Foundations Program

Launch Your Cybersecurity Career

An 8-week, live-plus-asynchronous course built with practicing GRC professionals. Move from conceptual knowledge to applied, employer-facing skills.

About the Program

Employer-Aligned. Experience-Based.

CyberForward Academy’s Foundations program is designed for learners who have completed introductory cybersecurity coursework and are ready to move from concepts to applied, employer-facing skills.

Built with practicing GRC professionals, the program teaches learners to think, communicate, and work like entry-level GRC analysts — with a curriculum anchored to industry frameworks, real scenario work, and structured professional practice.

  • Duration: 8 weeks
  • Format: Live-plus-asynchronous (Hybrid)
  • Live Sessions: 2 hours per week via Zoom
  • Total Learning Hours: ~96 hours
  • Prerequisite: Introductory cybersecurity coursework or TPS assessment
  • Delivery: Cohort-based, B2B / institutional

Who It’s For

A direct bridge from introductory learning into employer-aligned skill development.

High School CTE Completers

Students finishing CTE pathways who are ready for the next step into applied cybersecurity work.

AP Cybersecurity / College Intro

Students completing AP Cybersecurity or introductory college coursework looking to operationalize what they’ve learned.

Career Changers

Adults entering the cybersecurity field who want a structured, employer-aligned path to first-job readiness.

Pathway Learners

Anyone seeking a direct bridge to community college or employer pathways inside Orange County and beyond.

What Learners Study

A practical curriculum mapped to the daily work of an entry-level GRC analyst.

  • GRC mindset, lifecycle, and professional communication
  • Risk assessment, risk statements, and risk registers
  • Frameworks: NIST CSF, ISO 27001, SOC 2, and NIST AI RMF
  • Security policies, standards, and governance documentation
  • Network, endpoint, and vulnerability management oversight
  • Third-party and vendor risk management
  • Data classification, privacy, BIA, and business continuity
  • Integrated GRC practice and career pathway planning

Program Format

8 Weeks

One 2-hour live session per week via Zoom, plus structured asynchronous work.

~96 Total Hours

Approximate total student learning hours across live sessions, applied work, and assessments.

Weekly Assessments

Consultant Workbook, live performance task, and homework — graded against rubrics aligned to professional GRC analyst expectations.

Applied Scenario Work

A running mock company spans all 8 weeks, so risk, policy, and continuity work compound into a coherent narrative.

Credential Earned

CyberForward Foundation Certified digital credential badge

CyberForward Foundation Certified

Issued upon successful program completion. Shareable to LinkedIn, resume, and digital portfolios. Recognized by employers and community college partners.

Program Pathway

Foundations is the first stop in CyberForward’s employer-aligned pathway.

Foundations Training Lab Work Network

Community and Education Partners

  • Saddleback College
  • OC Department of Education — OC Pathways
  • Coastline ROP
  • Vital Link

Learner Outcomes — CROP Spring 2026

End-of-program NPS survey, 14 respondents.

100%

said course objectives were met

8.1

avg. recommendation score (out of 10)

+29

Net Promoter Score

What Learners Said

“The real-world examples and case studies were the most impactful because they showed how cybersecurity actually works, not just theory.”

— Theo Goodman, CROP Spring 2026

“Getting a solid understanding of the basics and seeing how they apply in real situations. It made everything feel more practical and less abstract.”

— Andrew Licea, CROP Spring 2026

“The course gave me foundational knowledge to allow me to continue on this career path.”

— Isaac Hingco, CROP Spring 2026

Graduate Spotlight

Victoria Cruz, Foundations Completer Went on to conduct NIST CSF-aligned risk assessments, perform policy reviews for mock enterprise stakeholders, and present on AI-driven security solutions. Currently completing a B.S. in Cybersecurity (3.9 GPA) and serves as Director of Strategic Relations for her institution’s Offensive Security Society.

Course Description

Through a mix of short pre-class learning, weekly virtual labs, and structured discussions, students learn to think like an entry-level GRC analyst — understanding business impact, working with risk registers, reading frameworks, and communicating clearly with both technical and non-technical stakeholders. The course provides a foundational layer that prepares learners for future specialization in security program management, vulnerability management, business continuity / disaster recovery (BCP/DR), privacy, and third-party / vendor risk.

Course Objectives

Upon completion, students will be able to:

  • Explain the difference between a technical mindset and a GRC mindset and why both are important.
  • Apply a simple GRC lifecycle (Discover → Assess → Recommend → Track) to real-world security scenarios.
  • Break down business processes into assets, threats, vulnerabilities, and impacts — documented in a basic risk register.
  • Describe how key frameworks (NIST CSF, ISO 27001, SOC 2, NIST AI RMF) guide security programs.
  • Distinguish between policies, standards, and procedures, and evaluate examples for clarity and alignment.
  • Interpret basic technical outputs (scan excerpts, incident tickets, vendor responses) as business risk signals.
  • Demonstrate Level 1 professional habits: showing up, following instructions, communicating status, and contributing in group work.

Weekly Schedule

Each week introduces a new topic with applied work that builds on the running mock company scenario.

Week 1 — GRC Transition: From Technical Expert to Strategic GRC Advisor

Subject: GRC Transition

Introduce the difference between a technical mindset and a GRC mindset. Learners practice applying the GRC lifecycle (Discover → Assess → Recommend → Track) to a vulnerability scenario and connect technical severity to business impact and risk tolerance. Professional habits (communication, organization, follow-through) are introduced as core expectations.

Week 2 — Practical Risk Assessment & Risk Registers

Subject: Practical Risk Assessment & Risk Registers

Learners break down a business process into assets, threats, vulnerabilities, and impacts. They practice writing clear risk statements, assigning qualitative likelihood and impact ratings, and populating a simple risk register. Emphasis is on consistent rating and explaining prioritization.

Week 3 — Controls & Frameworks (NIST CSF, ISO 27001, SOC 2, NIST AI RMF)

Subject: Controls & Frameworks

Introduce the idea of “controls” and how they reduce risk. Learners map familiar security practices to major frameworks at a high level and practice rephrasing control requirements in plain language.

Week 4 — Policies, Standards, and Procedures

Subject: Policies, Standards, and Procedures in a Security Program

Learners explore how risk and framework requirements are translated into written policies and procedures. They distinguish policy vs. standard vs. procedure vs. guideline, and review or revise a simple policy/procedure for clarity and completeness.

Week 5 — Cloud, Networks, Endpoints & Vulnerability Management

Subject: Oversight of Cloud, Networks, Endpoints & Vulnerability Management

Students connect their technical knowledge to GRC oversight. They read simplified technical outputs (network diagrams, vuln scan excerpts, incident tickets) and interpret them as business risks, practice basic prioritization, and connect findings back to frameworks and risk registers.

Week 6 — Third-Party & Vendor Risk + Customer Assurance

Subject: Third-Party & Vendor Risk + Customer Assurance

Learners examine why third-party risk is critical. They review a simplified vendor questionnaire, identify red flags, and summarize the vendor’s posture in simple language. They also see how customer assurance and responding to security questions fits into GRC work.

Week 7 — Privacy, Data Protection, BIA & BCP/DR

Subject: Privacy, Data Protection, BIA & Business Continuity / DR

Students connect data classification and privacy concepts to business impact. They revisit Business Impact Analysis (BIA) at an introductory level and see how it drives continuity and disaster recovery planning.

Week 8 — Integrated GRC Practice & Career Pathways

Subject: Integrated GRC Practice & Career Pathways

Learners pull together risk, controls, vendor risk, and continuity into one integrated picture. They complete a small integrated assignment based on a fictional organization and explore how different GRC-related service areas connect to future roles and learning paths.

Participation, Attendance & Policies

Participation & Attendance

Cameras must be on during live sessions unless otherwise approved by the instructor. Three (3) unexcused absences with no communication may lead to being dropped from the class.

Honesty Policy

A student caught cheating on any assignment will receive no credit for that assignment. Further academic integrity concerns may be handled according to program policies.

The syllabus may be updated at any point through the program at the instructor’s discretion. Any changes will be communicated via the LMS and in class.

Ready for the Next Step?

Foundations is sold to community colleges, school districts, and workforce partners as a cohort-based program. Reach out to bring it to your students.