← All 186 courses
SEC-402 Security

Incident Response & Recovery Engineering

Run incidents like our flagship's breached-estate capstone: a disciplined contain→scope→rotate→eradicate sequence, forensic-minded evidence preservation, stakeholder communication under pressure, and recovery to a hardened state — executed live against a seeded compromised environment with the clock running.

B5Advanced
6modules
42skill atoms
4role journeys
Curriculum

What this course covers.

6 modules, 42 named skill atoms. Expand any module to see them.

1IR Operating Model7 skill atoms
rolesseverity laddercomms cadenceincident commander, scribe & SME separationdeclaration criteria and downgrade ruleslegal, comms & exec engagement triggersexternal forensics retainer activation
2Containment First7 skill atoms
isolatepreserve evidencestop the bleedingnetwork isolation vs power-off trade-offorder of volatility in evidence capturesession & token revocationbusiness impact of containment choices
3Scoping & Investigation7 skill atoms
timeline buildinglateral-movement tracinginitial access hypothesis testingcross-cloud identity log correlationpersistence huntingdata staging & exfiltration indicatorsstating scope confidence honestly
4Rotate & Eradicate7 skill atoms
credential rotation at scalepersistence removalrotation ordering to avoid outagesfederation & signing key rotationrogue account and forwarding rule removalrebuild vs clean decisionverifying access is actually gone
5Recover Hardened7 skill atoms
rebuild decisionsvalidation gatesstaged restoration under elevated monitoringbackup integrity verificationclosing control gaps before reconnectionincident exit criteriapost-incident review inputs
6Live Breach Exercise7 skill atoms
seeded estatetimed responsereport-outdecision-making under incomplete informationexecutive briefing under time pressuredecision log qualityremediation backlog from findings
Where it fits

SEC-402 in the role journeys.

This course appears in 4 of our 45 role journeys. Here is what a learner takes immediately before and after it in each.

Site Reliability Engineer

Capstone stage
CL-323SEC-402journey complete

Security Engineer

Professional stage
SEC-210SEC-402SEC-403

SOC Analyst

Capstone stage
SEC-407SEC-402journey complete

OT / ICS Security Engineer

Capstone stage
SEC-407SEC-402journey complete

Roles this course serves

The capability ladder

This course is authored to band B5.

Every course we run is written to one rung of the CASI ladder, so a plan can be assembled to take a team from where they are to where they need to be.

What do B1–B6 mean?The CASI Capability Ladder — click to expand

Every course targets a band on the CASI Capability Ladder — our six-band proficiency scale, anchored to open standards (O*NET, ESCO, NICE, NIST AI RMF, Bloom's). A band tells you how deep a course goes, and what evidence proves it.

What the learner can doTypical evidence
B1
AwareUnderstands concepts and vocabulary; uses tools with guidance
Knowledge checks
B2
FoundationPerforms standard tasks correctly in familiar contexts
Guided labs, autograded exercises
B3
PractitionerDelivers complete pieces of work independently
Scenario labs, proctored hands-on exams
B4
ProfessionalHandles production-grade complexity, trade-offs and failure modes
Break-fix drills, design defenses
B5
AdvancedEngineers systems end-to-end under constraints; leads others
Rubric-scored capstones, vivas
B6
ExpertSets direction; recognised authority across teams
Portfolio + panel evaluation

A note on B6. Courses in this catalog target B1–B5. B6 is not taught — it is recognised, through a portfolio and a panel, once someone is setting direction for others. Every journey here is built to land a learner at B5.

Next step

Run SEC-402 for your team.

This course runs at several lengths depending on how deep you need to go and how much of it your people already have. Tell us who is being trained and we will scope it.

Add it to a training plan Talk to our team Check your team’s level free