Tooling only performs as well as the people operating it. Guardian Academy
delivers role-based curricula, hands-on cyber range exercises and recognised certification
tracks for security analysts, engineers and leaders — plus workforce awareness programmes
that measurably reduce the human attack surface.
42,000+Practitioners trained since the academy launched in 2018
96%Of certified analysts pass at first attempt after the full track
-71%Median reduction in phishing simulation failure rate at 12 months
31 minAverage improvement in mean time to triage after the analyst track
Metrics aggregated across 480 enterprise customer programmes,
measured against each customer's own pre-training baseline.
Role-based curricula
Six paths, each built around a job someone actually does
Generic security awareness does not make a tier-one analyst faster. Every
Guardian curriculum starts from the daily tasks of a specific role, then works backwards to
the knowledge, tooling fluency and muscle memory those tasks require.
SOC analyst
Alert triage discipline, evidence collection, escalation thresholds and shift handover.
Learners work a simulated queue of 200 alerts drawn from real detections, and are scored
on accuracy, not speed alone.
Scoping a compromise, forensic acquisition on live systems, containment sequencing,
memory and log analysis, and writing the incident record that a regulator will read.
Culminates in a 12-hour simulated ransomware event.
Hypothesis-driven hunting, ATT&CK-based coverage assessment, statistical baselining
and query craft. Learners build and defend three original hunts against a live range
containing planted adversary activity.
Detection-as-code practice: rule design, test harnesses, false-positive budgeting,
version control and deployment pipelines. Includes writing and validating 20 production
rules against emulated technique execution.
Identity-first cloud defence across AWS, Azure and Google Cloud: role design, policy
evaluation logic, workload identity, container runtime controls and infrastructure-as-code
guardrails that fail the build rather than the audit.
For directors and CISOs: programme design, risk quantification, board communication,
regulatory duty under NIS2 and DORA, and running the first ninety minutes of a major
incident when everyone is looking at you.
From first shift to specialist, on a published ladder
Each level has explicit entry criteria, an assessment and a competency
statement your HR system can consume. Managers can see exactly where each team member sits
and what the next step costs in hours.
Certification
Three certifications, all assessed on a live range
Guardian certifications are practical. There are no multiple-choice papers:
candidates are given an environment, an objective and a time limit, and are marked on what
they achieve and how well they document it.
GCSA
Certified Security Analyst
For analysts working a detection queue who need to prove triage
accuracy, evidence discipline and escalation judgement.
4 hpractical exam
60 alerts triaged against a graded rubric
Two escalation write-ups assessed by a Guardian analyst
Prerequisite: foundation level or 6 months on a SOC floor
Recognised for continuing education. Guardian certifications and courses
carry CPE credits accepted by (ISC)², ISACA and CompTIA renewal programmes. Credit
statements are issued automatically to each learner and to the programme administrator.
Catalogue
Current course catalogue
Every course is available in each delivery format. Hours shown are contact
hours excluding self-paced lab time, which typically adds 30–50%.
Guardian Academy catalogue, 2026 release. New courses are published quarterly.
Code
Course
Track
Level
Hours
CPE
SEC-101
Security operations fundamentals: telemetry, tooling and the alert lifecycle
SOC analyst
Foundation
8
8
SEC-118
Alert triage at scale: prioritisation, enrichment and defensible escalation
SOC analyst
Foundation
6
6
SEC-204
Windows internals for defenders: processes, tokens and event log semantics
SOC analyst
Practitioner
10
10
SEC-212
Linux and container telemetry: eBPF, audit and runtime signals
Cloud security
Practitioner
10
10
IR-220
Live response and forensic acquisition without destroying evidence
Incident response
Practitioner
12
12
IR-236
Containment strategy: when to isolate, when to watch, when to rebuild
Incident response
Practitioner
8
8
IR-310
Ransomware response: negotiation posture, recovery sequencing and regulatory clocks
Incident response
Specialist
14
14
DE-240
Detection engineering foundations: rule design and the false-positive budget
Detection engineering
Practitioner
10
10
DE-322
Detection as code: version control, test harnesses and safe deployment
Detection engineering
Specialist
12
12
TH-330
Hypothesis-driven threat hunting against ATT&CK coverage gaps
Threat hunting
Specialist
12
12
TH-344
Statistical baselining and anomaly interpretation for hunt teams
Threat hunting
Specialist
10
10
CLD-250
Identity-first cloud defence across AWS, Azure and Google Cloud
Cloud security
Practitioner
12
12
CLD-318
Kubernetes attack paths and runtime containment
Cloud security
Specialist
12
12
ID-260
Active Directory and Entra ID attack paths for defenders
Identity
Practitioner
10
10
LEAD-140
Running the first ninety minutes: executive decision-making in a major incident
Leadership
Executive
6
6
LEAD-186
Regulatory duty under NIS2, DORA and sector reporting regimes
Leadership
Executive
6
6
Scroll the table horizontally to see every column.
Private cohorts can substitute up to 30% of course content for material
drawn from your own environment, including your detection stack and runbooks. See
datasheets for the full syllabus of each course.
Delivery
Five ways to run it
Format changes the logistics, never the assessment. A learner who completes
the self-paced route sits exactly the same practical exam as one who attended in person.
Virtual instructor-led
Live cohorts of up to 16, four hours per day over the course length,
in your time zone. Recorded for 12 months. The default choice for distributed teams.
Cohorts start every second Monday
On-site
An instructor in your building, using your tooling and your incident
history as case material. Minimum eight learners; available in 41 countries.
Six weeks' notice typical
Self-paced
Full video, lab and assessment access for 12 months, with graded
checkpoints and instructor office hours twice weekly. Progress reporting for managers.
Immediate enrolment
Cyber range exercise
Team-versus-adversary exercises on a dedicated range instance. Run as
a one-day sprint or a recurring quarterly drill against fresh scenarios.
Up to 40 participants per instance
Private cohort
A curriculum assembled for one organisation, taught to one team,
with content substituted from your environment and a named academic lead for the year.
Annual programme, quarterly review
Cyber range
A full enterprise, running, breakable
Every practical assessment and every team exercise runs on a
dedicated range instance: a functioning enterprise with real user activity, a domain,
a cloud tenant, an OT segment and an adversary that behaves like the ones we track in
Guardian Labs intelligence.
Instances are provisioned per cohort and destroyed after the debrief — no shared state
Background user simulation generates realistic noise, so detections must be precise
28 scenarios currently in rotation, refreshed quarterly from live IR casework
Full session replay lets an instructor rewind to the exact moment a team went wrong
Bring your own stack. Range instances can be provisioned with your
SIEM, EDR and ticketing tools rather than ours, so the exercise rehearses the exact
workflow your team will use on a real incident.
Workforce awareness
Awareness that changes behaviour, not just completion rates
An annual video and a quiz produce compliance evidence and nothing else.
Guardian awareness programmes run continuously, target the people whose roles carry the
most risk, and are measured against the only metric that matters: whether the workforce
reports faster than it clicks.
Baseline
A no-blame simulation across the whole workforce establishes the starting failure and
reporting rates, broken down by department, seniority and tenure. Results are never
shared as individual league tables.
Target
Micro-learning of five to eight minutes is assigned only to those who need it, with
content matched to the lure that caught them. Finance sees invoice fraud; engineering
sees repository and token phishing.
Sustain
Monthly simulations of rising sophistication, quarterly reporting to the risk
committee, and an annual executive-level exercise covering deepfake voice and
business email compromise.
Programme outcome
Failure rate against report rate
Median across 480 customer programmes over the first twelve months.
The two lines crossing is the moment a workforce becomes a sensor.
Languages
31
Localised content and lures, including right-to-left layouts.
Module length
5–8 min
Short enough to complete between meetings; assigned, not broadcast.
Reporting
One click
Mail add-in reports and quarantines in a single action, feeding the SOC queue.
Evidence
Audit-ready
Completion and outcome records exportable for ISO 27001 and SOC 2 review.
We were hiring analysts faster than we could make them useful.
The practitioner track cut our ramp time from five months to nine weeks, and the range
exercises gave the team something no classroom does — the experience of getting it wrong
somewhere it does not matter.
9 weeksNew-analyst ramp time, down from 5 months
2.4×Increase in tier-one alerts closed without escalation
Do we need to run Guardian Sentinel to take the courses?
No. Courses teach concepts and tradecraft that transfer across tooling, and range
instances can be provisioned with your own SIEM and EDR. Guardian Sentinel is used as
the reference console in self-paced material simply because we can guarantee its
availability; every exercise states the underlying telemetry it depends on so you can
map it to your stack.
How do you handle learners in different time zones?
Virtual cohorts run in three regional bands — Americas, EMEA and APAC — with the same
curriculum and the same instructors rotating. Sessions are recorded and available for
twelve months, and lab environments stay provisioned for the duration of the course so
learners can complete exercises outside session hours.
Can training count towards our compliance obligations?
Yes. Completion records, assessment outcomes and awareness simulation results export
in a format designed for auditor review, and map to ISO 27001 Annex A 6.3, SOC 2 CC1.4,
PCI DSS 12.6 and HIPAA administrative safeguards. Our
compliance advisory team maintains the
mapping and will supply it as part of your evidence pack.
What does a private cohort cost?
Private cohorts are priced per programme rather than per seat, which usually becomes
the cheaper option above fourteen learners. Range instances, content customisation and
certification attempts are included. Annual enablement agreements bundle a fixed number
of cohorts, range days and awareness simulations — see
pricing or
request a quotation.
Is there a free tier for individual learners?
The foundation courses SEC-101 and SEC-118 are free to individuals with a verified
work or academic email address, including lab access and the knowledge check. Guardian
also funds 500 fully sponsored certification places each year for career changers and
candidates from under-represented backgrounds; applications open each January on the
careers page.
How current is the material?
Every course is reviewed quarterly and re-authored at least annually. Range scenarios
are rebuilt from Guardian incident response casework within ninety days of the
underlying campaign being observed, which means learners frequently practise against
tradecraft that is still active in the wild. Change logs are published with each
release on the blog.
Give your team the reps before the real thing
Tell us the roles you are trying to grow and the gaps you keep hitting. We will map a
twelve-month enablement plan with hours, cohorts and measurable outcomes attached.