Skip to main content

Digital forensics and crisis management

Work out afterwards what happened, and hold the organisation together during the crisis.

Block code
CYBER-REP
The format

Three months, two hours a day.

  • Certificate programme · 128 h
  • Two hours a day
  • 250,000 F — the same fee for all sixty
  • All in the same format, at the same fee.
The qualification

A CQP under MINEFOP accreditation.

  • Leads to the CQP — Certificat de Qualification Professionnelle, which the ministry used to call the AQP.
  • Awarded under MINEFOP accreditation.
  • The full programme for the same profession remains open to anyone aiming for the complete qualification.
Sessions

A new session opens every quarter.

Next intake: Monday 5 October, with enrolment open until 2 October. The following one starts on 4 January 2027.

  • First-quarter intake — enrolment closes on 2 October5 Oct.
  • Second-quarter intake — 20274 Jan.
Objectives

What you will be able to do.

  • Collect evidence in the right order, according to its volatility

  • Make a bit-for-bit copy, compute hashes and maintain a chain of custody

  • Know the Cameroonian judicial framework and identify the relevant contacts

  • Analyse a compromised file system, registry and RAM

  • Build an attack timeline by correlating logs

  • Handle the first hours of a ransomware attack: isolate, preserve, alert

  • Run a crisis unit, notify a data breach and close with a lessons-learned review

Programme

Four modules.

  1. Module 0132 h

    Evidence collection and chain of custody

  2. Module 0232 h

    Analysing compromised systems

  3. Module 0332 h

    Ransomware: decision, negotiation, rebuild

  4. Module 0432 h

    Crisis communication and lessons learned

Who it is for

Who it is aimed at.

  • Learners who have already handled incidents — in practice those who have completed Security operations analyst. The block is also aimed at IT managers called upon to run a crisis unit.
Afterwards

Where it leads.

  • Digital forensics analyst, incident response lead, crisis management consultant. This is the block that prepares you for the hours when everyone is looking at the IT person.
Method

How it works.

  • Systematic alternation between short theory sessions and practical work, with most of the time spent on practice

  • Progression from simple to complex: each module builds on what was learnt in the previous one

  • Realistic role-plays drawn from Cameroonian business cases

  • Considered use of generative AI as a working tool, in line with the common core

  • Regular formative assessments and a final integrative project drawing on all four modules

Assessment

How you are assessed.

  • Formative assessment at the end of each module (graded role-play and practical exercises)

  • Practical work assessed against competency sheets

  • Final integrative project, presented and defended before the trainer

  • One graded assignment per module in the online course space

Tools

What you work with.

  • FTK Imager or dd — bit-for-bit copying and hashes

  • Autopsy — file system analysis

  • Volatility — RAM analysis

  • Timesketch or a spreadsheet for building timelines

  • Templates for digital evidence seals, crisis logs and notifications

Join the next session

Ready to get started?

Sessions open every quarter. Apply now or request the detailed brochure — our advisers will get back to you.