Cybersecurity, learned like a practitioner.

24 learning paths · 398 modules live · every lesson written by someone who has shipped the control or run the engagement. Free to start.

24
Learning paths
398+
Live modules
0
You've completed
Free
Your tier
Browse the academy

Latest modules

Most recent practitioner playbooks across every track. Filter by topic, level, or search in the sidebar.

541 results · Page 5/55
Intermediate Free

Authentication and Session Management — Modern Patterns

Why this module exists. Modern authentication is not “username + password + check the DB.” It is a stack of OAuth flows, token handling, cookie discipline, MFA orchestration. This module covers what works. Password handling — when you must store one Argon2id is the current default for password hashing. PBKDF2 acceptable; bcrypt acceptable; scrypt OK. […]

May 14, 2026 30 min Open
Advanced Free

Application-Level Cryptography — Avoiding the Common Mistakes

Why this module exists. Cryptographic primitives have safe defaults that produce safe outcomes if used correctly. Developers who deviate — even with good intentions — introduce subtle but catastrophic bugs. This module is the practitioner safety pattern. The cardinal rule — use high-level APIs Cryptographic library design has converged on high-level APIs that hide the […]

May 14, 2026 35 min Open
Intermediate Free

Input Validation and Output Encoding — Universal Defences

Why this module exists. The single highest-leverage developer education is the principle “structure separates code from data.” Input validation and output encoding operationalise that principle. This module is the practitioner’s reference. The principle — structure separates code from data Injection vulnerabilities exist because data is interpreted as code by some downstream parser — SQL parser, […]

May 14, 2026 30 min Open
Intermediate Free

Vendor Audits — Conducting and Surviving Them

Why this module exists. Enterprise customers increasingly conduct annual security audits of their critical vendors. Done well by both parties, this is efficient and effective. Done badly, it consumes hundreds of hours and produces no real assurance. This module covers what works. Being audited — the customer-driven audit The typical customer audit pattern for SaaS […]

May 14, 2026 30 min Open
Intermediate Free

RBI / SEBI / IRDAI Cyber Audit — Indian Regulator Patterns

Why this module exists. Indian regulated entities are audited by their sector regulator (RBI, SEBI, IRDAI, TRAI, etc.) on a different cadence and framework than ISO 27001 or SOC 2. Treating these as the same as international audits leads to surprise findings. This module covers what differs. The regulators and their cyber audit programmes Regulator […]

May 14, 2026 30 min Open
Intermediate Free

SOC 2 Audit Preparation — Type I to Type II

Why this module exists. Most Indian SaaS companies aim for SOC 2 because their customers demand it. The discipline differs materially from ISO 27001 — different framework, different cadence, different auditor expectations. This module is the practitioner navigation. The fundamentals SOC 2 = Service Organization Controls 2. AICPA-defined framework. Auditor is a licensed CPA firm. […]

May 14, 2026 30 min Open
Advanced Free

Continuous Control Testing and Automation

Why this module exists. Manual quarterly access reviews break the moment the security team is busy with anything else. Continuous control testing — automated evidence collection — solves this for the controls that can be automated. This module is the operational pattern. Which controls automate well Control class Automation Configuration settings High — cloud APIs, […]

May 14, 2026 35 min Open
Intermediate Free

ISO 27001 Internal Audit — Pre-Certification Readiness

Why this module exists. ISO 27001:2022 has 93 Annex A controls grouped into four themes. The internal audit verifies these are implemented and effective. Done well, certification follows mechanically; done poorly, certification fails or extends. This module covers what works. The internal audit programme structure ISO 27001 requires internal audit at planned intervals. Practitioner cadence: […]

May 14, 2026 30 min Open
Advanced Free

Cloud-Native Security Architecture — Kubernetes, Service Mesh, Serverless

Why this module exists. Cloud-native architecture moves so much of the trust boundary into automation that the security architecture must shift correspondingly. This module is the cloud-native-specific architectural reference. The cloud-native trust model Three observations that drive cloud-native security architecture: Workloads are ephemeral — pods come and go in seconds. Static-IP-based controls do not apply. […]

May 14, 2026 35 min Open
Intermediate Free

Threat Modelling at the Architecture Stage

Why this module exists. Threat modelling is referenced in every security architecture guide and practised by few engineering teams. The reason: it sounds like a workshop without a clear deliverable. This module makes the deliverable concrete. What threat modelling produces A documented list of threats relevant to the system being built. For each threat: the […]

May 14, 2026 30 min Open
02 / Why learn here

Practitioners who've
shipped the controls.

Every module is written by someone who has built the defence or run the engagement. No repackaged tutorials, no generic theory.

Why learn here

01

Practitioner-written.

Each lesson is authored by someone who has shipped the control or run the engagement in production.

02

Quiz after every module.

20+ questions with explanations. 70%+ to mark complete. Unlimited retries.

03

Progress tracked.

Completions, scores and streaks saved automatically. Resume exactly where you left off.

04

India-priced.

Start free. ₹499/mo for intermediate. ₹4,999/yr for advanced. No hidden fees, ever.