Free online orientation · Saturday 7 November · 9:30am CET / 4:30pm Manila
Help build a digital world that is secure and trustworthy.
Voting, hospitals, payments, the electricity grid — all of it now rests on whether someone was paying attention. Foundation of Security takes capable professionals from other fields into that work in twelve weeks, part-time and online. The cybersecurity field is short of people, it rewards the ones it gets, and it is open to those arriving from other fields.
Come to the free online orientation on Saturday, 7 November 2026 (9:30am CET and 4:30pm Manila time) and find out whether it fits your situation — let's have a conversation and find out if this might be the right time for you to pivot into cybersecurity.
The thing nobody tells you
Cybersecurity is not short of people who can configure a firewall.
It is short of people who can sit in front of a board and explain why the firewall isn't the point. Who can translate between the engineers and the executives, run through an incident without the room descending into blame, and hold a supplier to a promise.
That work is judgment work — and judgment is the one skill a new college graduate does not yet have. Whether you are five years into a career or twenty, you have spent that time learning how to read a room before you make the ask, how to tell when a supplier is managing you, and how an organisation actually decides things as opposed to how the org chart says it does.
If you are already technical — systems, networks, infrastructure, development, data — the same gap applies in reverse. You do not need to be taught what a protocol is. What you need is the frame around the technology: governance, risk, legal and regulatory obligation, incident command, and the human layer. That frame is the difference between someone who can harden a server and someone who can own a security domain, and it is the thing most technologists are never formally taught.
You are not starting from zero. You are starting with valuable transferable skills that are needed in a steadily maturing and growing industry.
Six ways in
Over ten years of cohorts, six routes keep recurring.
Participants have arrived from very different starting points and left in very different directions. Most people recognise themselves in one of these; a few sit across two.
Most common route
The internal mover
You already work for a large organisation — a bank, an insurer, a utility, a government department, a regulator — and it has a security function you are not part of. The lowest-risk version of the whole move: you keep your employer, your tenure and your internal credibility, and cross into a different part of the same building.
Why it worksYou already know who decides things and where the bodies are buried — precisely what an external hire spends a year learning
5–10 years in
The practitioner
Real professional footing, but not yet defined by a single role. This is the route into the operational core of a cyber team, where an outsider's working knowledge of how a business actually runs is an advantage from week one.
Typically lands inGRC, security operations, identity and access management, third-party and vendor risk, audit and assurance, incident response
15–20 years in
The interface and the leader
You have run functions, budgets and people, and you are used to executive rooms. This route leads to where cyber meets the rest of the organisation. You are not starting at the bottom — you are adding a domain to a career that already has altitude.
Typically lands inSecurity governance and programme leadership, risk management, business continuity, regulatory engagement
Already technical
The technologist crossing over
Systems administration, networks, infrastructure, development, data or IT support — but not a security person, and the two are not the same thing. What you need is the frame around the technology, which is the thing most technologists are never formally taught.
Typically lands inApplication and product security, DevSecOps, security engineering
Working for yourself
The independent
Not everyone is trying to join a team. A substantial number of graduates now work for themselves — advising organisations too small to justify a full-time security hire, or founding companies of their own. For a mid-career professional with an established network, the demand is real and your existing contacts are your first clients.
Typically leads toFreelance consulting and advisory practice, partnership in a specialist consultancy, or your own firm
Not pivoting at all
Depth in the seat you already occupy
Legal, compliance, procurement, internal audit, privacy, risk or operations — and cybersecurity has arrived in your remit whether or not anyone formally put it there. You are signing off on risks you can describe but not evaluate.
Typically leads toDoing your existing job properly — challenging a control claim rather than accepting it, and sitting in a technical review as a participant rather than a spectator
All of these sit in the same cohort, and that turns out to be a feature rather than a compromise. The career-changers get a working view of how legal, procurement and risk actually see security. The technologists get twelve weeks of business context they would otherwise absorb by accident over years. The lawyers and procurement leads get the technical foundation. Each group teaches the others something the syllabus cannot.
At a glance
Built for people with jobs and families.
It runs alongside your working life rather than instead of it.
- Duration
- Twelve weeks, cohort-based. Several cohorts run each year.
- Weekly commitment
- One to two hours of on-demand video in your own time, plus optional reading, surveys and case studies.
- Live sessions / seminars
- Saturdays, 9:30–11:30am CET / 4:30–6:30pm Manila time, online — discussion, demonstrations and case studies with industry experts.
- Where you join from
- The Saturday slot is deliberately workable from both Europe and Asia — mid-morning in Brussels, late afternoon in Manila. Everything else is on-demand, so the rest of your week runs in your own time zone.
- Method
- Flipped classroom. You arrive having watched and read; the live hours are spent using the material, not receiving it.
- Assessment
- A fifteen-minute knowledge test at the end of each module, and a one-hour final test taken live. Pass everything and you receive a CWF certificate of completion.
- Prerequisites
- No IT or technical background is required — and if you already have one, the course supplies the governance, risk and human layers around it. English at roughly B2 reading and B1 speaking. A laptop, a stable connection, and willingness to be a beginner again for twelve weeks.
- Investment
- €1,845 excluding VAT. What VAT applies depends on where you are based and whether you are invoiced personally or through an employer — we will confirm before you pay. One-to-one career transition mentoring can be added at a combined rate — ask us.
From a graduate
Information security analyst, 2022 cohort“… The instructors are not just experts in the field, but active in it as well. Their real-world insights provide invaluable context to the theoretical knowledge being taught.
CWF's FoS track not only equipped me with the required technical basis but empowered me to transition with confidence by also encouraging me to leverage my skills and expertise from my previous career.”
The nine domains
The full common body of knowledge.
By the end you will have been through all of it.
What this prepares you to do
Across a decade of cohorts, graduates have left in very different directions.
Some built their own practice. Some now lead security functions. Some went deep into a single domain. Others stayed exactly where they were and do that job with an authority they did not have before.
Working for yourself
- Independent consulting and advisory practice — advising organisations too small to justify a full-time security function, or taking contract and interim work
- Partnership in a specialist consultancy, or founding a company of your own. Several graduates have done both
Leading and connecting
- Security leadership — heading a function, owning a domain, or running a programme, including at genuine scale
- Security governance and strategy — policy, standards and the risk framework
- Risk, resilience and crisis management — being the person trusted to run the room when something has actually gone wrong
- The translation layer — regulatory engagement and board reporting, where a long prior career pays the largest dividend
Going deep in a domain
- Governance, risk and compliance — where prior business experience converts fastest
- Third-party and supply chain risk — where procurement and commercial experience is a direct asset
- Security operations and threat intelligence
- Identity and access management, and Zero Trust programmes
- Application and product security, DevSecOps and security engineering
- Security awareness and human risk — a natural fit for people arriving from HR, communications or education
And where that work happens
Graduates are working in the places where the consequences of getting security wrong are real:
Who teaches it
The course is not handed to associates.
Foundation of Security is taught by CyberWayFinder's three co-founders, personally, alongside a network of senior practitioners currently working in the field.
Rosanna Kurrer
Co-founder
Born in the Philippines, she studied architecture at Kyoto University and practised as an architect before moving to Europe — and the underlying discipline turned out to be the same one: understanding how a complex structure holds together and what happens when one element fails. She now secures critical national infrastructure across Europe, including financial services and electricity producers, and has trained European Commissioners and Commission staff. Award-winner in the Belgian technology sector; speaker at RSA Conference and repeatedly at COSAC.
Marie Vinck
Co-founder
Marie has seen cybersecurity from both sides of the table. As former Senior Director of Cybersecurity at EY she worked at the consultancy end — how security is assessed, benchmarked and argued for. She is now a practising CISO at Circle K, across many countries and thousands of sites: accountable, distributed, commercially constrained and permanently in contact with reality. She answers the question participants most want settled — not what the framework says, but what happens when you try to apply it against a real budget and real resistance.
K. Patrick Wheeler, P.E.
Co-founder
Chief Security Architect for AI and Data Security at BNP Paribas Fortis, after seven years as Chief Security Architect for Payments and Anti-Fraud at the same institution. Earlier, as Chief Security Officer of a bank, he defended the full European attack surface through a multi-month nation-state cyberattack with no loss of service and no loss of data. A Registered Professional Engineer, recipient of the ISC² Senior Information Security Professional of the Year award, and a guest lecturer at Solvay, the LSE, Namur and Tilburg.
Alongside the founders, live sessions bring in senior security professionals working in major enterprises across sectors — so the people you learn from are currently doing the work you are moving towards.
The next step
Come to the orientation before you decide anything.
Ninety minutes, online, free.
- What the twelve weeks actually demand, week by week
- Which of the six ways into cybersecurity you fit, and what that usually leads to
- A walk through the nine domains and the assessment
- Live Q&A with the founders — including the awkward questions
- A straight answer about whether this is right for your situation
Saturday
7 November
9:30–11:00am CET
4:30–6:00pm Manila time
Online. Free to attend. No obligation to register for the course.
- 7 NovOnline orientation
- 23 JanCohort starts
- AprFinal test and CWF certificate
This is work that matters — and it is open to you.
It defends the organisation that employs you, and in aggregate it defends the country you live in. Very few mid-career moves offer that, and fewer still are genuinely open to professionals from different backgrounds and diverse transferable skills. This one has been for over ten years — and every person now working in cyber because of it arrived, like you, from another field.
Free online orientation · Saturday 7 November · 9:30am CET / 4:30pm Manila
Help build a digital world that is secure and trustworthy.
Voting, hospitals, payments, the electricity grid — all of it now rests on whether someone was paying attention. Foundation of Security takes capable professionals from other fields into that work in twelve weeks, part-time and online. The cybersecurity field is short of people, it rewards the ones it gets, and it is open to those arriving from other fields.
Come to the free online orientation on Saturday, 7 November 2026 (9:30am CET and 4:30pm Manila time) and find out whether it fits your situation — let's have a conversation and find out if this might be the right time for you to pivot into cybersecurity.
The thing nobody tells you
Cybersecurity is not short of people who can configure a firewall.
It is short of people who can sit in front of a board and explain why the firewall isn't the point. Who can translate between the engineers and the executives, run through an incident without the room descending into blame, and hold a supplier to a promise.
That work is judgment work — and judgment is the one skill a new college graduate does not yet have. Whether you are five years into a career or twenty, you have spent that time learning how to read a room before you make the ask, how to tell when a supplier is managing you, and how an organisation actually decides things as opposed to how the org chart says it does.
If you are already technical — systems, networks, infrastructure, development, data — the same gap applies in reverse. You do not need to be taught what a protocol is. What you need is the frame around the technology: governance, risk, legal and regulatory obligation, incident command, and the human layer. That frame is the difference between someone who can harden a server and someone who can own a security domain, and it is the thing most technologists are never formally taught.
You are not starting from zero. You are starting with valuable transferable skills that are needed in a steadily maturing and growing industry.
Six ways in
Over ten years of cohorts, six routes keep recurring.
Participants have arrived from very different starting points and left in very different directions. Most people recognise themselves in one of these; a few sit across two.
Most common route
The internal mover
You already work for a large organisation — a bank, an insurer, a utility, a government department, a regulator — and it has a security function you are not part of. The lowest-risk version of the whole move: you keep your employer, your tenure and your internal credibility, and cross into a different part of the same building.
Why it worksYou already know who decides things and where the bodies are buried — precisely what an external hire spends a year learning
5–10 years in
The practitioner
Real professional footing, but not yet defined by a single role. This is the route into the operational core of a cyber team, where an outsider's working knowledge of how a business actually runs is an advantage from week one.
Typically lands inGRC, security operations, identity and access management, third-party and vendor risk, audit and assurance, incident response
15–20 years in
The interface and the leader
You have run functions, budgets and people, and you are used to executive rooms. This route leads to where cyber meets the rest of the organisation. You are not starting at the bottom — you are adding a domain to a career that already has altitude.
Typically lands inSecurity governance and programme leadership, risk management, business continuity, regulatory engagement
Already technical
The technologist crossing over
Systems administration, networks, infrastructure, development, data or IT support — but not a security person, and the two are not the same thing. What you need is the frame around the technology, which is the thing most technologists are never formally taught.
Typically lands inApplication and product security, DevSecOps, security engineering
Working for yourself
The independent
Not everyone is trying to join a team. A substantial number of graduates now work for themselves — advising organisations too small to justify a full-time security hire, or founding companies of their own. For a mid-career professional with an established network, the demand is real and your existing contacts are your first clients.
Typically leads toFreelance consulting and advisory practice, partnership in a specialist consultancy, or your own firm
Not pivoting at all
Depth in the seat you already occupy
Legal, compliance, procurement, internal audit, privacy, risk or operations — and cybersecurity has arrived in your remit whether or not anyone formally put it there. You are signing off on risks you can describe but not evaluate.
Typically leads toDoing your existing job properly — challenging a control claim rather than accepting it, and sitting in a technical review as a participant rather than a spectator
All of these sit in the same cohort, and that turns out to be a feature rather than a compromise. The career-changers get a working view of how legal, procurement and risk actually see security. The technologists get twelve weeks of business context they would otherwise absorb by accident over years. The lawyers and procurement leads get the technical foundation. Each group teaches the others something the syllabus cannot.
At a glance
Built for people with jobs and families.
It runs alongside your working life rather than instead of it.
- Duration
- Twelve weeks, cohort-based. Several cohorts run each year.
- Weekly commitment
- One to two hours of on-demand video in your own time, plus optional reading, surveys and case studies.
- Live sessions / seminars
- Saturdays, 9:30–11:30am CET / 4:30–6:30pm Manila time, online — discussion, demonstrations and case studies with industry experts.
- Where you join from
- The Saturday slot is deliberately workable from both Europe and Asia — mid-morning in Brussels, late afternoon in Manila. Everything else is on-demand, so the rest of your week runs in your own time zone.
- Method
- Flipped classroom. You arrive having watched and read; the live hours are spent using the material, not receiving it.
- Assessment
- A fifteen-minute knowledge test at the end of each module, and a one-hour final test taken live. Pass everything and you receive a CWF certificate of completion.
- Prerequisites
- No IT or technical background is required — and if you already have one, the course supplies the governance, risk and human layers around it. English at roughly B2 reading and B1 speaking. A laptop, a stable connection, and willingness to be a beginner again for twelve weeks.
- Investment
- €1,845 excluding VAT. What VAT applies depends on where you are based and whether you are invoiced personally or through an employer — we will confirm before you pay. One-to-one career transition mentoring can be added at a combined rate — ask us.
From a graduate
Information security analyst, 2022 cohort“… The instructors are not just experts in the field, but active in it as well. Their real-world insights provide invaluable context to the theoretical knowledge being taught.
CWF's FoS track not only equipped me with the required technical basis but empowered me to transition with confidence by also encouraging me to leverage my skills and expertise from my previous career.”
The nine domains
The full common body of knowledge.
By the end you will have been through all of it.
What this prepares you to do
Across a decade of cohorts, graduates have left in very different directions.
Some built their own practice. Some now lead security functions. Some went deep into a single domain. Others stayed exactly where they were and do that job with an authority they did not have before.
Working for yourself
- Independent consulting and advisory practice — advising organisations too small to justify a full-time security function, or taking contract and interim work
- Partnership in a specialist consultancy, or founding a company of your own. Several graduates have done both
Leading and connecting
- Security leadership — heading a function, owning a domain, or running a programme, including at genuine scale
- Security governance and strategy — policy, standards and the risk framework
- Risk, resilience and crisis management — being the person trusted to run the room when something has actually gone wrong
- The translation layer — regulatory engagement and board reporting, where a long prior career pays the largest dividend
Going deep in a domain
- Governance, risk and compliance — where prior business experience converts fastest
- Third-party and supply chain risk — where procurement and commercial experience is a direct asset
- Security operations and threat intelligence
- Identity and access management, and Zero Trust programmes
- Application and product security, DevSecOps and security engineering
- Security awareness and human risk — a natural fit for people arriving from HR, communications or education
And where that work happens
Graduates are working in the places where the consequences of getting security wrong are real:
Who teaches it
The course is not handed to associates.
Foundation of Security is taught by CyberWayFinder's three co-founders, personally, alongside a network of senior practitioners currently working in the field.
Rosanna Kurrer
Co-founder
Born in the Philippines, she studied architecture at Kyoto University and practised as an architect before moving to Europe — and the underlying discipline turned out to be the same one: understanding how a complex structure holds together and what happens when one element fails. She now secures critical national infrastructure across Europe, including financial services and electricity producers, and has trained European Commissioners and Commission staff. Award-winner in the Belgian technology sector; speaker at RSA Conference and repeatedly at COSAC.
Marie Vinck
Co-founder
Marie has seen cybersecurity from both sides of the table. As former Senior Director of Cybersecurity at EY she worked at the consultancy end — how security is assessed, benchmarked and argued for. She is now a practising CISO at Circle K, across many countries and thousands of sites: accountable, distributed, commercially constrained and permanently in contact with reality. She answers the question participants most want settled — not what the framework says, but what happens when you try to apply it against a real budget and real resistance.
K. Patrick Wheeler, P.E.
Co-founder
Chief Security Architect for AI and Data Security at BNP Paribas Fortis, after seven years as Chief Security Architect for Payments and Anti-Fraud at the same institution. Earlier, as Chief Security Officer of a bank, he defended the full European attack surface through a multi-month nation-state cyberattack with no loss of service and no loss of data. A Registered Professional Engineer, recipient of the ISC² Senior Information Security Professional of the Year award, and a guest lecturer at Solvay, the LSE, Namur and Tilburg.
Alongside the founders, live sessions bring in senior security professionals working in major enterprises across sectors — so the people you learn from are currently doing the work you are moving towards.
The next step
Come to the orientation before you decide anything.
Ninety minutes, online, free.
- What the twelve weeks actually demand, week by week
- Which of the six ways into cybersecurity you fit, and what that usually leads to
- A walk through the nine domains and the assessment
- Live Q&A with the founders — including the awkward questions
- A straight answer about whether this is right for your situation
Saturday
7 November
9:30–11:00am CET
4:30–6:00pm Manila time
Online. Free to attend. No obligation to register for the course.
- 7 NovOnline orientation
- 23 JanCohort starts
- AprFinal test and CWF certificate
This is work that matters — and it is open to you.
It defends the organisation that employs you, and in aggregate it defends the country you live in. Very few mid-career moves offer that, and fewer still are genuinely open to professionals from different backgrounds and diverse transferable skills. This one has been for over ten years — and every person now working in cyber because of it arrived, like you, from another field.