Cloud Security Tactical Defence
Cloud defence training in Toronto for people who get paged, not people who write policy. The course runs on a simple premise: an attacker already has a foothold in your cloud tenancy, and your job starts now.
Each week pairs an attacker technique with the detection, containment and hardening response that answers it. You practice on live environments, under time pressure, and finish able to run a cloud incident from first alert to closing report.
- Duration
- 8 weeks
- Format
- Live online, instructor-led
- Prerequisites
- Cloud Security Essentials
- Class size
- Capped at 12 learners

What you will be able to do
- Triage a cloud alert and decide within minutes whether it is a real incident
- Trace an attacker path through CloudTrail and Azure Activity Log evidence
- Contain a compromised access key, role or service account without losing evidence
- Isolate a running workload while preserving memory and disk for analysis
- Detect persistence planted in identity, functions and scheduled jobs
- Reconstruct a timeline of attacker actions across multiple cloud services
- Apply hardening that closes the path used, not just the symptom seen
- Write an incident report that survives review by legal and management
Course outline
6 modules
- How cloud intrusions start: keys, tokens, misconfiguration and supply chain
- MITRE ATT&CK cloud matrix as a working reference
- What attackers do in the first hour inside a tenancy
- Signals that separate noise from a genuine intrusion
- Setting up your own alerting before you need it
What you need before you start
- Completion of Cloud Security Essentials or equivalent working cloud knowledge
- Familiarity with at least one cloud provider console and CLI
- Comfort reading logs and JSON without a graphical tool
- Availability for full live sessions, since exercises run in teams
Who this course is for
- SOC analysts now receiving cloud alerts alongside endpoint alerts
- Incident responders whose scope has expanded into cloud tenancies
- Cloud engineers who are the de facto first responder for their estate
- Detection engineers who want to see their rules tested by a live attacker
- Security leads building a cloud incident response capability from nothing
Where this leads
Prepares you for
CCSP
Awarded by ISC2
The defensive operations content supports the cloud operations and risk domains of the ISC2 CCSP. Certification itself is granted by ISC2 after its own exam and experience checks, never by this academy.
Questions about this course
More in cloud security
Ready to launch your cyber security career?
Join the next live online cohort. No experience required, just bring the curiosity.



