Resources
The first cybersecurity reflexes
Five measures cover the vast majority of incidents faced by a mid-sized organisation: controlled identities, applied updates, tested backups, network segmentation and team awareness.
Five measures, in order of their return
Identity control comes first: every account has a holder, a justified permission level, and multi-factor authentication on sensitive access. Then come updates applied on a schedule, backups whose restore has been tested, and segmentation preventing a compromised workstation from reaching the servers. Awareness closes the list and makes it effective: it turns every colleague into a sensor.
- One account per person, with justified and reviewed permissions
- Multi-factor authentication on access to sensitive data
- An update schedule that is kept, systems and applications included
- An offline backup whose restore is tested every quarter
- Network segmentation isolating workstations, servers and industrial equipment
What each measure prevents
Controlled identities
A shared account makes every trace unusable. A named account turns a log into evidence.
Updates
They close known vulnerabilities, the very ones automated attacks look for first.
The tested backup
It reduces an incident to a short interruption. The restore test is what makes it real.
Segmentation
It limits a compromised workstation's reach and buys the team time to respond.
The cybersecurity programme, block by block
From fundamentals to incident response, by way of penetration testing. Hour counts state the depth given to each skill.
| Teaching block | Year | Hours | Credits |
|---|---|---|---|
| Security fundamentals | 1 | 220 h | 22 |
| Network and systems security | 1 | 220 h | 22 |
| Application security | 1 | 120 h | 12 |
| Penetration testing | 2 | 220 h | 22 |
| Incident response and digital forensics | 2 | 180 h | 18 |
| Governance, risk and compliance | 2 | 100 h | 10 |
| Technical English and methodology | 1 | 80 h | 8 |
| Professional dissertation and sixteen-week placement | 2 | 60 h | 6 |
Common questions
Where do I start with limited means?
With an inventory of accounts and multi-factor authentication on sensitive access: both are done in house, cost little and close the most-used entry route. The tested backup comes immediately after.
What place for team awareness?
It multiplies the effect of every other measure: a team that reports a suspicious message saves hours of detection. The programme devotes a full strand to awareness in its governance block.
How often should permissions be reviewed?
At every staffing change, and through a general review twice a year. Access accumulated across successive roles is the most common situation, and the simplest to correct.
Explore next
- Responding to an incidentDetection, containment, eradication, restoration, evidence collection and the post-incident report: the response procedure and what it requires you to prepare.
- Service continuityAcceptable downtime, acceptable data loss, backups, switchover, power and drills: building a verifiable continuity plan.
- Networks and cloudAddressing, routing, segmentation, virtualisation, containers and cloud architectures: the fundamentals of a controlled infrastructure.
- Industrial maintenancePreventive plan, vibration analysis, thermography, alert thresholds, spare parts and availability indicators: organising a site's maintenance.
- OHADA accountingChart of accounts, journal, ledger, trial balance, financial statements, value added tax and fixed assets: OHADA accounting applied.
- Reading financial statementsBalance sheet, income statement, cash flow statement: the profitability, structure and liquidity ratios that support a reasoned diagnosis.