Guardian Academy

Build the team that runs the platform

Tooling only performs as well as the people operating it. Guardian Academy delivers role-based curricula, hands-on cyber range exercises and recognised certification tracks for security analysts, engineers and leaders — plus workforce awareness programmes that measurably reduce the human attack surface.

42,000+ Practitioners trained since the academy launched in 2018
96% Of certified analysts pass at first attempt after the full track
-71% Median reduction in phishing simulation failure rate at 12 months
31 min Average improvement in mean time to triage after the analyst track

Metrics aggregated across 480 enterprise customer programmes, measured against each customer's own pre-training baseline.

Role-based curricula

Six paths, each built around a job someone actually does

Generic security awareness does not make a tier-one analyst faster. Every Guardian curriculum starts from the daily tasks of a specific role, then works backwards to the knowledge, tooling fluency and muscle memory those tasks require.

SOC analyst

Alert triage discipline, evidence collection, escalation thresholds and shift handover. Learners work a simulated queue of 200 alerts drawn from real detections, and are scored on accuracy, not speed alone.

5 courses · 38 hours · Foundation to practitioner

See the analyst path

Incident responder

Scoping a compromise, forensic acquisition on live systems, containment sequencing, memory and log analysis, and writing the incident record that a regulator will read. Culminates in a 12-hour simulated ransomware event.

6 courses · 52 hours · Practitioner to specialist

Related IR service

Threat hunter

Hypothesis-driven hunting, ATT&CK-based coverage assessment, statistical baselining and query craft. Learners build and defend three original hunts against a live range containing planted adversary activity.

4 courses · 34 hours · Specialist

Threat intelligence

Detection engineer

Detection-as-code practice: rule design, test harnesses, false-positive budgeting, version control and deployment pipelines. Includes writing and validating 20 production rules against emulated technique execution.

5 courses · 40 hours · Practitioner to specialist

Automation & response

Cloud security engineer

Identity-first cloud defence across AWS, Azure and Google Cloud: role design, policy evaluation logic, workload identity, container runtime controls and infrastructure-as-code guardrails that fail the build rather than the audit.

5 courses · 44 hours · Practitioner to specialist

Cloud security

Security leadership

For directors and CISOs: programme design, risk quantification, board communication, regulatory duty under NIS2 and DORA, and running the first ninety minutes of a major incident when everyone is looking at you.

4 courses · 22 hours · Executive

Security consulting

Progression model

From first shift to specialist, on a published ladder

Each level has explicit entry criteria, an assessment and a competency statement your HR system can consume. Managers can see exactly where each team member sits and what the next step costs in hours.

Foundation 2 courses · 14 h Knowledge check Practitioner 4 courses · 32 h Lab assessment Specialist 5 courses · 46 h Range exam, 8 h Expert Capstone · 60 h Peer-reviewed project Threat hunter Detection engineer IR lead Cloud security eng. Role branches open at specialist level COMPETENCY LADDER Cumulative hours to expert: 152 · Typical elapsed time: 9–14 months alongside a full-time role

Certification

Three certifications, all assessed on a live range

Guardian certifications are practical. There are no multiple-choice papers: candidates are given an environment, an objective and a time limit, and are marked on what they achieve and how well they document it.

GCSA

Certified Security Analyst

For analysts working a detection queue who need to prove triage accuracy, evidence discipline and escalation judgement.

4 h practical exam
  • 60 alerts triaged against a graded rubric
  • Two escalation write-ups assessed by a Guardian analyst
  • Prerequisite: foundation level or 6 months on a SOC floor
  • Valid 3 years · 40 CPE credits
Register a cohort

GCDE

Certified Detection Engineer

For engineers who own detection content. Assessed on rules that must survive both an emulated attack and a false-positive budget.

8 h practical exam
  • Author 10 detections against undisclosed techniques
  • Rules scored on true-positive rate and noise per 10,000 events
  • Submit a test harness alongside every rule
  • Prerequisite: practitioner level, working query fluency
  • Valid 3 years · 60 CPE credits
Register a cohort

Recognised for continuing education. Guardian certifications and courses carry CPE credits accepted by (ISC)², ISACA and CompTIA renewal programmes. Credit statements are issued automatically to each learner and to the programme administrator.

Catalogue

Current course catalogue

Every course is available in each delivery format. Hours shown are contact hours excluding self-paced lab time, which typically adds 30–50%.

Guardian Academy catalogue, 2026 release. New courses are published quarterly.
Code Course Track Level Hours CPE
SEC-101 Security operations fundamentals: telemetry, tooling and the alert lifecycle SOC analyst Foundation 8 8
SEC-118 Alert triage at scale: prioritisation, enrichment and defensible escalation SOC analyst Foundation 6 6
SEC-204 Windows internals for defenders: processes, tokens and event log semantics SOC analyst Practitioner 10 10
SEC-212 Linux and container telemetry: eBPF, audit and runtime signals Cloud security Practitioner 10 10
IR-220 Live response and forensic acquisition without destroying evidence Incident response Practitioner 12 12
IR-236 Containment strategy: when to isolate, when to watch, when to rebuild Incident response Practitioner 8 8
IR-310 Ransomware response: negotiation posture, recovery sequencing and regulatory clocks Incident response Specialist 14 14
DE-240 Detection engineering foundations: rule design and the false-positive budget Detection engineering Practitioner 10 10
DE-322 Detection as code: version control, test harnesses and safe deployment Detection engineering Specialist 12 12
TH-330 Hypothesis-driven threat hunting against ATT&CK coverage gaps Threat hunting Specialist 12 12
TH-344 Statistical baselining and anomaly interpretation for hunt teams Threat hunting Specialist 10 10
CLD-250 Identity-first cloud defence across AWS, Azure and Google Cloud Cloud security Practitioner 12 12
CLD-318 Kubernetes attack paths and runtime containment Cloud security Specialist 12 12
ID-260 Active Directory and Entra ID attack paths for defenders Identity Practitioner 10 10
LEAD-140 Running the first ninety minutes: executive decision-making in a major incident Leadership Executive 6 6
LEAD-186 Regulatory duty under NIS2, DORA and sector reporting regimes Leadership Executive 6 6

Scroll the table horizontally to see every column.

Private cohorts can substitute up to 30% of course content for material drawn from your own environment, including your detection stack and runbooks. See datasheets for the full syllabus of each course.

Delivery

Five ways to run it

Format changes the logistics, never the assessment. A learner who completes the self-paced route sits exactly the same practical exam as one who attended in person.

Virtual instructor-led

Live cohorts of up to 16, four hours per day over the course length, in your time zone. Recorded for 12 months. The default choice for distributed teams.

Cohorts start every second Monday

On-site

An instructor in your building, using your tooling and your incident history as case material. Minimum eight learners; available in 41 countries.

Six weeks' notice typical

Self-paced

Full video, lab and assessment access for 12 months, with graded checkpoints and instructor office hours twice weekly. Progress reporting for managers.

Immediate enrolment

Cyber range exercise

Team-versus-adversary exercises on a dedicated range instance. Run as a one-day sprint or a recurring quarterly drill against fresh scenarios.

Up to 40 participants per instance

Private cohort

A curriculum assembled for one organisation, taught to one team, with content substituted from your environment and a named academic lead for the year.

Annual programme, quarterly review

Adversary infrastructure C2, phishing relay, staging host Internet edge VPN concentrator, reverse proxy, mail gateway DMZ Public web tier, jump host, file transfer Corporate LAN 2 domain controllers 40 workstations File and print cluster Certificate services Cloud tenant 3 accounts, 2 regions Kubernetes cluster Object storage CI/CD pipeline OT segment Historian, HMI Simulated PLCs Modbus / DNP3 Level 2 and 3 only Monitoring plane — learners work here Guardian Sentinel console · full endpoint, network, identity and cloud telemetry Every operator action is replayable frame by frame during the debrief

Cyber range

A full enterprise, running, breakable

Every practical assessment and every team exercise runs on a dedicated range instance: a functioning enterprise with real user activity, a domain, a cloud tenant, an OT segment and an adversary that behaves like the ones we track in Guardian Labs intelligence.

  • Instances are provisioned per cohort and destroyed after the debrief — no shared state
  • Background user simulation generates realistic noise, so detections must be precise
  • 28 scenarios currently in rotation, refreshed quarterly from live IR casework
  • Full session replay lets an instructor rewind to the exact moment a team went wrong

Bring your own stack. Range instances can be provisioned with your SIEM, EDR and ticketing tools rather than ours, so the exercise rehearses the exact workflow your team will use on a real incident.

Workforce awareness

Awareness that changes behaviour, not just completion rates

An annual video and a quiz produce compliance evidence and nothing else. Guardian awareness programmes run continuously, target the people whose roles carry the most risk, and are measured against the only metric that matters: whether the workforce reports faster than it clicks.

Baseline

A no-blame simulation across the whole workforce establishes the starting failure and reporting rates, broken down by department, seniority and tenure. Results are never shared as individual league tables.

Target

Micro-learning of five to eight minutes is assigned only to those who need it, with content matched to the lure that caught them. Finance sees invoice fraud; engineering sees repository and token phishing.

Sustain

Monthly simulations of rising sophistication, quarterly reporting to the risk committee, and an annual executive-level exercise covering deepfake voice and business email compromise.

Programme outcome

Failure rate against report rate

Median across 480 customer programmes over the first twelve months. The two lines crossing is the moment a workforce becomes a sensor.

0% 20% 40% 60% 80% M1 M4 M7 M10 M12 27% clicked 8% 11% reported 64% crossover, month 4 Median of 480 programmes · simulation difficulty held constant after month 3

Languages

31

Localised content and lures, including right-to-left layouts.

Module length

5–8 min

Short enough to complete between meetings; assigned, not broadcast.

Reporting

One click

Mail add-in reports and quarantines in a single action, feeding the SOC queue.

Evidence

Audit-ready

Completion and outcome records exportable for ISO 27001 and SOC 2 review.

We were hiring analysts faster than we could make them useful. The practitioner track cut our ramp time from five months to nine weeks, and the range exercises gave the team something no classroom does — the experience of getting it wrong somewhere it does not matter.

Daniel Okonjo

Head of Security Operations, Meridian Health Group

9 weeks New-analyst ramp time, down from 5 months
2.4× Increase in tier-one alerts closed without escalation

More outcomes in case studies, or read how training pairs with managed detection and response during a SOC build-out.

Programme questions

Running Guardian Academy in your organisation

Do we need to run Guardian Sentinel to take the courses?

No. Courses teach concepts and tradecraft that transfer across tooling, and range instances can be provisioned with your own SIEM and EDR. Guardian Sentinel is used as the reference console in self-paced material simply because we can guarantee its availability; every exercise states the underlying telemetry it depends on so you can map it to your stack.

How do you handle learners in different time zones?

Virtual cohorts run in three regional bands — Americas, EMEA and APAC — with the same curriculum and the same instructors rotating. Sessions are recorded and available for twelve months, and lab environments stay provisioned for the duration of the course so learners can complete exercises outside session hours.

Can training count towards our compliance obligations?

Yes. Completion records, assessment outcomes and awareness simulation results export in a format designed for auditor review, and map to ISO 27001 Annex A 6.3, SOC 2 CC1.4, PCI DSS 12.6 and HIPAA administrative safeguards. Our compliance advisory team maintains the mapping and will supply it as part of your evidence pack.

What does a private cohort cost?

Private cohorts are priced per programme rather than per seat, which usually becomes the cheaper option above fourteen learners. Range instances, content customisation and certification attempts are included. Annual enablement agreements bundle a fixed number of cohorts, range days and awareness simulations — see pricing or request a quotation.

Is there a free tier for individual learners?

The foundation courses SEC-101 and SEC-118 are free to individuals with a verified work or academic email address, including lab access and the knowledge check. Guardian also funds 500 fully sponsored certification places each year for career changers and candidates from under-represented backgrounds; applications open each January on the careers page.

How current is the material?

Every course is reviewed quarterly and re-authored at least annually. Range scenarios are rebuilt from Guardian incident response casework within ninety days of the underlying campaign being observed, which means learners frequently practise against tradecraft that is still active in the wild. Change logs are published with each release on the blog.

Give your team the reps before the real thing

Tell us the roles you are trying to grow and the gaps you keep hitting. We will map a twelve-month enablement plan with hours, cohorts and measurable outcomes attached.