Learning Outcomes

Core competencies developed throughout this foundational module

🛡️

Core Concepts Mastery

Exhibit a comprehensive grasp of essential cyber security concepts (least privilege, defence-in-depth, secure-by-design, Zero Trust) and their foundational role in the development of resilient systems.

🎯

Security Implementation

Implement security techniques (threat modelling, risk assessment, control selection) to guide design and operational decision-making within organisations.

📋

Framework Assessment

Assess the efficacy of control frameworks (e.g., ISO/IEC 27001, NIST CSF 2.0) for aligned recommendations.

💬

Communication Excellence

Appraise and communicate security findings to diverse audiences on risks and assurance.

Artefacts and Feedback

Practical implementations and peer review throughout the module

💬

Collaborative Discussion 1 — Initial Post

UNIT 1

Introduced the Log4j case to frame economic, legal (GDPR), and reputational impacts of cyber security; advocated for proactive investment over reactive spending and underlined the relationship between compliance and trust.

📁 Evidence: Initial Post.pdf

📊

Unit 3 - Summary Post

UNIT 3

Consolidated insights from the Log4j discussion, highlighting economic impacts, regulatory obligations (GDPR Art. 32), and reputational effects, with peer-suggested real-world examples.

📁 Evidence: Summary Post.pdf

📝

Key Considerations for Implementing a Comprehensive Backup and Recovery Plan for an Online Shopping System (OSS)

UNIT 9

Key considerations for an e-commerce backup and recovery plan include risk assessment, layered controls, failover, redundancy, RTO/RPO alignment, integrity checks, log monitoring, and routine recovery validation, highlighting governance and testing for resilient service continuity.

📁 Evidence: Essay9.pdf

🔒

Unit 12 — Secure Backup Application (Python)

UNIT 12

Created a secure backup prototype using secure-by-design and Zero Trust principles: TLS transport, credential authentication, encryption at rest and in transit, and integrity checks. The README covers assumptions, threat model, and testing methods.

📁 Evidence folder: assets/LauchingIntoCybersecurity/unit12

🗂️ Key files:
secure_backup.pyrequirements.txtREADME.mdTestData/ResultsScreenshots.pdf

📈

Risk Analysis — Summary

SUMMARY

During the Log4j analysis and backup/recovery efforts, I focused on practical risk management over theoretical catalogues. Decisions were driven by regulatory requirements (notably GDPR Article 32), service-continuity objectives (including Recovery Time Objectives and Recovery Point Objectives), and validated controls such as Transport Layer Security, encryption, credential verification, and integrity checks.

📁 Evidence: Initial Post.pdf (p.1); Summary Post.pdf (p.1); Essay9.pdf (pp.1–3); Unit 12 README

Personal SWOT Analysis

Self-evaluation of capabilities and development areas

💪 Strengths

  • Systematic approach to frameworks, assessments, and documentation
  • Strong grasp of NIST, ISO/IEC 27001, OWASP
  • Multilingual communication and cross-functional teamwork

⚠️ Weaknesses

  • Limited experience in quantitative risk modelling
  • Still building governance/policy-writing skills
  • Need deeper hands-on penetration testing exposure

🚀 Opportunities

  • Gain formal certification (CISSP/CISM) to validate expertise
  • Leverage e-portfolio for job applications in UK market
  • Contribute to open-source security projects or publications

Threats

  • Rapidly evolving threat landscape outpacing current knowledge
  • High competition for senior security roles
  • Potential burnout from balancing study, work, and upskilling

Action Plan

Concrete steps to address weaknesses and capitalise on opportunities

🔍

Monitor Threat Landscape

Steps: Subscribe to CVE/ENISA/NCSC feeds; weekly review and log one relevant vulnerability/TTP mapped to current controls.

📊

Build Quantitative Risk Scenarios

Steps: Develop scenario models (ransomware vs insider breach) and dashboards of assumptions/impacts; define action thresholds.

🏛️

Enhance Governance Capability

Steps: Study for CISSP/CISM; join a study group; apply governance patterns in projects; attempt exams; integrate new controls.

🗣️

Improve Communication Skills

Steps: Practise narrative slide walkthroughs; collect peer feedback on clarity; present Unit 12 to a non-technical audience.

✍️

Share Knowledge

Steps: Publish three short posts on threat modelling and backups; track engagement.

🎯

Conclusion

I entered confident in my technical skills and learned that resilience and ethics are central. I improved my ability to express risk in business terms while deepening governance and ethical awareness. I view security as an ongoing process requiring continuous threat assessment, collaboration, and evidence-based decisions.

Reflection produced concrete next steps that I'll apply in future projects to ensure security measures positively impact the organisation. I'm committed to lifelong learning, sharing best practice, and addressing emerging cybersecurity challenges.

References

ISO/IEC (2022) ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection — Information security management systems — Requirements. Geneva: International Organization for Standardization.

ISO/IEC (2011) ISO/IEC 27031:2011 Information technology — Security techniques — Guidelines for information and communication technology readiness for business continuity. Geneva: International Organization for Standardization.

National Institute of Standards and Technology (2024) The NIST Cybersecurity Framework (CSF) 2.0. NIST CSWP 29. Gaithersburg: NIST. Available at: https://doi.org/10.6028/NIST.CSWP.29

OWASP Foundation (2021) OWASP Top Ten. Available at: https://owasp.org/www-project-top-ten/

Council of the European Union (2016) Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data (General Data Protection Regulation). Brussels.