MODULE NAVIGATOR

The 16-week curriculum

Three 2-hour sessions a week plus an optional lab. Every week carries all seven required lab columns: physical, Docker, AR/VR, equipment, evidence, safety and competency.

WEEK 01
Cybersecurity Foundations & Ethics

A fictional regional manufacturer, Carrollton Precision Works, is standing up its first security team. You are the newest hire and must set up the training lab safely before anyone touches a tool.

Build and label a small isolated lab LAN; inventory every asset.
L1 container launch / stop / inspect / reset
OSI / network orientation walkthrough.
Guided slideshow + printed OSI map
NIST CSF 2.0 (Govern)ISO 31000
0%
WEEK 02
Networking I — OSI & TCP/IP

A help-desk ticket says 'the internet is down' for one floor. Trace the packet's journey layer by layer to find where it breaks.

Cable a segment; verify addressing; read device labels and specs.
L2 images / containers / networks / ports / volumes
Walk the seven OSI layers; watch a packet traverse them.
Desktop OSI viewer + worksheet
NIST CSF (Identify)CIS Control 12
0%
WEEK 03
Networking II — Segmentation & Traffic

Guest Wi-Fi and the finance servers share one flat network. Segment it before the auditor arrives Friday.

Configure two VLANs; capture with a tap or SPAN port.
L3–4 logs & exposed services
Build segmentation with virtual equipment; inspect a firewall.
Desktop segmentation simulator
CIS Controls 4 & 12NIST SP 800-53 (SC)
0%
WEEK 04
Network & Security Equipment

A new switch arrived with default credentials and three-year-old firmware. Baseline it before it goes in the rack.

Apply a secure baseline to a switch; review firmware versions.
L5 map comms to OSI / TCP-IP
Inspect switches, routers, firewalls, servers and a data diode.
Printed device-inspection cards
NIST SP 800-53 (SC/AC)ISA/IEC 62443
0%
WEEK 05
Social Engineering & Human Behavior

Finance received an 'urgent CEO wire request' and a stranger followed staff through the badge door. Design the defense for a fictional company.

Badge / tailgating tabletop drill in a controlled space.
L6 analyze phishing traffic
Recognize tailgating / unauthorized access; SE awareness scenario.
Desktop SE scenario + checklist
NIST CSF (Protect — Awareness)ISO 27002
0%
WEEK 06
NLP ×2, OSINT & Digital Footprint

Before an authorized assessment, map what a fictional company unknowingly publishes about itself — and separate fact from rumor.

Metadata scavenger hunt on provided sample files.
L7 authorized asset discovery
Virtual SOC entry; observe language-based lures.
Offline OSINT dataset on desktop
ISO 27002NIST CSF (Identify)
0%
WEEK 07
Ethical Hacking I — Methodology

The fictional client wants a web-app assessment next week. Nothing happens until scope and signatures are in place.

Set up an isolated target VM; confirm no external reachability.
L8 identify vulnerable web app
Penetration-tester role: plan an authorized assessment.
Desktop planning worksheet
PTES-style flowNIST SP 800-115 concepts
0%
WEEK 08
MIDTERM + Ethical Hacking II
midterm

Midterm engagement: assess the provided lab target end to end and prove every claim with evidence.

Midterm practical: assess a provided lab target end to end.
L9 secure config & hardening
Virtual evidence-collection exercise.
Desktop evidence-log exercise
NIST SP 800-53 (CA/RA)MITRE ATT&CK
0%
WEEK 09
Red / Blue / Purple

Red team has a two-hour window against the range. Blue must detect, respond and map every action to ATT&CK.

Stand up log forwarding from a device to a collector.
L10–11 auth logs → SIEM
Enter a virtual SOC; run a red-vs-blue simulation.
Desktop SIEM screenshots + rules
MITRE ATT&CK (Enterprise & ICS)NIST SP 800-61r3
0%
WEEK 10
Software & Secure Development Lifecycle

A vendor library in the fictional company's customer portal has a critical CVE. Find it, fix it and prove it's fixed.

Generate an SBOM for a sample app; review dependencies.
L8 revisit: exploit then patch
Desktop-first: walk a CI/CD pipeline's trust boundaries.
Desktop pipeline diagram task
NIST SSDF (SP 800-218)OWASP Top 10 2025
0%
WEEK 11
Hardware & Asset Lifecycle

Twelve retired laptops and an unknown device in the server room. Decommission safely and find the rogue.

Data-sanitization & secure decommission drill.
L13 segment IT / OT networks
Inspect a server room / data center; identify rogue devices.
Printed data-center inspection set
NIST SP 800-53 (SR/CM)CIS Controls 1 & 2
0%
WEEK 12
Governance & Standards Crosswalk

The board asks: 'Are we NIST or ISO?' Build the crosswalk that shows it's the same control in different words.

None (documentation week).
L14 test firewall / ACL rules
Create 62443 zones and conduits; navigate the Purdue Model.
Desktop crosswalk + zone template
NIST CSF 2.0ISO 27001:2022CIS v8.1ISA/IEC 62443
0%
WEEK 13
OT & Industrial Cybersecurity

Odd Modbus writes are hitting the simulated water-treatment PLC. Investigate without stopping the process.

Connect a simulated PLC + HMI; observe a safe process loop.
L15 investigate IT → OT intrusion
Explore an industrial facility; identify PLCs / HMIs / EWS / SIS; navigate Purdue.
Desktop Purdue navigator + cards
NIST SP 800-82r3ISA/IEC 62443MITRE ATT&CK for ICS
0%
WEEK 14
Cloud, IoT, AI & Emerging Tech

The fictional company wants smart sensors and an AI chatbot by next quarter. Assess the risk before launch.

Review IoT device settings; disable insecure defaults.
Cloud-sandbox redeploy & exposure check
AR/VR device-security & biometric-privacy walkthrough.
Desktop cloud / IoT checklist
NIST CSF 2.0OWASP (LLM / API)CIS cloud
0%
WEEK 15
Incident Response, Forensics & Exec Communication

Ransomware notes appeared on two workstations at 6 a.m. Contain it, preserve evidence, and brief the CEO by 9.

Acquire a disk / memory image from a lab machine (documented).
L16 restore & validate remediation
Present findings in a virtual executive briefing room.
Desktop briefing-deck exercise
NIST SP 800-61r3ISO 27035SP 800-86
0%
WEEK 16
CAPSTONE — Red vs. Blue (IT + OT)
capstone

Full-scale exercise against Carrollton Precision Works' IT and OT range. Red attacks, blue defends, purple maps, governance evaluates — then brief the board.

Physical networking equipment where available.
Full IT + OT range live
AR/VR facility + incident simulation + virtual executive briefing.
Desktop capstone role kit
NIST CSF / 800-53 / 800-82ISO 27001CIS v8.1ISA/IEC 62443ATT&CK (Enterprise + ICS)
0%