Skip to main content

Business Resilience, Incident Management and Threat Response

Key information

  • Application opening date: July 27, 2026
  • Next application deadline: September 25, 2026
  • Next course starts: October 1, 2026
  • Format: Fully online, synchronous and recorded for asynchronous access
  • Course duration: 12 weeks
  • Language: English
  • Awarding Institution: German University of Digital Science
  • Delivered by: Munster Technological University
  • Certified by: ASIIN
  • EQF Level: 7
  • ECTS: 5 ECTS (~125 hours of study workload, including course activities and self-directed learning)
  • Fees: €350

Microcredential Information

This module aims to provide learners with knowledge on documentation, strategies, and technologies that support the processes of business resilience, threat response, and incident management. The module will examine how an organisation can prepare for business disruption and what actions can be taken to prevent and contain an incident, reduce the impact to organisational systems and get the business operational as quickly as possible after an incident occurs. Learners will acquire the necessary incident management skills required to develop contextual plans, run books and the associated processes and tools to enable effective business resilience capabilities.

Furthermore, learners will be able to identify and illustrate the challenges associated with developing risk-based business resilience, threat response, and incident management processes. Learners will gain practical experience in aligning an organisation to industry standards and best practices that are commonly used for business resilience, threat response, and incident management tasks incorporating several stages, including preparation for incidents, detection and analysis of a security incident, containment, eradication, and full recovery, and post-incident analysis and learning.

Key Details

Time commitment

(Estimated) Total workload: 125 hours

The module is designed to fit around professional and personal commitments. All core content is available asynchronously for self-paced study, complemented by optional live sessions offered throughout the module.

Assessment

Grading Breakdown:

  • 40% Continuous Assessment 1: For this continuous assessment learners will have to evaluate real-world incidents and critique the incident response process. The CA is based on course content covered up to the date of assessment. Critical appraisal and evaluation required.
  • 60% Continuous Assessment 2: Terminal proctored assessment based on 5 varied themes covered during the course requiring critical evaluation and demonstration of conceptual learning based on scenarios, research and critical appraisal.
Register your interest

Subjects covered

1. Introduction

A background on the industry leading best practices (Including NIST Cybersecurity Framework for Incident Response). Understanding what risk means for an organisation and how an event ties into risk management processes. Providing an overview of where IR impacts governance, risk and compliance. Legal and regulatory compliance requirements for cyber incidents. Resilience standards (ISO 22301). Principles of incident management (ISO/IEC 27035).

2. Assessing Impact of Cyber Attacks

Understanding the threat landscape, recent incidents and developments in IR tools and processes. Overview of business resilience with business continuity and the IR focus on availability, while managing disruption. Cloud platform considerations and challenges.

3. System Security Concepts

How Blue teams evaluate and defend systems and environments. Understanding blue team activities during an incident.

4. Scaling Incident Response

Shaping and improving your IR posture. Focus on Red teams and how they play the role of attackers by identifying security vulnerabilities and launching attacks within a controlled environment. Understanding when and how to use a red team during an incident.

5. IR Roles and Responsibilities

Computer Incident Response Teams (CIRTs) operation. A mapping of IR roles to activities. How to prioritise these when directing incident response activities. Incident Management, Crisis Management and Business Continuity. Executive level stakeholders.

6. Incident Response Process

IR activities and processes to gain Business input for IR. Incident Response Plan. Detection, Investigation, Analysis and Activation. Cross-domain and border-domain knowledge related to cybersecurity.

7. Business Processes

The business perspective on regulation and operational resilience. Business Impact Analysis. The importance of process and service mapping to systems. Organisational and governance impact.

8.System Forensics and Tools

The role of Incident Response, Forensics and E-discovery and the intersection. Focus on system forensics and tools from an IR perspective.

9. Threat Intelligence & Threat Response

Threat intelligence processes. Importance of SIEM from threat hunting to performance monitoring.

10. Security operations for IR

Secure Operation Centres (SOCs) operation. Approaches, processes and roles within Sec Ops for monitoring, the three-tiered model for SOC. Threat intelligence processes and tooling.

11. IR Improvement process

How to evaluate your organisation’s posture for IR. IR Reporting. IR Measurement. IR Auditing. IR Testing. Post incident activities supporting continuous improvement.

12. Summary

Re-cap on core domains and takeaways.

Register your interest

Learning objectives

The Business Resilience, Threat Response, and Incident Management module is focussed on enabling learners to build, operate and critically assess an organisation’s incident response capabilities and the resilience of their current critical processes and services, including the systems underpinning them. This module will appraise the key technical controls required in addition to the people and process elements required to build and operate a resilient organisation. In addition to evaluating the risk profile of an organisation, the module will enable learners to understand the requirements for directing operations during an incident with next gen-technology mind-set.

 

On successful completion of this module the learner will be able to:

  • LO1: Evaluate incident response plans, their effectiveness and their alignment to industry leading standards and appropriate incident response principles and methodologies.
  • LO2: Critically appraise response activities for incident management from initial compromise to recovery and make recommendations for improvement.
  • LO3: Contrast methods to assess the maturity of an organisation’s incident response capabilities.
Register your interest

Module leaders

Title:  Dr.

Name: Deirdre Leahy

Register your interest

newsletterStay ahead in cybersecurity

Subscribe to our newsletter for exclusive insights and breakthroughs from Digital4Security directly to your inbox

Applications open
Hybrid Master's
Application deadline:
Friday, 11th September 2026, 22:00 CET
Course starts:
Monday, 28th September 2026
Course duration:
2 years | Hybrid (online + in-person intensives)
Course delivery:
Hybrid program
Certification:
ARACIS (Romania)-accredited masters's degree (120 ECTS)
Language:
English
Apply now
Applications closed
Microcredentials
Application deadline:
Friday, 25th September, 12:00 CEST
Course starts:
From October 2026 (application opens Monday, 27th July)
Course duration:
6-12 weeks depending on chosen course
Course delivery:
Online
Certification:
Official recognition of your completed learning outcomes and awarded ECTS
Language:
English
Register your Interest
Apply now Toggle