Cybersecurity Fundamentals
Practical defensive security: recognise real attacks, harden accounts, devices and networks, and respond properly when something goes wrong.
About this course
This course is for people stepping into security roles and for anyone responsible for protecting an organisation — IT staff, operations and finance managers, compliance officers, and business owners who have realised how much is at stake. It is entirely defensive. You will learn how attackers work so you can stop them, not so you can copy them.
You will work through the attacks Nigerian organisations actually face: business email compromise aimed at a finance officer, fake bank SMS and USSD-based fraud, credential phishing against staff webmail, ransomware arriving in an invoice attachment, and the insider who simply took the customer list with them. You will pull apart real phishing headers, harden a Windows machine and a router, read logs to reconstruct an incident, and run a tabletop response exercise.
You leave with a hardened set of personal and organisational defences, a written incident response plan and security policy you can put in front of management, working familiarity with the everyday tools of the trade, and a clear route towards CompTIA Security+ if certification is your next step.
Sessions are taught in person with hands-on labs on your own laptop, using safe, isolated environments. Nothing in this course involves attacking systems you do not own.
What you will cover
6 modules, 33 sessions.
Module 1: How Attacks Actually Happen
- The CIA triad and thinking in terms of risk1 hr
- Who attacks Nigerian organisations, and what they want1 hr 30 min
- The stages of an intrusion, from reconnaissance to exfiltration1 hr 30 min
- Malware families: ransomware, infostealers, trojans and worms1 hr 30 min
- Reading a real-world breach report1 hr
Module 2: Networks, and Watching What Moves Across Them
- TCP/IP, ports and what a packet carries1 hr 30 min
- Capturing and reading traffic with Wireshark2 hr
- Firewalls, segmentation and controlling what can reach what1 hr 30 min
- Securing wifi and the office router1 hr 30 min
- VPNs, remote access and working safely outside the office1 hr
- DNS, HTTPS and certificates: verifying you are talking to the right server1 hr 30 min
Module 3: Hardening Accounts, Devices and Data
- Passwords, password managers and how credentials get cracked1 hr 30 min
- Protecting accounts with multi-factor authentication1 hr 30 min
- Hardening Windows: updates, accounts, BitLocker and defender settings1 hr 30 min
- Securing phones and the risks of BYOD1 hr 30 min
- Backups that survive ransomware1 hr 30 min
- Encryption in practice: data at rest and in transit1 hr 30 min
Module 4: Phishing, Social Engineering and the Human Layer
- Anatomy of a phishing email, header by header1 hr 30 min
- Business email compromise and invoice fraud1 hr 30 min
- Smishing, vishing and fake bank alerts1 hr
- Pretexting, impersonation and physical social engineering1 hr
- Running phishing awareness that staff do not resent1 hr 30 min
Module 5: Detection, Incident Response and Policy
- Logs: what to collect and what they tell you1 hr 30 min
- An introduction to SIEM and centralised monitoring1 hr 30 min
- Vulnerability scanning and patch management1 hr 30 min
- The incident response lifecycle: detect, contain, eradicate, recover1 hr 30 min
- Tabletop exercise: responding to a live incident2 hr
- Writing a security policy management will approve1 hr 30 min
- NDPR obligations and reporting a breach1 hr
Module 6: Tools, Assessment and Your Next Step
- Building a safe home lab for practice1 hr 30 min
- The defender's toolkit: hands-on with core tools2 hr
- Security assessment: auditing an organisation end to end2 hr
- Careers in defensive security and the route to certification1 hr
Questions people ask
Will this teach me how to hack?
No, and deliberately so. This is a defensive course. You will study attacker behaviour closely — enough to recognise, prevent and respond to it — but every lab runs in an isolated environment you own. We do not teach or condone attacking systems that are not yours.
Do I need an IT background?
No. You need to be comfortable with a computer and willing to learn the networking basics we cover in Module 2. Career changers, finance and operations staff, and business owners all do well here; prior IT experience simply means you move faster through the early material.
What equipment do I need?
A laptop with at least 8GB of RAM (16GB is more comfortable) and enough free disk space to run virtual machines, plus administrator rights to install software. A corporate laptop that is locked down by your IT department will limit what you can do in the labs.
Does this prepare me for CompTIA Security+?
It covers a substantial share of the Security+ domains and gives you the practical grounding the exam assumes. It is not an exam cram course, and the certification fee is paid separately to CompTIA. We will show you exactly what to study to close the gap.
I am here to protect my own business, not to change careers. Is that a fit?
Yes — a good part of each cohort is exactly that. You will leave with your own accounts and devices hardened, a written security policy and incident response plan for your organisation, and a clear view of where your money is best spent.
Do I get a certificate?
Yes, a Toko Academy certificate on completion, which requires attendance and a passing security assessment submission. It is evidence of practical work completed, which is what interviewers ask about.
Scheduled classes
Tell us you are interested and the admissions team will be in touch about dates and payment.
Ask a question- Format
- Scheduled classes
- Contact hours
- 48 hours
- Sessions
- 33 across 6 modules
- Certificate
- Yes, on completion
- Who it is for
- Youth, Professionals, Corporate & Government