Cybersecurity Architect (AKB1)

Cybersecurity, ICT Security

The course trains you to design, implement and continuously improve an organisation's information security architecture, aligning technical security controls, operational governance and ISMS/ISO 27001 practices. It links implementation to Czech laws 264/2025, 266/2025 and EU NIS2/CER.

You will learn the role of a Cybersecurity Architect in designing system components, ensuring risk analysis, identity & access controls, logging and auditing, and integrating detection and monitoring. The course also covers supplier management and planning for high availability.

THIS TRAINING COURSE WILL HELP YOU:

  • Understand current cybersecurity and critical infrastructure laws
  • Describe the role and responsibilities of a security architect
  • Perform risk analysis in regulated and critical infrastructure settings
  • Design identity, access control and logging solutions for OSes
  • Implement continuous event evaluation, detection and monitoring

WHO SHOULD ATTEND?

  • IT and security professionals seeking an architect role
  • System and network architects responsible for secure design
  • Risk, compliance and operations staff in regulated sectors

COURSE LOCATION AND AVAILABLE DATES



Choose whether to attend in person in our classroom or join online. You can select your preferred format during registration. Learn more about hybrid training.

Unlock your employees' potential. We can adapt every course in our portfolio to your objectives and participants.
Need training at your premises or want to tailor the content and duration? We will prepare the right solution, in Czech or English.

Request customised training

Course content:

Hide details
  • Introduction to the Cybersecurity Act (ZoKB) and risk management
    1. Introduction to current cybersecurity legislation, critical infrastructure and risk management
    2. Requirements of Act No. 264/2025 on Cybersecurity and Act No. 266/2025 on resilience of critical infrastructure entities
    3. NIS2 and CER directives, related laws and standards
    4. Role of the Cybersecurity Architect
    5. Implementing ISMS and ISO 27001 in regulated or critical infrastructure organisations
    6. Critical infrastructure, regulated services and significant information systems
    7. Physical security of critical infrastructure facilities
    8. Risk analysis and risk handling in critical infrastructure environments
    9. Linking security measures to risk analysis
    10. Asset management and governance in regulated environments
    11. Supplier management
  • Identity and access control
    1. Using identities in Windows and Active Directory
    2. Using identities in Linux
    3. User identity management with centralized IdM systems
    4. Access control and secure user behaviour
    5. OS-level resource access control
    6. Database access control
    7. Password management
    8. Implementing 2FA
    9. 2FA vulnerabilities
  • Endpoint security
    1. Antivirus and anti-malware
    2. Next-generation endpoint protection
    3. Data Loss Prevention (DLP) systems
    4. Client certificate management
    5. Disk and USB encryption – BitLocker and EFS
    6. Securing email and web communication
  • Logging and audit
    1. Logging in Windows
    2. Logging in Linux
    3. Application logging
    4. Common logging mechanisms
    5. Defining recording requirements under current cybersecurity legislation
    6. Time sync requirements (NTP)
    7. Network device access logging and handling
    8. OS- and application-level logging
    9. Central tools for log collection and event analysis
    10. Basic SIEM functionality
  • Secure development and applications
    1. Comparison of different application architectures
    2. Application vulnerabilities
    3. Acquisition, development and maintenance
    4. Secure software development principles
    5. Systems Development Life Cycle (SDLC)
    6. Testing developed applications
    7. Using common templates for automation and management
  • Network architecture
    1. Next-generation firewalls
    2. Next-Generation Intrusion Prevention Systems (NGIPS)
    3. DDoS fundamentals and protection methods
    4. L2 and L3 network segmentation principles
    5. Designing DMZs
    6. Grouping and assigning applications to VLANs
    7. VPN implementation and detection of cybersecurity events and incidents
    8. Network and application perspectives
  • Network security
    1. Basic L2 and L3 network design rules
    2. Principles of L2 attacks
    3. ARP-based man-in-the-middle attacks
    4. STP (Spanning Tree) attacks
    5. VLAN attacks
    6. Attacks on L3 routing protocols
    7. Switch configuration recommendations – access control
  • Detection and intrusion monitoring
    1. Requirements for continuous evaluation of cybersecurity events
    2. Behavioral analysis of network traffic
    3. SIEM implementation and deployment
    4. Analysis of detected cybersecurity events
    5. Event evaluation and incident response
  • Ensuring high availability
    1. Business continuity analysis methods
    2. Design requirements for highly available systems
    3. High availability in practice
    4. High availability for control and real-time systems
    5. Links to business continuity analyses
    6. Support and service considerations
    7. SLAs to ensure high availability
    8. Spare parts and replacements
Prerequisites:
Basic familiarity with current cybersecurity legislation, TCP/IP and OSI, operating systems, and common technical security controls.
Schedule:
5 days (9:00-17:00)
Price per person:
1 472.00 € (1 781.12 € incl. 21% VAT)

Training and learning environment