The learning field guide

Start with a question.

You don’t need to know the vocabulary yet. Choose a path, build your understanding, and practice making decisions with imperfect information.

PATH 01 / 8 LESSONS

Cybersecurity foundations

Eight lessons that teach a beginner to name assets and losses, judge risk under uncertainty, trace a request, handle identity, write scoped policies, plan recovery, read evidence, and connect those skills to frameworks and product categories.

beginner71 min reading
Explore this path ↗

PATH 02 / 4 LESSONS

SOC analyst introduction

Four lessons that take the foundations path into evidence-to-decision work: identity-alert triage, vulnerability prioritization, investigation with verified recovery, and an honest introduction to an Agentic SOC and IRIS. Each lesson lists the foundation skills it depends on.

intermediate38 min reading
Explore this path ↗

All field lessons.

Practice what you learn ↗
01

What we protect: assets, confidentiality, integrity, and availability

Learn to name the things worth protecting and describe a concrete loss as a confidentiality, integrity, or availability failure before talking about products.

8 MIN
02

Threat, vulnerability, likelihood, impact, and uncertainty

Learn why two similar weaknesses can receive different priorities by separating threat, vulnerability, exploitation evidence, impact, and what you still do not know.

9 MIN
03

How systems communicate: network, DNS, HTTP, and TLS

Trace a browser request to a tracking portal and identify what the network, DNS, HTTP, and TLS each do and do not protect.

10 MIN
04

Identity, authentication, authorization, and recovery

Distinguish proving who someone is from granting access, and treat account recovery as part of the same control system.

9 MIN
05

Least privilege, secure defaults, trust boundaries, and layered controls

Choose a scoped access policy by naming trust boundaries and stacking independent controls instead of one powerful exception.

8 MIN
06

Data protection, updates, backups, and resilience

Build a small organization's prevention and recovery plan that covers classification, updates, backups, and what must still work when a warehouse is down.

8 MIN
07

Logs, alerts, and evidence

Separate observed facts, hypotheses, and missing information when reading logs and alerts so a later decision can be defended.

9 MIN
08

From principles to frameworks and product categories

Relate a named risk to an outcome, a control, the evidence you would collect, and the product category that might help—without treating a purchase as the outcome.

10 MIN
09

Triage a synthetic identity alert

Practice stating what is known, what is hypothesized, and which evidence to request next when a synthetic identity alert fires.

9 MIN
10

Prioritize vulnerabilities and exposures

Combine severity, exploitation evidence, exposure, and business context to order a synthetic vulnerability backlog without pretending a single score is enough.

9 MIN
11

Investigate, respond, and verify recovery

Propose a scoped response with a human decision and postcondition checks, using a synthetic identity-and-export case.

10 MIN
12

Understand and build toward an Agentic SOC

Explain IRIS components as a reference architecture, complete a synthetic walkthrough, and keep human authority separate from model text.

10 MIN

Find your next idea.

Tip: press / to open search. Escape closes this window.