Cyber Security Training
Australian cyber security work is shaped by specific instruments, and generic international content skips all of them. The ASD Essential Eight sets the maturity model most Commonwealth and state agencies are measured against. The Security of Critical Infrastructure Act imposes obligations on operators in eleven sectors, including reporting timeframes that assume somebody has already been trained to recognise a reportable incident. The notifiable data breach scheme under the Privacy Act sets a thirty-day assessment clock that starts whether or not anyone noticed.
Twenty-eight courses cover three quite different audiences, and they are not interchangeable. Awareness and hygiene for a whole organisation, where the objective is that nobody clicks the link. Deep technical work for practitioners — penetration testing, endpoint detection and response, digital forensics, and the operational technology environments where a patch window is measured in years rather than days. And governance for the people who have to sign the risk off: boards, executives, and compliance leads who need to ask the right question rather than run the tool.
Our instructors run security operations commercially. That is the difference between teaching the Essential Eight as eight bullet points and teaching what maturity level two actually costs to reach in an organisation that still has an unsupported application nobody is allowed to turn off.
3 courses
Where to start
- New to security — Cyber Security Awareness Essentials — free, four hours — then the Cyber Security Practitioner Program.
- Practising engineer — Zero Trust Architecture · Endpoint Detection & Response · Advanced Penetration Testing.
- Board or executive — Cyber Security for Executives & Boards · Cyber Governance Frameworks.
- Critical infrastructure — Essential Eight Implementation · Critical Infrastructure Protection (SOCI Act) · SCADA/OT Security.
Common questions
Do these courses make our organisation Essential Eight compliant?
No. The Essential Eight is a set of technical controls implemented in your environment; training gives your people the capability to implement and maintain them. Nobody can make you compliant by teaching a course, and any provider who says otherwise is selling something they cannot deliver.
Is this an accredited qualification?
No. Haibridge Institute is not a Registered Training Organisation. These are non-accredited professional development programs that carry CPD hours and a verifiable certificate. Where you need an accredited outcome we will say so and refer you.
We run OT and SCADA. Is the general security content relevant?
Partly, and that is the reason SCADA/OT Security is separate. Availability outranks confidentiality in an operational environment, patching windows can be annual, and a control that is routine in an office network can trip a safety system. Take the OT course rather than assuming the IT one transfers.
Can our whole team do the free awareness course?
Yes, and it is the intended use. It is free permanently, not a trial. For teams above about twenty people the seat pool makes assignment and completion reporting considerably easier than sending a link around.
Training this team?
Haibridge Institute delivers professional development and applied skills training. We are not a Registered Training Organisation, and our programs are not accredited qualifications under the Australian Qualifications Framework. They are designed to build practical capability alongside formal qualifications, not to replace them.