Training
A platform your teams cannot operate stays a cost. Our programmes build on the vendors’ official material and run on a dedicated lab platform, where things can be handled without risk.
A dedicated lab, so people can practise without risk
Our courses build on the vendors’ official material, which is the reference on the product. We add our own operational practice: what the documentation does not say, what breaks in production, what surfaces after six months.
Hands-on exercises run on a lab platform we provide. Nobody practises on a production environment: participants can break things, start again, try a bad idea in order to understand why it is a bad one.
- Two thirds of the time spent on hands-on exercises
- A dedicated lab, separate from any production environment
- Official vendor material, complemented by our operational experience
- Assessment at the start and at the end of the programme
- A remote consolidation session a few weeks later
Exercises run on a dedicated lab platform, where a mistake has no consequences.
Four programmes, one per role
Each programme can be taken on its own or combined to build a complete SOC team.
SIEM platform administrator
For the infrastructure and operations teams taking charge of the platform.
- Architecture and components of the solution
- Installation, configuration and sizing
- Source onboarding and normalisation
- Index, retention and licence management
- Backup, restore and capacity planning
- Diagnosing collection incidents
SOC analyst — tiers 1 and 2
For the teams responsible for monitoring and qualifying alerts.
- Reading and interpreting security events
- Search language and investigation
- Triage and qualification process
- Introduction to MITRE ATT&CK and attack techniques
- Tier 1 incident response procedures
- Writing an incident report people can act on
Detection engineering
For the people who build detection rules and keep them alive.
- Methodology for designing a use case
- Writing, testing and validating a correlation rule
- Reducing false positives, and tuning
- Coverage and measurement through the MITRE ATT&CK matrix
- Enrichment through threat intelligence
- Documentation and rule life cycle
Continuous exposure management
For security operations and vulnerability management teams.
- The CTEM framework and its five stages
- Contextual prioritisation: CVSS, EPSS and CISA KEV
- Asset mapping and inventory
- Principles and reading of BAS validation campaigns
- Steering remediation and tracking MTTR
- Reporting to the board and evidencing compliance
Format and organisation
| Item | Detail |
|---|---|
| Format | On site at your offices, remotely in a virtual classroom, or a mix of both |
| Duration | 2 to 5 days per programme, depending on the scope chosen and the starting level |
| Group size | Recommended: 4 to 10 participants, to preserve interaction and access to the exercises |
| Environment | A dedicated lab platform, provided by us |
| Language | English or French. Materials available in either language |
| Prerequisites | They vary by programme and are set out during scoping. A placement test is available |
| Follow-up | Course material kept by your teams, and a remote consolidation session included |
When training accompanies a deployment we are delivering, it is built into the skills transfer plan and scheduled before go-live. Your teams take over a platform they watched being built.
Let us build your training plan
Tell us which platform you operate and which profiles you need to bring up to speed. We will propose a suitable programme and a quotation.