Skip to content

Academy

Cybersecurity sessions for practitioners — built on the products and methods we use every day.

The Academy is not a theory course. Every session comes out of the platform we operate ourselves: how we write a rule, how we separate an attack, how we cut false positives, and what we do in the first hour of an incident.

So sessions are not slides to watch but tasks to work through at a desk. Participants work against their own organisation, not a synthetic range.

Tracks

Six Tracks

Web application defence (WAF / ADR)

  • OWASP Top 10 in practice: SQL injection, XSS, privilege-escalation chains
  • Writing and testing rules: observe mode before blocking
  • Cutting false positives: which signal is enough on its own and which is not
  • Session-level analysis — attacker behaviour rather than a single request
  • Virtual patching: closing exploitation before the fix ships

Who It Is For

Each track targets a specific role. The table shows who benefits and what is assumed beforehand.

Track, audience and prerequisites
TrackForAssumed beforehand
WAF / ADRWeb application and infrastructure administrators, DevSecOpsHow HTTP and web applications work
DDoSNetwork engineers, SRE, hosting teamsTCP/IP basics, DNS
SIEMSOC analysts (L1–L2), security engineersLogs and operating system basics
Email securityMail administrators, IT security staffA working idea of SMTP and DNS records
Threat intelSOC analysts, security managersNo specific prerequisite
Incident responseIT and security teams, accountable managersKnowledge of your own infrastructure

First we establish what your team already knows.

Every topic is worked through at a desk.

Practice runs on your own infrastructure.

What changed is written down.

The process
/04
Scroll
01
02
03
04

Assessment

Before anything starts: a short interview and a practical task — who uses which tool, where they get stuck, which jobs are daily. The programme is assembled after that, rather than a ready-made course laid over the top.

The session

Not slides: a rule gets written, tested, fires wrongly, and is fixed. At the end of each block the participant shows their own result — they did it rather than watched it.

Your environment

What a synthetic range teaches tends to stay on the range. So the second half runs against the participant's own domain, logs and policies — and the result goes back to work with them.

The outcome

Three things remain at the end: a list of what was done, a record of the topics covered, and a recommendation for the next step. The line for questions stays open afterwards.

Hands-on tasks

A desk, not a deck.

  • A task to complete for every topic
  • Working against your own organisation
  • Room to get it wrong and fix it

Open group or in-house

Two formats.

  • Open group — participants from several organisations
  • In-house — for your team only
  • The programme bends to your team's actual work

Language and materials

In the local language.

  • In Uzbek or Russian
  • Materials stay with you afterwards
  • The line for questions stays open after the session
Questions

Frequently Asked Questions

It depends on the track. Threat intel assumes nothing in particular; SIEM and WAF assume an administrator or analyst baseline. The prerequisites are stated per track in the table.

Yes. In-house, the programme is shaped around your infrastructure and what your team does daily — only mail and phishing, say, or only SIEM triage.

No. The sessions are about method and approach, and they carry over to another vendor's WAF or SIEM. The examples come from our platform because that is what we operate every day.

You receive a record of attendance listing the topics covered. It is not an internationally accredited certification and is not presented as one.

Group intake and in-house dates are agreed individually. Send us the track, the number of participants and the format, and we will come back with timing and terms.

Academy

The material keeps moving: a new attack technique reaches a session before it reaches anything else.

Let’s start
Register interest
Register interest