HUMAIN CYBER ACADEMY
Cybersecurity Essentials Training Program — IT & Security Edition

The End
of Breaches.

Five focused modules on the risks that matter most: third parties inside your perimeter, the privileged identities that hold your Tier-0 keys, the code your teams ship to production, a field-wide foundation that maps the whole discipline, and the NCA regulatory landscape you answer to.

5 modules 5 animated explainers 33 mandatory questions AI risk in every module ≈ 105 minutes Certificate at ≥ 80%
EXPLORE
Third-Party Risk Access Management NCA ECC-2:2024 AI Security Zero Trust Supply Chain Least Privilege Deepfake Defence
Built for the threats ahead

One Course.
Full-stack Awareness.

Each module pairs an animated explainer with hands-on content and a short knowledge check. Then sit the final exam — 20 questions sampled from every module — and score 80% to earn your completion certificate. You can retake the exam as many times as you like.

✓ Completed MODULE 01

Third-Party Risk

Your security is only as strong as your weakest supplier. Learn how supply-chain attacks unfold and what ECC Domain 4 demands of every vendor relationship.

Supply chainECC 4-1SLA clausesAI supply chain
✓ Completed MODULE 02

Access Management

Identity is the new perimeter. Master the ECC 2-2 minimum requirements — MFA, least privilege, segregation of duties and privileged access management.

IAMECC 2-2PAMDeepfake threats
✓ Completed MODULE 03

Application Development Security

Every line of code is attack surface. Build security into the SDLC — from threat modeling to the ECC's secure-development (1-6-3) and web-application (2-15) controls.

Secure SDLCECC 1-6 & 2-15OWASPAI coding risks
✓ Completed MODULE 04

Cybersecurity at a Glance

The whole field on one map — the CIA triad, threats, secure architecture, operations and governance. Five pillars that structure everything else.

CIA triadDefence in depthZero TrustGRC
✓ Completed MODULE 05

NCA Regulation Awareness

Who the National Cybersecurity Authority is, how ECC-2:2024 is structured, who must comply, and where the wider framework family fits in.

NCAECC-2:2024ComplianceAI governance
Module 01 — Third-Party Risk

Trust Is Not
a Control.

Vendors, integrators, cloud providers and managed services all hold a piece of your attack surface. This module covers how third-party compromise happens — and the controls ECC-2:2024 requires before, during and after every engagement.

In this module you will learn to

The Update That Betrayed You

PHASE 1/4 · MAP YOUR ENTITY ADMIN ACCESSREMOTE SESSIONSYOUR DATACODE & OAUTH TOKENS 🛠️IT VENDOR 🛡️MSSP / SOC ☁️CLOUD (CSP) 📦CODE SUPPLIER

One Flaw, a Thousand Victims

PHASE 2/4 · PIVOT 🕶️ATTACKER 🛠️SOFTWARE VENDOR ⚠️ SUNSPOT implant · build serverSOLARWINDS SUPPLY CHAIN · 2020 Support laptop · vendor VPNOKTA VIA SITEL · 2022 1 vendor → ~1,500 orgs hitKASEYA VSA · REVIL · 2021

The Economics of One Weak Link

PHASE 3/4 · PAYLOAD 🛠️VENDOR YOUR ENTITY 📦 SIGNED ✓ SUNBURST · validly signedSOLARWINDS ORION · 2020 CVE-2023-34362 · SQLiMOVEIT · CL0P · 2023 Stolen tokens & secretsCIRCLECI BREACH · 2023

Contract the Risk, Not the Regret

PHASE 4/4 · GOVERN PROTECTED Risk-assess before signingECC 4-1-3-1 · PRE-CONTRACT NDA + secure data removalECC 4-1-2-1 · IN CONTRACT Incident comms proceduresECC 4-1-2-2 · IN CONTRACT Bind them to your policiesECC 4-1-2-3 · IN CONTRACT SOC operations inside KSAECC 4-1-3-2 · IN SERVICE Reassess at renewal & incidentsECC 4-1-4 · ALWAYS
Explainer 01
Why it matters

One Vendor.
Thousands of Victims.

≈18,000organisations downloaded the trojanised SolarWinds Orion update in 2020 — including government agencies and security firms.Source: SolarWinds SEC filings / public reporting
2,700+organisations were impacted through a single file-transfer product in the 2023 MOVEit campaign — most had no direct relationship with the exploited software.Source: Emsisoft / public CL0P MOVEit victim tracking, 2023
4-1is the ECC-2:2024 subdomain dedicated to third-party cybersecurity — covering IT outsourcing, cybersecurity outsourcing and managed services.Source: NCA ECC-2:2024, Domain 4
The vendor lifecycle

Security at Every Stage.

01

Due Diligence

Assess the vendor's security posture, certifications, breach history and subcontractors (your fourth parties) before commitment.

02

Contract

Embed cybersecurity clauses: NDA, data handling, incident notification, right to audit, secure data removal at exit.

03

Onboarding

Provision least-privilege, time-bound, individually attributable access — federated to the vendor’s own identity where possible, so leavers on their side are leavers on yours. No shared accounts, no standing admin, no vendor access to Tier-0 without a brokered, recorded session.

04

Monitoring

Log and review vendor sessions, track SLA compliance, reassess risk on contract change or after incidents.

05

Offboarding

Revoke all access immediately, recover assets, and verify secure removal of your data — as contractually required.

Regulation deep-dive

What ECC 4-1 Requires.

Subdomain 4-1 protects the entity's assets against third-party risk across IT outsourcing, cybersecurity outsourcing and managed services. Expand each control:

Cybersecurity requirements for the entity's contracts and agreements with third parties must be identified, documented and approved — before you rely on them. Ad-hoc, verbal or assumed security expectations do not satisfy the control.
Where impairment could affect your data or services, contracts and SLAs must include, as a minimum:
  • 4-1-2-1 — Non-disclosure clauses and secure removal of the entity's data by the third party upon end of service.
  • 4-1-2-2Communication procedures in case of a cybersecurity incident.
  • 4-1-2-3 — Obligating the third party to apply the entity's cybersecurity requirements and policies and relevant legislative and regulatory requirements.
For third parties providing IT or cybersecurity outsourcing or managed services:
  • 4-1-3-1 — Conduct a cybersecurity risk assessment and ensure risk-mitigation controls are available before signing contracts, or upon relevant regulatory changes.
  • 4-1-3-2 — Cybersecurity managed service centers (SOC) for monitoring and operations that use remote access must be fully located inside the Kingdom of Saudi Arabia.
Third-party cybersecurity requirements must be periodically reviewed. Vendor risk is not a one-time gate at procurement — posture drifts, subcontractors change, and contracts must keep pace.
Cloud providers are third parties too. Subdomain 4-2 additionally requires, as a minimum: protection of data per its classification level and its return in a usable format upon service completion (4-2-3-1), and separation of the entity's environment — especially virtual servers — from other tenants (4-2-3-2).
Spot the risk — tap each card

Six Red Flags in Practice.

AI Spotlight — Third-Party Risk

Your Newest Vendor
Is a Model.

AI services are third parties too — and so are the pre-trained models, datasets and AI-powered tools your teams adopt. ECC 4-1 and 4-2 apply to them in full, with some new failure modes to assess.

Threat

Shadow AI

Staff pasting source code, credentials or classified documents into unapproved public AI tools is an unassessed third-party data flow. Treat AI tool adoption like any vendor onboarding: approved list, DLP controls, clear usage policy.

Threat

Model & Dataset Supply Chain

Pre-trained models, weights and training datasets pulled from public hubs are software components from external parties: they can carry poisoned behaviour, backdoors or malicious serialization payloads. Verify sources, pin versions, scan artifacts.

Threat

Your Data in Their Training

Some AI vendors reserve the right to train on customer inputs. Contract review must cover data residency, retention and training-use clauses — the AI-era extension of the 4-1-2-1 secure-removal requirement.

Defence

AI on Your Side

AI also strengthens vendor management: continuous vendor-risk scoring, anomaly detection on third-party connections and sessions, and automated contract-clause analysis at scale.

AI Vendor Due-diligence — Ask Before You Sign

  • Is our data used to train or fine-tune your models? Can we opt out contractually?
  • Where is inference and data processing hosted — and does it meet KSA residency requirements?
  • How are prompts, outputs and logs retained, and how are they securely deleted at exit?
  • What guardrails exist against prompt injection and data leakage between tenants?
  • Which sub-processors and foundation-model providers sit behind your service (our fourth parties)?
  • Has the service been risk-assessed per ECC 4-1-3-1 before contract signature?

Module RecapFive Things to Remember

  • Third parties operate inside your perimeter — risk-assess them before signing (4-1-3-1)
  • Contracts carry the minimums: NDA + secure data removal, incident comms, policy obligations (4-1-2)
  • Managed SOCs using remote access must be fully located in Saudi Arabia (4-1-3-2)
  • Vendor access is least-privilege, time-bound, individually attributable and monitored
  • Review third-party requirements periodically (4-1-4) — and hold AI vendors to the same bar

Module 01 — Knowledge Check.

6 questions · all mandatory · answered in order Answered 0 / 6

Module 02 — Access Management

Identity Is
The Perimeter.

Most breaches don't break in — they log in, and then they escalate. This module covers the full IAM chain, the five minimum requirements of ECC 2-2-3, and — in depth — the crown-jewel problem of administrative and remote administrative access: standing domain admin, Tier-0 assets, jump hosts, and the lateral-movement techniques that turn one stolen credential into full control in minutes.

In this module you will learn to

The Chain Behind Every Login

STEP 1/4 · CHAIN 🧑IDENTIFICATIONWho are you? 🔑AUTHENTICATIONProve it 🔒AUTHORIZATIONWhat may you do? 📜ACCOUNTABILITYAttributable & logged Break one link → the chain failsSTOLEN CREDS = TOP INITIAL-ACCESS VECTOR · VERIZON DBIR

Passwords Are Already Sold

STEP 2/4 · FACTORS UNLOCKED ONLY WITH ALL FACTORS 🧠 Something you knowPASSWORD · PIN 📱 Something you haveFIDO2 KEY · TOTP APP 👆 Something you areBIOMETRICS MFA for remote access& privileged accountsECC 2-2-3-2 Not all factors are equalSMS & PUSH PHISHABLE · FIDO2 IS NOT

The Blast Radius of "Yes"

STEP 3/4 · GRANTS 🧑‍💼USER FULL ADMINEVERYTHING TEAM SHAREPRIVILEGE CREEP THIS TASK ONLYLEAST PRIVILEGE Need-to-know · Least privilege · SoDECC 2-2-3-3 · REQUESTER ≠ APPROVER

Caging the Keys to the Kingdom

STEP 4/4 · PAM 🔐 CREDENTIAL VAULT ⏰ Just-in-time elevationAUTO-EXPIRES · NO STANDING ADMIN 🎥 Record & monitor sessionsECC 2-2-3-4 · REPLAYABLE EVIDENCE 🔄 Periodic access reviewECC 2-2-3-5 · ORPHANS = FINDINGS
Explainer 02
Regulation deep-dive

The ECC 2-2-3 Minimum.

Subdomain 2-2 exists to prevent unauthorized logical access and restrict access to what the task requires. Control 2-2-3 sets five minimum requirements:

The baseline for standard access: one unique, individually attributable identity per user, authenticated by username and password under a governed policy — length over forced complexity, screening against breached-password lists, lockout on brute force, and rotation on suspected compromise. This is the floor, not the ceiling: the moment access becomes remote or privileged, 2-2-3-2 raises the bar to MFA. Shared or generic accounts break accountability and are non-compliant.
Multi-factor authentication is mandatory for remote access and privileged accounts. The number and type of factors must follow an impact assessment of authentication failure and bypass — higher impact, stronger factors. Prefer phishing-resistant methods (FIDO2 keys, certificate-based) over SMS where feasible.
Authorization must apply the Need-to-Know / Need-to-Use, Least Privilege and Segregation of Duties principles. No single person should request, approve and implement the same critical change.
Admin and service credentials belong in a managed vault with rotation, just-in-time elevation, session recording and separate admin identities (no browsing email as domain admin). Privileged accounts are the primary target of lateral movement.
Recertify access on a schedule and on role change (joiner–mover–leaver). Hunt for orphan accounts (owner left), dormant accounts (unused >90 days) and privilege creep. Control 2-2-4 additionally requires the whole IAM implementation to be reviewed periodically.
Deep-Dive — Privileged Access

The Crown-Jewel Problem:
Administrative & Remote Access.

Administrative access is the endgame of almost every serious intrusion. Attackers rarely breach the firewall — they steal one credential and escalate. In a poorly segmented network, the path from a phished helpdesk password to full domain control can take under an hour; red teams routinely demonstrate "ten minutes to domain admin." The danger multiplies when that admin access is reachable over the internet. ECC 2-2-3-2, 2-2-3-4 and 2-2-3-5 exist precisely to make privileged access hard to reach, impossible to reuse silently, and fully accountable.

Internet-exposed RDP (port 3389) and SSH (port 22) are among the most-scanned, most-brute-forced ports on earth, and a favourite ransomware entry vector — BlueKeep (CVE-2019-0708) was even a wormable, pre-authentication RDP RCE needing no credentials. Administrative access must never be published directly to the internet. Broker it through a hardened jump host / bastion or Zero Trust Network Access (ZTNA), which authenticates identity and device before any network path exists — unlike a legacy VPN that grants broad network reach once connected. 2-2-3-2 mandates MFA for remote access and for privileged accounts; admin-over-remote triggers both at once, and the factors should be phishing-resistant (FIDO2 / certificate-based) (MITRE ATT&CK T1021.001, T1133).
A domain admin account is a master key to every workstation, server and secret in the domain — your Tier-0 tier. Every hour a privileged account sits standing (permanently assigned) it is a target waiting to be stolen. The fix is a tiered administration model: Tier-0 is administered only from dedicated Privileged Access Workstations, never from an internet-facing or email-reading device, and Tier-0 credentials never touch lower tiers. Eliminate standing admin in favour of just-in-time elevation that auto-expires — a stolen JIT-eligible identity still faces MFA, approval and a time window, not an open door (T1078.002).
Privileged credentials belong in a vault, checked out per-use and rotated automatically — including after every session, so a captured password is already dead. The hardest cases are service accounts and local admin passwords: static, shared, and often identical across thousands of machines — the classic pass-the-hash accelerator. Rotate local admin passwords per-host (a LAPS-style solution), give service accounts scoped, monitored, non-interactive identities, and never embed admin secrets in scripts, config files or scheduled tasks.
Once inside, attackers move sideways using the credentials they find. Pass-the-hash (T1550.002) replays a stolen hash without cracking it. Kerberoasting (T1558.003) requests service tickets for weak-password accounts and cracks them offline — admin-rights service accounts are prime targets. Token theft and cached-credential harvesting turn any admin who logged into a compromised box into a foothold. Defences are structural: least privilege (2-2-3-3) shrinks what any account can reach, the tiered model stops a workstation compromise from touching Tier-0, and long random service-account passwords defeat Kerberoasting.
Every environment needs a small number of emergency "break-glass" accounts to regain control when MFA, federation or the PAM system itself fails. But an always-valid superuser is exactly what an attacker wants. Control it: store the credential sealed in the vault, alert loudly on any use, and review and rotate it after every activation. A break-glass account used routinely, or never reviewed, has stopped being a safety net and become a backdoor (T1078.001).
Privileged sessions must be recorded and monitored — replayable evidence of exactly what an administrator (or a compromised one) did, satisfying audit and forensic needs. Recording is only half the loop: periodic access review (2-2-3-5) hunts the privilege that shouldn't exist — orphaned admin accounts (owner left), dormant privileged accounts, privilege creep from role changes, and vendor admin access that outlived its contract. Standing privilege you can't explain is a finding waiting to happen — find it before the auditor, or the attacker, does.
Admin & Remote Administration

Tier Your Admin Plane.

Not all admin is equal. A tiered model stops a compromised workstation from ever reaching a domain controller — credentials never cross tiers.

TIER 0

Identity & Control Plane

Domain Controllers · PAM · CA

Anything that can control identity for the whole estate. Administered only from dedicated, hardened Privileged Access Workstations — never from a device that browses email.

Crown JewelsPAW Only
TIER 1

Servers & Applications

Business Systems · Databases

Server and app administration. Separate admin identity, JIT elevation, recorded sessions. Tier-1 admins can never log on to Tier-0 assets, and vice-versa.

High ImpactSeparate Identity
TIER 2

Workstations & Devices

Helpdesk · Endpoints

Endpoint and user support — the tier most exposed to phishing, so it holds the least privilege and can reach nothing above it.

Least PrivilegeNo Lateral Path
Remote Admin Exposure

Where Admin Access Leaks.

ExposureSeverityWhy It's DangerousControl
RDP exposed to the internetCriticalBrute-forced and sold as initial access; the top ransomware entry vector.Bastion / ZTNA + MFA, never public 3389 (2-2-3-2)
Standing domain adminCriticalOne phished session = full estate; the endgame of every lateral-movement chain.JIT elevation, tiered model, no permanent membership (2-2-3-4)
VPN appliance, unpatchedCriticalInternet-facing and trusted; pre-auth RCEs hand attackers a foothold with no credentials.Aggressive patch SLA, MFA in front, shift to ZTNA
Flat network, no segmentationHighAny foothold reaches every server — nothing contains the blast radius.Segment admin VLANs; jump hosts between tiers
Shared local-admin passwordHighPass-the-hash spreads one credential across every workstation.Unique per-host passwords (LAPS-style), vaulted & rotated
Unrecorded admin sessionsHighNo replayable evidence when an admin account is abused.Session recording & monitoring (2-2-3-4)
Field Guide

Practice vs. Malpractice.

AreaDoDon't
Admin exposureRDP/SSH reachable only via bastion; internet-facing 3389/22 closedPublic RDP "for convenience" — brute-forced within minutes
Admin workSeparate privileged identity, JIT elevation, logged sessionsDay-to-day work from a domain-admin account
Remote accessPhishing-resistant MFA; admin brokered through a bastion/ZTNARDP/SSH exposed to the internet, or a flat password-only VPN onto Tier-0
Service accountsVaulted, rotated, scoped to one function, monitoredStatic passwords in scripts and config files
LeaversSame-day revocation wired into HR offboarding"IT will get to it" — accounts alive weeks after exit
Access requestsRole-based, approved, time-limited, recertifiedCopy the permissions of a colleague ("mirror access")
Know your adversary — tap each card

How Identities Get Stolen.

AI Spotlight — Access Management

When the Caller
Isn't Human.

Generative AI has industrialised identity attacks: flawless phishing at scale, cloned voices, and synthetic video. Your IAM controls are the counterweight — if they don't rely on "sounding legitimate".

Threat

Deepfake Social Engineering

Cloned voices and live video deepfakes are used to push helpdesk password resets and approve fraudulent transfers — in a Feb 2024 case reported at engineering firm Arup, a finance employee paid out ~US$25M after a deepfaked video call impersonating the CFO and colleagues. Verification must use callbacks and strong identity proofing, never voice or face familiarity.

Threat

AI-generated Phishing

LLMs remove the typos and awkward phrasing users were trained to spot, and generate fluent, personalised lures in any language. Assume perfect text: verify via the request's context and channel, not its polish.

Threat

Machine-speed Credential Attacks

AI automates password spraying, MFA-fatigue timing and target research. Weak factors fall fast — which is why phishing-resistant MFA (FIDO2 / certificate-based) matters more every year.

Defence

AI-driven Identity Defence

Modern IAM fights back with behavioural analytics (UEBA), identity threat detection & response (ITDR), and risk-based conditional access that challenges or blocks impossible travel, anomalous sessions and token replay in real time.

Deepfake-resistant Procedures — Adopt Now

  • Helpdesk resets require verified identity (ID + registered channel callback), never voice recognition.
  • High-risk approvals need a second, out-of-band channel — no matter who appears on the call.
  • Deploy number matching and phishing-resistant factors for privileged and remote access (ECC 2-2-3-2).
  • Establish a no-blame fast-report path: seconds matter when a "CEO call" felt wrong.
  • Feed identity telemetry into monitoring (ECC 2-12) so AI-speed attacks meet AI-speed detection.
  • Brief executives: their public audio and video are cloning material.

Module RecapFive Things to Remember

  • MFA is mandatory for remote access and privileged accounts, factors chosen by impact (2-2-3-2)
  • Authorize by need-to-know, least privilege and segregation of duties (2-2-3-3)
  • Privileged accounts get PAM: vaulting, just-in-time elevation, recorded sessions (2-2-3-4)
  • Review identities and access rights periodically — orphan accounts are findings (2-2-3-5)
  • Voice and face are no longer identity proof — verify resets via registered channels only

Module 02 — Knowledge Check.

9 questions · all mandatory · answered in order Answered 0 / 9

Module 04 — Cybersecurity at a Glance

The Whole Field,
on One Map.

Now zoom out. Here is the whole discipline on one map — the concepts, threats, defences, operations and governance every practitioner is expected to know. Five pillars that turn "cybersecurity" from a vague word into a structured field, and set the stage for the regulation that follows.

In this module you will learn to

It All Protects Three Things

PILLAR 1 · CONCEPTS ASSET CCONFIDENTIALITY INTEGRITYI AVAILABILITYA Preventive controlSTOP IT HAPPENING Detective controlSPOT IT HAPPENING Corrective controlPUT IT RIGHT AFTER

Know Every Way In

PILLAR 2 · THREATS 😈THREAT ACTOR 🦠 Malware & ransomwarePATCH · EDR · BACKUP 🎣 Phishing & social engineeringTRAIN · FILTER · MFA 🔑 Stolen creds & exploitsMFA · SEGMENT · PATCH MAP THREAT → MITIGATION

Defend in Depth

PILLARS 3–4 · ARCHITECTURE & OPS DATA PERIMETER NETWORK HOST · APP Segment · harden · encryptEACH LAYER INDEPENDENT Design to fail safe & recoverRESILIENCE & BACKUP

Govern the Whole Program

PILLAR 5 · GOVERNANCE GOVERNANCE · RISK · COMPLIANCE ⚖️ Assess riskWHAT COULD GO WRONG 📝 Set policy & trainPEOPLE & PROCESS 🔍 Audit & improvePROVE IT WORKS Where the field becomes regulation → the NCA's ECC
Explainer 04
The Field at a Glance

Five Pillars Hold It All Up.

Every cybersecurity topic — and every professional certification — organises the field into the same handful of pillars. These are mandatory: read each pillar and mark it complete to unlock the next, and to open the knowledge check.

0 of 5 pillars completeComplete every pillar to unlock the quiz.
The foundation the rest of the field is built on — master this first. The CIA triad — Confidentiality, Integrity, Availability — names what you protect. Control types (preventive, detective, corrective, deterrent, compensating, directive) name how. Zero Trust — "never trust, always verify" — assumes no request is safe by location. And cryptography basics — encryption for confidentiality, hashing for integrity, PKI for trust — are the tools underneath.
Know the adversary. Threat actors range from opportunists to nation-states; malware spans ransomware, trojans and worms; social engineering — phishing, pretexting, deepfakes — targets people, not machines. A vulnerability is a weakness; an exploit is its use. Mitigation is systematic: patch, filter, segment, train, and monitor — mapping each threat to a defence.
Security designed in, not bolted on. Defence in depth layers independent controls so one failure isn't fatal. Network security — segmentation, firewalls, VPN and Zero Trust access — controls reachability. Data protection classifies and encrypts information at rest and in transit. And resilience — backups, redundancy, fail-safe design — keeps services alive through an incident.
The day-to-day discipline. Identity & access management decides who can do what (see Module 02). Monitoring & logging — SIEM, alerting — turns events into detection. Vulnerability & patch management closes gaps before attackers use them. And the incident response lifecycle — Prepare, Detect & Analyse, Contain/Eradicate/Recover, then Learn — turns a crisis into a repeatable process.
The program layer that ties it together. Risk management weighs likelihood against impact and decides to accept, mitigate, transfer or avoid. Policies and standards turn intent into rules; awareness training turns rules into behaviour; third-party risk (Module 01) extends control outward; and audits against a framework prove it all works. This is exactly where Module 05 — the NCA's ECC — turns these principles into regulation.
Networking Foundations

How Networks Actually Work.

You can't secure what you don't understand. Every control, threat and attack in this course rides on a network — so here is the wiring beneath it all: how data moves layer by layer, how devices are addressed, and the ports attackers scan for.

LayerNameWhat It DoesLives Here
7ApplicationServices people actually useHTTP, DNS, SMTP
6PresentationFormats & encrypts dataTLS, JPEG
5SessionOpens & manages sessionsRPC, NetBIOS
4TransportEnd-to-end delivery & portsTCP, UDP
3NetworkLogical addressing & routingIP, routers, ICMP
2Data LinkLocal frames & MAC addressesSwitches, VLANs, ARP
1PhysicalBits on the mediumCables, Wi-Fi, fibre

Two models, same idea: the 7-layer OSI model is how we teach and troubleshoot networks; the leaner 4-layer TCP/IP model (Link · Internet · Transport · Application) is what they actually run on.

Networking, Card by Card — tap each

Six Networking Essentials.

Quick Reference — tap each card

Six Ideas Worth Memorising.

AI Spotlight — Cybersecurity at a Glance

AI Rewrites Every Pillar.

Generative AI is now woven through the whole field — a sharper threat, a new attack surface, and a powerful defensive tool all at once. Every pillar above now has an AI dimension.

Threat

AI-Accelerated Attacks

LLMs write flawless phishing in any language, clone voices for fraud, and speed up malware and reconnaissance. Assume attackers move faster — and verify by context, never by how convincing something sounds.

Threat

Shadow AI & Data Leakage

The most common AI risk today is an employee pasting sensitive data into a public chatbot. Classify your data, approve specific tools, and keep confidential information out of external models.

Defence

AI on Your Side

The same technology strengthens defence: anomaly detection, alert triage that cuts false positives, log summarisation, and faster incident analysis for stretched security teams.

Governance

Govern AI Like Any Asset

AI systems are information assets — inventory them, classify their risk, and apply the same access, logging and third-party controls. In the Kingdom, SDAIA's principles and the ECC already apply.

The One-Minute AI Rule for Staff

  • Never paste secrets, credentials or classified data into a public AI tool.
  • Treat AI output as a draft to verify, not a fact to trust.
  • Assume phishing is now flawless — verify unusual requests out of band.
  • Use only approved AI tools for work data; ask if unsure.
  • A "video call" or voice can be faked — confirm high-risk actions independently.
  • Report anything that feels off; speed limits the damage.

Module RecapFive Things to Remember

  • Every control protects the CIA triad — Confidentiality, Integrity, Availability
  • Name the threat, map it to a mitigation — patch, filter, train, segment, monitor
  • Security is layered: defence in depth means no single wall has to hold
  • Operations is the daily loop — monitor, detect, respond, recover, learn
  • Governance, risk & compliance turn practice into a program — and into regulation
🔒 Knowledge check locked. Work through and complete all five pillars above to unlock the Module 04 quiz.

Module 04 — Knowledge Check.

6 questions · all mandatory · answered in order Answered 0 / 6

Module 05 — NCA Regulation Awareness

Compliance,
By Design.

The National Cybersecurity Authority sets the cybersecurity baseline for the Kingdom. Know its mandate, the structure of ECC-2:2024, who must comply, and how compliance is actually assessed.

In this module you will learn to

The Night 30,000 Machines Died

NCA · ORIGINS 2012SHAMOON · 30K WIPED 2017NCA · ROYAL ORDER 2018ECC-1 2024ECC-2 2017 Established by Royal Order — the Kingdom'scybersecurity regulator and national authority All government agencies must abide by NCA frameworksHIGH ORDER NO. 57231

ECC, by the Numbers

ECC · STRUCTURE 4MAIN DOMAINS 28SUBDOMAINS 108MAIN CONTROLS 92SUBCONTROLS C·I·A — Strategy · People · Process · Tech2-2-3-2 = domain · subdomain · control · subEVERY CONTROL ID IS COORDINATES

Four Domains Hold the Line

ECC · 4 DOMAINS GOVERNANCE DIRECTS THE REST ECC 🏛️ GovernanceDOMAIN 1 · 10 SUBDOMAINS 🛡️ DefenseDOMAIN 2 · 15 SUBDOMAINS 🔄 ResilienceDOMAIN 3 · BCM 🤝 Third-Party & CloudDOMAIN 4 · 2 SUBDOMAINS Module 1 → Domain 4 · Module 2 → Domain 2 · Module 4 → Domains 1 & 2

Compliance Is a Loop, Not a Trophy

COMPLY · THE LOOP CONTINUOUS COMPLIANCE 📋 Self-assessmentENTITY-RUN 📈 Tool reportsECC COMPLIANCE TOOL 🔍 Field auditsAUDIT · EVIDENCE REQUESTFINDINGS → CORRECTIVE PLAN + DEADLINE 🏢 Government + affiliatesECC · MANDATORY ⚡ CNI owners & operatorsECC · MANDATORY
Explainer 05
Framework anatomy

Inside ECC-2:2024.

The 2024 revision streamlined ECC-1:2018 (which had 5 domains and 114 controls) into four sharper domains. Here's the map:

1

Cybersecurity Governance

Strategy · management · policies & procedures · roles & responsibilities · risk management · project management · compliance · periodical review & audit · human resources · awareness & training.

2

Cybersecurity Defense

15 subdomains: asset management · identity & access management (2-2) · systems protection · email · network · mobile devices · data protection · cryptography · backup · vulnerabilities · pentesting · logs & monitoring · incident & threat management · physical security · web applications.

3

Cybersecurity Resilience

One subdomain (3-1): cybersecurity resilience aspects of Business Continuity Management — keeping critical services running through and after an incident.

4

Third-Party & Cloud

Two subdomains: third-party cybersecurity (4-1) and cloud computing & hosting cybersecurity (4-2) — eight controls governing every external dependency.

Beyond the ECC

The NCA Framework Family.

The ECC is the baseline. Depending on what your entity is and what it runs, additional NCA control sets apply on top:

Baseline — gov & CNIECC-2:2024

Essential Cybersecurity Controls — the minimum for government agencies and CNI operators. Everything else builds on it.

Critical systemsCSCC

Critical Systems Cybersecurity Controls — stricter requirements for systems whose disruption has national-level impact.

CloudCCC

Cloud Cybersecurity Controls — obligations for both cloud service providers and cloud service tenants.

DataDCC

Data Cybersecurity Controls — protecting data across its lifecycle, aligned with national data classification.

IndustrialOTCC

Operational Technology Cybersecurity Controls — for ICS/OT environments in industrial and utility sectors.

Remote workTCC

Telework Cybersecurity Controls — securing remote-work systems and the people who use them.

Social mediaOSMACC

Organizations' Social Media Accounts Cybersecurity Controls — protecting official accounts from hijacking and misuse.

Sector overlaySAMA CSF

The financial sector's Cyber Security Framework from the Saudi Central Bank — a sector regulator's overlay, alongside (not from) the NCA.

Staying compliant

How Compliance Works.

SCOPE

Know If You're in

ECC: government agencies and affiliates, plus private-sector owners, operators or hosts of Critical National Infrastructure.

APPLY

Implement What Applies

Each entity complies with every control applicable to it: applicability is scoped by what you are and what you run. Subdomain 4-2 binds only cloud users; 2-15 only those exposing web apps; sector overlays (SAMA CSF) and stricter sets (CSCC, OTCC) layer on top. Document your applicability decisions — "not applicable" is an auditable claim.

PROVE

Assess & Report

NCA evaluates via entity self-assessment, periodic reports through the ECC-2:2024 Assessment & Compliance Tool, and field audit visits.

SUSTAIN

Keep It Continuous

Compliance is ongoing, not annual theatre: periodic reviews are built into the controls themselves (2-2-4, 4-1-4, 4-2-4...).

AI Spotlight — Regulation

Governing AI,
The Saudi Way.

AI governance in the Kingdom sits alongside the NCA's cybersecurity mandate. If your entity builds or deploys AI, these are the instruments IT and security teams must know.

SDAIA

AI Ethics Principles (2023)

SDAIA's Principles and Controls of AI Ethics set the national framework for responsible AI — fairness, privacy & security, reliability & safety, transparency, accountability, humanity, and social benefit — with a risk-based classification applied across the AI lifecycle.

SDAIA

Generative AI Guidelines (2024)

Issued in two editions — one for government employees, one for the public — covering responsible adoption, transparency, human oversight and incident handling for GenAI systems, cross-referencing existing cybersecurity and procurement rules.

NCA

ECC Applies to AI Systems

There is no AI exemption: AI workloads are information and technology assets, so ECC controls apply in full — identity and access (2-2) for model endpoints and pipelines, third-party rules (4-1/4-2) for AI vendors and cloud-hosted models, logging (2-12) for AI platforms.

Horizon

PDPL & Policy-led AI Governance

The Personal Data Protection Law (PDPL) governs personal data feeding AI systems. There is no dedicated AI law yet — the Kingdom governs AI through SDAIA's frameworks, while the draft Global AI Hub Law (2025 consultation) focuses on "data embassies", and SDAIA has declared 2026 the Year of AI. Build compliance-ready AI practices now.

For IT & Security Teams Deploying AI

  • Inventory every AI use-case and classify it by risk, per SDAIA's lifecycle approach.
  • Map each AI system to applicable ECC controls before go-live — treat it like any critical workload.
  • Apply Module 1's third-party rigor to AI vendors, model providers and AI-in-cloud services.
  • Protect training data and prompts per data classification (ECC 2-7, DCC) and PDPL.
  • Log and monitor AI system access and behaviour — models are assets and attack surfaces.
  • Track SDAIA and NCA publications: AI regulation in the Kingdom is evolving fast.

Module RecapFive Things to Remember

  • The NCA sets the national baseline; agencies must abide by its frameworks (High Order 57231)
  • ECC-2:2024 = 4 domains, 28 subdomains, 108 main controls, 92 subcontrols
  • ECC binds government agencies and affiliates, plus CNI owners & operators
  • Compliance is continuous — self-assessment, compliance-tool reports and field audits
  • AI systems get no exemption: SDAIA frameworks and ECC controls apply in full

Module 05 — Knowledge Check.

6 questions · all mandatory · answered in order Answered 0 / 6

Module 03 — Application Development Security

Secure by Design.
Shipped That Way.

Every application your teams build is production attack surface. This module covers the secure development lifecycle, the attacks that exploit rushed code, and the ECC controls — 1-6-3 and 2-15 — that make security a requirement, not a patch.

In this module you will learn to

The Bug Gets Costlier Every Hour

COST · SHIFT LEFT DESIGN 5–10×CODE 15×TEST 30×+PRODUCTIONORDER-OF-MAGNITUDE ESTIMATES · BOEHM 1981AVG BREACH: US$4.44M · 241 DAYS (IBM 2025) Security starts at the whiteboardSHIFT LEFT — ECC 1-6-1

When Your Input Becomes a Command

ATTACK · INJECTION WHERE user = '' OR 1=1 --' ' OR 1=1 -- LOGIN FORMCWE-89 · OWASP A05:2025 DATABASE · EVERY RECORD The fix: parameterized queries + input validationDATA ≠ CODE · SAME FAMILY AS LOG4SHELL · CVE-2021-44228

The Gate That Can't Be Skipped

PIPELINE · GATES 🗺️THREAT MODELDESIGN 🔍SAST · SCA · SECRETSCI 🛡️DAST · PENTESTRELEASE ⚙️CONFIG REVIEW1-6-2-2 REJECTED: HARDCODED SECRET · AKIA… Vulnerabilities assessed and remediated before launch — not after (ECC 1-6)

No Single Wall Holds Forever

DEFENCE IN DEPTH ONE GETS THROUGH — MULTI-TIER CONTAINS IT WAF 2-15-3-1 · NOT A SUBSTITUTE PRESENTATION TIERPUBLIC APPLICATION TIERRESTRICTED DATA TIERMULTI-TIER · 2-15-3-2 🔒 HTTPS (TLS 1.2+) · 2-15-3-3 🔑 IMPACT-BASED AUTHN · 2-15-3-5 📜 Usage policy · 2-15-3-4
Explainer 03
Why it matters

Bugs Are Cheap.
Breaches Aren't.

#1Broken Access Control tops the OWASP Top 10 — authorization flaws written into application code, not the network. Module 2's principles apply inside your apps too.Source: OWASP Top 10:2025
30×the cost — a widely cited systems-engineering estimate for fixing a defect in production versus catching it at the design stage. Shifting left is an economic decision.Source: Boehm-lineage software-engineering estimates (indicative, order-of-magnitude)
1-6-3is the ECC control that makes secure coding standards, trusted development tooling and pre-launch compliance testing mandatory for every software project.Source: NCA ECC-2:2024, Domain 1
The secure SDLC

Five Gates Before Go-live.

01

Requirements

Security requirements written alongside functional ones — data classification, authn/authz needs, regulatory constraints (ECC 1-6-1).

02

Design

Threat modeling: what can go wrong, who attacks, what hurts most. Multi-tier architecture decided here (2-15-3-2).

03

Code

Secure coding standards (1-6-3-1), trusted and licensed tools and libraries (1-6-3-2), no secrets in source, peer review.

04

Test

SAST, DAST, dependency and secrets scanning in CI; compliance testing against the entity's cybersecurity requirements (1-6-3-3).

05

Deploy & Operate

Secure config and hardening review before launch (1-6-3-5), WAF and HTTPS in front (2-15-3), then monitor, patch, and periodically review (2-15-4).

Regulation deep-dive

What the ECC Requires.

Two subdomains anchor application security: 1-6 makes security part of every project, and 2-15 protects what you expose to the internet.

Cybersecurity requirements must be included in project management methodology and change management — identifying and managing cyber risks across the whole technology project lifecycle. Security is a requirement, not a review at the end.
As a minimum, every project and change requires:
  • 1-6-2-1Vulnerability assessment and remediation.
  • 1-6-2-2 — Review of secure configuration, hardening and update packages before launching projects and changes.
Software and application development projects must include, as a minimum:
  • 1-6-3-1 — Using secure coding standards.
  • 1-6-3-2 — Using trusted and licensed sources for software development tools and libraries.
  • 1-6-3-3Compliance testing of software against the entity's cybersecurity requirements.
  • 1-6-3-4Secure integration between applications.
  • 1-6-3-5 — Reviewing secure configuration, hardening and update packages before launching software products.
External web applications must be protected with, as a minimum:
  • 2-15-3-1 — A web application firewall.
  • 2-15-3-2Multi-tier architecture (presentation, application and data layers separated).
  • 2-15-3-3Secure protocols, e.g. HTTPS.
  • 2-15-3-4 — A clarified secure usage policy for users.
  • 2-15-3-5User authentication with factors chosen from an impact assessment of authentication failure and bypass.
Control 2-15-4 requires these protections to be periodically reviewed.
Subdomains 2-10 (Vulnerability Management) and 2-11 (Penetration Testing) close the loop after release: continuously discover, classify and remediate weaknesses in your applications — before someone else does it for you.
Know the enemy — tap each card

Six Ways Apps Get Owned.

AI Spotlight — Application Development

Your Co-pilot
Writes Bugs Too.

AI coding assistants accelerate delivery — and replicate insecure patterns at scale. Meanwhile, the LLM features you embed in products open a brand-new attack surface. Both need engineering discipline.

Threat

AI-generated Insecure Code

Assistants reproduce the patterns they were trained on — including vulnerable ones — with confident, plausible-looking output. AI code gets zero trust: same review, same SAST, same compliance testing (1-6-3-3) as human code.

Threat

Hallucinated Dependencies

Assistants sometimes suggest packages that don't exist — until an attacker registers them with malware inside ("slopsquatting"). Verify every suggested dependency against trusted, licensed sources (1-6-3-2) before installing.

Threat

Prompt Injection in LLM Features

If your app feeds user content, documents or web pages into an LLM, attackers can embed instructions that hijack the model's behaviour — exfiltrating data or triggering tool actions. Treat all model input as untrusted, and model output as untrusted too.

Defence

AI on Your Side

Use AI to strengthen the pipeline: AI-assisted code review, smarter SAST triage that cuts false positives, test-case generation, and anomaly detection on application behaviour in production.

AI-era Secure Development — Team Rules

  • All AI-generated code passes the same review, SAST and compliance gates as human code.
  • Verify AI-suggested packages exist, are maintained, and come from trusted licensed sources.
  • Never paste secrets, credentials or classified code into external AI tools.
  • For LLM features: least-privilege tool access, output validation, and prompt-injection testing.
  • Log AI-feature usage in your apps — model calls are security events too (ECC 2-12).
  • Document where AI is used in the SDLC so audits and reviews can account for it.

Module RecapFive Things to Remember

  • Security shifts left: cybersecurity is a key requirement of every project (1-6-1)
  • Development minimums: secure coding, trusted licensed libraries, compliance testing (1-6-3)
  • External web apps: WAF, multi-tier architecture, HTTPS, impact-based authentication (2-15-3)
  • Secrets never live in code — vault them, scan for them in CI, rotate on any leak
  • AI-generated code and LLM features pass the same gates as everything else

Module 03 — Knowledge Check.

6 questions · all mandatory · answered in order Answered 0 / 6

Final exam

The Final Exam.

20 questions, sampled from all five modules and re-shuffled on every attempt. Score 80% (16/20) to unlock your Certificate of Achievement. You can retake the exam as many times as you like — only a passing attempt counts.

Final Exam.

20 questions · sampled from all modules · answered in order Answered 0 / 20

Final assessment

Your Results.

0%0 / 33
Module 01 · Third-Party Risk
Module 02 · Access Management
Module 03 · AppDev Security
Module 04 · Cybersecurity at a Glance
Module 05 · NCA Regulations
Cybersecurity Essentials Training Program

Certificate of Achievement.

This certificate is proudly presented to

for successfully completing the interactive Cybersecurity Essentials Training Program covering Third-Party Risk Management, Identity & Access Management, Application Development Security, Cybersecurity Fundamentals, and NCA Regulation Awareness (ECC-2:2024), passing the final exam with a score of .

Course HCA-CSA-401 · Version 2.0 · Aligned with NCA ECC-2:2024
Date Awarded
Sara AlOthman
Program Director
Signature
Certificate ID:
Keep going — official sources