Defensible Security Architecture and Zero Trust
Zero trust architecture training in Toronto for people who sign off designs. Across ten weeks you architect and engineer defensible hybrid systems, applying zero trust at the identity, network, endpoint, application and data layers rather than at one of them.
Zero trust is treated as an engineering programme, not a product category. Every design decision you make in class has to survive a hostile review and an existing estate you cannot rebuild.
- Duration
- 10 weeks
- Format
- Live online, instructor-led
- Prerequisites
- Security Engineering: Threat Detection and Monitoring
- Class size
- Capped at 12 learners

What you will be able to do
- Produce a zero trust roadmap sequenced by risk rather than by vendor order
- Design identity controls that hold when the network perimeter is gone
- Segment a hybrid estate without breaking the applications running on it
- Specify device trust signals and enforce them at access time
- Apply data classification to actual access decisions, not just to a policy document
- Review an architecture and produce findings a delivery team can act on
- Explain to an executive what a zero trust programme will and will not fix
- Sequence migration work so each phase leaves the estate more defensible
Course outline
6 modules
- Threat modelling an estate rather than an application
- Trust boundaries, chokepoints and enforcement
- Reading and writing architecture decision records
- Constraints: legacy, budget, politics and time
- Assessing an existing design honestly
What you need before you start
- Security Engineering: Threat Detection and Monitoring, or equivalent design experience
- Working knowledge of enterprise identity and networking
- Experience with at least one cloud platform in production
- Comfort defending a design decision in front of peers
Who this course is for
- Security architects and senior security engineers
- Infrastructure architects taking on security ownership
- Technical leads running a zero trust or segmentation programme
- Consultants delivering architecture reviews
- Experienced defenders preparing for the CISSP architecture domains
Where this leads
Prepares you for
CISSP
Awarded by ISC2
This course supports the architecture and engineering domains of the ISC2 CISSP, though CISSP is broader and carries an experience requirement. ISC2 examines and certifies candidates; we teach. Use this alongside dedicated CISSP preparation rather than in place of it.
Questions about this course
More in cyber defence
Ready to launch your cyber security career?
Join the next live online cohort. No experience required, just bring the curiosity.



