01Introductory level
Information Security and Cybersecurity Fundamentals
The path builds the vocabulary and the conceptual models on which all the rest of the training rests: what we protect, from whom, with which controls and with what risk logic. It is the recommended prerequisite for the other paths.
Risk analysisSecurity controlsCryptography and identity
How it is delivered
- Delivery
- Entirely online and asynchronous, from any device: you study when you want, at your own pace.
- Passing the tests
- At least 70% correct answers; every answer comes with an explanation of why.
- Attempts per test
- Unlimited: the best attempt counts.
- Time per test
- 25-30 minutes per test.
- Progress
- Tracked module by module: each module unlocks when you pass the test of the previous one.
- On completion
- A personal PDF certificate, with a unique verification code.
- Length of access
- You have 90 days from enrolment to complete the learning path. Once you complete it your access stays available with no expiry; if the deadline passes without the path being completed, the enrolment is suspended and the results you have already achieved stay on record.
- Enrolment
- With a personal key, after you have created your account.
The learning path in detail
Welcome. This is the path the Academy recommends starting from: it builds the vocabulary and the conceptual models all the others rest on. Without a shared language for risk, threat and control, every security discussion slides into improvisation: this is where the foundations are laid.
Objectives of the path
By the end of the path you will be able to:
- distinguish Information Security, Cybersecurity and ICT Security, and place a problem within the right perimeter (Module 1)
- use the CIA triad and the extended properties to describe what must be protected and from which compromise (Module 2)
- reason with the threat-vulnerability-risk model and order the actions by priority (Module 3)
- recognise threat actors and read the anatomy of a real attack (Module 4)
- classify security controls - preventive, detective, corrective - and combine them into defence in depth (Module 5)
- understand where cryptography and identity management solve the problems, and where they do not (Module 6)
Who it is for and prerequisites
Anyone who works with information: technical and non-technical staff, managers and new joiners. No prerequisite is required: the path starts from zero and is the recommended prerequisite for all the other paths in the Academy.
How it is run
The path is delivered entirely online, asynchronously: you can study when you want, at your own pace, from any device. The estimated total duration is 26 hours, to be spread within the completion deadline set out below.
Each module is organised into four lessons and two tests:
- Lesson. A reasoned treatment of the topic, with diagrams, examples and concrete cases.
- In depth. The up-to-date regulatory and technical picture, with the deadlines that matter and references you can verify at source.
- Real-world cases. What actually happens on the market: documented episodes always read with the same grid, down to the control that would have broken the chain.
- In practice. What you do on Monday morning: procedures, checklists, ready-made templates and indicators to measure the result.
- Test. Closed-answer questions on the whole module. Passing requires at least 70%; attempts are unlimited and the best mark counts. At the end of every attempt you receive a detailed explanation of each answer, including the correct ones.
- Exercise. A case to work through by deciding: every choice opens a different path and the outcome depends on what you chose, with an explanation of what would have happened otherwise. Marking is automatic and you can retake it as many times as you like.
Progression. The 6 modules are taken in sequence: each module unlocks only after you have passed the test of the previous module. The exercises do not block progress, but they are an integral part of the path and of the overall assessment.
Final test and certificate
Once you have passed the tests of all the modules, the final test unlocks: 30 questions drawn at random from the topics of the whole path, with the same 70% threshold and unlimited attempts. On passing it you obtain the path certificate, downloadable as a PDF, with a unique code that allows its authenticity to be verified.
Completion deadline
You have 90 days from enrolment to complete the learning path. 15 days before the deadline you receive an email reminder.
If you complete the path within the deadline, your access stays available with no time limit and you receive the certificate. If the deadline passes without the path being completed, the enrolment is suspended: the results you have already achieved stay on record, and to carry on you need a new enrolment key.
Support
In the Announcements forum you will find the tutor's messages. For questions on the content or on the exercises, use the channels indicated by your training contact.
Programme
The modules are taken in sequence: each one opens when you pass the test of the previous one.
Module 1
Information Security and Cybersecurity: scope and definitions
Tell apart the two perimeters, place information security in relation to IT security and set the basic vocabulary. Includes the European regulatory map updated to August 2026 and the data on the Italian threat landscape.
LessonLessonLessonLessonTest · 16 questionsExercise
Module 2
The CIA triad and the extended properties
Confidentiality, integrity and availability as design criteria, the conflicts between the three properties, the reversal of priorities in industrial settings and the properties the triad does not cover: authenticity, non-repudiation, traceability.
LessonLessonLessonLessonTest · 15 questionsExercise
Module 3
Threat, vulnerability, risk: the conceptual model
The relationship between asset, threat, vulnerability and impact, and how you get to a risk estimate usable for deciding: public prioritisation tools (CVSS, EPSS, already exploited vulnerabilities), matrix, quantitative approach and treatment options.
LessonLessonLessonLessonTest · 16 questionsExercise
Module 4
Threat actors and the anatomy of an attack
Who attacks and with what motive, how a modern attack is structured according to the kill chain and MITRE ATT&CK, and how artificial intelligence has changed the cost and scale of campaigns.
LessonLessonLessonLessonTest · 15 questionsExercise
Module 5
Security controls: preventive, detective, corrective
Taxonomy of controls by function and by nature, defence in depth and the independence of the layers, the zero trust model, compensating controls and the hierarchy of effectiveness it is best to start from.
LessonLessonLessonLessonTest · 15 questionsExercise
Module 6
Applied cryptography and identity management
Symmetric, asymmetric and hash explained for what they are actually used for; digital signature, certificates and what the padlock does not guarantee; the post-quantum transition and the five practices that hold up access management.
LessonLessonLessonLessonTest · 16 questionsExercise
Final test and certificate
Thirty questions drawn at random from the topics of all the modules. On passing, the path certificate is issued.
Test · 30 questionsCertificate
How to get access to the learning path
To follow "Information Security and Cybersecurity Fundamentals" you need an account on the platform: registration is free and takes a minute. Once the account is created you can request the enrolment key for the learning path.
Enrol meI already have an account
Back to all learning paths