Learning Center

Cybersecurity, taught in order

Three tracks take you from everyday online safety to professional defensive practice. Every article ends with concrete defensive recommendations and official references.

Beginner

Everyday protection for your accounts, devices and personal data.

  • · Cybersecurity basics
  • · Internet safety
  • · Password security
  • · Two-factor authentication
  • · Phishing awareness
  • · Malware awareness
  • · Safe browsing
  • · Email security
  • · Social-media security

Intermediate

Applied defensive skills for developers, admins and IT generalists.

  • · Web security
  • · Network security
  • · API security
  • · Authentication
  • · Session security
  • · Secure coding
  • · Linux security
  • · Cloud security
  • · Database security

Advanced

Professional practice for security engineers and authorised testers.

  • · Penetration testing concepts
  • · Vulnerability research
  • · Digital forensics
  • · Threat hunting
  • · Incident response
  • · Security architecture
  • · Secure DevOps
  • · Security automation

Articles

Search the knowledge base

BeginnerCybersecurity basics

Cybersecurity Basics: How Attacks Actually Happen

A plain-language introduction to the threats most people and small businesses really face, and the defences that stop the majority of them.

8 min read · updated 2026-09-02

BeginnerPassword security

Password Security and Passphrases That Hold Up

How password attacks work at a conceptual level, why length beats complexity, and how to manage credentials without memorising them.

7 min read · updated 2026-08-21

BeginnerTwo-factor authentication

Two-Factor Authentication: Apps, Keys and Passkeys

A comparison of second-factor options, their trade-offs, and how to roll them out without locking yourself out.

6 min read · updated 2026-07-30

BeginnerPhishing awareness

Phishing Awareness: Recognising Fake Logins and Support Scams

The signals that give away a phishing page or message, and what to do in the minutes after you realise you clicked.

9 min read · updated 2026-09-10

IntermediateWeb security

Web Application Security: The Defensive Fundamentals

How the most common web vulnerability classes arise and the framework-level controls that prevent them.

12 min read · updated 2026-08-14

IntermediateAPI security

API Security: Authorisation, Rate Limits and Data Exposure

APIs fail differently from web pages. This guide covers object-level authorisation, over-fetching, and abuse controls.

10 min read · updated 2026-07-18

IntermediateSecure coding

Secure Coding Practices for Small Teams

Lightweight practices that catch security defects early without slowing a small engineering team down.

9 min read · updated 2026-06-29

IntermediateAuthentication

Authentication and Session Security

Designing login, session and recovery flows that resist credential stuffing, fixation and token theft.

11 min read · updated 2026-08-05

AdvancedPenetration testing concepts

Penetration Testing Concepts and Scoping

How authorised security testing is planned, scoped and reported — and why written authorisation comes first.

12 min read · updated 2026-09-05

AdvancedVulnerability research

Vulnerability Research and Responsible Disclosure

How researchers find, validate and report flaws ethically, and how organisations should receive those reports.

10 min read · updated 2026-07-11

AdvancedIncident response

Incident Response Basics for Individuals and Small Teams

A practical sequence for the first hours of a suspected compromise, from containment to evidence preservation.

11 min read · updated 2026-09-12