Category · Free · No card

Free IT security and SOC analyst courses with certificate

Free IT cyber security courses, from beginner fundamentals to CompTIA Security+ (SY0-701) preparation, SOC analyst work with Splunk, and AWS and Azure cloud security, plus courses written for small businesses, finance teams, healthcare and AI applications.

8 courses · 82 modules · 49h 23m of video · Updated 27 September 2026
Cybersecurity Fundamentals for Beginners course cover
FreeCybersecurityBeginner

Cybersecurity Fundamentals for Beginners

Start in cybersecurity from zero: the eight security domains, the CIA triad, risk and the NIST frameworks, networks and firewalls, Linux and access control, malware, incident response, and how to communicate as an analyst, with honest advice on landing a first job. Built on Google's public Cybersecurity Certificate lessons.

  • Explain the eight security domains and where an analyst fits
  • Describe incidents using the CIA triad
  • Score risks and use NIST CSF 2.0 and the NIST RMF
9 modules 5h 57mView course
CompTIA Security+ (SY0-701) Exam Prep course cover
FreeCybersecurityBeginner

CompTIA Security+ (SY0-701) Exam Prep

Prepare for CompTIA Security+ SY0-701 with Professor Messer's complete free video course: every exam objective across the five domains, with EDWartens notes, worked calculations, practice questions and an optional security project. Exam preparation only: the EDWartens certificate is not the CompTIA Security+ certification, which is earned only by passing CompTIA's exam.

  • Classify security controls and explain CIA, AAA and zero trust
  • Explain PKI, encryption, hashing and digital signatures
  • Recognise threat actors, vectors, social engineering and attacks
13 modules 15h 11mView course
SOC Analyst Level 1 with Splunk course cover
FreeCybersecurityBeginner

SOC Analyst Level 1 with Splunk

Train for a Level 1 SOC analyst role: what the job is really like, the incident response process, the Windows event IDs you read every shift, Splunk search and SPL, hunting through Boss of the SOC v1, Wireshark traffic analysis, phishing email analysis, and MITRE ATT&CK with free threat intelligence.

  • Describe the SOC analyst's job, tools, verdicts and metrics
  • Follow the incident response process and contain without losing evidence
  • Read Windows logon, account and process event IDs
9 modules 4h 47mView course
Cloud Security Fundamentals: AWS and Azure course cover
FreeCybersecurityBeginner

Cloud Security Fundamentals: AWS and Azure

Secure what you run in AWS and Azure: the shared responsibility model, AWS IAM and Microsoft Entra ID with Conditional Access, zero trust, network security groups and private endpoints, encryption and key management, and posture management with Defender for Cloud and Sentinel.

  • Explain what cloud security covers and how it differs from on-premises
  • Apply the shared responsibility model to IaaS, PaaS and SaaS
  • Write least-privilege AWS IAM policies and predict how they are evaluated
9 modules 5h 43mView course
Cybersecurity for Small Business course cover
FreeCybersecurityBeginner

Cybersecurity for Small Business

Protect a small business without a security team: the owner's role, phishing and payment fraud, passwords and MFA, devices and Wi-Fi, ransomware and backups, customer data under data-protection law, and what to do in the first hours of an incident. Built on public lessons from the FTC, CISA, the FBI and Professor Messer.

  • Explain why small businesses are attacked and rank the risks to your own
  • Lead security as an owner: responsibilities, budget and policies
  • Recognise phishing, scams and business email compromise, and stop fraudulent payments
9 modules 2h 46mView course
Cyber Fraud and Security for Finance Teams course cover
FreeCybersecurityBeginner

Cyber Fraud and Security for Finance Teams

Stop the frauds aimed at finance teams: business email compromise, vendor bank-change and invoice fraud, fictitious vendors, the Arup deepfake video call, accounts payable controls that work, scam messages, passwords and MFA, data breach response, and audits, third parties and agreements.

  • Explain business email compromise and recognise its forms
  • Verify vendor bank-detail changes independently
  • Detect invoice fraud and fictitious vendors with simple analytics
9 modules 2h 19mView course
Cybersecurity for Healthcare and Medical Devices course cover
FreeCybersecurityBeginner

Cybersecurity for Healthcare and Medical Devices

How hospitals are attacked and how they recover: WannaCry, AIIMS and Ascension, ransomware and double extortion, the HHS 405(d) practices, phishing aimed at clinical staff, connected medical devices and FDA Section 524B, patient data under data-protection law (India's DPDP Act, with HIPAA and GDPR compared), backups that survive ransomware, and incident response when patients are on the wards.

  • Explain why hospitals are targeted, using WannaCry, AIIMS and Ascension
  • Describe modern ransomware and double extortion
  • Apply the five HICP threats and ten practices
9 modules 3h 20mView course
AI Security and the OWASP Top 10 for LLMs course cover
FreeAI and machine learningIntermediate

AI Security and the OWASP Top 10 for LLMs

The security course for people who have already built something with an LLM: the attack surface a model adds, all ten 2026 OWASP LLM risks one at a time, indirect injection and zero-click agent attacks, what leaks out through a chatbot, securing agents with identity and least privilege, the OWASP MCP and agentic guidance, red-teaming with MITRE ATLAS, and the NIST-based governance a plant or a GCC can actually enforce.

  • Draw an AI feature as its parts and mark where an outsider's text can enter
  • Name all ten 2026 OWASP LLM risks and sort a real incident into the right one
  • Trace an indirect injection from a poisoned document to an executed action
15 modules 9h 21mView course

Compare the IT security and SOC courses

CourseLevelModulesVideoBrand
Cybersecurity Fundamentals for BeginnersBeginner95h 57mVendor-neutral
CompTIA Security+ (SY0-701) Exam PrepBeginner1315h 11mCompTIA
SOC Analyst Level 1 with SplunkBeginner94h 47mVendor-neutral
Cloud Security Fundamentals: AWS and AzureBeginner95h 43mVendor-neutral
Cybersecurity for Small BusinessBeginner92h 46mVendor-neutral
Cyber Fraud and Security for Finance TeamsBeginner92h 19mVendor-neutral
Cybersecurity for Healthcare and Medical DevicesBeginner93h 20mVendor-neutral
AI Security and the OWASP Top 10 for LLMsIntermediate159h 21mVendor-neutral

How to choose

Complete beginners should start with Cybersecurity Fundamentals. From there, Security+ Exam Prep follows the SY0-701 objectives, and SOC Analyst with Splunk teaches the detection and triage work most security careers begin in.

Cloud and DevOps engineers should take Cloud Security Fundamentals. The small business, finance and healthcare courses are written for the people in those organisations, not for security specialists.

IT security protects business systems and data. If you work with PLCs, SCADA or building systems, see the OT and ICS security courses instead.

Questions

I am a complete beginner. Where do I start?
Cybersecurity Fundamentals. It assumes no security background.
Does this prepare me for CompTIA Security+?
The Security+ course follows the SY0-701 objectives. The exam itself is booked and taken with CompTIA, which is not affiliated with EDWartens.
What is the difference between IT and OT security?
IT security protects business systems and data. OT security protects industrial control systems, where availability and safety come first.
Is it free, and is there a certificate?
Every lesson, note and assessment is free. The EDWartens certificate is optional and paid, and it is not a CompTIA or vendor certification.