Work out afterwards what happened, and hold the organisation together during the crisis.
Next intake: Monday 5 October, with enrolment open until 2 October. The following one starts on 4 January 2027.
Collect evidence in the right order, according to its volatility
Make a bit-for-bit copy, compute hashes and maintain a chain of custody
Know the Cameroonian judicial framework and identify the relevant contacts
Analyse a compromised file system, registry and RAM
Build an attack timeline by correlating logs
Handle the first hours of a ransomware attack: isolate, preserve, alert
Run a crisis unit, notify a data breach and close with a lessons-learned review
Systematic alternation between short theory sessions and practical work, with most of the time spent on practice
Progression from simple to complex: each module builds on what was learnt in the previous one
Realistic role-plays drawn from Cameroonian business cases
Considered use of generative AI as a working tool, in line with the common core
Regular formative assessments and a final integrative project drawing on all four modules
Formative assessment at the end of each module (graded role-play and practical exercises)
Practical work assessed against competency sheets
Final integrative project, presented and defended before the trainer
One graded assignment per module in the online course space
FTK Imager or dd — bit-for-bit copying and hashes
Autopsy — file system analysis
Volatility — RAM analysis
Timesketch or a spreadsheet for building timelines
Templates for digital evidence seals, crisis logs and notifications
Sessions open every quarter. Apply now or request the detailed brochure — our advisers will get back to you.