Become a Cybersecurity Analyst
From a reported email to a closed incident, with real FBI, CISA and NIST figures as you go: what security analysts do and earn, confidentiality, integrity and availability, threats, vulnerabilities and risk scored by likelihood and impact, defense in depth, phishing and the SPF, DKIM and DMARC results you read in a forged email's header, credential stuffing and password spraying found in a sign-in log, ransomware and CISA's first hours, MFA ranked from FIDO keys down to SMS codes, patching by the KEV catalog and BOD 26-04's four questions, least privilege and zero trust, logs, SIEM and the moment an event becomes an incident, a clerk who calls after typing her password on a fake page, NIST's 2025 incident response model, the six Functions of CSF 2.0, encryption and hashing, awareness training that counts reports, and the degree, certifications, pay and outlook that get you in.
01Use the CIA triad, threats, vulnerabilities and risk as NIST defines them
02Read a forged email's header and catch credential attacks in a sign-in log
03Rank MFA as CISA does and patch what attackers exploit first
04Apply least privilege, zero trust and the basics of encryption
05Run an incident from the first report to recovery, and map the work to CSF 2.0
Every lesson of Become a Cybersecurity Analyst
15 lessons in 5 levels, about 3 hours. Level 1 is free.
Level 1The Job and Its Core IdeasFree · 3 lessons
- What Security Analysts ProtectKnow what information security analysts do, and the three things every security measure protects.12 min
- Threats, Vulnerabilities and RiskTell a threat from a vulnerability, grade impact, and rank risks by likelihood and impact.13 min
- Checkpoint: Defense in DepthStack people, technology and operations so that one failed layer doesn't become a breach.13 min
Level 2How Attacks Get InMembership · 3 lessons
- Phishing, Read Like an AnalystName the forms of social engineering, and read a reported email's authentication results.13 min
- Credential Stuffing in the LogsSpot credential stuffing and password spraying in a sign-in log, and know the defenses.13 min
- Checkpoint: RansomwareKnow how ransomware gets in, what to do in the first hours, and why backups must be offline.14 min
Level 3Lock the Doors Attackers UseMembership · 3 lessons
- Phishing-Resistant MFARank MFA the way CISA does, explain why typed codes can be phished, and plan who moves first.12 min
- Patch What Attackers ExploitPrioritize patching with CISA's KEV catalog and the four questions of BOD 26-04.13 min
- Checkpoint: Least Privilege and Zero TrustApply least privilege and the tenets of zero trust to everyday access decisions.13 min
Level 4Detect and RespondMembership · 3 lessons
- Logs and SIEM in Plain WordsTell events from incidents, and know which logs to collect and what a SIEM adds.12 min
- Incident Response, Phase by PhaseHandle a reported phish from first call to lessons learned: triage by risk, contain, eradicate, recover.14 min
- Checkpoint: The Cybersecurity Framework 2.0Sort security work into CSF 2.0's six Functions, and explain what Govern added.13 min
Level 5Crypto, People and Your Way InMembership · 3 lessons
- Encryption BasicsTell symmetric encryption, public-key cryptography and hashing apart, and where each protects data.12 min
- Security Awareness That WorksPlan awareness training the way CISA and NIST describe it, and measure behavior, not just attendance.12 min
- Your Way In, and the Final TestPlan your route into the job, then use the whole path at once.14 min