The four security paths are independent but designed to be
followed in sequence: first the language of security, then everyday practice, then
the human factor, finally governance. Together they form a complete curriculum, from the
first notion of risk through to the compliance audit. Alongside them, four specialised
paths: the Linux command line, from zero to administering a server in production; incident
management under NIS2 and ACN (Italy's National Cybersecurity Agency) determinations, from
preparation to notifying CSIRT Italia (the national CSIRT); artificial intelligence, from
the fundamentals of generative models to the obligations of the AI Act; and business
continuity, which answers the question all the others depend on: how long the organisation
can stay down, and what it takes not to go beyond that.
01
Introductory level
Information Security Fundamentals
The vocabulary and the conceptual models everything else rests on:
what you protect, against which adversaries, with which controls and with what risk logic.
It is the recommended prerequisite for the other paths.
Risk analysisSecurity controlsCryptography and identity
6 modules · 24 lessons · 26 hours · final certificate
EnrolExplore this path
02
Operational level
Cybersecurity Hygiene
The everyday practices that measurably reduce the attack
surface, from credential management to data continuity. Every module
closes with a checklist you can apply straight away.
Credentials and MFAUpdatesBackup and recovery
6 modules · 24 lessons · 26 hours · final certificate
EnrolExplore this path
03
Behavioural level
Cybersecurity Awareness
The human factor is not the weak link: trained properly, it is your
first detection sensor. How manipulation works, how to recognise attempted attacks
and how to build a culture of reporting.
Social engineeringPhishing and fraudReporting
6 modules · 24 lessons · 26 hours · final certificate
EnrolExplore this path
04
Advanced level
Compliance and frameworks
The regulatory and methodological framework of a defensible security
programme: not only what the frameworks require, but how they map onto each other and how
they turn into evidence an auditor can verify.
NIS2ACN specificationsNIST CSF 2.0ISO/IEC 27001
8 modules · 32 lessons · 35 hours · final certificate
EnrolExplore this path
05
Technical path
Linux system administration from the command line
From the meaning of the prompt to the day to day running of a server.
For every command: what it answers, in which situation you use it, how you write it and
what happens when you get it wrong. Every lesson contains terminal sessions meant
to be reproduced, not read, and points to the official documentation.
Filesystem and permissionsStreams and pipelinesProcesses and systemdNetworking and SSHScripting and hardening
9 modules · 36 lessons · 39 hours · final certificate
EnrolExplore this path
06
Specialist level
Security incident management and response
The process that NIS2 and Legislative Decree 138/2024 really require:
preparing with a plan and defined roles, classifying with the ACN (Italy's National
Cybersecurity Agency) taxonomy, notifying CSIRT Italia (the national CSIRT) within 24
and 72 hours, responding while preserving the evidence and learning from the incident.
With a precise link to the GDPR whenever the data is personal.
NIS2 and Legislative Decree 138/2024ACN determinationsNotifications to CSIRT Italia
6 modules · 24 lessons · 26 hours · final certificate
EnrolExplore this path
07
Cross-cutting level
Artificial intelligence: fundamentals, tools and the AI Act
From the basics of AI to the obligations of Regulation (EU) 2024/1689:
how generative models really work and why they get things wrong, how to work with
them methodically, what European law asks of those who provide them and those who use
them, and what security and data protection risks they bring into the organisation.
No technical skills required.
Fundamentals and generative modelsWorking methodAI ActData and security
7 modules · 29 lessons · 31 hours · final certificate
EnrolExplore this path
08
Organisational level
Business continuity and disaster recovery
Sooner or later every organisation comes to a halt: the difference between
a disruption you manage and one you simply suffer is decided beforehand. How to measure
the cost of downtime with a business impact analysis, how to set RTO and RPO, how to
design backups that hold up against an encryption attack, how to write plans that can
be used under pressure and how to test them. With the continuity obligations of
NIS2, DORA and the GDPR.
ISO 22301Business impact analysisStrategies and plansNIS2 and DORA
6 modules · 24 lessons · 26 hours · final certificate
EnrolExplore this path