02Operational level

Cybersecurity Hygiene

The everyday practices that measurably reduce the attack surface of a person and of an organisation. Practical in style: every module closes with concrete actions to apply straight away.

Credentials and MFAUpdatesBackup and recovery

Enrol meI already have an account

6modules
26estimated hours
93test questions
6exercises
30questions in the final test

How it is delivered

Delivery
Entirely online and asynchronous, from any device: you study when you want, at your own pace.
Passing the tests
At least 70% correct answers; every answer comes with an explanation of why.
Attempts per test
Unlimited: the best attempt counts.
Time per test
25 minutes per test.
Progress
Tracked module by module: each module unlocks when you pass the test of the previous one.
On completion
A personal PDF certificate, with a unique verification code.
Length of access
You have 90 days from enrolment to complete the learning path. Once you complete it your access stays available with no expiry; if the deadline passes without the path being completed, the enrolment is suspended and the results you have already achieved stay on record.
Enrolment
With a personal key, after you have created your account.

The learning path in detail

Welcome. Cyber hygiene means a few practices, applied consistently: they are the ones that measurably reduce the attack surface of a person and of an organisation. The approach is entirely operational: every module closes with a checklist you can apply straight away, and the exercise asks you to apply it for real to your own context.

Path objectives

By the end of the path you will be able to:

  • build and keep strong credentials, with passphrases and a password manager (Module 1)
  • choose and use the right multi-factor authentication, recognising the attacks that bypass it, MFA fatigue included (Module 2)
  • set up a sustainable update discipline, knowing how to read the life cycle of a vulnerability (Module 3)
  • applying the 3-2-1-1-0 rule to backups and checking the ability to restore (Module 4)
  • secure the endpoint and the workstation: encryption, least privilege, removable devices (Module 5)
  • manage the everyday channels with hygiene: email, browsing, cloud and remote working (Module 6)

Who it is for and prerequisites

All staff, regardless of technical role. Having taken the fundamentals path first is recommended but not required: this path recalls the concepts of risk and control where they are needed.

Format

The path is delivered entirely online, asynchronously: you can study when you want, at your own pace, from any device. The estimated total duration is 26 hours, to be spread within the completion deadline set out below.

Each module is organised into four lessons and two tests:

  1. Lesson. A reasoned treatment of the topic, with diagrams, examples and concrete cases.
  2. In depth. The up-to-date regulatory and technical picture, with the deadlines that matter and references you can verify at source.
  3. Real-world cases. What actually happens on the market: documented episodes always read with the same grid, down to the control that would have broken the chain.
  4. In practice. What you do on Monday morning: procedures, checklists, ready-made templates and indicators with which to measure the result.
  5. Test. Closed-answer questions on the whole module. Passing requires at least 70%; attempts are unlimited and the best mark counts. At the end of every attempt you receive a detailed explanation of each answer, including the correct ones.
  6. Exercise. A case to work through by deciding: every choice opens a different path and the outcome depends on what you chose, with an explanation of what would have happened otherwise. Marking is automatic and you can retake it as many times as you like.

Progression. The 6 modules are taken in sequence: each module unlocks only after you have passed the previous module test. The exercises do not block progress, but they are an integral part of the path and of the overall assessment.

Final test and certificate

Once you have passed the tests of all the modules, the final test unlocks: 30 questions drawn at random from the topics of the whole path, with the same 70% threshold and unlimited attempts. On passing it you obtain the path certificate, downloadable as a PDF, with a unique code that allows its authenticity to be verified.

Completion deadline

You have 90 days from enrolment to complete the learning path. 15 days before the deadline you receive an email reminder.

If you complete the path within the deadline, your access stays available with no time limit and you receive the certificate. If the deadline passes without the path being completed, the enrolment is suspended: the results you have already achieved stay on record, and to carry on you need a new enrolment key.

Support

In the Announcements forum you will find the trainer's messages. For questions about the content or the exercises, use the channels indicated by your training contact.

Programme

The modules are taken in sequence: each one opens when you pass the test of the previous one.

  1. Module 1

    Credential hygiene

    Why reuse is more dangerous than poor complexity, how a passphrase is built, what has changed in the rules on passwords and why the password manager is the measure with the best ratio of benefit to effort.

    LessonLessonLessonLessonTest · 15 questionsExercise

  2. Module 2

    Multi-factor authentication and phishing resistance

    Authentication factors, the substantial difference between code-based methods and phishing-resistant methods (FIDO2 and passkeys), how attacks with a proxy in the middle work and a realistic order of adoption.

    LessonLessonLessonLessonTest · 16 questionsExercise

  3. Module 3

    Updates and patch management

    The life cycle of a vulnerability from CVE to exploit, the exposure window you can actually govern, the prioritisation criteria based on real-world exploitation, the differentiated timescales and the compensating controls when the fix cannot be applied.

    LessonLessonLessonLessonTest · 15 questionsExercise

  4. Module 4

    Backup and recovery capability

    The 3-2-1-1-0 rule explained digit by digit, immutability as a defence against ransomware and the principle that an untested backup is not a backup, with the test plan that produces the evidence required in an audit.

    LessonLessonLessonLessonTest · 16 questionsExercise

  5. Module 5

    Endpoint and workstation security

    Disk encryption, screen lock, least privilege, behavioural detection, unauthorised software, removable devices and mixed personal and work use: the six actions that count and why permanent administrative privilege is the central problem.

    LessonLessonLessonLessonTest · 15 questionsExercise

  6. Module 6

    Email, browsing, cloud and home network

    Email domain authentication with SPF, DKIM and DMARC, criteria for judging links and attachments that hold up even against perfect messages, sharing mistakes in the cloud, the real limits of a VPN and securing the home network.

    LessonLessonLessonLessonTest · 16 questionsExercise

  7. Final test and certificate

    Thirty questions drawn at random from the topics of all the modules. On passing, the path certificate is issued.

    Test · 30 questionsCertificate

How to get access to the learning path

To follow "Cybersecurity Hygiene" you need an account on the platform: registration is free and takes a minute. Once the account is created you can request the enrolment key for the learning path.

Enrol meI already have an account

Back to all learning paths