Skip to main content
IHETC Academy

IHETC Academy

Becoming a in-house cybersecurity lead

They do not spend their days repelling sophisticated attacks: they get simple rules applied by busy people. The vast majority of incidents start with a reused password or a fraudulent message, and that is where the role creates its value.

The job as it is actually done

They do not spend their days repelling sophisticated attacks: they get simple rules applied by busy people. The vast majority of incidents start with a reused password or a fraudulent message, and that is where the role creates its value.

steps
4

Work delivered, measured as such.

of actual work
95 h
fields covered
3

What the market says

The function is appearing on org charts in the sub-region, often part time and given to a generalist IT profile. It is a realistic entry point: the role is rarely taken from outside, it is built from within.

The sequence

Each step builds on the previous one. Following that order is what keeps the path short: each notion arrives when it is needed, and it sticks.

  1. 01

    Digital hygiene

    Passwords, two-factor, backups, updates. Unspectacular, and responsible for most of the risk avoided. — about 20 hours of work.

  2. 02

    Common threats and response

    Phishing, ransomware, payment fraud: detect, contain, record within the hour. — about 30 hours of work.

  3. 03

    Personal data and compliance

    Processing register, individuals' rights, framing transfers. — about 25 hours of work.

  4. 04

    Getting it applied

    Training colleagues, writing a rule people can follow, getting a decision from management. — about 20 hours of work.

The fields feeding this path

Each step draws on one field of the base. The count shown is that of the whole field: it states the depth available to go beyond the path itself, once you hold the role.

Cybersecurity
18 (26 %)
Legal
33 (47 %)
Education
19 (27 %)
Total: 70 modules

By the end, you will be able to

  • Assess an organisation's digital risk posture
  • Write internal rules people can follow, and get them adopted
  • Handle an incident: contain, record, alert the right people
  • Keep a processing register and answer an access request

Questions about this path

Is this enough for a security operations centre role?

The path prepares for the in-house lead role — by far the most widespread need in the sub-region, and a genuine door to what comes next. The deeper technical specialisations build on exactly this base.

Are offensive techniques taught?

No. Penetration testing is a regulated trade requiring a written mandate from the system owner, and distributing an offensive playbook outside that frame would be irresponsible. The path is defensive throughout: understanding how an attack unfolds in order to detect it, contain it and report on it.

Becoming a in-house cybersecurity lead — IHETC Academy | IHETC — IHETC