Key information
- Application opening date: July 27, 2026
- Next application deadline: September 25, 2026
- Next course starts: October 1, 2026
- Format: Fully online, asynchronous and synchronous
- Course duration: 12 weeks
- Language: English
- Awarding Institution: German University of Digital Science
- Delivered by: German University of Digital Science
- Certified by: ASIIN
- EQF Level: 7
- ECTS: 5 ECTS (~125 hours of study workload, including course activities and self-directed learning)
- Fees: €350
Microcredential Information
The module delves into AI and its impact on cybersecurity, highlighting its offensive and defensive applications. Using both lectures and flipped classroom sessions, students will learn key AI concepts and their applications in today’s Security Operations Centers (SOCs). Finally, they will apply their learning in a group project, developing AI-powered cyber defense or attack scenarios.
Key Details
Time commitment
- Total workload: 125 h
- Contact hours: 24 h
- Lecture: 12 h
- Hands-on/Tutorials: 6 h
- Seminar/discussion & guest-lecture: 2 h
- Flipped classroom: 4 h
- Group Project: 40
- Private study: 61 h
Assessment
- Mid-term assessment (proctored quiz) end of W5 (15%)
- Flipped classroom in W6 & W11 (10%)
- Group project from W6 to W12 (30%)
- Intermediate presentation (a pitch) in W8 (5%)
- Final presentation in W12 (12.5%)
- Technical report / scientific paper by W12 (12.5%)
- Final proctored exam (45%)
Subjects covered
Week 1: Security Operations & Cybersecurity Foundations
Summary:
Recap the essentials of cybersecurity, focusing on SOC operations and using the NIST Cybersecurity Framework as a reference. Bring students up to speed on fundamental concepts and ensure consistent prerequisite knowledge.
Lecture Content:
- NIST Cybersecurity Framework (Identify, Protect, Detect, Respond, Recover, Govern)
- Key SOC operations: vulnerability management, threat detection, incident response, red teaming, …
- SOC tools/technologies: SIEM, SOAR, IDS/IPS, EDR/NDR/XDR, TIP, …
- Standards and frameworks: NIST CSF, MITRE ATT&CK, CIS
- Data in SOC: Types, Values, and Significance
- Key SOC challenges: alert fatigue, evolving threats, APTs, …
Week 2: Data Science/Engineering Foundations
Summary:
Recap foundational concepts in data science and engineering with a focus on AI/ML.
Lecture Content:
- Data science/analytics concepts: statistical analysis. unsupervised and supervised ML, anomaly detection, neural networks, deep learning, reinforcement learning, CNN, RNNs, LSTM, …
- Data engineering concepts: data cleaning, normalization, enrichment, ETL, distributed data processing and big data architectures., …
Week 3: Rise of AI – Generative Models & LLMs
Summary:
Introduction to modern AI with a focus on generative models and LLMs. Bridge the gap between traditional data analytics and advanced AI concepts.
Lecture Content:
- Modern AI: Generative models and transformers.
- LLMs and their architecture.
- Applications of AI in Cybersecurity
Week 4: AI-powered Cyber Attack (Part 1)
Summary:
Explore how AI can be leveraged to automate and enhance cyber-attacks, guided by the MITRE ATT&CK framework.
Lecture Content:
- Introduction to cyber threat landscape: attackers TTPS
- AI-powered social engineering and phishing attacks (initial access).
- AI-generated malware (execution)
Week 5: AI-powered Cyber Defense (Part 1)
Summary:
Explore how AI strengthens cyber defense and improves SOC operations, guided by NIST Cybersecurity framework.
Lecture Content:
- AI for advanced threat detection and hunting.
- AI to enhance monitoring and reduce alert fatigue
- AI for automated incident response
Week 6: AI-powered Cyber Attack/Defense (Part 2) – Flipped Classroom
Summary:
A flipped classroom approach where students present on topics exploring AI applications in cyberattacks or defenses.
Lecture Content: (Potential Topics)
- AI-Driven Threat Intelligence
- AI for Secure Coding
- AI in Forensic Analysis and Incident Investigation
- AI for Adoptive Honeypots and Sandboxes
- AI-Powered Security Training and Awareness Programs
- AI for Penetration Testing and Red Team Operations
- AI for Vulnerability Management (Identification, Prioritization, and Patching)
- AI for Reporting and Summarization
- AI in Automated Reconnaissance
- AI for Automated Exploit Generation…
Week 7: AI-powered Cyber Attack/Defense (Part 3)
Summary:
Continuing the lecture series on AI for defensive and offensive security.
Lecture Content:
- The missing topics from week 6.
- Concerns & Considerations of AI in Cybersecurity
Week 8: Security Concerns in AI-driven Cybersecurity
Summary:
Addressing the security concerns and risks associated to AI systems and their usage in cybersecurity.
Lecture Content:
- AI-powered applications weaknesses & vulnerabilities.
- Adversarial Machine Learning (weaknesses & vulnerabilities of AI models).
- Related Frameworks: OWASP Machine Learning Security Top Ten, OWASP Top 10 for LLM Applications MITRE ATLAS, AIID, ADML.
Week 9: Reliability in AI-driven Cybersecurity
Summary:
Focusing on key considerations when applying AI systems in cybersecurity.
Lecture Content:
- Importance of explainability and interpretability in AI (Explainable AI – XAI).
- Building trust and ensuring accountability in AI-driven systems.
- Domain-specific AI models (RAG systems) and the importance of fine-tuning.
- Metrics and KPIs for benchmarking AI systems in cybersecurity (robustness, accuracy, security, etc.).
Week 10: Responsible AI-driven Cybersecurity
Summary:
Examine the ethical, legal, and regulatory concerns associated with AI, particularly in cybersecurity.
Lecture Content:
- Ethical considerations of AI systems: fairness, bias, and transparency.
- Privacy concerns with AI systems
- Legal and regulatory requirements for AI systems, e.g., GDPR, AI Act, etc.
–Emerging Cross-cutting Topics—
Week 11: Future Trends in AI & Cybersecurity
Flipped classroom + (optional) guest lecture
Summary:
Engage students (in form of flipped classroom) in exploring cutting-edge trends and controversial topics in AI and cybersecurity.
Guest lecture (if available) to provide industry insight.
Lecture Content: (potential topics)
- Post-quantum cryptography and AI’s role in post-quantum security
- AI in zero trust architecture
- Privacy-preserving AI & federated learning
- AI and its impact on cyber warfare
- AI in zero-day exploit discovery
- AI at the edge (from cloud computing to edge computing)
- Trust in the era of AI generated data
- Human-AI Collaboration
- AI-generated vulnerable codes
Week 12: Wrap-up
- Overview of the course.
- Final project presentations by students.
- Discussions.
- Guest lecture (from industry).
Learning objectives
On successful completion of this module, the learner will be able to:
LO1: Demonstrate well-developed knowledge of core AI concepts, including generative AI and large language models, and explain their relevance to cybersecurity operations.
LO2: Critically analyse the opportunities and limitations of AI in offensive and defensive cybersecurity applications, including within Security Operations Centers (SOCs).
LO3: Identify and assess vulnerabilities, adversarial threats, and ethical risks associated with the use of AI in cybersecurity.
LO4: Apply AI methods and tools to design and prototype solutions addressing real-world cybersecurity challenges in both defensive and offensive contexts.
LO5: Collaborate effectively in teams to develop and present AI-driven scenarios, integrating technical, organisational, and regulatory considerations.
LO6: Evaluate emerging trends and regulatory developments in AI for cybersecurity, anticipating their impact on professional practice and policy.
Register your interest