Key information
- Application opening date: July 27, 2026
- Next application deadline: September 25, 2026
- Next course starts: October 1, 2026
- Format: Fully online, synchronous and recorded for asynchronous access
- Course duration: 12 weeks
- Language: English
- Awarding Institution: German University of Digital Science
- Delivered by: Munster Technological University
- Certified by: ASIIN
- EQF Level: 7
- ECTS: 5 ECTS (~125 hours of study workload, including course activities and self-directed learning)
- Fees: €350
Microcredential Information
This module aims to provide learners with knowledge on documentation, strategies, and technologies that support the processes of business resilience, threat response, and incident management. The module will examine how an organisation can prepare for business disruption and what actions can be taken to prevent and contain an incident, reduce the impact to organisational systems and get the business operational as quickly as possible after an incident occurs. Learners will acquire the necessary incident management skills required to develop contextual plans, run books and the associated processes and tools to enable effective business resilience capabilities.
Furthermore, learners will be able to identify and illustrate the challenges associated with developing risk-based business resilience, threat response, and incident management processes. Learners will gain practical experience in aligning an organisation to industry standards and best practices that are commonly used for business resilience, threat response, and incident management tasks incorporating several stages, including preparation for incidents, detection and analysis of a security incident, containment, eradication, and full recovery, and post-incident analysis and learning.
Key Details
Time commitment
- (Estimated) Total workload: 125 hours
- Directed e-Learning Activities: 24 hours
- Synchronous Lectures: 12 hours
- Tutorial Sessions: 12 hours
- Private study including examination preparation, specified in hours: 77 hours
Assessment
Grading Breakdown:
- 40% Continuous Assessment 1: For this continuous assessment learners will have to evaluate real-world incidents and critique the incident response process. The CA is based on course content covered up to the date of assessment. Critical appraisal and evaluation required.
- 60% Continuous Assessment 2: Terminal proctored assessment based on 5 varied themes covered during the course requiring critical evaluation and demonstration of conceptual learning based on scenarios, research and critical appraisal.
Subjects covered
1. Introduction
A background on the industry leading best practices (Including NIST Cybersecurity Framework for Incident Response). Understanding what risk means for an organisation and how an event ties into risk management processes. Providing an overview of where IR impacts governance, risk and compliance. Legal and regulatory compliance requirements for cyber incidents. Resilience standards (ISO 22301). Principles of incident management (ISO/IEC 27035).
2. Assessing Impact of Cyber Attacks
Understanding the threat landscape, recent incidents and developments in IR tools and processes. Overview of business resilience with business continuity and the IR focus on availability, while managing disruption. Cloud platform considerations and challenges.
3. System Security Concepts
How Blue teams evaluate and defend systems and environments. Understanding blue team activities during an incident.
4. Scaling Incident Response
Shaping and improving your IR posture. Focus on Red teams and how they play the role of attackers by identifying security vulnerabilities and launching attacks within a controlled environment. Understanding when and how to use a red team during an incident.
5. IR Roles and Responsibilities
Computer Incident Response Teams (CIRTs) operation. A mapping of IR roles to activities. How to prioritise these when directing incident response activities. Incident Management, Crisis Management and Business Continuity. Executive level stakeholders.
6. Incident Response Process
IR activities and processes to gain Business input for IR. Incident Response Plan. Detection, Investigation, Analysis and Activation. Cross-domain and border-domain knowledge related to cybersecurity.
7. Business Processes
The business perspective on regulation and operational resilience. Business Impact Analysis. The importance of process and service mapping to systems. Organisational and governance impact.
8.System Forensics and Tools
The role of Incident Response, Forensics and E-discovery and the intersection. Focus on system forensics and tools from an IR perspective.
9. Threat Intelligence & Threat Response
Threat intelligence processes. Importance of SIEM from threat hunting to performance monitoring.
10. Security operations for IR
Secure Operation Centres (SOCs) operation. Approaches, processes and roles within Sec Ops for monitoring, the three-tiered model for SOC. Threat intelligence processes and tooling.
11. IR Improvement process
How to evaluate your organisation’s posture for IR. IR Reporting. IR Measurement. IR Auditing. IR Testing. Post incident activities supporting continuous improvement.
12. Summary
Re-cap on core domains and takeaways.
Register your interestLearning objectives
The Business Resilience, Threat Response, and Incident Management module is focussed on enabling learners to build, operate and critically assess an organisation’s incident response capabilities and the resilience of their current critical processes and services, including the systems underpinning them. This module will appraise the key technical controls required in addition to the people and process elements required to build and operate a resilient organisation. In addition to evaluating the risk profile of an organisation, the module will enable learners to understand the requirements for directing operations during an incident with next gen-technology mind-set.
On successful completion of this module the learner will be able to:
- LO1: Evaluate incident response plans, their effectiveness and their alignment to industry leading standards and appropriate incident response principles and methodologies.
- LO2: Critically appraise response activities for incident management from initial compromise to recovery and make recommendations for improvement.
- LO3: Contrast methods to assess the maturity of an organisation’s incident response capabilities.