The learning field guide

Start with a question.

Learn the shared principles, then explore how the decisions change in your industry. Build your understanding with concrete examples and practice under realistic constraints.

ONE FOUNDATION. DIFFERENT STAKES.

Find your context.

Choose an industry, then work through its decisions.

START WITH THE SHARED SKILLS

Build a foundation. Develop an analyst’s judgment.

New to security? Start here. Industry paths link back to these lessons whenever you need a concept explained.

8 LESSONS / beginner

Cybersecurity foundations

Eight lessons that teach a beginner to name assets and losses, judge risk under uncertainty, trace a request, handle identity, write scoped policies, plan recovery, read evidence, and connect those skills to frameworks and product categories.

71 min reading

Explore this path ↗

4 LESSONS / intermediate

SOC analyst introduction

Four lessons that take the foundations path into evidence-to-decision work: identity-alert triage, vulnerability prioritization, investigation with verified recovery, and an honest introduction to an Agentic SOC and IRIS. Each lesson lists the foundation skills it depends on.

38 min reading

Explore this path ↗

INDUSTRY FIELD GUIDE / 01

Protect financial decisions, access, and recovery

Practice verifying payment changes and restoring trustworthy financial services.

  • Transaction integrity
  • Independent authorization
  • Reconciliation

3 applied lessons · 21 min · synthetic decision checks

Explore finance ↗

THE DECISIONS YOU’LL PRACTICE

  1. Verify a changed payment destination
  2. Constrain a vendor’s financial access
  3. Restore service and reconcile the books

These synthetic U.S. examples illustrate financial controls; regulatory coverage depends on the institution, regulator, activity, and jurisdiction.

INDUSTRY FIELD GUIDE / 02

Preserve safe utility operations during cyber incidents

Practice operator-led access, trustworthy telemetry, and controlled recovery.

  • Safety and service continuity
  • Operator-led decisions
  • Trusted configurations

3 applied lessons · 21 min · synthetic decision checks

Explore utilities ↗

THE DECISIONS YOU’LL PRACTICE

  1. Approve a bounded maintenance session
  2. Check the trustworthiness of operational evidence
  3. Rehearse recovery with the operational owner

These synthetic U.S. utility exercises use general OT guidance; electricity and water subsectors have different legal requirements and operating procedures.

INDUSTRY FIELD GUIDE / 03

Protect production, designs, and approved process changes

Practice decisions that preserve safety, quality, and recoverable production.

  • Production and quality
  • Recipe and design integrity
  • Supplier access

3 applied lessons · 21 min · synthetic decision checks

Explore manufacturing ↗

THE DECISIONS YOU’LL PRACTICE

  1. Protect the approved recipe
  2. Limit a supplier to the work it needs
  3. Restore production with a quality gate

These synthetic manufacturing examples apply general engineering practices; sector-specific product, safety, contractual, and legal obligations require separate assessment.

INDUSTRY FIELD GUIDE / 04

Protect patient information and service continuity

Practice coordinated downtime, biomedical access, and evidence-based recovery.

  • Patient-service continuity
  • Biomedical access
  • Health-data boundaries

3 applied lessons · 21 min · synthetic decision checks

Explore healthcare ↗

THE DECISIONS YOU’LL PRACTICE

  1. Coordinate a service outage
  2. Review a biomedical vendor’s access
  3. Recover the workflow as well as the database

These synthetic U.S. healthcare cases illustrate security coordination, not medical treatment; HIPAA and other requirements depend on the organization, data, and relationship.

INDUSTRY FIELD GUIDE / 05

Protect learning, student records, and open collaboration

Practice separating educational data needs from excessive access.

  • Student privacy
  • Open collaboration
  • Academic calendars

3 applied lessons · 24 min · synthetic decision checks

Explore education ↗

THE DECISIONS YOU’LL PRACTICE

  1. Separate student records from open research
  2. Review identities when educational roles change
  3. Restore a student service around its deadline

These synthetic U.S. examples distinguish K–12 student records from university research; FERPA coverage depends on Department of Education funding, and CISA recommendations are guidance.

INDUSTRY FIELD GUIDE / 06

Keep resident services trustworthy and accessible

Practice accountable access and recovery for public services.

  • Essential resident services
  • Delegated suppliers
  • Public and confidential records

3 applied lessons · 24 min · synthetic decision checks

Explore public sector ↗

THE DECISIONS YOU’LL PRACTICE

  1. Recover the resident’s service, not just the portal
  2. Keep supplier administration accountable
  3. Distinguish public information from confidential evidence

These synthetic U.S. public-service examples use voluntary risk guidance; federal FISMA obligations do not automatically apply to every state or local agency.

INDUSTRY FIELD GUIDE / 07

Protect checkout, seasonal access, and order integrity

Practice securing the customer journey through fulfilment and refunds.

  • Payment trust boundaries
  • Seasonal access
  • Order and refund integrity

3 applied lessons · 24 min · synthetic decision checks

Explore retail & e-commerce ↗

THE DECISIONS YOU’LL PRACTICE

  1. Inspect the checkout trust boundary
  2. Review seasonal refund permissions
  3. Restore the storefront without duplicating orders

These synthetic retail exercises treat PCI DSS as an industry standard within payment compliance programs, with scope determined by the actual payment architecture and responsibilities.

INDUSTRY FIELD GUIDE / 08

Preserve trustworthy dispatch and controlled recovery

Practice protecting partner access and operational information without unsafe disruption.

  • Dispatch integrity
  • Partner dependencies
  • Controlled degraded operations

3 applied lessons · 24 min · synthetic decision checks

Explore transport & logistics ↗

THE DECISIONS YOU’LL PRACTICE

  1. Verify a changed dispatch instruction
  2. Review partner access across device lifecycles
  3. Return from degraded operations deliberately

These synthetic scenarios use general transport and OT guidance; road, rail, aviation, maritime, warehouse, and public-transit operations have different rules and safety procedures.

Core field lessons.

Practice what you learn ↗
01

What we protect: assets, confidentiality, integrity, and availability

Learn to name the things worth protecting and describe a concrete loss as a confidentiality, integrity, or availability failure before talking about products.

8 MIN
02

Threat, vulnerability, likelihood, impact, and uncertainty

Learn why two similar weaknesses can receive different priorities by separating threat, vulnerability, exploitation evidence, impact, and what you still do not know.

9 MIN
03

How systems communicate: network, DNS, HTTP, and TLS

Trace a browser request to a tracking portal and identify what the network, DNS, HTTP, and TLS each do and do not protect.

10 MIN
04

Identity, authentication, authorization, and recovery

Distinguish proving who someone is from granting access, and treat account recovery as part of the same control system.

9 MIN
05

Least privilege, secure defaults, trust boundaries, and layered controls

Choose a scoped access policy by naming trust boundaries and stacking independent controls instead of one powerful exception.

8 MIN
06

Data protection, updates, backups, and resilience

Build a small organization's prevention and recovery plan that covers classification, updates, backups, and what must still work when a warehouse is down.

8 MIN
07

Logs, alerts, and evidence

Separate observed facts, hypotheses, and missing information when reading logs and alerts so a later decision can be defended.

9 MIN
08

From principles to frameworks and product categories

Relate a named risk to an outcome, a control, the evidence you would collect, and the product category that might help—without treating a purchase as the outcome.

10 MIN
09

Triage a synthetic identity alert

Practice stating what is known, what is hypothesized, and which evidence to request next when a synthetic identity alert fires.

9 MIN
10

Prioritize vulnerabilities and exposures

Combine severity, exploitation evidence, exposure, and business context to order a synthetic vulnerability backlog without pretending a single score is enough.

9 MIN
11

Investigate, respond, and verify recovery

Propose a scoped response with a human decision and postcondition checks, using a synthetic identity-and-export case.

10 MIN
12

Understand and build toward an Agentic SOC

Explain IRIS components as a reference architecture, complete a synthetic walkthrough, and keep human authority separate from model text.

10 MIN

Find your next idea.

Tip: press / to open search. Escape closes this window.