Sorry, this page is no longer available
We may earn an affiliate commission when you visit our partners.
Course image
Debra Baker

Cyber threats are evolving at an unprecedented pace, making security a top priority for every organization. Whether you are a seasoned Chief Information Security Officer (CISO), an IT professional, or a business leader, this course will provide you with the knowledge and tools to build a resilient cybersecurity strategy.

Led by Debra Baker Through practical insights, real-world case studies, and expert strategies, you'll gain a deep understanding of security awareness, risk management, data protection, endpoint security, AI threats, and much more.

What You’ll Learn:

Read more

Cyber threats are evolving at an unprecedented pace, making security a top priority for every organization. Whether you are a seasoned Chief Information Security Officer (CISO), an IT professional, or a business leader, this course will provide you with the knowledge and tools to build a resilient cybersecurity strategy.

Led by Debra Baker Through practical insights, real-world case studies, and expert strategies, you'll gain a deep understanding of security awareness, risk management, data protection, endpoint security, AI threats, and much more.

What You’ll Learn:

  • Security Awareness & Phishing Prevention – Train your employees to be the first line of defense against cyber threats.

  • Multi-Factor Authentication (MFA) & Password Security – Implement robust authentication strategies to prevent account takeovers.

  • Vulnerability Management & Threat Detection – Learn to proactively identify, assess, and remediate security weaknesses.

  • Data Protection & Compliance – Secure sensitive data with encryption, backups, and third-party risk management.

  • Risk Management & Security Policies – Develop a structured approach to balancing security risks and business priorities.

  • Endpoint & Cloud Security – Protect your organization’s devices and cloud infrastructure from sophisticated attacks.

This practical course includes real-life cybersecurity case studies, step-by-step implementation guides, and expert Q&A sessions to reinforce your learning.

  1. Who Should Take This Course?

  • CISOs, CIOs, and IT Security Leaders who want to enhance their organization’s cyber resilience.

  • IT Professionals & Security Analysts looking to upskill in modern security strategies.

  • Business Executives & Decision Makers who need a solid understanding of cybersecurity best practices.

  • Anyone interested in Cybersecurity who wants to strengthen their knowledge of security frameworks and risk management.

  1. Why This Course?

  • Actionable Strategies – No fluff, just real-world, battle-tested security tactics.

  • Industry-Recognized Best Practices – Learn frameworks like

  • Expert Guidance – Leverage Debra Baker’s CISO experience to build a security-first culture in your organization.

  • Stay Ahead of Cyber Threats – Gain insights into emerging attack vectors, AI-driven threats, and Zero Trust security models.

  1. Let’s Build a Cyber-Resilient Future.

Cybersecurity is no longer just an IT issue—it’s a business imperative. Join us on this journey to fortify your organization against evolving cyber threats and establish a resilient, proactive security posture.

Enroll now and take your cybersecurity knowledge to the next level.

Enroll now

What's inside

Learning objectives

  • Implement a robust cyber resilience strategy – develop and execute a cybersecurity framework that aligns with industry best practices, including nist.
  • Strengthen security awareness & threat detection – train employees on cybersecurity hygiene, phishing prevention, and social engineering tactics.
  • Secure critical data & assets – apply encryption, backup strategies, and third-party risk management techniques to protect sensitive information from breaches.
  • Enhance endpoint & cloud security – deploy advanced security controls, including endpoint detection & response (edr), zero trust models, and cloud security.
  • Leverage ai for cyber defense – understand both the risks and benefits of artificial intelligence in cybersecurity, including ai-driven threat detection.

Syllabus

Introduction

After completing this section, learners will be able to explain the concept of cyber resilience, its importance in modern organizations.

Read more

This session provides a real-world scenario of a major cybersecurity breach, breaking down how an attack unfolds and how organizations can respond and recover. By the end of this session, students will be able to:

  • Analyze how cybercriminals infiltrate an organization through phishing, RDP, and SMB vulnerabilities.

  • Understand the stages of a ransomware attack and how data exfiltration occurs.

  • Evaluate incident response strategies used by CISOs and IT teams to mitigate damage.

  • Learn from case studies such as Colonial Pipeline and SolarWinds attacks.

  • Develop an effective breach response plan to contain, remediate, and recover from cyber incidents.

Why is this important?
Understanding how attacks happen in the real world helps organizations strengthen defenses and improve resilience against sophisticated cyber threats.

This session covers best practices in authentication and access control, helping students build a secure identity management strategy. By the end of this session, students will be able to:

  • Implement Multi-Factor Authentication (MFA) to reduce unauthorized access.

  • Use secure password policies in alignment with NIST 800-63B guidelines.

  • Understand and deploy passwordless authentication using passkeys and biometrics.

  • Recognize common authentication attacks, such as credential stuffing and phishing.

  • Implement role-based and least-privilege access to minimize insider threats.

Why is this important?
IAM is the first line of defense in cybersecurity. A strong IAM strategy prevents 99.9% of account compromise attacks.

These questions will help reinforce the key concepts covered in Section 3 MFA Quiz.

This session guides students on developing and enforcing security policies to ensure compliance and reduce risk. By the end of this session, students will be able to:

  • Draft and implement essential security policies, including acceptable use and data protection policies.

  • Ensure compliance with industry regulations like ISO 27001, SOC2, and NIST.

  • Understand how security policies protect against legal and financial consequences after a breach.

  • Develop an employee security awareness plan to ensure policies are followed.

  • Audit and update policies regularly to adapt to new cybersecurity threats.

Why is this important?
A well-defined security policy is the foundation of any cybersecurity program, ensuring consistency, compliance, and risk mitigation.

These questions will help reinforce the key concepts covered in Section 4 Developing Security Policies.

This session covers risk management strategies, helping organizations balance cyber risks, security investments, and business objectives. By the end of this session, students will be able to:

  • Conduct risk assessments using Impact vs. Likelihood models.

  • Understand key risk management frameworks like NIST CSF and ISO 27001.

  • Implement preventive, detective, and corrective security controls.

  • Develop a risk register to prioritize cybersecurity initiatives.

  • Align security budgets with risk tolerance and business goals.

Why is this important?
Cybersecurity isn’t about eliminating all risks—it’s about managing them effectively while ensuring business continuity.

These questions will help reinforce the key concepts covered in Section 5 Security & Risk Management.

This session introduces endpoint security strategies, helping students protect devices from malware, ransomware, and unauthorized access. By the end of this session, students will be able to:

  • Implement Endpoint Detection and Response (EDR) solutions.

  • Utilize antivirus, firewalls, and application control to secure endpoints.

  • Harden endpoint configurations using disk encryption and VPNs.

  • Deploy Network Access Control (NAC) and Zero Trust security.

  • Protect mobile devices using Mobile Device Management (MDM) solutions.

Why is this important?
Endpoints are the most common attack vector for cybercriminals. Securing them is critical to prevent unauthorized access and data breaches.

These questions will help reinforce the key concepts covered in Section 6 -

Endpoint & Network Security.

This session covers data protection strategies, ensuring data integrity, availability, and confidentiality. By the end of this session, students will be able to:

  • Understand backup strategies (full, incremental, differential) for disaster recovery.

  • Create business continuity and disaster recovery (BC/DR) plans.

  • Ensure backups are tested at least annually, quarterly is recommended

Why is this important?
Proper data protection ensures organizations stay resilient against cyberattacks, ransomware, and compliance violations.

These questions will help reinforce the key concepts covered in Section 7 -

Data Safeguarding & Disaster Recovery.

This session helps students develop security awareness programs to reduce human error-related breaches. By the end of this session, students will be able to:

  • Train employees on phishing, social engineering, and password security.

  • Develop engaging cybersecurity awareness campaigns.

  • Measure training effectiveness using phishing simulations and KPIs.

  • Choose the best security awareness tools (KnowBe4, Curricula, NINJIO).

  • Foster a culture of cybersecurity responsibility within an organization.

Why is this important?
Many breaches result from human error—security awareness training is the best defense against phishing and social engineering attacks.

These questions will help reinforce the key concepts covered in Section 8 -

Security Awareness & Asset Inventory Management.

This session teaches students how to identify, assess, and remediate vulnerabilities before they are exploited. By the end of this session, students will be able to:

  • Use vulnerability scanning tools (Nessus, Qualys, OpenVAS).

  • Prioritize vulnerabilities using CVSS and CISA’s KEV catalog.

  • Implement patch management best practices.

  • Secure applications using OWASP Top 10 guidance.

  • Integrate security into DevOps (DevSecOps) for continuous protection.

Why is this important?
Regular vulnerability management is essential to prevent cybercriminals from exploiting known weaknesses in systems.

These questions will help reinforce the key concepts covered in Section 9 Vulnerability Management.

This session covers asset inventory management, helping students identify and protect critical assets. By the end of this session, students will be able to:

  • Create a comprehensive asset inventory of hardware, software, and cloud resources.

  • Use automated discovery tools like ServiceNow, CloudWize.io, and Drata.

  • Align asset tracking with compliance frameworks (NIST, CIS, ISO 27001).

  • Secure mobile devices and endpoints using MDM.

  • Integrate asset inventory with change management processes.

Why is this important?
You can’t protect what you don’t know exists—an updated asset inventory is critical for cyber resilience.

These questions will help reinforce the key concepts covered in Section 10 Asset Inventory.

This session teaches students how to protect sensitive data from breaches and unauthorized access. By the end of this session, students will be able to:

  • Implement strong encryption (AES-256, TLS, VPNs).

  • Protect PII and sensitive business data.

  • Assess third-party vendors for security risks.

  • Align data protection policies with compliance (SOC2, GDPR, HIPAA).

Why is this important?
Data breaches cost millions—strong data protection strategies minimize risks and ensure compliance.

These questions will help reinforce the key concepts covered in Section 11 Data Protection & Encryption Quiz.

Traffic lights

Read about what's good
what should give you pause
and possible dealbreakers
Provides actionable strategies and real-world, battle-tested security tactics, which are valuable for leaders looking to enhance their organization’s cyber resilience
Covers industry-recognized best practices and frameworks like NIST, ISO 27001, and GDPR, which are essential for professionals upskilling in modern security strategies
Offers insights into emerging attack vectors, AI-driven threats, and Zero Trust security models, which are crucial for executives needing a solid understanding of cybersecurity
Led by Debra Baker, who brings CISO experience to help build a security-first culture in organizations, which is beneficial for IT security leaders
Requires learners to understand how cybercriminals infiltrate networks and execute ransomware attacks, which may require some prior knowledge for those new to cybersecurity
Includes quizzes to reinforce key concepts, which may not be suitable for learners who prefer a more hands-on or project-based learning approach

Save this course

Create your own learning path. Save this course to your list so you can find it easily later.
Save

Reviews summary

Practical guide to cyber resilience for leaders

According to learners, this course offers actionable strategies and real-world insights crucial for building cyber resilience. Many appreciate the focus on practical applications derived from the instructor's extensive CISO experience. The content is described as highly relevant to current cybersecurity challenges, covering key areas like risk management, data protection, and endpoint security. Students particularly highlight the value of case studies and the emphasis on frameworks like NIST and ISO 27001. While largely seen as positive, a few reviewers suggest the course might be more suitable for those with some existing knowledge, and express a desire for deeper technical dives in certain topics.
Might be fast-paced for total beginners.
"If you are completely new to cybersecurity, some concepts might feel a bit fast-paced."
"Having some prior IT or security background will help you get the most out of this course."
"I recommend this for professionals who already have a basic understanding of the field."
Great overview for leaders and managers.
"This course is perfect for business leaders and IT managers who need a strategic overview."
"It provided me with a solid understanding of cybersecurity best practices from a C-suite perspective."
"Excellent course for understanding the business imperative of cyber resilience."
Instructor's experience is highly valued.
"Debra Baker's experience shines through; her insights are practical and authoritative."
"Learning from an experienced CISO like Debra made the concepts much more relatable."
"The expert guidance provided real value beyond just the standard course material."
Content is highly relevant to current threats.
"The course addresses current cyber threats and compliance requirements that we face daily."
"Learning from recent case studies like SolarWinds helped me understand real attack scenarios."
"The topics covered are highly relevant for anyone in a leadership or strategic security role."
"This course provides valuable insights into managing risks in today's complex environment."
Offers practical steps for implementation.
"This course is packed with immediately actionable strategies I can apply to my work as a CISO."
"Unlike theoretical courses, this one gives you battle-tested tactics for real-world security."
"I learned practical steps for implementing MFA, endpoint security, and data protection."
"The content is not just theory; it provides clear, step-by-step guides for deployment."
Could benefit from more technical depth.
"While strategic, some sections could go into more technical detail for security analysts."
"I was hoping for slightly deeper dives into specific technical controls like EDR or NAC implementation."
"Good for the 'what' and 'why', but sometimes lacks the 'how' for technical teams."

Activities

Be better prepared before your course. Deepen your understanding during and after it. Supplement your coursework and achieve mastery of the topics covered in CISO Guide to Cyber Resilience with these activities:
Review NIST Cybersecurity Framework
Familiarize yourself with the NIST Cybersecurity Framework to better understand the course's focus on industry best practices and compliance.
Show steps
  • Download the NIST Cybersecurity Framework documentation.
  • Read the core functions: Identify, Protect, Detect, Respond, Recover.
  • Identify areas where your current organization aligns or needs improvement.
Review 'Cybersecurity Law'
Study a book on cybersecurity law to understand the legal and regulatory aspects of cybersecurity and compliance.
View Cybersecurity Law on Amazon
Show steps
  • Obtain a copy of 'Cybersecurity Law'.
  • Read the chapters on data breach notification laws and privacy regulations.
  • Take notes on key legal and regulatory requirements.
Review 'Practical Cybersecurity Architecture'
Study a book on cybersecurity architecture to gain a deeper understanding of how to design and implement robust security systems.
View Melania on Amazon
Show steps
  • Obtain a copy of 'Practical Cybersecurity Architecture'.
  • Read the chapters on risk management and security controls.
  • Take notes on key concepts and implementation strategies.
Four other activities
Expand to see all activities and additional details
Show all seven activities
Develop a Security Awareness Training Module
Create a security awareness training module to reinforce your understanding of security awareness best practices and phishing prevention.
Show steps
  • Identify a target audience within your organization or a hypothetical one.
  • Research common phishing techniques and social engineering tactics.
  • Create a presentation or interactive module covering these topics.
  • Include quizzes and simulations to test understanding.
Follow a Tutorial on Setting Up Multi-Factor Authentication
Follow a tutorial to gain hands-on experience with implementing multi-factor authentication, a critical security control.
Show steps
  • Find a tutorial on setting up MFA for a common service (e.g., Google, Microsoft).
  • Follow the steps in the tutorial to enable MFA on your account.
  • Document the process and any challenges you encounter.
Create a Risk Management Plan
Develop a risk management plan to apply the concepts of risk assessment, security controls, and business alignment learned in the course.
Show steps
  • Identify critical assets within your organization or a hypothetical one.
  • Conduct a risk assessment using Impact vs. Likelihood models.
  • Develop a risk register to prioritize cybersecurity initiatives.
  • Align security budgets with risk tolerance and business goals.
Write a Blog Post on Endpoint Security
Write a blog post summarizing key endpoint security strategies to reinforce your understanding of endpoint protection solutions.
Show steps
  • Research current trends and best practices in endpoint security.
  • Outline the key topics you want to cover in your blog post.
  • Write a draft of your blog post, including examples and case studies.
  • Edit and proofread your blog post before publishing.

Career center

Learners who complete CISO Guide to Cyber Resilience will develop knowledge and skills that may be useful to these careers:
Information Security Manager
An Information Security Manager safeguards an organization's data and systems. The work of an Information Security Manager involves developing and implementing security policies, managing risk, and ensuring compliance. This course, with its focus on building a resilient cybersecurity strategy, is directly applicable to this role. Specifically, the modules on security awareness, risk management, and data protection provide the knowledge base needed. Learning about NIST, ISO 27001, and GDPR helps ensure policies are up to date. An Information Security Manager can use the knowledge in this course to enhance existing strategies.
Cybersecurity Analyst
A Cybersecurity Analyst monitors and protects networks and systems from security breaches. The work of a Cybersecurity Analyst often includes identifying vulnerabilities, responding to security incidents, and implementing security measures. This course directly helps build the skills needed to detect, prevent, and mitigate cyber threats. The course's instruction on vulnerability management and threat detection is particularly helpful. The course's insight into endpoint and cloud security also directly informs the work of a Cybersecurity Analyst. A Cybersecurity Analyst can use the training in this course to take their skills to the next level.
IT Security Consultant
An IT Security Consultant advises organizations on how to improve their cybersecurity posture. The work of an IT Security Consultant involves assessing risks, recommending security solutions, and implementing security policies. This course provides valuable insights into risk management, security policies, and industry best practices. The case studies and step by step guides included in this course will inform the mind of an IT Security Consultant. Modules on data protection, endpoint security, and cloud security can be directly applied when working with clients. An IT Security Consultant can use this course to provide effective solutions to their clients.
Risk Manager
A Risk Manager identifies and assesses potential risks to an organization. The work of a Risk Manager involves developing strategies to mitigate these risks and ensuring compliance with relevant regulations. This course's focus on risk management and security policies will be very helpful to those in this position. The framework is taught helps build a foundation in the core competencies of a Risk Manager. Specifically, the sections on risk assessment and security controls provide a structured approach to risk management. This course may be especially useful to those who want to take on the role of Risk Manager, due to the focus on practical strategies.
Compliance Officer
A Compliance Officer ensures that an organization adheres to laws, regulations, and internal policies. The work of a Compliance Officer involves developing and implementing compliance programs, conducting audits, and investigating potential violations. This course, with its focus on security policies and industry regulations like ISO 27001 and GDPR, may be useful to a Compliance Officer, especially one who wants to develop their cyber security expertise. The material on data protection and third party risk management is directly related. This course provides a foundation for those who want to take on the role of Compliance Officer.
Security Architect
A Security Architect designs and implements security systems and networks. The work of a Security Architect involves assessing security requirements, developing security architectures, and ensuring the integration of security controls. This course may be useful, especially as it relates to strategies for building a resilient cybersecurity infrastructure. Security Architects would benefit from the understanding of endpoint, network, and cloud security provided. A Security Architect can use the knowledge from this course to ensure the cybersecurity solutions they design are resilient.
Network Security Engineer
A Network Security Engineer is responsible for securing an organization's network infrastructure. The work of a Network Security Engineer involves implementing firewalls, intrusion detection systems, and other security measures. This course does align with this role. The modules on endpoint and cloud security may be useful for shoring up the foundation for this role. A Network Security Engineer can use the training in this course to proactively protect the network against evolving cyber threats.
Data Protection Officer
A Data Protection Officer is responsible for overseeing an organization's data protection strategy and compliance with data privacy regulations. The work of a Data Protection Officer involves developing data protection policies, conducting data protection impact assessments, and ensuring data security. This course may be useful to a Data Protection Officer. As part of their work, Data Protection Officers will be required to stay up-to-date on security awareness and password security. A Data Protection Officer may find new ideas for data protection policies and strategies.
Incident Responder
An Incident Responder handles and manages security incidents. The work of an Incident Responder includes analyzing security breaches, containing incidents, and restoring systems. This course may be useful to an Incident Responder. The course's instruction on how cyber attacks unfold and how organizations respond is helpful. An Incident Responder may find this instruction helps them develop more effective incident response strategies.
Security Operations Center Analyst
A Security Operations Center Analyst is responsible for monitoring and analyzing security events. The work of a Security Operations Center Analyst includes detecting security incidents, investigating alerts, and escalating issues. This course may be useful to a Security Operations Center Analyst, especially the modules on threat detection and vulnerability management. The training included in this course may better prepare Security Operations Center Analysts for success in their role.
Penetration Tester
A Penetration Tester assesses the security of systems and networks by simulating attacks. The work of a Penetration Tester involves identifying vulnerabilities and providing recommendations for remediation. This course may be helpful to a Penetration Tester. Penetration Testers benefit from training that enables them to stay up to date on the latest methodologies. This course may help Penetration Testers stay ahead of cyber threats.
Chief Technology Officer
A Chief Technology Officer oversees an organization's technology strategy and ensures alignment with business goals. The work of a Chief Technology Officer involves evaluating new technologies, managing IT infrastructure, and ensuring cybersecurity. This course may be useful for a Chief Technology Officer. The course's insights into emerging attack vectors and zero trust security models helps CTOs stay informed. A Chief Technology Officer can use the training to make strategic decisions about cybersecurity investments.
IT Director
An IT Director manages an organization's IT department and ensures the effective operation of IT systems. The work of an IT Director involves overseeing IT projects, managing IT budgets, and ensuring data security. This course may be useful for IT Directors. The modules on security policies, security awareness training, and risk management are helpful. An IT Director can use this course to enhance their understanding of cybersecurity best practices and improve IT operations.
Business Continuity Manager
A Business Continuity Manager develops and implements plans to ensure business operations can continue in the event of a disruption. This role often requires an advanced degree. The work of a Business Continuity Manager involves assessing risks, creating recovery strategies, and testing continuity plans. While this course may be somewhat useful to a Business Continuity Manager, the parts on data protection and encryption are particularly relevant. A Business Continuity Manager can use the training to improve their business disaster recovery plans.
Project Manager
A Project Manager plans, executes, and closes specific projects. The work of a Project Manager involves defining project scope, managing resources, and ensuring project goals are met. While this course may be somewhat useful to a Project Manager, it helps to understand the nuances of cyber resilience. A Project Manager may be able to manage their resources more effectively.

Reading list

We've selected two books that we think will supplement your learning. Use these to develop background knowledge, enrich your coursework, and gain a deeper understanding of the topics covered in CISO Guide to Cyber Resilience.
Provides a comprehensive overview of cybersecurity law and regulations. It covers topics such as data breach notification laws, privacy regulations, and cybersecurity standards. It useful reference for CISOs and IT professionals who need to understand the legal and regulatory landscape of cybersecurity. This book adds breadth to the course by providing a legal perspective on cybersecurity issues.

Share

Help others find this course page by sharing it with your friends and followers:

Similar courses

Similar courses are unavailable at this time. Please try again later.
Our mission

OpenCourser helps millions of learners each year. People visit us to learn workspace skills, ace their exams, and nurture their curiosity.

Our extensive catalog contains over 50,000 courses and twice as many books. Browse by search, by topic, or even by career interests. We'll match you to the right resources quickly.

Find this site helpful? Tell a friend about us.

Affiliate disclosure

We're supported by our community of learners. When you purchase or subscribe to courses and programs or purchase books, we may earn a commission from our partners.

Your purchases help us maintain our catalog and keep our servers humming without ads.

Thank you for supporting OpenCourser.

© 2016 - 2025 OpenCourser