Cybersecurity Foundations
Gain practical cybersecurity fundamentals you can apply immediately
Cybersecurity Foundations introduces core principles and practical practices for protecting networks, users, and data in modern environments. It teaches learners how to assess and mitigate cyber risk, detect and respond to incidents, and map controls to recognised frameworks such as NIST and COBIT.
Designed for beginners and professionals who need actionable security literacy, the course blends threat analysis, incident response, AI security considerations, and supply‑chain and zero‑trust concepts to build decision‑ready knowledge. Graduates should be able to explain threat types, recommend appropriate controls, and communicate risk across technical and non‑technical stakeholders.
At a Glance
Cybersecurity Foundations is an introductory online course that establishes core concepts for protecting networks, users, and data.
Taught by cybersecurity consultant Malcolm Shore, it covers common threat types, risk management and control frameworks such as NIST and COBIT, incident response, and the intersections of cybersecurity with AI and international norms.
| Level | Beginner |
| Rating | 4.6 out of 5 |
| Duration | 3+ hours |
| Languages | English |
| Certificate | Certificate of completion (shareable) |
| Access | Access for as long as your subscription is active |
| Course includes |
|
| Price | Included with LinkedIn Learning subscription; monthly or annual plans (free trial may be available) |
What This Course Teaches
The course frames outcomes as measurable competencies that let learners evaluate risk, select controls, and take concrete defensive and incident-response actions.
On completion, learners should be able to analyze threat activity, apply risk and control frameworks, implement incident-response procedures, and explain AI and international cyber norms.
How the Course Is Structured
The course is organized into eight broad sections made up of a series of short, focused video lessons; the syllabus lists 52 individual lessons in total.
The full run time is roughly 3.5 hours, with most lessons presented as concise, standalone videos grouped by topic from threats through frameworks, operations, AI, and diplomacy.
Curriculum overview
01Introduction▾
Opens the course with scope, objectives, and how the material is organized.
02Understanding the cybersecurity frameworks and standards▾
Provides a brief orientation to the role of standards and frameworks in shaping cybersecurity practice.
03What you should know▾
Summarises prerequisites and the baseline knowledge expected for learners beginning the course.
04Understanding the Cyber Kill Chain▾
Explains attacker workflows and the stages commonly used to model intrusions.
05Pre-cyber threats▾
Discusses preconditions and enabling activities that lead to cyber incidents.
06The emergence of the cyber threats▾
Traces how modern cyber threats evolved and the forces driving current risk trends.
07Botnets and the cybercrime industry▾
Examines botnets, monetization models, and how criminal ecosystems support attacks.
08Cloaking and alternate data streams▾
Describes techniques attackers use to hide payloads and evade detection mechanisms.
09Hiding using processes▾
Covers process-based concealment techniques and indicators defenders can monitor.
10Controlling the target through a rootkit▾
Outlines how rootkits provide persistent control and the defensive challenges they pose.
11Phishing and watering holes▾
Reviews social-engineering vectors and site‑based compromise techniques used to dupe targets.
12Understanding advanced persistent threats▾
Defines APT actors, their motivations, and how long‑term campaigns are conducted.
13Ransomware: A modern form of extortion▾
Explains ransomware tactics, business impact, and common attacker workflows.
14Cryptomining▾
Briefly describes illicit cryptomining and how it manifests on compromised systems.
15Hardware implants and other cyber FUD▾
Discusses hardware threats and separates real risks from exaggerated or misleading claims.
16The Orange Book: Early concepts in computer security▾
Introduces historical foundations that influenced modern security thinking and policy.
17Understanding the NIST Cybersecurity Framework▾
Explains the core functions and structure of the NIST CSF.
18Adopting the NIST Cybersecurity Framework▾
Covers practical steps and considerations when mapping controls to the NIST framework.
19Understanding the basics of cyber risk▾
Defines risk terms and how to interpret likelihood and impact in a cybersecurity context.
20Analyzing cyber threats and controls▾
Shows how to map threats to appropriate technical and organisational controls.
21Recording, reporting, and the risk context▾
Covers how to document and communicate risk findings for stakeholders and compliance.
22An advanced risk framework▾
Introduces a more sophisticated model for contextualizing cyber risk across the enterprise.
23Managing security with COBIT▾
Explains COBIT’s governance focus and how it complements technical controls.
24COBIT for operational security▾
Discusses applying COBIT practices to day‑to‑day security operations and accountability.
25Introduction to cybersecurity controls▾
Offers a taxonomy of common controls used to reduce cyber risk.
26Cybersecurity control framework▾
Explores how control frameworks are structured and applied across environments.
27Cybersecurity standards of good practice▾
Summarises widely accepted standards and the behaviours they encourage.
28Architecting for security▾
Discusses design principles and patterns used to reduce attack surface and improve manageability.
29Protecting payment card data▾
Covers approaches and considerations for securing payment card information and compliance drivers.
30Clouding the issues▾
Looks at cloud-specific security trade-offs and common misconfigurations to watch for.
31Securing things on the internet▾
Addresses security patterns for internet-exposed devices and services.
32Affordable cybersecurity▾
Explores cost-effective measures and prioritisation for organisations with limited budgets.
33Ensuring security is effective▾
Covers validation, testing, and metrics used to assess control effectiveness.
34Protecting privacy with cybersecurity▾
Discusses how security measures can support privacy objectives and regulatory compliance.
35Understanding the zero trust approach to network access▾
Introduces zero‑trust principles for access control and segmentation strategies.
36Resilience as an emerging approach▾
Explores organisational resilience concepts and how they apply to cyber incidents.
37Ensuring supply chain security through SBOMs▾
Explains software bill of materials (SBOMs) and their role in managing third‑party risk.
38Incident management basics▾
Introduces principles, roles, and processes for handling security incidents.
39Measuring incident management maturity▾
Describes maturity models and metrics to evaluate incident-response capabilities.
40Detecting an attack▾
Covers detection signals, telemetry sources, and practical monitoring approaches.
41Hunting for threats▾
Introduces proactive threat-hunting concepts and simple techniques to find anomalies.
42Responding to an incident▾
Outlines immediate response actions and coordination steps during an active incident.
43Communications plan and notification▾
Covers stakeholder communication, legal considerations, and notification best practices.
44Intoduction to AI security▾
Introduces the intersection of AI systems and security concerns at a conceptual level.
45Understand the AI threats▾
Examines specific threats to and from AI, including data‑poisoning and misuse risks.
46AI application guardrails▾
Describes practical constraints and controls to reduce AI-related operational risk.
47ISO42001 AI Management System▾
Provides a brief overview of emerging standards for AI management and governance.
48Cybersecurity goes global▾
Discusses how geopolitical and cross-border issues shape cyber policy and practice.
49Understanding cyber norms▾
Explains norms, voluntary agreements, and expectations that govern state behaviour in cyberspace.
50Cybil and the Global Forum on Cyber Expertise▾
Introduces international initiatives and organisations that support capacity building and best practice sharing.
51The Traffic Light Protocol▾
Describes the Traffic Light Protocol as a mechanism for graded information sharing among stakeholders.
52What’s next▾
Suggests follow-up steps, further learning paths, and ways to apply the course material professionally.
Audience & Requirements
Cybersecurity Foundations is aimed at beginners, early-career IT staff, and non-technical professionals who need a practical introduction to core cybersecurity concepts and governance.
It is best for learners seeking a compact, career‑oriented overview to support upskilling, role changes, or managerial awareness rather than deep technical certification prep.
- IT generalists and help‑desk staff taking on security responsibilities.
- Managers and risk owners who must understand cyber risk and policy implications.
- Career changers exploring entry roles in cybersecurity.
- Students or non‑technical professionals seeking baseline cybersecurity literacy.
- No special prerequisites; course is pitched at beginners.
- Familiarity with general IT concepts (helpful but not required).
- A LinkedIn Learning account and signed‑in access to download exercise files and obtain the certificate.
Note: Although labelled for beginners, the course covers a wide range of topics in a relatively short timeframe, so learners seeking deep technical skill should plan follow‑up study or hands‑on practice.
Final Verdict
Cybersecurity Foundations is a compact, well-organised introduction that delivers practical conceptual grounding suitable for beginners and for professionals who need a clear overview of cyber risk, controls, and incident handling.
Given its favourable platform rating, the availability of a shareable completion certificate, and inclusion with a subscription access model, the course represents good value for learners seeking a credible, time‑efficient primer.
It is recommended for managers, IT generalists, and career‑starters who want to gain confidence in security concepts quickly; those pursuing hands‑on technical roles should treat it as a first step and plan follow‑up study or practical labs to build operational skills.

Pluralsight
Codecademy