Skip to content

Get Africoders on your phone

Applied Cybersecurity for Builders cover
Intermediate Security Free

Cybersecurity

Identify assets, harms, adversaries, data flows, and trust boundaries

Cybersecurity teaches defensive security for people who design, build, ship, or operate web products, APIs, and services.

LEARN to identify assets and trust boundaries, create threat models, design safer authentication and authorization, manage secrets, prevent injection failures, and participate in vulnerability triage and incident response. BUILD a Secure Feature Design Review and a Defensive Security Readiness Pack. GROW the habit of secure-by-default decisions in everyday delivery work.

This is not a penetration-testing or red-team programme. Exercises use design reviews, pseudocode, and tabletop scenarios — never unauthorised access or exploitation. Completing it earns an Africoders Certificate of Completion. It is not government clearance, industry offensive-security certification, or an employment guarantee.

What you will learn

  • Identify assets, harms, adversaries, data flows, and trust boundaries
  • Create scoped threat models and prioritised security requirements
  • Design safer authentication, recovery, sessions, and account lifecycles
  • Enforce object and function authorization with least privilege
  • Manage secrets, configuration, rotation, and exposure response
  • Prevent injection and common web or API boundary failures
Learn Practice Build Prove

Who this course is for

  • Developers and builders shipping web or API products who need defensible security practice
  • Operators and technical founders responsible for production systems
  • Freelancers offering security-aware delivery or hardening reviews
  • Team members who document risk, controls, and evidence responsibly

Skills you will develop

Threat modelling · Security requirements · Authentication and sessions · Authorization and least privilege · Secrets management · Injection prevention · Web and API security · Data protection and privacy · Dependency and CI security · Incident response basics

Prerequisites

  • Basic understanding of web products, APIs, or service operations
  • Ability to read simple request flows or pseudocode
  • Willingness to document risk, controls, ownership, and evidence
  • No offensive-security or penetration-testing experience required

Who this is for

  • Developers and builders shipping web or API products who need defensible security practice
  • Operators and technical founders responsible for production systems
  • Freelancers offering security-aware delivery or hardening reviews
  • Team members who document risk, controls, and evidence responsibly

Prerequisites

  • Basic understanding of web products, APIs, or service operations
  • Ability to read simple request flows or pseudocode
  • Willingness to document risk, controls, ownership, and evidence
  • No offensive-security or penetration-testing experience required

Skills you’ll develop

Threat modelling Security requirements Authentication and sessions Authorization and least privilege Secrets management Injection prevention Web and API security Data protection and privacy Dependency and CI security Incident response basics

Course completion demonstrates these skills. Verification requires assessment or reviewed challenge work.

What you will build and prove

  • Practice: Practice: Encryption and key boundaries
  • Project: Capstone: Defensive Security Readiness Pack
  • Final assessment: Applied Cybersecurity for Builders assessment (pass 70%)
12 Modules
36 Lessons
19h Study time
Intermediate Level

Course journey

Learn → Practice → Build → Prove. Lessons teach the idea. Practice applies it. The project is what you can submit as evidence.

  1. Security as Product Quality
  2. Practical Threat Modelling
  3. Identity and Authentication
  4. Authorization and Access Control
  5. Secrets and Configuration
  6. Input, Output, and Injection Safety
  7. Web and API Security
  8. Data Protection and Privacy
  9. Dependencies and Delivery Pipelines
  10. Cloud, Infrastructure, and Operations
  11. Vulnerability and Incident Basics
  12. Secure Builder Capstone Studio

Practice

1 optional practice exercise — apply what you learned. Practice is not required to complete the course.

Assessment

  • Applied Cybersecurity for Builders assessment · pass mark 70%

Prove

Course completion means finishing required lessons , required assignments , the course project , and the course assessment . That grants a certificate of completion — not a professional certification. Optional practice does not block completion.

Builder Passport evidence is awarded for the completed project, not for watching lessons or passing a quiz alone.

Curriculum

Week 1: Security as Product Quality

  • Assets, harms, and adversaries Preview 30min
  • Trust boundaries and data flows 30min
  • Secure defaults and least privilege 30min

Week 2: Practical Threat Modelling

  • Scope and assumptions 30min
  • STRIDE-minded questions 30min
  • Risk ranking and treatment 30min

Week 3: Identity and Authentication

  • Identity proofing and account lifecycle 30min
  • Passwords, MFA, and passkeys 30min
  • Sessions and re-authentication 30min

Week 4: Authorization and Access Control

  • Authentication is not authorization 30min
  • Object and function-level checks 30min
  • Roles, attributes, and privilege review 30min

Week 5: Secrets and Configuration

  • Secret types and exposure paths 30min
  • Storage, injection, and rotation 30min
  • Responding to exposed credentials 30min

Week 6: Input, Output, and Injection Safety

  • Validation and canonicalisation 30min
  • Parameterized queries and safe APIs 30min
  • Output encoding and browser boundaries 30min

Week 7: Web and API Security

  • Request forgery, origins, and cookies 32min
  • API boundaries and abuse controls 32min
  • Files, URLs, and server-side requests 32min

Week 8: Data Protection and Privacy

  • Data classification and minimisation 32min
  • Encryption and key boundaries Practice 32min
  • Logs, analytics, and deletion 32min

Week 9: Dependencies and Delivery Pipelines

  • Dependency selection and updates 32min
  • Build integrity and CI permissions 32min
  • Security checks without alert fatigue 32min

Week 10: Cloud, Infrastructure, and Operations

  • Environment and network boundaries 32min
  • Backups and recovery 32min
  • Logging, alerting, and audit trails 32min

Week 11: Vulnerability and Incident Basics

  • Vulnerability intake and remediation 32min
  • Incident roles and first actions 32min
  • Communication and post-incident learning 32min

Week 12: Secure Builder Capstone Studio

  • Architecture and security requirements 32min
  • Verification and release review 32min
  • Incident exercise and improvement plan 32min
Free

Free to enroll — no purchase required.

Instructor: Africoders

Start learning Already have an account? Sign in Course forum →