Learning path3 levels8 steps
Cybersecurity basicsfrom staying safe online to testing for security.
Three levels, read in order: what security protects and the habits that stop most attacks, how testers find weaknesses before attackers do, and how organizations manage security risk across their own code and their vendors'.
Level 1
Start hereStudents, families, and anyone curious. No experience needed.
What security protects, the everyday habits that stop most attacks, and the common ways software gets broken into.
- 01ArticleWhat Is Cybersecurity? The Ideas Behind Keeping Systems SafeThe ideas the whole field is built on: confidentiality, integrity, availability, and risk.Read →
- 02ArticleStaying Safe Online: Passwords, Sign-In, Phishing, and UpdatesPasswords, multi-factor sign-in, phishing, and updates: the habits that stop most attacks.Read →
- 03ArticleHow Software Gets Attacked: Common Vulnerabilities in Plain EnglishThe common vulnerabilities in software, each with the defense that stops it.Read →
Level 2
FoundationsNew testers, developers, and career changers.
How testers find security weaknesses on purpose, legally and systematically, and how a development team reduces security risk end to end.
- 04ArticleSecurity Testing Basics: Finding Weaknesses Before Attackers DoThreat modeling, abuse cases, access control tests, and where scanners and penetration tests fit.Read →
- 05ArticleSeven Steps to Reducing Software Security RiskSeven steps that build security into the way a team designs, codes, and tests.Read →
Level 3
PractitionerTesters, engineers, and leads responsible for release quality.
Rank security alongside other quality risks, and manage the risk that arrives with outsourced code, vendors, and third-party components.
- 06ArticleQuality Risk Analysis: Five Techniques, Seven Lifecycle Benefits, One ProcessRank security and other quality risks by likelihood and impact, so effort goes where it matters.Read →
- 07ArticleQuality Risks in Integrating Outsourced and Third-Party ComponentsThe risks that arrive with outsourced and third-party components, and how to test for them.Read →
- 08ArticleVerifying Third-Party Quality: Entry and Exit Criteria Across the Vendor BoundaryEntry and exit criteria that hold vendors to a quality bar before their work reaches production.Read →
For teams
Taking a whole team through this?We teach it, coach it, and certify it.
Keep reading
Related reading
- Primer
Careers in Software Quality: Roles, Skills, and First Steps
What testers, test automation engineers, quality engineers, and test managers actually do, the skills each role uses, and practical first steps for students and career changers, including the ISTQB Foundation certification.
Read → - Primer
Errors, Defects, and Failures: What a Bug Really Is
Everyone says 'bug', but testers use three precise words: error, defect, and failure. Learn the difference, why it matters, and how severity and priority decide which problems get fixed first.
Read → - Primer
How Software Gets Attacked: Common Vulnerabilities in Plain English
The most common ways attackers break into software, explained without jargon: trusting input, broken access control, weak sign-in, misconfiguration, and outdated components. Each one comes with the defense that stops it.
Read → - Primer
How to Report a Bug So It Actually Gets Fixed
Finding a bug is half the job. Learn how to write a bug report a developer can act on: a clear summary, exact steps to reproduce, expected versus actual results, and the habits professional testers use to make every report count.
Read → - Primer
Security Testing Basics: Finding Weaknesses Before Attackers Do
An introduction to security testing for new testers and developers: thinking in threats, designing abuse cases, testing access control, the role of automated scanners and penetration tests, and the rules that keep security testing legal and ethical.
Read → - Primer
Staying Safe Online: Passwords, Sign-In, Phishing, and Updates
The everyday security habits that stop most attacks: strong unique passwords, multi-factor sign-in, spotting phishing, keeping devices updated, and sharing carefully. Written for students, families, and anyone starting out.
Read →
Practices
Where this leads
- TrainingQA and AI training
ISTQB certification and hands-on courses for testers, engineers, and leaders, from one of the first ASTQB-accredited training providers in the United States.
Book a call → - QA & testingSoftware testing
Software quality consulting since 1994: we test the releases that matter, coach your team on the method, and measure how its testing matures.
Book a call →