Skip to Content
CyberWayFinder

Free online orientation · Saturday 7 November · 9:30am CET / 4:30pm Manila

Help build a digital world that is secure and trustworthy.

Voting, hospitals, payments, the electricity grid — all of it now rests on whether someone was paying attention. Foundation of Security takes capable professionals from other fields into that work in twelve weeks, part-time and online. The cybersecurity field is short of people, it rewards the ones it gets, and it is open to those arriving from other fields.

Come to the free online orientation on Saturday, 7 November 2026 (9:30am CET and 4:30pm Manila time) and find out whether it fits your situation — let's have a conversation and find out if this might be the right time for you to pivot into cybersecurity.

The thing nobody tells you

Cybersecurity is not short of people who can configure a firewall.

It is short of people who can sit in front of a board and explain why the firewall isn't the point. Who can translate between the engineers and the executives, run through an incident without the room descending into blame, and hold a supplier to a promise.

That work is judgment work — and judgment is the one skill a new college graduate does not yet have. Whether you are five years into a career or twenty, you have spent that time learning how to read a room before you make the ask, how to tell when a supplier is managing you, and how an organisation actually decides things as opposed to how the org chart says it does.

If you are already technical — systems, networks, infrastructure, development, data — the same gap applies in reverse. You do not need to be taught what a protocol is. What you need is the frame around the technology: governance, risk, legal and regulatory obligation, incident command, and the human layer. That frame is the difference between someone who can harden a server and someone who can own a security domain, and it is the thing most technologists are never formally taught.

You are not starting from zero. You are starting with valuable transferable skills that are needed in a steadily maturing and growing industry.

Six ways in

Over ten years of cohorts, six routes keep recurring.

Participants have arrived from very different starting points and left in very different directions. Most people recognise themselves in one of these; a few sit across two.

Most common route

The internal mover

You already work for a large organisation — a bank, an insurer, a utility, a government department, a regulator — and it has a security function you are not part of. The lowest-risk version of the whole move: you keep your employer, your tenure and your internal credibility, and cross into a different part of the same building.

Why it worksYou already know who decides things and where the bodies are buried — precisely what an external hire spends a year learning

5–10 years in

The practitioner

Real professional footing, but not yet defined by a single role. This is the route into the operational core of a cyber team, where an outsider's working knowledge of how a business actually runs is an advantage from week one.

Typically lands inGRC, security operations, identity and access management, third-party and vendor risk, audit and assurance, incident response

15–20 years in

The interface and the leader

You have run functions, budgets and people, and you are used to executive rooms. This route leads to where cyber meets the rest of the organisation. You are not starting at the bottom — you are adding a domain to a career that already has altitude.

Typically lands inSecurity governance and programme leadership, risk management, business continuity, regulatory engagement

Already technical

The technologist crossing over

Systems administration, networks, infrastructure, development, data or IT support — but not a security person, and the two are not the same thing. What you need is the frame around the technology, which is the thing most technologists are never formally taught.

Typically lands inApplication and product security, DevSecOps, security engineering

Working for yourself

The independent

Not everyone is trying to join a team. A substantial number of graduates now work for themselves — advising organisations too small to justify a full-time security hire, or founding companies of their own. For a mid-career professional with an established network, the demand is real and your existing contacts are your first clients.

Typically leads toFreelance consulting and advisory practice, partnership in a specialist consultancy, or your own firm

Not pivoting at all

Depth in the seat you already occupy

Legal, compliance, procurement, internal audit, privacy, risk or operations — and cybersecurity has arrived in your remit whether or not anyone formally put it there. You are signing off on risks you can describe but not evaluate.

Typically leads toDoing your existing job properly — challenging a control claim rather than accepting it, and sitting in a technical review as a participant rather than a spectator

All of these sit in the same cohort, and that turns out to be a feature rather than a compromise. The career-changers get a working view of how legal, procurement and risk actually see security. The technologists get twelve weeks of business context they would otherwise absorb by accident over years. The lawyers and procurement leads get the technical foundation. Each group teaches the others something the syllabus cannot.

At a glance

Built for people with jobs and families.

It runs alongside your working life rather than instead of it.

Duration
Twelve weeks, cohort-based. Several cohorts run each year.
Weekly commitment
One to two hours of on-demand video in your own time, plus optional reading, surveys and case studies.
Live sessions / seminars
Saturdays, 9:30–11:30am CET / 4:30–6:30pm Manila time, online — discussion, demonstrations and case studies with industry experts.
Where you join from
The Saturday slot is deliberately workable from both Europe and Asia — mid-morning in Brussels, late afternoon in Manila. Everything else is on-demand, so the rest of your week runs in your own time zone.
Method
Flipped classroom. You arrive having watched and read; the live hours are spent using the material, not receiving it.
Assessment
A fifteen-minute knowledge test at the end of each module, and a one-hour final test taken live. Pass everything and you receive a CWF certificate of completion.
Prerequisites
No IT or technical background is required — and if you already have one, the course supplies the governance, risk and human layers around it. English at roughly B2 reading and B1 speaking. A laptop, a stable connection, and willingness to be a beginner again for twelve weeks.
Investment
€1,845 excluding VAT. What VAT applies depends on where you are based and whether you are invoiced personally or through an employer — we will confirm before you pay. One-to-one career transition mentoring can be added at a combined rate — ask us.

From a graduate

“… The instructors are not just experts in the field, but active in it as well. Their real-world insights provide invaluable context to the theoretical knowledge being taught.

CWF's FoS track not only equipped me with the required technical basis but empowered me to transition with confidence by also encouraging me to leverage my skills and expertise from my previous career.”

Information security analyst, 2022 cohort

The nine domains

The full common body of knowledge.

By the end you will have been through all of it.

01Introduction to CybersecurityThe shape of the whole field, the threat landscape, and the vocabulary everything else is built on
02Security Operations and AdministrationAssets, controls, change and patch management, monitoring, vulnerabilities
03Access ControlAuthentication, authorisation, privilege, Zero Trust
04CryptographyKeys, PKI, signatures, hashing — from the basics, without assumed mathematics
05Network and Communication SecurityProtocols, layered defence, segmentation, firewalls, network-based threats
06Application and Systems SecuritySecure development, security by design, the OWASP Top 10, supply chain risk
07Security Governance, Risk and ComplianceThe domain where your existing experience pays out fastest
08Incident Response, Business Continuity and Disaster RecoveryDetection, containment, recovery, and keeping the organisation running through it
09Human Risk ManagementSecurity culture and behaviour, social engineering, phishing, cyber trauma

What this prepares you to do

Across a decade of cohorts, graduates have left in very different directions.

Some built their own practice. Some now lead security functions. Some went deep into a single domain. Others stayed exactly where they were and do that job with an authority they did not have before.

Working for yourself

  • Independent consulting and advisory practice — advising organisations too small to justify a full-time security function, or taking contract and interim work
  • Partnership in a specialist consultancy, or founding a company of your own. Several graduates have done both

Leading and connecting

  • Security leadership — heading a function, owning a domain, or running a programme, including at genuine scale
  • Security governance and strategy — policy, standards and the risk framework
  • Risk, resilience and crisis management — being the person trusted to run the room when something has actually gone wrong
  • The translation layer — regulatory engagement and board reporting, where a long prior career pays the largest dividend

Going deep in a domain

  • Governance, risk and compliance — where prior business experience converts fastest
  • Third-party and supply chain risk — where procurement and commercial experience is a direct asset
  • Security operations and threat intelligence
  • Identity and access management, and Zero Trust programmes
  • Application and product security, DevSecOps and security engineering
  • Security awareness and human risk — a natural fit for people arriving from HR, communications or education

And where that work happens

Graduates are working in the places where the consequences of getting security wrong are real:

National cybersecurity agencies and cyber defence Government, public administration and regulators Financial market infrastructure and banking Insurance and financial services Energy, utilities and industrial control systems Global consultancies and professional services Technology, fintech and healthcare Their own founded ventures

Who teaches it

The course is not handed to associates.

Foundation of Security is taught by CyberWayFinder's three co-founders, personally, alongside a network of senior practitioners currently working in the field.

Rosanna Kurrer

Co-founder

Born in the Philippines, she studied architecture at Kyoto University and practised as an architect before moving to Europe — and the underlying discipline turned out to be the same one: understanding how a complex structure holds together and what happens when one element fails. She now secures critical national infrastructure across Europe, including financial services and electricity producers, and has trained European Commissioners and Commission staff. Award-winner in the Belgian technology sector; speaker at RSA Conference and repeatedly at COSAC.

Marie Vinck

Co-founder

Marie has seen cybersecurity from both sides of the table. As former Senior Director of Cybersecurity at EY she worked at the consultancy end — how security is assessed, benchmarked and argued for. She is now a practising CISO at Circle K, across many countries and thousands of sites: accountable, distributed, commercially constrained and permanently in contact with reality. She answers the question participants most want settled — not what the framework says, but what happens when you try to apply it against a real budget and real resistance.

K. Patrick Wheeler, P.E.

Co-founder

Chief Security Architect for AI and Data Security at BNP Paribas Fortis, after seven years as Chief Security Architect for Payments and Anti-Fraud at the same institution. Earlier, as Chief Security Officer of a bank, he defended the full European attack surface through a multi-month nation-state cyberattack with no loss of service and no loss of data. A Registered Professional Engineer, recipient of the ISC² Senior Information Security Professional of the Year award, and a guest lecturer at Solvay, the LSE, Namur and Tilburg.

Alongside the founders, live sessions bring in senior security professionals working in major enterprises across sectors — so the people you learn from are currently doing the work you are moving towards.

The next step

Come to the orientation before you decide anything.

Ninety minutes, online, free.

  • What the twelve weeks actually demand, week by week
  • Which of the six ways into cybersecurity you fit, and what that usually leads to
  • A walk through the nine domains and the assessment
  • Live Q&A with the founders — including the awkward questions
  • A straight answer about whether this is right for your situation

Saturday
7 November

9:30–11:00am CET
4:30–6:00pm Manila time

Online. Free to attend. No obligation to register for the course.

Save my place
  • 7 NovOnline orientation
  • 23 JanCohort starts
  • AprFinal test and CWF certificate

This is work that matters — and it is open to you.

It defends the organisation that employs you, and in aggregate it defends the country you live in. Very few mid-career moves offer that, and fewer still are genuinely open to professionals from different backgrounds and diverse transferable skills. This one has been for over ten years — and every person now working in cyber because of it arrived, like you, from another field.