Category · Free · No card

Free cyber security courses with certificate

Defensive cybersecurity for IT and OT, free and complete: security fundamentals, Security+ exam preparation, SOC work with Splunk, cloud security, and ISA/IEC 62443 for plants, PLCs and building systems, with notes, quizzes, projects and an optional verifiable certificate.

13 courses · 139 modules · 116h 52m of video · Updated 27 September 2026
OT Security Assessment: Testing a Plant Without Stopping It course cover
FreeCybersecurityIntermediate

OT Security Assessment: Testing a Plant Without Stopping It

The assessment half of OT security, for engineers who have to do it on a plant that is running. Rules of engagement first, then passive capture, careful enumeration, what an attacker does with a protocol that has no authentication, the Windows machines nobody mentions, the logging that would have caught it, and a report written in the language of consequence.

  • Write rules of engagement with a window, a named owner and an abort condition, for a plant that cannot stop
  • Draw the zones yourself and test each conduit from the side it is meant to protect
  • Capture and read ICS traffic in Wireshark, tshark and Zeek before sending a single packet
12 modules 8h 50mView course
ICS Security Foundations: Control Systems, Defence in Depth and the 62443 Requirements course cover
FreeCybersecurityBeginner

ICS Security Foundations: Control Systems, Defence in Depth and the 62443 Requirements

The ground floor of industrial cyber security, taught through the systems themselves: what a DCS, PLC, SCADA, BACS and safety system actually do, the Purdue model, why OT is not IT, how industrial attacks unfold, defence in depth and a layered architecture, then the seven ISA/IEC 62443 foundational requirements one at a time, asset registers, segmentation, discovery, IDS and IPS, secure remote access, SIEM and endpoint protection.

  • Tell a DCS, PLC, SCADA, BACS and safety system apart
  • Place any device on a Purdue level and defend the choice
  • Explain why an IT security policy cannot be applied to a plant
11 modules 4h 46mView course
OT and ICS Cybersecurity with ISA/IEC 62443 course cover
FreeCybersecurityIntermediate

OT and ICS Cybersecurity with ISA/IEC 62443

Defensive cybersecurity for plants: ICS/OT fundamentals and threats, protocols, the Purdue model, zones and conduits, secure architecture, the ISA/IEC 62443 series, security levels, risk assessment, asset inventory, vulnerability management, incident response, governance, implementation, an introduction to authorised OT testing and certification mock tests.

  • Explain OT versus IT security and the threat landscape
  • Map plants with the Purdue model into zones and conduits
  • Apply ISA/IEC 62443 parts, roles and security levels
16 modules 43h 50mView course
Cybersecurity for PLC Programmers: Hardening Siemens and Rockwell Controllers course cover
FreeCybersecurityIntermediate

Cybersecurity for PLC Programmers: Hardening Siemens and Rockwell Controllers

Harden the PLCs you already program: Siemens access levels, know-how, copy and project protection, secure communication and users, Rockwell source protection, CIP Security and zones, and the Top 20 Secure PLC Coding Practices, from the people who wrote them.

  • Explain how controllers are attacked and which controls break each step
  • Set Siemens access levels and use the TIA Portal security wizard
  • Apply know-how, write, copy and project protection
9 modules 4h 51mView course
CompTIA Security+ (SY0-701) Exam Prep course cover
FreeCybersecurityBeginner

CompTIA Security+ (SY0-701) Exam Prep

Prepare for CompTIA Security+ SY0-701 with Professor Messer's complete free video course: every exam objective across the five domains, with EDWartens notes, worked calculations, practice questions and an optional security project. Exam preparation only: the EDWartens certificate is not the CompTIA Security+ certification, which is earned only by passing CompTIA's exam.

  • Classify security controls and explain CIA, AAA and zero trust
  • Explain PKI, encryption, hashing and digital signatures
  • Recognise threat actors, vectors, social engineering and attacks
13 modules 15h 11mView course
Cybersecurity Fundamentals for Beginners course cover
FreeCybersecurityBeginner

Cybersecurity Fundamentals for Beginners

Start in cybersecurity from zero: the eight security domains, the CIA triad, risk and the NIST frameworks, networks and firewalls, Linux and access control, malware, incident response, and how to communicate as an analyst, with honest advice on landing a first job. Built on Google's public Cybersecurity Certificate lessons.

  • Explain the eight security domains and where an analyst fits
  • Describe incidents using the CIA triad
  • Score risks and use NIST CSF 2.0 and the NIST RMF
9 modules 5h 57mView course
SOC Analyst Level 1 with Splunk course cover
FreeCybersecurityBeginner

SOC Analyst Level 1 with Splunk

Train for a Level 1 SOC analyst role: what the job is really like, the incident response process, the Windows event IDs you read every shift, Splunk search and SPL, hunting through Boss of the SOC v1, Wireshark traffic analysis, phishing email analysis, and MITRE ATT&CK with free threat intelligence.

  • Describe the SOC analyst's job, tools, verdicts and metrics
  • Follow the incident response process and contain without losing evidence
  • Read Windows logon, account and process event IDs
9 modules 4h 47mView course
Cloud Security Fundamentals: AWS and Azure course cover
FreeCybersecurityBeginner

Cloud Security Fundamentals: AWS and Azure

Secure what you run in AWS and Azure: the shared responsibility model, AWS IAM and Microsoft Entra ID with Conditional Access, zero trust, network security groups and private endpoints, encryption and key management, and posture management with Defender for Cloud and Sentinel.

  • Explain what cloud security covers and how it differs from on-premises
  • Apply the shared responsibility model to IaaS, PaaS and SaaS
  • Write least-privilege AWS IAM policies and predict how they are evaluated
9 modules 5h 43mView course
Cybersecurity for Building Automation: BMS and BACnet course cover
FreeCybersecurityIntermediate

Cybersecurity for Building Automation: BMS and BACnet

Secure the building management systems you design, install or run: real building hacks, BMS network architecture and its weak points, hardening controllers and front ends, secure design with zones and conduits, BACnet Secure Connect, defence in depth for BACnet/IP, secure vendor remote access and zero trust.

  • Explain how buildings have been hacked and why a BMS can be a way into the business
  • Describe BMS architecture and find the weak points in BACnet, Modbus and MS/TP networks
  • Harden controllers, servers and accounts in the building's priorities
9 modules 5h 12mView course
Cybersecurity for Healthcare and Medical Devices course cover
FreeCybersecurityBeginner

Cybersecurity for Healthcare and Medical Devices

How hospitals are attacked and how they recover: WannaCry, AIIMS and Ascension, ransomware and double extortion, the HHS 405(d) practices, phishing aimed at clinical staff, connected medical devices and FDA Section 524B, patient data under data-protection law (India's DPDP Act, with HIPAA and GDPR compared), backups that survive ransomware, and incident response when patients are on the wards.

  • Explain why hospitals are targeted, using WannaCry, AIIMS and Ascension
  • Describe modern ransomware and double extortion
  • Apply the five HICP threats and ten practices
9 modules 3h 20mView course
Cyber Fraud and Security for Finance Teams course cover
FreeCybersecurityBeginner

Cyber Fraud and Security for Finance Teams

Stop the frauds aimed at finance teams: business email compromise, vendor bank-change and invoice fraud, fictitious vendors, the Arup deepfake video call, accounts payable controls that work, scam messages, passwords and MFA, data breach response, and audits, third parties and agreements.

  • Explain business email compromise and recognise its forms
  • Verify vendor bank-detail changes independently
  • Detect invoice fraud and fictitious vendors with simple analytics
9 modules 2h 19mView course
Cybersecurity for Small Business course cover
FreeCybersecurityBeginner

Cybersecurity for Small Business

Protect a small business without a security team: the owner's role, phishing and payment fraud, passwords and MFA, devices and Wi-Fi, ransomware and backups, customer data under data-protection law, and what to do in the first hours of an incident. Built on public lessons from the FTC, CISA, the FBI and Professor Messer.

  • Explain why small businesses are attacked and rank the risks to your own
  • Lead security as an owner: responsibilities, budget and policies
  • Recognise phishing, scams and business email compromise, and stop fraudulent payments
9 modules 2h 46mView course
AI Security and the OWASP Top 10 for LLMs course cover
FreeAI and machine learningIntermediate

AI Security and the OWASP Top 10 for LLMs

The security course for people who have already built something with an LLM: the attack surface a model adds, all ten 2026 OWASP LLM risks one at a time, indirect injection and zero-click agent attacks, what leaks out through a chatbot, securing agents with identity and least privilege, the OWASP MCP and agentic guidance, red-teaming with MITRE ATLAS, and the NIST-based governance a plant or a GCC can actually enforce.

  • Draw an AI feature as its parts and mark where an outsider's text can enter
  • Name all ten 2026 OWASP LLM risks and sort a real incident into the right one
  • Trace an indirect injection from a poisoned document to an executed action
15 modules 9h 21mView course

Compare the Cybersecurity courses

CourseLevelModulesVideoBrand
OT Security Assessment: Testing a Plant Without Stopping ItIntermediate128h 50mVendor-neutral
ICS Security Foundations: Control Systems, Defence in Depth and the 62443 RequirementsBeginner114h 46mVendor-neutral
OT and ICS Cybersecurity with ISA/IEC 62443Intermediate1643h 50mVendor-neutral
Cybersecurity for PLC Programmers: Hardening Siemens and Rockwell ControllersIntermediate94h 51mVendor-neutral
CompTIA Security+ (SY0-701) Exam PrepBeginner1315h 11mCompTIA
Cybersecurity Fundamentals for BeginnersBeginner95h 57mVendor-neutral
SOC Analyst Level 1 with SplunkBeginner94h 47mVendor-neutral
Cloud Security Fundamentals: AWS and AzureBeginner95h 43mVendor-neutral
Cybersecurity for Building Automation: BMS and BACnetIntermediate95h 12mVendor-neutral
Cybersecurity for Healthcare and Medical DevicesBeginner93h 20mVendor-neutral
Cyber Fraud and Security for Finance TeamsBeginner92h 19mVendor-neutral
Cybersecurity for Small BusinessBeginner92h 46mVendor-neutral
AI Security and the OWASP Top 10 for LLMsIntermediate159h 21mVendor-neutral

Questions

Is this offensive security?
No. It is defence: architecture, standards, detection, risk and response.
Where should I start?
Cybersecurity Fundamentals if you are new to the field. Engineers who work with PLCs, SCADA or building systems can go straight to the OT courses, which are written for them.
Is OT cybersecurity a job for network engineers or automation engineers?
Both, and the shortage is on the automation side: people who know what a PLC does and can read IEC 62443.