Skip to main content
Application
Opened
 - 
Dates
 - 
Training topics
Cybersecurity
Languages
English
Coordinators
  • Alex Högback
  • Fanny Rotino
  • Caroline Troein
Course level

Intermediate

Duration
12 hours
Event email contact
ituacademy@itu.int
Price
$0

Event Organizer(s)

Initiative

Description

As countries expand school connectivity, they must also strengthen their capacity to prepare for, respond to, and recover from cyber incidents affecting the education sector. This course provides a policy- and decision-focused introduction to the incident response (IR) lifecycle, enabling participants to understand how organizations and governments coordinate their response to cybersecurity incidents in education environments. 

Through three realistic scenarios - a school ransomware attack, a student data breach, and a national-level education system attack - participants will apply incident response principles in collaborative tabletop exercises. These exercises focus on decision-making, stakeholder coordination, communication, and policy implementation rather than technical investigation or digital forensics. Participants are expected to have a basic understanding of information technology and cybersecurity concepts, but no advanced technical skills or prior incident response experience are required. 

Throughout the course, participants will develop practical outputs, including an Incident Response Policy, a Breach Notification Guide, and a National Education Incident Response Playbook, all designed for immediate adaptation within their own institutions and national contexts. They will also become familiar with internationally recognized cybersecurity frameworks and baseline security controls, including the NIST Cybersecurity Framework (CSF) 2.0, CIS Critical Security Controls, ISO/IEC 27001, and NIST SP 800-61, and learn how these support organizational preparedness and resilience. 

The course is specifically designed for resource-constrained environments and requires no specialist software, laboratory infrastructure, or advanced technical expertise. 

This course is specifically designed for government officials, regulators, and policy makers responsible for developing, implementing, or supervising national strategies on school connectivity and digital transformation. It targets participants engaged in expanding internet access to schools and improving the resilience of national education networks. This course is particularly suited for: 

  • Ministry of Education officials responsible for school IT infrastructure and digital learning policy 
  • National cybersecurity agency staff involved in sectoral incident response and CIRT/CERT/CSIRT operations 
  • Telecommunications regulators overseeing school connectivity programmes under the Giga initiative 
  • Giga initiative national coordinators and project leads 
  • School network administrators and IT coordinators at the national or regional level. 

Kindly note this course is restricted to users who meet the following criterial:

Members of the above-mentioned target population are invited to apply for the training if they meet the following criteria:  

  • Hold an undergraduate degree in a relevant field OR a minimum of three years of experience in a related field if no degree is held.  
  • Participants should possess basic knowledge of information technology and cybersecurity concepts. No advanced technical skills or prior experience in incident response are required.  
  • Possess English language proficiency. 

Government officials, members of cybersecurity agencies, and regulatory bodies — and particularly women — are encouraged to apply. Selection will be conducted by the course organizers, who will consider the above entry requirements along with an analysis of the application questionnaire, CV, and recommendation or motivation letters. 

Number of available places for the cohort: 40  

Upon completion of this course, participants will be able to: 

Apply the core stages of the incident response lifecycle (Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned) using policy- and decision-focused incident response frameworks adapted to low-resource education environments. 

Develop an Incident Response Policy for the education sector, including clear roles and responsibilities for school leaders, ministry focal points, IT liaisons, telecom operators, and CIRT/CERT/CSIRT contacts 

Execute structured tabletop exercises for three core incident types — ransomware on school systems, student personal data breaches, and a national-level EMIS attack — practising identification, containment, communication, and recovery decisions. 

Design cross-sector escalation paths and communication strategies that bridge local schools, ministries, telecom operators, national CIRTs/CERTs, and Giga partners during infrastructure emergencies. 

Produce an Incident Response Playbook and a Breach Notification Guide tailored to the education sector, incorporating relevant stakeholder communication templates, escalation pathways, and child online protection obligations 

Evaluate the effectiveness of an incident response through structured post-incident review, identifying lessons learned and improvements for continuous national capacity building. 

Identify and recommend preventive cybersecurity policies, standards, and baseline security controls for education environments using internationally recognized frameworks such as the NIST Cybersecurity Framework (CSF 2.0), CIS Critical Security Controls, ISO/IEC 27001, and the CIS Benchmarks. 

The course is delivered using an online instructor-led methodology via Zoom, allowing participants to join from anywhere. It is intentionally designed so that no specialist software, lab environments, or advanced IT infrastructure are required. All exercises are policy- and decision-focused, reflecting the realities of government and education stakeholders in Giga partner countries. Participants apply basic cybersecurity concepts while practicing decision-making, stakeholder coordination, communication, and policy implementation. The exercises do not require technical incident investigation, digital forensics, or hands-on use of cybersecurity tools. 

Each of the 8 live sessions follows a consistent two-part structure: 

  • Focused input segment (30–40 minutes): Instructor-led content, case study review, and framework or template introduction 
  • Guided exercise and debrief (50–60 minutes): Small-group tabletop simulation in breakout rooms of 6–8 participants, followed by structured whole-group reflection 

The course structure is as follows: 

  • Session 1: Course introduction, IR foundations, and participant group formation 
  • Sessions 2–7: Instructor-led input and tabletop scenario exercises (three scenarios, two sessions each) 
  • Session 8: Capstone multi-stakeholder simulation and group presentations 
  • Asynchronous individual deliverables: Two practical templates submitted between sessions 
  • Final quiz: 20-question knowledge check, open for four days after Session 8 

The assessment methodology recognises both individual and collaborative learning, producing practical outputs that participants can use immediately after the course. 

 

Activity  Weighting (%) 

Active participation in live sessions 20% 

Individual deliverables (IR Policy + Breach Notification Guide) 20% 

Capstone group simulation and presentation (Session 8) 30% 

Final quiz 30% 

TOTAL 100% 

To successfully complete the course and obtain the ITU Certificate, participants must achieve a minimum overall score of 70%

Session 1 - Introduction & IR Foundations 

Session 2 -IR Policy, Team Structure & Communication Protocols 

Session 3 - Scenario 1 Input — Ransomware Attack on a School System 

Session 4 - Scenario 1 Tabletop — Ransomware Containment & Leadership Briefing 

Session 5Scenario 2 Input — Student Data Breach & Child Online Protection 

Session 6 - Scenario 2 Tabletop — Regulatory & Parental Communications 

Session 7 - Scenario 3 Input — Education Management Information System (EMIS) Attack & Vulnerability in Interconnected School Systems 

Session 8 - Capstone: National Education Cybersecurity and Incident Response Playbook 

Instructors

Dimitar Bogatinov

Registration information

Unless specified otherwise, all ITU Academy training courses are open to all interested professionals, irrespective of their race, ethnicity, age, gender, religion, economic status and other diverse backgrounds. We strongly encourage registrations from female participants, and participants from developing countries. This includes least developed countries, small island developing states and landlocked developing countries.

Related documentation and links
Share in