Request a Consultation
Specialized Industry Training — Sector-Specific Training

Cybersecurity Training for the Defence & Security Sector

Role-based training built for the people who protect national security — uniformed personnel, contractors, intelligence officials, law enforcement, and the cyber defenders behind them all.

29%
Of public-sector breaches are espionage-motivated — far above the cross-industry average (Verizon DBIR, 2025)
Nov 2026
Third-party CMMC 2.0 certification becomes mandatory for DoD contractors handling controlled information
67%
Of public-sector breaches are driven by external actors — nation-states and organized threat groups
1
Foundation Module — completed by every participant before entering their role-specific track

General Cybersecurity & Risk Awareness for Defence & Security

Few sectors carry the same weight of consequence. Defence and security organizations run on a web of uniformed personnel, contractors, agencies, and cyber defenders, all handling information that adversaries specifically want — operational plans, controlled technical data, and intelligence. That combination of high-value targets and a broad, multi-party ecosystem makes the sector a persistent focus for nation-state actors. This module gives every participant the shared vocabulary, threat picture, and regulatory context that the role-specific modules build on.

29%
Of public-sector breaches are espionage-motivated, well above the cross-industry average (Verizon DBIR, 2025)
67%
Of public-sector breaches are driven by external actors, including nation-states and organized groups
30%
Of public-sector breaches involve ransomware, disrupting operations as well as data

Core Risk Areas Covered

Nation-State Espionage & APTs

How advanced persistent threat groups target defence and security organizations, and what that looks like from the inside.

Spear-Phishing & Social Engineering

Including "MFA fatigue" and prompt-bombing attacks, which succeeded in over 1 in 5 social engineering incidents last year.

Supply Chain & Defence Industrial Base Risk

How subcontractors and vendors become the entry point into otherwise well-defended programs.

Insider Threat

Recognizing behavioral and technical indicators, and knowing how and when to report them.

Credential Compromise

Why stolen credentials remain the leading way attackers gain access — and what stops them.

Ransomware & Operational Disruption

Protecting mission continuity when systems, not just data, are the target.

The Regulatory Landscape, Explained Plainly

CMMC 2.0

Third-party certification against NIST SP 800-171 becomes mandatory for DoD contractors handling controlled unclassified information starting November 2026.

CJIS Security Policy

Multi-factor authentication using two of three factor types has been mandatory for law enforcement systems access since October 2024.

OMB M-22-09

The federal zero trust strategy required agencies to implement phishing-resistant authentication and related controls by the end of FY2024.

Regulatory emphasis is tailored to your country and jurisdiction — tell us where you operate in the form below and we'll scope the frameworks that matter most to you.

Role-Specific Tracks

Built Around Who Actually Touches the Risk

After the shared foundation, participants split into focused tracks. A field officer and a SOC analyst face very different decisions — so the training does too.

2

Military Officers & Defence Contractors

Military Officers · Contractors · Program Staff

Operational security (OPSEC) for communications, travel, and daily routine
Safeguarding Controlled Unclassified Information (CUI) in everyday work
Recognizing spear-phishing crafted to look like official orders or requests
Secure use of government and contractor systems, including remote access
Protecting field, deployed, and mobile communications
Supply chain risk across the defence industrial base
3

Cybersecurity Professionals

SOC Analysts · Incident Responders · Security Engineers

Threat intelligence fundamentals for tracking nation-state adversaries
Incident response and escalation under CMMC and CJIS obligations
Detecting credential-based intrusion and MFA-fatigue attacks
Red team / blue team collaboration basics
Securing environments that handle CUI and classified-adjacent data
Vulnerability management and continuous monitoring

"Why split the training this way? An officer in the field needs to recognize a spoofed order before acting on it; a SOC analyst needs to reason about detection logic and escalation paths. Teaching both groups the same generic content wastes time and leaves the sector's real gaps unaddressed — so each track is built from the systems and decisions that group actually owns."

Military & Contractor Scenarios

An "urgent" order arrives by email outside normal channels
A subcontractor requests access beyond its scope of work
A personal device connects to a program network by mistake

Cybersecurity Professional Scenarios

A user approves an MFA prompt they didn't request
Tabletop exercise: suspected APT lateral movement
Triaging an alert against CJIS reporting timelines

Format for These Tracks

On-site / on-base Cleared-facility delivery available Virtual instructor-led Self-paced e-learning
4
With extensive coverage of sensitive information handling — the discipline this role depends on most

Intelligence Officials & Law Enforcement Agencies

Intelligence Officials · Law Enforcement Officers · Investigators

Intelligence and law enforcement work runs on information that must move — between analysts, across agencies, into evidence files — without ever moving to the wrong person. A lapse here isn't just a cybersecurity incident, it's an operational and legal one. This track goes deeper on sensitive-information handling than any other module in the program.

Sensitive Information Handling — Covered in Depth

Classification levels and handling requirements for sensitive and classified material
Need-to-know and least-privilege access principles in practice
Chain of custody for evidence and case data
CJIS-compliant authentication and access control
Safeguards for cross-agency and interagency information sharing
Insider threat indicators and reporting channels
Secure use of investigative and surveillance systems
Incident and breach reporting obligations under agency and CJIS policy
Delivery Format
  • Instructor-led workshops
  • Self-paced e-learning modules
  • Scenario & tabletop exercises
  • Role-specific refreshers

All four modules can be delivered together as a full program, or the role-specific tracks can be licensed independently for organizations that only need one audience covered.

Why It Matters at This Scale

The stakes behind the training

One Record, Many Agencies

A single case file can move through multiple agencies and systems — every handoff is a governance decision.

Compliance Is Not Optional

Mishandled sensitive information carries legal and operational exposure alongside the security risk — this module treats them as one problem.

People, Not Just Systems

Most handling failures are procedural, not technical — the wrong person seeing the wrong record. Training targets exactly that.

Register Interest

Bring this training to your unit, agency, or program

Schedule a consultation to scope the right modules for your teams. Tell us your country and we'll tailor the regulatory focus and delivery format to your region.

Modular by design

Run the full four-module program, or license just the tracks your organisation needs — military/contractor, cybersecurity, intelligence/LEA, or all three built on the shared foundation module.

We reply within one business day. Prefer email? Write to info@thecyberdiplomat.com.

Looking for a different sector?

Explore our full range of accredited training categories.

View All Training