Core lessons / Topics

Find the lesson that answers the question.

Foundations, the SOC analyst introduction, AI application and agent security, application supply chain, email authentication, GRC practice, the privacy boundary, and identity federation, in path order and from A to Z. Minutes and prerequisites are on each row. A figure mark means the lesson includes a static diagram.

Cybersecurity foundations

Open this path ↗

Ten lessons that teach a beginner to name assets and losses, judge risk under uncertainty, trace a request, handle identity, write scoped policies, see where an application stops trusting the browser, plan recovery, name who owns cloud and SaaS work, read evidence, and connect those skills to frameworks and product categories.

F8

From principles to frameworks and product categories

Relate a named risk to an outcome, a control, the evidence you would collect, and the product category that might help, without treating a purchase as the outcome.

Prerequisites: F1 What we protect: assets, confidentiality, integrity, and availability · F2 Threat, vulnerability, likelihood, impact, and uncertainty · F4 Identity, authentication, authorization, and recovery · F5 Least privilege, secure defaults, trust boundaries, and layered controls · F7 Logs, alerts, and evidence

10 MIN

SOC analyst introduction

Open this path ↗

Four lessons that take the foundations path into evidence-to-decision work: identity-alert triage, vulnerability prioritization, investigation with verified recovery, and an honest introduction to an Agentic SOC. Each lesson lists the foundation skills it depends on.

AI application and agent security

Open this path ↗

Four lessons on treating user, retrieved, and tool text as untrusted, keeping tools and credentials outside the model, and requiring a human gate before high-impact actions. Builds on identity, least privilege, and evidence. Agentic SOC remains the place for investigation architecture.

From dependency to decision

Open this path ↗

Four lessons on threat-modeling a small checkout API, seeing transitive dependencies, separating who can write code from who can promote it, and using an SBOM as inventory evidence rather than as a control. Builds on risk, least privilege, and framework vocabulary. TrackPort’s client and TLS lesson stays in Foundations.

What the mailbox proves

Open this path ↗

One lesson on what SPF, DKIM, and DMARC each check, which phishing still gets through, and how a synthetic domain moves from monitoring (p=none) to enforcement without treating a pass as safe mail.

From risk sentence to operating cadence

Open this path ↗

Three lessons that turn one Riverstone risk into an owned control, the evidence that shows the control ran, and a month of CSF 2.0 Govern work. Builds on risk, evidence, and framework vocabulary. Practices the framework cards.

Privacy is not a CIA checkbox

Open this path ↗

One foundations-adjacent lesson on the boundary between security objectives (confidentiality, integrity, availability, and resilience) and privacy objectives (appropriate use, minimization, and individual rights). Encryption and access control are not privacy done. Sector laws stay in separate explainers.

Trust tickets, not hallway trust

Open this path ↗

Three lessons on OAuth tickets, OIDC and SAML sign-in claims, and five federation failure habits. Builds on F4. Practices trust decisions. Does not replace the glossary term guides.

Find your next idea.

Tip: press / to open search. Escape closes this window.