Introducing Cyberismo Learning: practical cybersecurity courses for your teams

Introducing Cyberismo Learning: practical cybersecurity courses for your teams

Sami Lempinen |

Most cybersecurity training has a familiar shape. Everyone in the organisation is enrolled, everyone clicks through a set of slides, everyone answers the quiz, and everyone receives a certificate. A quarter later, nothing about how the teams actually work has changed.

We kept running into this from the other direction. In consulting engagements, we would sit down with a development team to work on threat modelling or EU CRA compliance, and spend the first sessions teaching fundamentals that a course should already have covered.

So we built the courses we wished those teams had already taken. Today we are launching Cyberismo Learning.

Three courses

The catalogue starts with three courses, each built around a real obligation our customers are facing rather than around a syllabus.

Developing Secure Software Fundamentals — eight modules for developers, DevOps professionals, and software engineers. It embeds security into the practices developers already use every day: requirements, design, implementation, testing, and deployment. Rather than treating security as something a specialist handles later, it covers what you can do about risk, secure design, input validation, memory safety, verification techniques, cryptography, and operations. No prior security training is assumed.

EU Cyber Resilience Act (CRA) — four modules on what the CRA actually requires of anyone placing products with digital elements on the EU market. Scope and product categories, economic operator roles, the essential cybersecurity requirements of Annex I, vulnerability handling and the reporting clock, support periods, and the documentation of Annex II and VII. It opens with a foundations module that anyone with a security background can skim, so engineers, product managers, and compliance specialists can take it as one group without either half being lost or bored.

Vulnerability Management — seven modules, around 90 minutes, on establishing and operating a vulnerability management process based on IEC 62443-4-1. Reporting channels and disclosure policies, telling findings apart from genuine security issues, assigning severity in the context of your product rather than the CVSS score in isolation, coordinating remediation and disclosure, and closing the loop with root cause analysis.

Two ways to take them

Every course is available in two formats.

Online learning packages are self-paced, split into modules and short sections so they fit the gaps in a working week instead of demanding a cleared calendar. Each module ends with a knowledge check, and every section works as a standalone reference afterwards — which is where a lot of the long-term value sits, because people come back to the section on support periods or severity classification when the question actually lands on their desk. The packages are also available as SCORM packages if you would rather run them in your own learning management system.

Classroom training is the same material delivered by an experienced Cyberismo consultant, on site or remotely. This is the format to pick when the goal is not only knowledge transfer but a conversation about your products, your architecture, and your obligations. We adjust the depth of each module to the audience, and it combines naturally with consulting work such as a threat modelling session or an EU CRA kickstart.

You can read the whole thing before you buy

Buying training normally means trusting a course description and a list of learning outcomes. We would rather you judged the real thing.

Our online service lets you read through the complete content of any course — every module, every section — before deciding whether to purchase it. Access is licensed per customer, so get in touch and we will set it up for your organisation. Then you can check the level, the tone, and the coverage against what your teams actually need, instead of finding out afterwards.

Where the material comes from

None of this was written to fill a catalogue. The courses are assembled from the material our consultants already use with customers, which is why the examples tend to be specific and the advice tends to be about what to do on Monday.

The Developing Secure Software Fundamentals course was developed by amending the Developing Secure Software course from the Open Source Security Foundation (OpenSSF), a Linux Foundation project focused on securing the open source ecosystem — we extended the material, added modules, and added knowledge checks and exams.

Getting started

Have a look at the Learning section for the full course outlines — every module and section is listed, so you can see exactly what is covered before you talk to us.

If you already know who needs to learn what, tell us and we will suggest a combination of online packages and classroom sessions, and quote it. And if you are not sure yet, that is a fine conversation to have too. Working out what a team genuinely needs to know is usually the hardest part.

Customisation

One size does not necessarily fit all. Our course portfolio can be easily adapted to your local needs, processes, conventions, and terminology. Simply contact us and we can discuss your requirements in detail.