Academy
Cybersecurity sessions for practitioners — built on the products and methods we use every day.
Cybersecurity sessions for practitioners — built on the products and methods we use every day.
The Academy is not a theory course. Every session comes out of the platform we operate ourselves: how we write a rule, how we separate an attack, how we cut false positives, and what we do in the first hour of an incident.
So sessions are not slides to watch but tasks to work through at a desk. Participants work against their own organisation, not a synthetic range.
Each track targets a specific role. The table shows who benefits and what is assumed beforehand.
| Track | For | Assumed beforehand |
|---|---|---|
| WAF / ADR | Web application and infrastructure administrators, DevSecOps | How HTTP and web applications work |
| DDoS | Network engineers, SRE, hosting teams | TCP/IP basics, DNS |
| SIEM | SOC analysts (L1–L2), security engineers | Logs and operating system basics |
| Email security | Mail administrators, IT security staff | A working idea of SMTP and DNS records |
| Threat intel | SOC analysts, security managers | No specific prerequisite |
| Incident response | IT and security teams, accountable managers | Knowledge of your own infrastructure |








Before anything starts: a short interview and a practical task — who uses which tool, where they get stuck, which jobs are daily. The programme is assembled after that, rather than a ready-made course laid over the top.
Not slides: a rule gets written, tested, fires wrongly, and is fixed. At the end of each block the participant shows their own result — they did it rather than watched it.
What a synthetic range teaches tends to stay on the range. So the second half runs against the participant's own domain, logs and policies — and the result goes back to work with them.
Three things remain at the end: a list of what was done, a record of the topics covered, and a recommendation for the next step. The line for questions stays open afterwards.
A desk, not a deck.
Two formats.
In the local language.
It depends on the track. Threat intel assumes nothing in particular; SIEM and WAF assume an administrator or analyst baseline. The prerequisites are stated per track in the table.
Yes. In-house, the programme is shaped around your infrastructure and what your team does daily — only mail and phishing, say, or only SIEM triage.
No. The sessions are about method and approach, and they carry over to another vendor's WAF or SIEM. The examples come from our platform because that is what we operate every day.
You receive a record of attendance listing the topics covered. It is not an internationally accredited certification and is not presented as one.
Group intake and in-house dates are agreed individually. Send us the track, the number of participants and the format, and we will come back with timing and terms.
The material keeps moving: a new attack technique reaches a session before it reaches anything else.

