SC100: Cyber Security Foundation UPDATE

Training: Security - Certification

The participants receive a compact overview of the cybersecurity landscape. They learn attack and defense mechanisms in theory and practice and train the interaction of people, organization, and technology. The course introduces current threats, AI-powered attacks and defense strategies, the new regulatory requirements (NIS-2, DORA, Cyber Resilience Act, EU AI Act) as well as the latest security incidents from the Infosec industry.

Online event Online event

Start: 2026-09-21 | 09:00 am

End: 2026-09-22 | 04:00 pm

Location: Online

Price: 1.350,00 € plus VAT.

Online event Online event

Start: 2026-11-09 | 09:00 am

End: 2026-11-10 | 04:00 pm

Location: Online

Price: 1.350,00 € plus VAT.

Request prefered appointment period:

* All fields marked with an asterisk are mandatory fields.

Agenda:

  • Developing attack scenarios for companies based on publicly visible attack vectors as a moderated live demonstration

  • Discussion and creative exploration of attack and defense

    • How do offense and defense affect each other?

    • New dimension: AI-based attacks and attacks on AI systems – a new class of threats and how to counter them (prompt injection, jailbreaks, data poisoning, model theft – based on the OWASP Top 10 for LLM Applications)

    • Agentic AI systems as a new attack surface: autonomous agents, tool integrations (e.g. via MCP) and their protection based on the principles of least privilege and least capability

    • Defense through AI-supported defense mechanisms such as machine learning for anomaly detection, automated threat hunting systems and AI copilots in the SOC

    • Integration of current infosec incidents (e.g. ransomware trends with double/triple extortion, supply chain attacks, AI-supported fraud and deepfake CEO fraud)

  • Expanding the attack surface (technology – organization – human)

    • How do protection requirements classification, risk analysis, risk management, compliance strengthen security?

    • Specific considerations for cloud outsourcing (shared responsibility model, vendor lock-in, geographic risk, digital sovereignty, exit strategy)

    • Introduction to the Lockheed Martin Cyber Kill Chain and the MITRE ATT&CK framework

    • Regulation as a driver of information security – the new set of obligations

    • NIS-2 and the German NIS2-Umsetzungsgesetz (NIS2UmsuCG/BSIG-neu): relevance check, registration and reporting obligations (24h early warning, 72h report, final report), the ten action areas of risk management

    • Personal responsibility and liability of executive management – why cybersecurity is a top management priority

    • Contextualization of DORA (financial sector), Cyber Resilience Act (products with digital elements) and EU AI Act (risk-based AI regulation)

  • Standards, best practices and frameworks – what is the difference and how to deploy them?

    • What is this needed for? Identifying protection needs and developing a compliance framework. How does the process work, from strategy through tactical measures to operational evidence?

    • Introduction to the NIST Cybersecurity Framework 2.0, the ISO 2700X family, BSI™ Basic Grundschutz Standards, and other relevant organizations such as Teletrust, ENISA, and OWASP

    • Mapping regulatory requirements to standards: How do ISO 27001 and IT-Grundschutz support NIS 2 compliance?

  • Fundamentals of technical IT security

    • Network architecture

    • Secure connection of local networks to the internet

    • Secure use of WLAN

    • Secure deployment of IPv4 and IPv6

  • Network components

    • Hardening of clients and servers

    • What do gateways, firewalls and load balancers do?

    • Hardening of a server

    • Virtual environments and containers

    • Serverless computing vs. microservices – what is more secure?

  • Internet services and applications

    • AI concepts: 6 layers of AI, least privilege and least capability

    • Shadow AI in the enterprise: detect and govern uncontrolled use of AI tools

    • Secure use and operation of email solutions (incl. SPF, DKIM, DMARC)

    • Secure provision and use of web services

    • Securing of digital supply chains (vendor assessment, SBOM, requirements from NIS-2 and CRA)

    • Secure remote access to local networks (VPN, Zero Trust Network Access)

    • Identity as the new perimeter

    • Identity-based attacks: phishing-resistant vs. classic MFA, MFA fatigue, session token theft

    • Modern authentication with passkeys/FIDO2 and Identity and Access Management

  • How do vulnerabilities arise, and how can they be brought under control?

  • Workshop: Identifying and mitigating vulnerabilities through technical, human, and organizational measures in various scenarios

  • Fundamentals of social engineering

    • Psychological principles

    • OSINT and information gathering

    • Typical attack scenarios (phishing, vishing, lishing, smishing, deepfakes, tailgating, spoofing)

    • AI-enhanced social engineering: hyper-personalized phishing campaigns, voice cloning, deepfake video conferences

    • Defense against SE attacks (incl. training in detecting AI-generated content)

  • The cybercrime landscape

    • Hacktivists, nation state actors, commercial hackers, script kiddies – and Cybercrime-as-a-Service as a business model

    • Darknet, deep web, Trojans/viruses/worms, infostealers, WLAN and USB attacks, DDoS, ransomware, lateral movement in in identity and access systems (using Active Directory and Entra ID as examples)

  • Building a resilient ISMS

    • Defining its purpose, identifying stakeholders, selecting the system, conducting risk analysis, defining roles and functions, establishing compliance and governance, and developing policies, security concepts, and measures

    • The ISMS as the backbone of NIS-2 compliance: from gap analysis to providing evidence to the supervisory authority

  • Cybersecurity technology:

    • Preventive: firewalls, proxy, segmentation, hardening, IAM, cryptography (classic methods, key management, Zero Trust approaches, post-quantum cryptography and migration paths based on BSI™ and NIST recommendations), patching, backup

    • Detective: advanced analytics, antivirus protection (signature/heuristics/NextGen), EDR/XDR, NBAD (Network Behavior Anomaly Detection), mail protection, honeypots

    • Reactive: quarantine, behavior blocking, SIEM, SOC, CERT, forensics, incident response incl. legal reporting processes

    • Predictive: darknet monitoring/underground spotting, threat intelligence, bug bounty, BCM, BIA

  • BCM – emergency preparedness and resilience measures

    • How to prepare for the unexpected (Black Swan, N.N.Taleb)?

    • Resilience as a regulatory requirement: business continuity and crisis management under NIS-2 and DORA

  • Awareness – campaign design, a constructive error culture, team building, flagship projects, and training obligations for executive management and employees

Objectives:

  • Deepen your understanding of the interaction between attack and defense across the core dimensions of technology, organization, and people.

  • Learn about measures for achieving a target security level and how frequency, potential impact, and likelihood of occurrence can be addressed to reduce risk.

  • Get an overview of the most important current security standards and their interaction.

  • Understand the new regulatory requirements under NIS-2, DORA, the Cyber Resilience Act, and the EU AI Act – and how to address them pragmatically through an ISMS instead of treating each regulation in isolation.

  • Explore the use of cryptography in the modern security landscape – from everyday data encryption to post-quantum cryptographic methods and migration planning.

  • Complete your fundamentals: from the origins of the German hacker underground scene, through the founding of ENISA and the BSI™, to best practices for establishing an ISMS and auditors’ favorite controls.

  • Using recent real-world incidents, reflect on the role of AI in attack and defense – from AI-enabled fraud and agentic AI systems to securing your own AI applications – and learn strategies for addressing emerging threats.

  • Develop your social skills with an experienced hacker and social engineer – including the detection of deepfakes and AI-based social engineering attacks – and create your own awareness program as part of a group exercise.

  • Prepare yourself and your colleagues with best practices of resilience and IT emergency management for the worst case scenario - including the new legal reporting processes.

 

Target audience:

The workshop SC100 Cyber Security Foundation provides participants with current situational awareness across the entire breadth of cyber security, and is therefore aimed equally at experienced and new employees in the information security domain. In addition, professionals and managers are addressed who assume responsibility for information security due to new regulatory requirements (in particular NIS-2) – such as information security officers, IT managers, compliance and risk managers.

Prerequisites:

No specific prior knowledge regarding information security and IT security is required for participation in the SC100 Cyber Security Foundation course.

Description:

The workshop SC100 Cyber Security Foundation provides you with a compact overview of the entire cyber security landscape.
You will gain an understanding of how IT environments are attacked and defended, both through theoretical concepts and practical examples. You will explore the interaction of people, organization, and technology and their influence on cybersecurity. The workshop is delivered in an online conference format and includes interactive elements.

Assessment/Certificate:
The workshop concludes with a 45-minute gamified assessment. Participants who pass the assessment receive a qSkills™™ certificate.

Check Icon

Guaranteed implementation:

from 2 Attendees

Booking information:

Duration:

2 Days

Price:

1.350,00 € plus VAT.

For in-person attendance, lunch and beverages are included in the price.

Exam (Optional):

100,00 € plus VAT.

Authorized training partner

NetApp Partner Authorized Learning
Commvault Training Partner
CQI | IRCA Approved Training Partner
Veeam Authorized Education Center
DEKRA Certification GmbH
AWS Partner Select Tier Training
ISACA Accredited Partner
iSAQB
CompTIA Authorized Partner
EC-Council Accredited Training Center

Memberships

Allianz für Cyber-Sicherheit
TeleTrust Pioneers in IT security
Bundesverband der IT-Sachverständigen und Gutachter e.V.
Bundesverband mittelständische Wirtschaft (BVMW)
Allianz für Sicherheit in der Wirtschaft
NIK - Netzwerk der Digitalwirtschaft
BVSW
Bayern Innovativ
KH-iT
CAST
IHK Nürnberg für Mittelfranken
eato e.V.
Sicherheitsnetzwerk München e.V.