IHETC Academy
Becoming a in-house cybersecurity lead
They do not spend their days repelling sophisticated attacks: they get simple rules applied by busy people. The vast majority of incidents start with a reused password or a fraudulent message, and that is where the role creates its value.
The job, unvarnished
They do not spend their days repelling sophisticated attacks: they get simple rules applied by busy people. The vast majority of incidents start with a reused password or a fraudulent message, and that is where the role creates its value.
- steps
- 4
- of actual work
- 95 h
- fields covered
- 3
Not connection time.
What the market says
The function is appearing on org charts in the sub-region, often part time and given to a generalist IT profile. It is a realistic entry point: the role is rarely taken from outside, it is built from within.
The sequence
Each step assumes the previous one. Taking them out of order is possible, and it is the most common way to lose time.
- 01
Digital hygiene
Passwords, two-factor, backups, updates. Unspectacular, and responsible for most of the risk avoided. — about 20 hours of work.
- 02
Common threats and response
Phishing, ransomware, payment fraud: detect, contain, record within the hour. — about 30 hours of work.
- 03
Personal data and compliance
Processing register, individuals' rights, framing transfers. — about 25 hours of work.
- 04
Getting it applied
Training colleagues, writing a rule people can follow, getting a decision from management. — about 20 hours of work.
By the end, you will be able to
- Assess an organisation's digital risk posture
- Write internal rules people can follow, and get them adopted
- Handle an incident: contain, record, alert the right people
- Keep a processing register and answer an access request
What this path does not give you
This path is defensive. It does not teach penetration testing, a regulated trade requiring a written mandate, and it does not prepare for security operations centre analyst roles — the base holds eighteen modules in this field, none at advanced level.
Questions about this path
Is this enough for a security operations centre role?
No, and we would rather say so. Those roles need a technical specialisation the current base does not cover. The path prepares for the in-house lead role, a far more widespread need in the sub-region and a genuine door to what comes next.
Are offensive techniques taught?
No. Penetration testing is a regulated trade requiring a written mandate from the system owner, and distributing an offensive playbook outside that frame would be irresponsible. The path is defensive throughout: understanding how an attack unfolds in order to detect it, contain it and report on it.