

Course Overview

The Certificate in Cybersecurity is a comprehensive professional programme designed to provide learners with the knowledge and practical skills required to protect information, networks, systems, applications and digital services from cyber threats

Explore Course Overview

Professional

Successful degree selection structures grant graduation map pathways with exemptions toward examinations under global professional accountancy bodies like ACCA, ICAEW, and the CIMA accelerated system.

For dynamic changes to course availability or to review details under the official School Calendar rules, view the official Course Specifications Guide.

Certificate in Cybersecurity

The Certificate in Cybersecurity is a comprehensive professional programme designed to provide learners with the knowledge and practical skills required to protect information, networks, systems, applications and digital services from cyber threats.

The programme combines cybersecurity fundamentals, information security, network security, threat intelligence, ethical security testing, digital forensics, incident response, cloud security, security governance, cyber risk and emerging technologies.

Rather than focusing exclusively on technical hacking skills, the programme develops a broader understanding of how organisations can identify, protect, detect, respond to and recover from cybersecurity incidents.

The curriculum is internationally benchmarked against the NIST Cybersecurity Framework (CSF) 2.0, the U.S. NICE Cybersecurity Workforce Framework, the European Cybersecurity Skills Framework (ECSF) developed by ENISA, and ISO/IEC 27001 information-security management principles. NIST CSF 2.0 provides a framework for managing cybersecurity risk, while NICE provides a common language for cybersecurity work, knowledge and skills.

The European component is aligned with the ECSF, which identifies 12 cybersecurity professional profiles and is used as an EU reference for cybersecurity skills, competence and training design.

Standard Entry

Applicants should normally have:

  • Completed secondary/high-school education or equivalent.
  • GCSE/GCE O-Level, High School Diploma or equivalent international qualification.
  • Basic knowledge of computers and information technology.

Professional Entry

Applicants with relevant qualifications or experience in:

  • Information Technology
  • Computer Science
  • Cybersecurity
  • Banking and Finance
  • Accounting
  • Auditing
  • Risk Management
  • Telecommunications
  • Engineering
  • Digital technology
  • Information systems

may also be considered.

Mature Entry

Applicants who do not possess the standard academic qualification may be considered based on relevant professional experience.

Relevant experience may include:

  • IT support
  • Network administration
  • Systems administration
  • Banking technology
  • Information security
  • Audit
  • Compliance
  • Risk management
  • Telecommunications
  • Government ICT
  • Digital services.

International Applicants

International applicants may be required to submit:

  • Academic certificates/transcripts
  • Passport or other identification
  • Qualification equivalency documentation where applicable
  • Certified English translations where documents are not in English
  • Evidence of English proficiency where required.

Duration: 6 Months
Structure: 2 Semesters × 3 Months
Delivery: On-Campus | Online | Hybrid | In-House
Level: Professional Certificate
Target Group: IT professionals, banking and finance professionals, government officials, auditors, compliance officers, risk professionals, ICT officers and aspiring cybersecurity specialists

  1. Foundations of Cybersecurity & Information Security
  • Cybersecurity concepts and principles
  • Information security fundamentals
  • Confidentiality, Integrity and Availability
  • Cybersecurity terminology
  • Cyber threat landscape
  • Cybersecurity roles and career pathways
  • Security policies and procedures
  • Cybersecurity governance
  • Cybersecurity ethics and professional conduct
  1. Computer Networks & Network Security
  • Network architecture
  • TCP/IP fundamentals
  • LAN/WAN technologies
  • Network protocols
  • Firewalls
  • Network segmentation
  • Secure remote access
  • VPNs
  • Intrusion detection and prevention
  • Network monitoring
  • Wireless security
  • Network attack vectors
  1. Cyber Threats, Vulnerabilities & Risk Management
  • Cyber threat landscape
  • Malware
  • Ransomware
  • Phishing and social engineering
  • Credential attacks
  • Insider threats
  • Vulnerability management
  • Threat modelling
  • Cybersecurity risk assessment
  • Risk treatment
  • Risk registers
  • Security controls
  • Cybersecurity risk reporting

Students are introduced to the NIST CSF 2.0 approach to managing cybersecurity risk and communicating cybersecurity outcomes across an organisation.

  1. Identity, Access Management & Data Protection
  • Identity and access management
  • Authentication and authorisation
  • Password security
  • Multi-factor authentication
  • Privileged access management
  • Role-based access control
  • Identity governance
  • Data classification
  • Data protection
  • Encryption fundamentals
  • Data-loss prevention
  • Privacy and cybersecurity
  1. Secure Systems, Applications & Cloud Security
  • Secure system architecture
  • Operating-system security
  • Application security
  • Secure software development
  • Web application vulnerabilities
  • API security
  • Database security
  • Cloud computing security
  • Cloud identity and access
  • Cloud configuration risks
  • Third-party technology risks
  • Secure development lifecycle
  1. Cybersecurity Governance, Policies & Compliance
  • Information-security governance
  • Cybersecurity policies
  • Security standards
  • ISO/IEC 27001 principles
  • Security controls
  • Security audits
  • Cybersecurity compliance
  • Third-party risk
  • Security awareness
  • Board and management responsibilities
  • Cybersecurity metrics and reporting

ISO/IEC 27001:2022 defines requirements for an information-security management system and provides a structured approach to managing information-security risks.

  1. Ethical Hacking & Vulnerability Assessment
  • Ethical hacking principles
  • Reconnaissance
  • Vulnerability identification
  • Security scanning
  • Penetration-testing concepts
  • Web application security testing
  • Network security testing
  • Password and authentication testing
  • Vulnerability prioritisation
  • Security remediation
  • Ethical and legal boundaries

Practical activities are conducted in authorised laboratory environments.

  1. Security Operations, Threat Detection & Threat Intelligence
  • Security Operations Centre (SOC)
  • Security monitoring
  • Security logs
  • Security Information and Event Management (SIEM)
  • Indicators of compromise
  • Threat intelligence
  • Threat hunting
  • Detection engineering concepts
  • Malware indicators
  • Alert triage
  • Security dashboards
  • Cyber threat reporting

The curriculum maps relevant competencies to U.S. NICE work categories such as Analyze, Protect and Defend, Investigate, Operate and Maintain, Securely Provision, and Oversee and Govern.

  1. Cyber Incident Response & Digital Forensics
  • Incident identification
  • Incident classification
  • Incident response lifecycle
  • Incident containment
  • Eradication and recovery
  • Digital evidence
  • Evidence preservation
  • Chain of custody
  • Disk and memory forensics
  • Log analysis
  • Malware investigation
  • Cyber incident reporting
  • Post-incident lessons learned
  1. Cybersecurity, Cloud, AI & Emerging Technology Risk
  • Cloud-security risks
  • Container and virtualisation security
  • Internet of Things security
  • Artificial intelligence and cybersecurity
  • Generative AI security risks
  • AI-enabled cyber attacks
  • Deepfakes and synthetic identity
  • Automation in cybersecurity
  • Blockchain security
  • Critical infrastructure cybersecurity
  • Emerging cyber threats
  1. Cyber Resilience, Business Continuity & Disaster Recovery
  • Cyber resilience
  • Business continuity
  • Disaster recovery
  • Backup strategies
  • Recovery planning
  • Crisis management
  • Cyber incident communications
  • Operational resilience
  • Third-party resilience
  • Cyber recovery
  • Testing and exercising
  • Lessons learned
  1. Cybersecurity Strategy, Risk & Capstone Project
  • Enterprise cybersecurity strategy
  • Cybersecurity maturity assessment
  • Cyber risk governance
  • Security architecture
  • Cybersecurity investment
  • Security performance metrics
  • Executive cybersecurity reporting
  • Cybersecurity programme management
  • Emerging threat assessment
  • Integrated Cybersecurity Capstone Project

Capstone Project

Students undertake a practical cybersecurity project such as:

“Cybersecurity Assessment and Resilience Plan for a Financial Institution.”

The project may involve:

  1. Asset identification
  2. Threat assessment
  3. Vulnerability analysis
  4. Risk assessment
  5. Security-control evaluation
  6. Incident-response plan
  7. Business-continuity considerations
  8. Cybersecurity improvement roadmap
  9. Management/executive presentation.

The programme is deliberately designed to provide European, U.S. and international exposure.

United States

The curriculum incorporates:

  • NIST Cybersecurity Framework 2.0
  • NICE Cybersecurity Workforce Framework
  • U.S. cybersecurity workforce role and competency concepts
  • Risk-management principles
  • Security operations
  • Incident response
  • Cybersecurity governance.

NIST CSF 2.0 is designed for organisations of different sizes, sectors and maturity levels and focuses on cybersecurity-risk outcomes.

The NICE Framework provides a common vocabulary for cybersecurity work, including work roles, tasks, knowledge, skills and competencies.

European Union

The curriculum incorporates the European Cybersecurity Skills Framework (ECSF) developed by ENISA. The ECSF provides a common European language for cybersecurity roles, competencies, skills and knowledge and supports the design of cybersecurity training programmes.

Relevant European themes include:

  • Cybersecurity skills and workforce development
  • Cyber resilience
  • Digital risk
  • Security governance
  • Secure digital products and services
  • Incident management
  • Regulatory compliance.

International Standards

The programme also draws on:

  • ISO/IEC 27001 — Information Security Management Systems
  • NIST cybersecurity guidance
  • NICE Workforce Framework
  • ENISA/ECSF
  • International cybersecurity risk-management practices
  • Information-security governance principles
  • Cyber-resilience practices.

The programme adopts a strongly practical and laboratory-oriented learning model.

 

Learning Method Weight
Expert instruction 25%
Practical cybersecurity laboratories 25%
Cybersecurity case studies 20%
Security simulations 15%
Applied projects 15%

Practical Activities

Learners may undertake:

  • Network-security configuration exercises
  • Vulnerability assessment
  • Threat-analysis exercises
  • Log analysis
  • Security-monitoring exercises
  • Phishing analysis
  • Incident-response simulations
  • Digital-forensics exercises
  • Risk assessments
  • Security-policy development
  • Cybersecurity maturity assessments
  • Cloud-security exercises
  • Executive cybersecurity reporting.

By the end of the programme, graduates should be able to:

  • Explain fundamental cybersecurity and information-security concepts.
  • Identify common cyber threats and vulnerabilities.
  • Conduct basic cybersecurity risk assessments.
  • Apply cybersecurity controls.
  • Understand network and systems security.
  • Apply identity and access-management principles.
  • Understand cloud and application-security risks.
  • Conduct basic vulnerability assessments.
  • Interpret security logs and alerts.
  • Understand SOC and threat-intelligence operations.
  • Participate in cyber incident response.
  • Apply basic digital-forensics principles.
  • Develop cybersecurity policies and procedures.
  • Assess cybersecurity governance and resilience.
  • Communicate cybersecurity risks to technical and non-technical stakeholders.
Assessment Component Weight
Continuous Assessment Tests 15%
Cybersecurity Assignments 15%
Practical Laboratory Exercises 15%
Cybersecurity Case Studies 10%
Mid-Term Examination 10%
Final Examination 15%
Cybersecurity Capstone Project 20%
TOTAL 100%

The assessment structure deliberately combines knowledge, technical practice, analysis, investigation and applied cybersecurity planning, rather than relying solely on examinations.

The programme provides a foundation for entry-level and junior professional roles across cybersecurity, information security, IT risk and digital resilience.

Potential Job Titles

 

Cybersecurity

  • Cybersecurity Officer
  • Junior Cybersecurity Analyst
  • Information Security Officer
  • Cybersecurity Support Analyst
  • Cybersecurity Operations Assistant
  • Security Administrator

Security Operations

  • SOC Analyst
  • Security Monitoring Analyst
  • Cyber Threat Analyst
  • Junior Threat Intelligence Analyst
  • Security Operations Officer

Risk & Governance

  • Cyber Risk Analyst
  • IT Risk Officer
  • Information Security Governance Assistant
  • Cybersecurity Compliance Officer
  • Security Controls Analyst
  • IT Audit Assistant

Incident Response & Investigation

  • Incident Response Analyst
  • Cyber Incident Analyst
  • Digital Forensics Assistant
  • Cybercrime Investigation Assistant
  • Security Investigation Analyst

Technical Security

  • Network Security Assistant
  • Vulnerability Assessment Analyst
  • Security Testing Assistant
  • Cloud Security Assistant
  • Identity & Access Management Analyst.